⢠éŖčÆęå”åØåØē½ē»äøęÆå¦åÆēØļ¼å¹¶äøé
置为äøčÆ„ē£åø¦åŗäøčµ·ä½æēØć ęå
³é
ē½®ęå”åØä»„äøčÆ„ē£åø¦åŗäøčµ·ä½æēØ
ēäæ”ęÆļ¼čÆ·åé
ęå”åØę攣ć
注: å¦ęč®”åä½æēØ IBM Security Key Lifecycle Manager (SKLM)ļ¼čÆ·č½¬č³ ē¬¬ xxvii 锵ēćēøå
³åŗēē©ć 仄č·
åęå
³č®¾ē½®åé
ē½®ēäæ”ęÆć
⢠å¦ęå·²ęø
é¤å¹¶éę°é
ē½®āē£åø¦åŗå åÆā设置ļ¼ęØéč¦åØä½æēØē£åø¦åŗčŖē¾åčÆä¹¦ę¶åØęå”åØäøę„åę°čÆä¹¦ć
åÆé„ē®”ēäŗęä½ę§åč®® (KMIP) å åÆ
1. åØęä½čåäøļ¼åå»ē®”ē KMIP å åÆä»„åÆåØå导ć
2. é»č¾ē£åø¦åŗéę©å±å¹ę¾ē¤ŗ KMIP é
ē½®é锹ļ¼åÆä»„å°čæäŗé锹设置为ęęé»č¾ē£åø¦åŗēē¼ŗēå¼ļ¼ä¹åÆä»„设置
äøŗęÆäøŖé»č¾ē£åø¦åŗēē¼ŗēå¼ć 第äŗéØåęä¾äŗé锹ļ¼åÆå° KMIP é
置设置å¤å¶å°ęęé»č¾ē£åø¦åŗļ¼ē¼ŗē
å¼ļ¼ęęå®ēé»č¾ē£åø¦åŗć
3. Wizard Information å±å¹ę¾ē¤ŗå
³äŗå导ēäæ”ęÆć åØčÆ„å±å¹äøļ¼čæåÆä»„éē½®å åÆč®¾ē½®ć å¦ęē£åø¦åŗé
ē½®å®
ęļ¼äø KMIP ęå”åØåØē½ē»äøåÆēØļ¼čÆ·åå» Nextć
4. Certiī“cate Option å±å¹ę¾ē¤ŗäøäŗäøåēčÆä¹¦é锹ļ¼čæäŗé锹åÆä»„ēØę„建ē«äø KMIP ęå”åØēå®å
Øéäæ”ć
åÆä»ä»„äøé锹äøéę©ļ¼
⢠Library Self-Signed Certiī“cateļ¼ē¼ŗēé锹ļ¼- 使ēØē±ē£åø¦åŗēęēčŖē¾åčÆä¹¦ć
⢠Uploaded Certiī“cate - äøč½½äøäøŖå
å«čÆä¹¦å对åŗåÆé„ē PCKS #12 ęä»¶ć
⢠Generate Certiī“cate Request (CSR) - ē±ē£åø¦åŗēęäøåæ
é”»ē± CA ęå”åØē¾åē CSRć 评ę¹ę³éč¦åæ
é”»åØę§č”å导ę„éŖ¤ęé“ęä¾ē CA čÆä¹¦ć
a. Certiī“cation Conī“guration
ā Library Self-Signed Certiī“cate - č·³č³äøäøę„ć
ā Uploaded Certiī“cate
i) åØ Certiī“cate Option å±å¹äøēčÆä¹¦åŗåäøäøč½½ PKCS #12 ęä»¶ć
ii) å¦ę评ęä»¶éč¦åÆē ļ¼åæ
é”»åØ Certiī“cate Password č¾å
„åꮵäøęä¾ć å¦ęę²”ęåÆē ļ¼čÆ„å
ꮵåÆä»„ē空ć
iii) ęåäøč½½čÆä¹¦åļ¼åå» Nextć
ā Generate Certiī“cate Request (CSR)
i) Certiī“cate Authority Information å±å¹ę¾ē¤ŗä½æēØ KMIP čÆä¹¦ēå
å³ę”ä»¶ć 滔足å
å³ę”ä»¶åļ¼
åå» Nextć
ii) Certiī“cate Authority Certiī“cate Entry å±å¹ę¾ē¤ŗč·å KMIP ęå”åØē CA čÆä¹¦ēę示俔ęÆć
éµå¾Ŗčæäŗę示俔ęÆļ¼ä»„ä»ē®”ēę§å¶å°å¤å¶ CA čÆä¹¦ć å°čÆ„ CA čÆä¹¦ē²č““å°å导äøļ¼ē¶ååå»
Nextć
iii) Library Certiī“cate Information å±å¹ę¾ē¤ŗå
³äŗåē»å导ę„éŖ¤ēäæ”ęÆć åå»äøäøę„ć
b. KMIP Client Conī“guration å±å¹äøŗäø¤ē§ē±»åēęå”åØč®¤čÆęä¾äŗé锹ć
ā å¦ę KMIP ęå”åØä½æēØå®¢ę·ęŗēØę·åååÆē čæč”认čÆļ¼čÆ·č¾å
„åØē£åø¦åŗē KMIP ē®”ēę§å¶å°äøę
å®ēēØę·åååÆē ć
ā å¦ę KMIP ęå”åØä½æēØčÆä¹¦éŖčÆčæč”认čÆļ¼čÆ·éę©ä»
åÆēØ KMIP čÆä¹¦č®¤čÆć å¦ęęØä½æēØäøęÆę客
ę·ęŗēØę·åååÆē ē KMIP ęå”åØļ¼čÆ·éę©ę¤é锹ć å½ KMIP äø IBM Security Key Lifecycle
Manager é
å使ēØę¶ļ¼å°ä½æēØę¤ē¼ŗēę¹ę³ć
i) åØ KMIP ęå”åØé
ē½®å±å¹äøļ¼č¾å
„ęå¤ 10 äøŖ KMIP ęå”åØē IP å°åęę åäø»ęŗåå端å£å·ć
ę¤å¤ļ¼éę©äøŗå åÆåÆé„ęä¾ęå”ēåÆé„ęå”åØē±»åć åÆä»ä»„äøé锹äøéę©ļ¼
- IBM SKLM - IBM Security Lifecycle Manager 2.6.0 ęę“é«ēę¬ KMIP ęå”åØć
- KMIP å
¼å®¹ - ęÆę OASIS ę ååÆé„ē®”ēäŗęä½ę§åč®® (KMIP) ēåÆé„ęå”åØć
ii) č¦éŖčÆåƹ KMIP ęå”åØē访é®ę
åµļ¼čÆ·åå» Connectivity Checkć
iii) åØ KMIP ęå”åØē«Æę£ę„ęå”åØęÆå¦ę„åē£åø¦åŗēčÆä¹¦ć
IBM Conī“dential
82ī¦ī¦IBM TS4300 Tape Library ęŗåØē±»å 3555ļ¼ ēØę·ęå