Chapter 1 System Management
1.11 Key Management
ETERNUS Web GUI User’s Guide (Settings)
Copyright 2015 FUJITSU LIMITED
P2X0-1270-13ENZ0
178
1.11.9
Import SSL/KMIP Certificate
This function registers the SSL/KMIP certificate in the ETERNUS DX S3 series. The SSL/KMIP certificate is used
for communication with the key server.
When performing management of the key in the key server, communication between the key server and the
ETERNUS DX100 S3/DX200 S3, the ETERNUS DX500 S3/DX600 S3, or ETERNUS DX8700 S3/DX8900 S3 is
required. To establish communication, register the "SSL/KMIP certificate" (a trusted certificate of the key
server) in the ETERNUS DX S3 series.
For details on the parameters for this function, refer to
"A.1.10.7 Import SSL/KMIP Certificate" (page 760)
The procedure to register the SSL/KMIP certificate is as follows:
Procedure
1
Click [Import SSL/KMIP Certificate] in [Action].
The SSL/KMIP certificate cannot be registered when a common key (*1) is not specified. Refer to
Register SED Authentication Key" (page 47)
for details.
*1: The common key for SEDs that are managed in the ETERNUS DX S3 series.
•
Export the SSL/KMIP certificate from the key server and register this certificate in the ETERNUS DX S3
series.
•
To establish communication between the key server and the ETERNUS DX S3 series, the SSL certificate of
the storage system is also required. Refer to
"1.8.15 Create Self-signed SSL Certificate" (page 135)
"1.8.16 Create Key/CSR" (page 137)
for details.
•
The SSL / KMIP certificate can be registered even when the key server is not specified.
•
The SSL / KMIP certificate can be registered even when the key group is not created.
Summary of Contents for Eternus DX200F
Page 2: ...This page is intentionally left blank ...
Page 1082: ......