DD - Vormetric integration.

Summary: Integrating DSM server with DD.

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Instructions

Note: confirm DD system is running following DDOS Version
Data Domain OS
6.2.0.012-629552

Step 1:
Configuring KMIP on the Data Domain system
    Complete the following steps to configure KMIP on the Data Domain system.
    
Procedure
1. Set the
"system passphrase."
A strong passphrase is required in order for the KMIP feature to work and must
contain:
     A minimum of nine characters,
     A minimum of one lowercase character,
     A minimum of one uppercase character,
     A minimum of one digit, and
     A minimum of one special character.

a. In DDSH, run 
    
#system passphrase set.
        Type passphrase: *********
        Re-enter passphrase: *********

Note: 
- A weak passphrase that does not comply with the guidelines will cause the KMIP feature to fail. 
- No spaces are allowed in passphrase.
- If a weak passphrase was previously set, update the system passphrase according to the guidelines previously listed.
- Please save the passphrase in a secure place, if the passphrase is misplaced or forgotten then there is no way to recover the data, the system need to be reimaged at which time all data will be lost.

Step 2:
 Generate the CSR on DDR.

#adminaccess certificate cert-signing-request generate <add parameters>

Step 3:
 Confirm the certificate creation.

#adminaccess certificate show
Subject                              Type            Application   Valid From                 Valid Until                Fingerprint
----------------------------------   -------------   -----------   ------------------------   ------------------------   ------------------------------------------------------------
maaddvor001.ti.census.gov            host            https         Mon Sep  3 02:25:59 2018   Fri Sep  2 09:25:59 2022   ED:2A:29:19:A4:6B:12:FB:BA:1E:F3:B6:96:5B:67:93:C8:51:95:A3
maaddvor001.ti.census.gov            ca              trusted-ca    Mon Sep  3 09:25:59 2018   Sun Sep  1 09:25:59 2024   FD:71:4E:0D:CF:65:F7:68:D5:7D:8B:87:BF:52:34:10:98:FA:E9:73
----------------------------------   -------------   -----------   ------------------------   ------------------------   ------------------------------------------------------------
Certificate signing request (CSR) exists at /ddvar/certificates/CertificateSigningRequest.csr

Step 4:
 Verify the CSR certificate in /ddr/var/certificate
 
 
!!!! maaddvor001 YOUR DATA IS IN DANGER !!!! # ls -l  /ddr/var/certificates
 total 12
 -rw-r--r-- 1 root admin 1501 Oct  7 11:27 -notext
 -rw-r--r-- 1 root admin 1050 Oct  2 12:04 CertificateSigningRequest.csr


Step 5:

Copy the csr certicate and get it signed by KeySecure CA.

Step 6:
Copy the signed cert back to /ddr/var/certificate and verify the copied "crt" certificate

!!!! maaddvor001 YOUR DATA IS IN DANGER !!!! # cd /ddr/var/certificates
!!!! maaddvor001 YOUR DATA IS IN DANGER !!!! # ls

-notext  CertificateSigningRequest.csr  abccdsm01.ti.census.gov.cer  maaddvor001.bdc.ti.census.gov.crt

Step 7:
Run the following command


!!! maaddvor001 YOUR DATA IS IN DANGER !!!! # openssl s_client -connect 10.253.210.7:5696 -showcerts
CONNECTED(00000005)
depth=1 CN = CG CA S on abccdsm01.ti.census.gov, OU = TI, O = U.S. Census Bureau, L = Washington, ST = DC, C = US
verify error:num=19:self signed certificate in certificate chain

