Brocade Fabric OS Encryption Administrator's Guide v6.3.0 (53-1001341-02, July 2009)

220 Encryption Administrator’s Guide
53-1001341-02
The HP Secure Key Manager
D
Importing a signed certificate
After a signed certificate is obtained, it must be imported and registered.
1. Select a switch from the Encryption Targets dialog box, and click the Properties tab.
FIGURE 76 Switch Properties dialog box
2. Click the Import button.
The Import Signed Certificate dialog box displays.
FIGURE 77 Import Signed Certificate dialog box
3. Browse to the location of the stored, signed certificate, and click OK.
A connection is now established between the switch and the HP Secure Key Manager (SKM).
4. Register the SKM key vault on the group leader using the CA certificate for the CA that signed
the SKM key vault certificate. The group leader automatically shares this information with
other group members.
SecurityAdmin:switch>cryptocfg --import -scp <CA certificate file>
<host IP> <host username> <host path>
SecurityAdmin:switch>cryptocfg --reg -keyvault <CA certificate file>
<RKM IP> primary
5. Display the group configuration, using the cryptocfg - - show -groupcfg command.