●
Configuration Procedure
Audit log transmission
Perform the following settings with the ETERNUS DX Disk storage system:
•
Audit log setup
Use ETERNUS Web GUI to specify the message format of audit logs that are sent and specify the domain
name or the IP address for the Syslog server that receives these logs.
For details on the settings for a Syslog server that receives audit logs, refer to the manuals of the Syslog
management software.
Key management server linkage
•
Settings for the ETERNUS DX Disk storage system
Register the following information with ETERNUS Web GUI.
-
SED authentication key registration
Register the key that is managed in the ETERNUS DX Disk storage system (common key).
-
Self-signed SSL certificate creation
Create a self-signed SSL certificate as the SSL certificate of the ETERNUS DX Disk storage system to estab-
lish communication between the ETERNUS DX Disk storage system and the key server.
-
Key management device name setup
Specify the name (machine ID) of the ETERNUS DX Disk storage system that is used for key management.
-
Key server setup
Specify the FQDN or the IP address of the key server that is linked.
-
Key group creation
Create a key group to register the RAID groups that use the same key.
-
SSL/KMIP server certificate import
Register the SSL/KMIP server-side certificate that is exported from the key server in the ETERNUS DX Disk
storage system.
-
SED authentication key update
Obtain the key that is set to the key group from the server.
-
Creating the key group
Register the RAID groups that use the same key in the key group.
•
Settings for ETERNUS SF KM
Register the following information in the key server (ETERNUS SF KM):
-
SSL certification registration
Perform the setting to use the self-signed SSL certificate of the ETERNUS DX Disk storage system in order
to provide the key.
-
Network setting
Add the IP address and the host name of the ETERNUS DX Disk storage system in the hosts file.
-
Specifying the ETERNUS DX Disk storage system that is the target for management
Specify the group name that is registered in the ETERNUS DX Disk storage system and the name (ma-
chine ID) of the ETERNUS DX Disk storage system that is set for key management.
Chapter 11 Solution Configuration
11.5 Security
185
FUJITSU Storage ETERNUS DX100 S3/DX200 S3 Disk storage system Configuration Guide (Basic)
Copyright 2014 FUJITSU LIMITED
P3AM-7652-02ENZ0
Содержание ETERNUS DX100 S3
Страница 2: ...This page is intentionally left blank ...
Страница 188: ......