---
Certificate chain

 0 s:/CN=abccdsm01.ti.census.gov
   i:/CN=CG CA S on abccdsm01.ti.census.gov/OU=TI/O=U.S. Census Bureau/L=Washington/ST=DC/C=US
-----BEGIN CERTIFICATE-----
MIIDpjCCAo6gAwIBAgIGCBPjOgHiMA0GCSqGSIb3DQEBDAUAMIGGMSswKQYDVQQD
EyJDRyBDQSBTIG9uIGFiY2Nkc20wMS50aS5jZW5zdXMuZ292MQswCQYDVQQLEwJU
STEbMBkGA1UEChMSVS5TLiBDZW5zdXMgQnVyZWF1MRMwEQYDVQQHEwpXYXNoaW5n
dG9uMQswCQYDVQQIEwJEQzELMAkGA1UEBhMCVVMwHhcNMTcxMTAxMTM0NzE0WhcN
MjcxMTAyMTM0NzE0WjAiMSAwHgYDVQQDDBdhYmNjZHNtMDEudGkuY2Vuc3VzLmdv
djCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALBbTjMf7OKQ4jsKZ8f3
SWbduQqmO1mgGSnlf8x4JuVtNVNbUwSexrQf9L+bU8Y1KROjzzz3pKqrQHT2AauJ
eUu16Arbjs4WrYgme/fediWCU3jSNilnNA63uRqsZIiY6l3mHJhApU/n1c2uRVFj
WsP+VKy7+2mT7m/5wrPS8CZbH0zQt14oQP9klp92+X45fuUfAWQWqRbTlLGqEJjA
YM8WS5hv6LR+BJrB04hjfcsxcyCGAzzl/gbA9kxNYyk4RvvrSRLrW+clRNB53TRX
9GDucz/GPnf6WDnj0Yi1cK8LBFXiPTEPl4d8Mpqvjy0zcnVL/imlwiUUwuTdMiva
FUcCAwEAAaN9MHswEwYDVR0lBAwwCgYIKwYBBQUHAwEwDAYDVR0TAQH/BAIwADAO
BgNVHQ8BAf8EBAMCA6gwHQYDVR0OBBYEFD74MtHTq2Bd0lAMhYe8MGliQ8hpMCcG
A1UdIwQgMB6AFJWWUH7Y5MYwFs8BGxcSHCVW50PKggYAs6GOtbowDQYJKoZIhvcN
AQEMBQADggEBAFN6mBFVznpnVINaL1uA/a2iPiVORtAXwwf8/biHOLoDXlrgVkNM
LnUGmE+k2qaX0+ljV9Z5UEsh7doOd8YcGfiOs68hCYqNiT6/AABH2eC1B9oTn5sS
Cg6dbuUJgvQ33k/Bx1CN0qsxak78hNdiXpJ3Qe4QXwRxib9qfOWOYiUCEPZKh6zf
KR46uXHKTjqg6utq0udngrMBGzLYA64VUuYuboQ4TbllbSdq37eqb19UEGtI1Rwp
u2A18gVfA+O5KpHrOpqBb9hU9waULUb0KAgE4mnf6ghD9NGzgijN8K8OjSqhWtiU
jfziDSE3uWGR0hy7pLIL6umIdaXC0Wje+sY=
-----END CERTIFICATE-----
 1 s:/CN=CG CA S on abccdsm01.ti.census.gov/OU=TI/O=U.S. Census Bureau/L=Washington/ST=DC/C=US
   i:/CN=CG CA S on abccdsm01.ti.census.gov/OU=TI/O=U.S. Census Bureau/L=Washington/ST=DC/C=US
-----BEGIN CERTIFICATE-----
MIID/DCCAuSgAwIBAgIGALOhjrW6MA0GCSqGSIb3DQEBDAUAMIGGMSswKQYDVQQD
EyJDRyBDQSBTIG9uIGFiY2Nkc20wMS50aS5jZW5zdXMuZ292MQswCQYDVQQLEwJU
STEbMBkGA1UEChMSVS5TLiBDZW5zdXMgQnVyZWF1MRMwEQYDVQQHEwpXYXNoaW5n
dG9uMQswCQYDVQQIEwJEQzELMAkGA1UEBhMCVVMwHhcNMTcxMTAxMTM0NjM0WhcN
MjcxMTAzMTM0NjM0WjCBhjErMCkGA1UEAxMiQ0cgQ0EgUyBvbiBhYmNjZHNtMDEu
dGkuY2Vuc3VzLmdvdjELMAkGA1UECxMCVEkxGzAZBgNVBAoTElUuUy4gQ2Vuc3Vz
IEJ1cmVhdTETMBEGA1UEBxMKV2FzaGluZ3RvbjELMAkGA1UECBMCREMxCzAJBgNV
BAYTAlVTMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA8I7GB+2X8aFi
6wTyVAuWcrJbCkEqQYRCw7EM4vy1iAANil7o0jAP2kTKMcDEFwA67iB8GrtQYta0
j7HgyOjgTp7O39RfUfxzzVwqGjoqouxltPjFGXX3hkGNu2fvowfgJZRW+xSUOzFV
Qu1jPIoBqlZWptTRXgCtZkfeztShJwH0yGzyxSQvp2TTnuSSQxRBmQonFccYl+Qo
HI5akgfBrdVoklHhsiksbmgy3K/+YXPwI0m59BQ+kofQvX9rvqrgxflgCXnaYWeX
M785ticfWa1qA2ukjbtYij/UQam59SXQJi4j45h+pbOXioo0w0yQfz2gHTO8NZFs
x5JL55+hvwIDAQABo24wbDASBgNVHRMBAf8ECDAGAQH/AgEAMA4GA1UdDwEB/wQE
AwIBBjAdBgNVHQ4EFgQUlZZQftjkxjAWzwEbFxIcJVbnQ8owJwYDVR0jBCAwHoAU
