![SafeNet Luna SA Скачать руководство пользователя страница 105](http://html1.mh-extra.com/html/safenet/luna-sa/luna-sa_configuration-manual_798623105.webp)
CHAPTER 7 Prepare the Client for Network Trust Link
Register the Client Certificate to an HSM Server
The client certificate, which has been securely transferred (scp’d) from the client to the HSM Server, in previous
sections, must be registered by the HSM Server.
You must be connected to the HSM Server and logged in as “admin”.
The basic command is:
lunash:> client register -client <client’s-name>
-hostname <client’s-hostname>
The <client’s-name>, above can be any string that allows you to easily identify this client - many people use the
hostname, but the <client's-name> can be any string that you find convenient. This might sound a little redundant
(naming the client twice in one command), but it becomes especially useful if you are not using DNS -in that case, a
well-considered <client's-name> is likely going to be easier to remember or recognize ( more meaningful ) than would
the client's ip-address.
The command is expecting to find (on the Luna SA appliance) a client certificate filename that matches the client’s
hostname (or ip-address if you are not using DNS hostnames), as you provide it here. In other words, this is a check
that you are registering the client whose .pem file you created in the previous steps and scp'd to the appliance. You can
register several clients to the appliance.
Example – lunash client registerClient Command
lunash:> client register -client MyClient -hostname MyClient
Client registration successful.
lunash:> client list
registered client 1: MyClient
lunash:>
Note:
If you are working without DNS, then register the client by its IP address, rather than its
hostname.
lunash:> client register -client <client’s-name> -ip <clientIPaddress>
The foregoing is sufficient for "real" (non-VM) clients. See below if your client is a virtual-machine instance.
The Client is now registered with the Luna SA.
You can verify on the Luna SA, with the
client list
command.
Refer to the Reference section of this Help for command syntax and descriptions.
Note: De-Register (registration not complete)
If you have multiple HSM appliances connected and registered with a client and you de-register
that client from one of the HSM appliances, then you must also de-register that HSM appliance
on the client side.
Failure to do so will result in a “Broken pipe” error, which indicates an incomplete registration.
Luna SA Configuration Guide
Release 5.4.1 007-011136-007 Rev C July 2014 Copyright 2014 SafeNet, Inc. All rights reserved.
105
Содержание Luna SA
Страница 1: ...Luna SA Configuration Guide ...