Install and configure Entrust Cryptographic Security Platform Key Management Vault

Upload the Key Management Vault ISO in AHV

For reference, see the following Nutanix online documentation:

  1. Log in to the Nutanix Prism Central web UI.

  2. Select Prism Center > Infrastructure > Compute > Images.

  3. Select Add Image.

  4. Under Image Source, ensure the Image File radio button is selected and then select Add File.

  5. Locate and add the Entrust ISO file.

  6. Enter a Name, select the Image Type, and enter a Description, then select Next.

    add image 1
  7. On the next screen, leave the default values selected.

    add image 2
  8. Select Save. The operation may take close to a minute to complete.

Deploy a Key Management Vault node on AHV

For more information, refer to VM Management in the Nutanix online documentation.

  1. Log in to the Nutanix Prism Central web UI.

  2. Select Prism Center > Infrastructure > Compute > VM.

  3. Select Create VM.

  4. Complete the Create VM dialog as follows, then select Next:

    1. Name: Enter a name for the vault, for example, "entrust-csp-vault-1".

    2. Description: If required, add a description for the VM. This field is optional.

    3. Project: Leave the default value

    4. Cluster: Leave the default value

    5. Number of VMs: 1

    6. VM Properties: 4 CPUs, 2 Cores, 8 GB RAM

      create vm
  5. Attach the CD-ROM: Under Disks, select Attach Disk.

  6. Complete the Attach Disk window as follows, then select Save:

    1. Type: Select CD-ROM.

    2. Operation: Select Clone from Image

    3. Image: Select the image you created earlier.

    4. Bus Type: Select SATA.

    5. Leave the other fields set to the default values.

      select image
  7. Attach another Disk: Under Disks, select Attach Disk.

  8. Complete the Attach Disk window as follows, then select Save.

    1. Type: Select Disk.

    2. Operation: Select Allocate on Storage Container.

    3. Capacity: 80 GB.

      For the Compliance Manager VM, the minimum requirement is 250 GB.
    4. Bus Type: Select SATA.

    5. Leave the other fields set to the default values.

      add disk
  9. Attach a Subnet: Under Network, select Attach to Subnet.

  10. Complete the Attach to subnet window as follows, then select Save:

    1. Subnet: Select the Subnet.

    2. Assignment Type: Select Assign Static IP.

    3. IP Address: Enter the IP address.

    4. Leave the other fields set to the default values.

      add nic
  11. In the Boot Configuration, select Legacy BIOS, then select Next.

  12. Set the Timezone, then select Next.

  13. Select Create VM.

    You can track the progress of the VM creation process:

    watch progress
  14. Repeat all steps to create a second Entrust Key Management Vault node and a Compliance Manager node.

Initial Configuration of Entrust Key Management Vault and Compliance Manager Nodes

Perform the following steps for each of the VMs you have created:

  1. Log in to the Nutanix Prism Central web UI.

  2. Select Prism Center > Infrastructure > Compute > VM.

  3. Search for and select the required VM.

    vm listed
  4. Under Power Operations, select Power On.

  5. Select Launch Console.

  6. After the installer finishes, when prompted for a password for the htadmin account, set the password and select OK.

    htadmin password
  7. Enter the network information.

    network info
  8. Verify the network information and select Yes.

  9. Select OK once setup is complete.

  10. In a browser, go to the URL (https://Node IP address) and log in with the default secroot credentials.

    The default secroot password is secroot.

  11. Accept the license agreement.

  12. Select Continue as a Standalone Node.

  13. Enter a new password for the secroot user and select Update Password.

  14. Configure the email settings then select Continue.

  15. Select Download and save the admin key.

  16. Select Continue.

Configure the Compliance Manager node

Configure the Compliance Manager to establish an initial Appliance Cluster connection with the first Key Management Vault node. For more information, refer to Creating an Appliance Cluster Connection.

Join the two Key Management Vault nodes to form a cluster

Join the two Key Management Vault nodes in a high-availability cluster following the instructions in Installing an Additional CSP Vault Cluster Node on a VM from an ISO Image.

Create a KMIP Key Management Vault

  1. Sign in to the KeyControl Appliance Manager.

  2. If it loads in the Appliance Management view, select SWITCH TO: Manage Vaults in the toolbar at the top of the window.

  3. On the Vault Management home page, select Create Vault. The Create Vault dialog appears.

  4. Complete the Create Vault dialog as follows, then select Create Vault:

    1. Type: Select KMIP.

    2. Name: Enter a name for the vault.

    3. Description: Enter a description.

    4. Email Notifications: Leave it Off unless you configured email when you set up the CSP Vault node.

    5. Administrator: Enter Administrator.

    6. Admin Email: Enter your company email.

      create vault
  5. Bookmark the URL and save the credentials displayed in the confirmation dialog.

    csp vault created
  6. In a web browser, navigate to the vault URL.

Sign in to the Vault with the user name and the temporary password that you saved in the previous step.

+ The user name should be the email address that you specified when you created the vault.

  1. Change the initial password when prompted.

  2. Sign in again to verify the new credentials.

    vault homepage