lZZQftjkxjAWzwEbFxIcJVbnQ8qCBgCzoY61ujANBgkqhkiG9w0BAQwFAAOCAQEA
i8HUfFMXpFUYra+v+fPFELeTq/m9RJFavjYUtlApIXPVIIaznmFSiJ51mI/M/HNg
bohaCDme9+kU95eDC/xU0Gkej1c+HNNlMh1gSz3v39xMXmg+6+iDUqKfdSJ8IyaZ
fXqMIJ1waPIE8YADvamZ5d7vNxWBpBORGbvgmiEPJR/R0y6D/Yn/DNyY9RZlWcpr
GB0JcBguI6BoI710KG3Wylf9RR7dwXREtPytWbvkZREuZcijBvchqH5yuOMcRI1Q
8k6JyLslY1H0/pI39Q72FD9Tu3D8OXY1ZzeytN2JgXo9RRPY0MOssyPTPobdE3De
+vFAM1sQX4orZuheXk0ugw==
-----END CERTIFICATE-----
---
Server certificate
subject=/CN=abccdsm01.ti.census.gov
issuer=/CN=CG CA S on abccdsm01.ti.census.gov/OU=TI/O=U.S. Census Bureau/L=Washington/ST=DC/C=US
---
Acceptable client certificate CA names
/CN=CG CA S on abccdsm01.ti.census.gov/OU=TI/O=U.S. Census Bureau/L=Washington/ST=DC/C=US
Client Certificate Types: RSA sign, DSA sign, ECDSA sign
Requested Signature Algorithms: RSA+SHA512:DSA+SHA512:ECDSA+SHA512:RSA+SHA384:DSA+SHA384:ECDSA+SHA384:RSA+SHA256:DSA+SHA256:ECDSA+SHA256:RSA+SHA224:DSA+SHA224:ECDSA+SHA224:RSA+SHA1:DSA+SHA1:ECDSA+SHA1
Shared Requested Signature Algorithms: RSA+SHA512:DSA+SHA512:ECDSA+SHA512:RSA+SHA384:DSA+SHA384:ECDSA+SHA384:RSA+SHA256:DSA+SHA256:ECDSA+SHA256:RSA+SHA224:DSA+SHA224:ECDSA+SHA224:RSA+SHA1:DSA+SHA1:ECDSA+SHA1
Peer signing digest: SHA512
Server Temp Key: ECDH, P-256, 256 bits
---
SSL handshake has read 2800 bytes and written 443 bytes
---
New, TLSv1/SSLv3, Cipher is ECDHE-RSA-AES256-GCM-SHA384
Server public key is 2048 bit
Secure Renegotiation IS supported
Compression: NONE
Expansion: NONE
No ALPN negotiated
SSL-Session:
    Protocol  : TLSv1.2
    Cipher    : ECDHE-RSA-AES256-GCM-SHA384
    Session-ID: 7C5611F5CAE956CE42764385ECB14BC83FCE949BEB86A7FEA10D5C7F7688CE49
    Session-ID-ctx:
    Master-Key: 9B2517ECD3BA62426D44E11289768728219BEE29D9E90466F7A57428814D2112AE80FE9E9C76A70396E62FD7562D7DA4
    Key-Arg   : None
    PSK identity: None
    PSK identity hint: None
    SRP username: None
    TLS session ticket lifetime hint: 300 (seconds)
    TLS session ticket:
    0000 - 44 ab 77 16 fe 1c f4 8b-f7 27 be bf e4 7d 50 c7   D.w......'...}P.
    0010 - b4 d4 e3 7a da 5c 8d b3-18 b3 0d 5f 38 27 68 e1   ...z.\....._8'h.
    0020 - e7 5d a5 b7 f5 f7 8b 2f-4a d9 2a 19 36 8c 4d 98   .]...../J.*.6.M.
    0030 - 4f ff 89 ba 69 e5 01 5d-83 63 85 73 f5 ff 41 c9   O...i..].c.s..A.
    0040 - 60 f4 9a 7b 4c bd 87 23-c8 56 00 d8 ef 68 34 07   `..{L..#.V...h4.
    0050 - 31 c3 71 fc c9 8f 43 06-f1 c9 d0 5d a4 0e 7d 1e   1.q...C....]..}.
    0060 - e8 62 6f 6c 21 39 48 c3-d7 72 d8 58 cf a3 e3 87   .bol!9H..r.X....
    0070 - 6d 3f 93 91 1c 47 cc a8-fb 4b 26 84 ad 9b 1d a2   m?...G...K&.....
    0080 - 30 0b d3 3f 8b 45 a5 fa-1c 8e 24 f3 68 23 b0 2b   0..?.E....$.h#.+
    0090 - cd 02 7a 21 e5 69 e0 07-73 53 2f f6 b9 9e e2 88   ..z!.i..sS/.....

