data:image/s3,"s3://crabby-images/9133f/9133fc94ede046923e5d45532576a548e3af6089" alt="Quasonix RDMS Installation And Operation Manual Download Page 125"
3
rd
Generation Rack-
Mount RDMS™
105
Quasonix, Inc.
b.
When prompted, provide the Country, State, Locality, Organization, Organizational Unit, Common
Name, and Email Address for the RDMS Server Certificate. Common Name is required and must be
either the DNS name of the server or its IP address.
4.4.2.27.3.1.1.4 Sign Server Certificate
If you have created a Certificate Authority above, use it to sign the server certificate. Otherwise, present your CSR
to your authority to create a signed certificate for the RDMS.
1.
Create a Signed Server Certificate
a.
openssl ca -config openssl.cnf -extensions server_cert -days 375 -notext -md sha256 -in
csr/rdms1.csr.pem -out certs/rdms1.cert.pem
b.
Enter the CA password created above
c.
The contents of the newly signed certificate are displayed.
d.
When prompted, answer ‘y’ to two questions “Sign the certificate?” and “1 out of 1 certificate requests
certified, commit?”
4.4.2.27.3.1.1.5 Upload Certificate and Private Key to RDMS
4.4.2.27.3.1.1.5.1 Admin User
A
user named ‘admin’ is provided to allow for uploading of the certificate and private key to the RDMS. This user
has very restricted capability and is limited to uploading files and changing its password.
The default password for the user ‘admin’ is QRSAtM
C3L53HXLgtx.
The password should be changed by the user, but understand that there is currently no way to reset or
retrieve the password if it is forgotten. Be sure to record the password in some fashion and keep it protected.
In order to change the admin password, first ssh to the RDMS server using
•
ssh admin@IP
where IP is the IP address of the RDMS
When connected, use the following command to change the password:
•
passwd
When prompted, provide the current password, then the desired new password.
Type ‘exit’ to exit the ssh session.
4.4.2.27.3.1.1.5.2 Uploading Files to RDMS
In order to upload the Server Certificate and Private Key, use the scp utility.
First change the certificate file name (certs/rdms1.cert.pem above) to user.cert.pem and the key file name
(private/rdms1.key.pem above) to user.key.pem. Note that the file names cannot be changed via the scp utility and
only one file can be sent at a time
. ‘IP’ is the IP address of the RDMS.
1.
scp certs/user.cert.pem admin@IP:~/
2.
scp private/user.key.pem admin@IP:~/
4.4.2.27.3.1.1.5.3 Enable User Certificate
After the certificate and key files have been uploaded to the RDMS, they must be latched into place and utilized by
the server.