Integrate KeyControl with StoreEver
Follow these steps to register Entrust KeyControl as a KMS in HPE StoreEver Tape Library.
Obtain the CA certificate
The Entrust KeyControl KMIP server can accept a certificate from your local root CA or a trusted CA, or can act as local root CA itself. For the purpose of this integration the Entrust KeyControl KMIP server will act as the local root CA. Execute the following steps to obtain the local root CA certificate for the Entrust KeyControl KMIP server.
-
Sign in to the KMIP Vault with the URL and credentials from Create a KMIP Vault in the Entrust KeyControl.
-
Go to the Vault Management window by selecting SWITCH TO Manage Vaults / SWITCH TO Appliance Management in the top right corner of the window.
-
Select the ? icon in the top right corner of the window, then select Download CA certificate.
-
Save the certificate for later use. Example filename:
240614140352_cacert.pem
.
Configure the KMIP server
-
Log into the StoreEver webGUI using an account with Security Admin privileges.
-
Select the Configuration box.
-
Expand the Encryption menu in the right toolbar, then select KMIP Wizard.
-
Select Clear All Wizard Settings to remove any prior configuration.
-
Select Next twice.
-
In the Certificate Authority Certificate Entry window, copy-paste the certificate from section Obtain the CA certificate into the Certificate Authority (CA): text box, then select Next.
-
Select Next twice.
-
In the KMIP Client Configuration Window, check Enable KMIP Certificate-only authentication, then select Next.
-
In the Certificate Generation window, select the Generate New Certificate radio button.
-
When certificate request has been generated, copy the certificate request to a file, for example,
hpe-storeever-3040.csr
, then select Next. -
Pause configuring the KMIP server. You will continue further down.
Create the client certificate bundle
-
Sign in to the KMIP Vault with the URL and credentials from section Create a KMIP Vault in the Entrust KeyControl.
-
Select Security, then Client Certificates.
-
In the Manage Client Certificate page, select the + icon on the right to create a new certificate. The Create Client Certificate dialog box appears.
-
In the Create Client Certificate dialog box:
-
Enter the Certificate Name.
-
Select the Certificate Expiration.
-
Upload the certificate request created in section Configure the KMIP server.
-
Select Create.
For example:
The new certificates are added to the Manage Client Certificate pane.
-
-
Select the certificate and select the Download icon to download the certificate.
-
Unzip the downloaded file. It contains the following:
-
A
certname.pem
file that includes both the client certificate and private key. In this example, this file is calledHPEStoreEver3040.pem
.The client certificate section of the
certname.pem
file includes the lines -----BEGIN CERTIFICATE----- and -----END CERTIFICATE----- and all text between them.The private key section of the
certname.pem
file includes the lines -----BEGIN PRIVATE KEY----- and -----END PRIVATE KEY----- and all text in between them. -
A
cacert.pem
file which is the root certificate for the KMS cluster. It is always namedcacert.pem
.
-
See the following link for additional information Managing KMIP Objects in the KeyControl KMIP Vault webGUI.
Import tenant client certificate into the StoreEver Tape Library
This resumes section Configure the KMIP server.
-
In the Certificate Generation window, select the Keep Current Certificate radio button this time.
-
In the Signed Library Certificate, paste the certificate created in section Create the client certificate bundle, then select Next.
File
HPEStoreEver3040.pem
contains the certificate. -
In the KMIP Server Configuration window, enter the IP of the Entrust KeyControl KMIP server nodes. Select Connectivity Check to test connectivity to the nodes, it should check OK, then select Next
-
In the Setup Summary windows, select Finish, then select Exit.
Set the default encryption mode
-
Log into the StoreEver webGUI using an account with Security Admin privileges.
-
In the Set Default Encryption for new Partitions section, select KMIP (Licensed) from the pull-down menu.
-
Select Apply to all existing partitions. Notice the change in Set Encryption Mode per Partitions.
-
Select Submit.