Brocade Fabric OS Encryption Administrator’s Guide Supporting HP Secure Key Manager (SKM) and HP Enterprise Secure Key Manager (ESKM) Environments (Supporting Fabric OS v7.2.0) User Manual

Page 167

Advertising
background image

Fabric OS Encryption Administrator’s Guide (SKM/ESKM)

147

53-1002923-01

Steps for connecting to an SKM or ESKM appliance

3

Server SDK Version: 4.8.1

Encryption Node (Key Vault Client) Information:

Node KAC Certificate Validity: Yes

Time of Day on the Switch: 2010-03-17 17:22:05

Client SDK Version: 4.8.2.000017

Client Username: brcduser1

Client Usergroup: brocade

Connection Timeout: 10 seconds

Response Timeout: 10 seconds

Connection Idle Timeout: N/A

Key Vault configuration and connectivity checks successful, ready for key

operations.

Authentication Quorum Size: 0

Authentication Cards:

Certificate ID / label : qc.4250420d02048578 /

sumita:gorla:qc.4250420d02048578

Certificate ID / label : qc.4250420d02047881 /

sumita:gorla:qc.4250420d02047881

NODE LIST

Total Number of defined nodes: 2

Group Leader Node Name: 10:00:00:05:1e:53:8a:67

Encryption Group state: CLUSTER_STATE_CONVERGED

Node Name IP address Role

10:00:00:05:1e:53:8a:83 10.32.71.127 MemberNode (current node)

EE Slot: 0

SP state: Online

10:00:00:05:1e:53:8a:67 10.32.71.129 GroupLeader

EE Slot: 0

SP state: Online

Registering the SKM/ESKM Brocade group user name and password

The Brocade group user name and password you created when configuring a Brocade group on the
SKM/ESKM must also be registered on each Brocade encryption node.

1. Log in to the switch as Admin or SecurityAdmin.

2. Register the HP SKM/ESKM Brocade group user password and user name by issuing the

following command.

SecurityAdmin:switch> cryptocfg --reg -KAClogin primary

NOTE

This command is must be used only for the primary key vault.

3. When prompted, enter the user name.

4. When prompted enter and confirm the password.

5. Repeat the procedure for each node.

Keep the following rules in mind when registering the Brocade user name and password:

Advertising