544
Brocade Network Advisor SAN User Manual
53-1002696-01
Steps for connecting to a DPM appliance
20
Steps for connecting to a DPM appliance
All switches that you plan to include in an encryption group must have a secure connection to the
RSA Data Protection Manager (DPM). The following is a suggested order of steps needed to create
a secure connection to the DPM.
NOTE
The Fabric OS encryption switch uses the manual enrollment of identities with client registration to
connect with DPM 3.x servers. Client registration is done automatically when you upgrade to
Fabric OS 7.1.0 from an earlier version; no user interaction is required.
Once completed, client registration occurs after key vault registration, when the Fabric OS
encryption switch attempts to connect to the DPM server for the first time.
1. Export the KAC CSR to a location accessible to a CA for signing. Refer to
“Exporting the KAC
certificate signing request (CSR)”
on page 544.
2. Submit the KAC CSR for signing by a CA. Refer to
“Submitting the CSR to a certificate authority”
on page 545.
3. Set the KAC certificate registration expiry. Refer to
“KAC certificate registration expiry”
on
page 545.
4. Import the signed certificate into the Fabric OS encryption node. Refer to
“Importing the signed
KAC certificate”
on page 546.
5. Upload the signed KAC and CA certificates onto the DPM appliance and select the appropriate
key classes. Refer to the following:
•
“Uploading the CA certificate onto the DPM appliance (and first-time configurations)”
on
page 546.
•
“Uploading the KAC certificate onto the DPM appliance (manual identity enrollment)”
on
page 548.
6. If dual DPM appliances are used for high availability, the DPM appliances must be clustered,
and must operate in maximum availability mode, as described in the DPM appliance user
documentation. Refer to
“DPM key vault high availability deployment”
on page 548.
Exporting the KAC certificate signing request (CSR)
1. Export the KAC CSR to a temporary location prior to submitting the KAC CSR to a CA for signing.
2. Synchronize the time on the switch and the key manager appliance. Time settings should be
within one minute of each other. Differences in time can invalidate certificates and cause key
vault operations to fail.
3. Select a switch from the Encryption Center Devices table, then select Switch > Properties from
the menu task bar to display the Properties dialog box.
NOTE
You can also select a switch from the Encryption Center Devices table, then click the
Properties icon.
Summary of Contents for Network Advisor 12.0.0
Page 36: ...xxxvi Brocade Network Advisor SAN User Manual 53 1002696 01...
Page 82: ...34 Brocade Network Advisor SAN User Manual 53 1002696 01 License downgrade 2...
Page 86: ...38 Brocade Network Advisor SAN User Manual 53 1002696 01 Uninstalling a patch 3...
Page 122: ...74 Brocade Network Advisor SAN User Manual 53 1002696 01 VM Manager discovery 4...
Page 184: ...136 Brocade Network Advisor SAN User Manual 53 1002696 01 Fabric tracking 5...
Page 214: ...166 Brocade Network Advisor SAN User Manual 53 1002696 01 User profiles 6...
Page 284: ...236 Brocade Network Advisor SAN User Manual 53 1002696 01 User defined performance monitors 8...
Page 320: ...272 Brocade Network Advisor SAN User Manual 53 1002696 01 Grouping on the topology 9...
Page 434: ...386 Brocade Network Advisor SAN User Manual 53 1002696 01 Port Auto Disable 12...
Page 442: ...394 Brocade Network Advisor SAN User Manual 53 1002696 01 Exporting Host port mapping 13...
Page 450: ...402 Brocade Network Advisor SAN User Manual 53 1002696 01 Exporting storage port mapping 14...
Page 536: ...488 Brocade Network Advisor SAN User Manual 53 1002696 01 Virtual FCoE port configuration 16...
Page 552: ...504 Brocade Network Advisor SAN User Manual 53 1002696 01 Security configuration deployment 17...
Page 878: ...830 Brocade Network Advisor SAN User Manual 53 1002696 01 Removing thresholds 24...
Page 922: ...874 Brocade Network Advisor SAN User Manual 53 1002696 01 VLAN routing 26...
Page 990: ...942 Brocade Network Advisor SAN User Manual 53 1002696 01 SAN Connection utilization 29...
Page 1138: ...1090 Brocade Network Advisor SAN User Manual 53 1002696 01 Call Home Event Tables B...
Page 1144: ...1096 Brocade Network Advisor SAN User Manual 53 1002696 01 IP Performance monitoring events C...
Page 1186: ...1138 Brocade Network Advisor SAN User Manual 53 1002696 01 Regular Expressions F...
Page 1486: ...1438 Brocade Network Advisor SAN User Manual 53 1002696 01 Views H...