KMIP Wizard configuration
1.
In the Actions menu, click Manage Encryption to start the wizard.
2.
The Wizard Information screen displays information about the wizard. On this screen, it is also
possible to clear all the settings that can be done in the wizard. If the library configuration is complete
and the KMIP server is available on the network, click Next.
3.
The Certificate Option screen displays the different certificate options that can be used to establish a
secure communication to the KMIP server. You can select from the following options:
v
Library Self-Signed Certificate
(default option) - A self-signed certificate that is generated by the
library is used.
v
Uploaded Certificate
- Upload a PCKS #12 file that includes a certificate and corresponding key.
v
Generate Certificate Request (CSR)
- A CSR is generated by the library that must be signed by a
CA server. This method requires a CA certificate that must be provided during the wizard steps.
a.
Certification Configuration
– Library Self-Signed Certificate – skip to the next step.
– Uploaded Certificate
1)
Upload the PKCS #12 file in the certificate area on the Certificate Option screen.
2)
If this file requires a password, it must be provided in the Certificate Password input
field. If no password, the field can be left empty.
3)
After successfully upload of the certificate, click Next.
– Generate Certificate Request (CSR)
1)
The Certificate Authority Information screen displays prerequisites for using the KMIP
certificate. When the prerequisites are met, click Next.
2)
The Certificate Authority Certificate Entry screen displays instructions for obtaining the
CA certificate for the KMIP server. Follow the instructions to copy the CA certificate from
the management console. Paste the CA certificate into the wizard and then click Next.
3)
The Library Certificate Information screen displays information about the next wizard
steps. Click Next.
b.
The KMIP Client Configuration screen provides options for two types of server authentication.
– If your KMIP server uses a client user name and password for authentication, enter the user
name and password that were specified on the KMIP management console for the library.
– If your KMIP server uses only certificate validation for authentication, select Enable KMIP
Certificate only
authentication. Select this option only if you are using a KMIP server that
does not support a client user name and password. This default method is used when KMIP
is used with the IBM Security Key Lifecycle Manager.
1)
In the KMIP Server Configuration screen, enter the IP address or fully qualified host
name and port number for up to ten KMIP servers.
2)
To verify access to the KMIP servers, click Connectivity Check.
3)
Check at the KMIP server side that the server accepts the certificate of the library.
4)
The Setup Summary screen displays the settings that are collected by the wizard. Verify
that the settings are correct and that no errors are in the Done column.
- If you need to modify any settings or fix any issues, either click Back to reach the
applicable screen or Cancel to leave the wizard to fix the issues and return later.
- If the settings are correct and no errors are reported, click Finish.
Once the wizard finishes, the Library Managed Encryption (KMIP) encryption mode is selectable in the
Logical Library Wizard (Expert Mode)
on the Library > Logical Libraries page.
Managing
71
Содержание 3555-E3A
Страница 1: ...Dell EMC ML3 Tape Library User s Guide ...
Страница 2: ......
Страница 4: ...iv Dell EMC ML3 Tape Library User s Guide ...
Страница 8: ...viii Dell EMC ML3 Tape Library User s Guide ...
Страница 10: ...x Dell EMC ML3 Tape Library User s Guide ...
Страница 20: ...xx Dell EMC ML3 Tape Library User s Guide ...
Страница 22: ...xxii Dell EMC ML3 Tape Library User s Guide ...
Страница 44: ...22 Dell EMC ML3 Tape Library User s Guide ...
Страница 54: ...32 Dell EMC ML3 Tape Library User s Guide ...
Страница 94: ...72 Dell EMC ML3 Tape Library User s Guide ...
Страница 126: ...104 Dell EMC ML3 Tape Library User s Guide ...
Страница 153: ...Figure 81 Unlocked spooling mechanism enlarged view Upgrading and servicing 131 ...
Страница 164: ...142 Dell EMC ML3 Tape Library User s Guide ...
Страница 174: ...152 Dell EMC ML3 Tape Library User s Guide ...
Страница 176: ...154 Dell EMC ML3 Tape Library User s Guide ...
Страница 195: ...XRA External register address register Glossary 173 ...
Страница 196: ...174 Dell EMC ML3 Tape Library User s Guide ...
Страница 200: ...178 Dell EMC ML3 Tape Library User s Guide ...
Страница 201: ......
Страница 202: ...Printed in USA ...