    Start Time: 1570475077
    Timeout   : 300 (sec)
    Verify return code: 19 (self signed certificate in certificate chain)

---
Step: 8

create "cacert.pem" file under /ddr/var/certificate and add the following content from above output.

!!!! maaddvor001 YOUR DATA IS IN DANGER !!!! #
vi cacert.pem
-----BEGIN CERTIFICATE-----
MIID/DCCAuSgAwIBAgIGALOhjrW6MA0GCSqGSIb3DQEBDAUAMIGGMSswKQYDVQQD
EyJDRyBDQSBTIG9uIGFiY2Nkc20wMS50aS5jZW5zdXMuZ292MQswCQYDVQQLEwJU
STEbMBkGA1UEChMSVS5TLiBDZW5zdXMgQnVyZWF1MRMwEQYDVQQHEwpXYXNoaW5n
dG9uMQswCQYDVQQIEwJEQzELMAkGA1UEBhMCVVMwHhcNMTcxMTAxMTM0NjM0WhcN
MjcxMTAzMTM0NjM0WjCBhjErMCkGA1UEAxMiQ0cgQ0EgUyBvbiBhYmNjZHNtMDEu
dGkuY2Vuc3VzLmdvdjELMAkGA1UECxMCVEkxGzAZBgNVBAoTElUuUy4gQ2Vuc3Vz
IEJ1cmVhdTETMBEGA1UEBxMKV2FzaGluZ3RvbjELMAkGA1UECBMCREMxCzAJBgNV
BAYTAlVTMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA8I7GB+2X8aFi
6wTyVAuWcrJbCkEqQYRCw7EM4vy1iAANil7o0jAP2kTKMcDEFwA67iB8GrtQYta0
j7HgyOjgTp7O39RfUfxzzVwqGjoqouxltPjFGXX3hkGNu2fvowfgJZRW+xSUOzFV
Qu1jPIoBqlZWptTRXgCtZkfeztShJwH0yGzyxSQvp2TTnuSSQxRBmQonFccYl+Qo
HI5akgfBrdVoklHhsiksbmgy3K/+YXPwI0m59BQ+kofQvX9rvqrgxflgCXnaYWeX
M785ticfWa1qA2ukjbtYij/UQam59SXQJi4j45h+pbOXioo0w0yQfz2gHTO8NZFs
x5JL55+hvwIDAQABo24wbDASBgNVHRMBAf8ECDAGAQH/AgEAMA4GA1UdDwEB/wQE
AwIBBjAdBgNVHQ4EFgQUlZZQftjkxjAWzwEbFxIcJVbnQ8owJwYDVR0jBCAwHoAU
lZZQftjkxjAWzwEbFxIcJVbnQ8qCBgCzoY61ujANBgkqhkiG9w0BAQwFAAOCAQEA
i8HUfFMXpFUYra+v+fPFELeTq/m9RJFavjYUtlApIXPVIIaznmFSiJ51mI/M/HNg
bohaCDme9+kU95eDC/xU0Gkej1c+HNNlMh1gSz3v39xMXmg+6+iDUqKfdSJ8IyaZ
fXqMIJ1waPIE8YADvamZ5d7vNxWBpBORGbvgmiEPJR/R0y6D/Yn/DNyY9RZlWcpr
GB0JcBguI6BoI710KG3Wylf9RR7dwXREtPytWbvkZREuZcijBvchqH5yuOMcRI1Q
8k6JyLslY1H0/pI39Q72FD9Tu3D8OXY1ZzeytN2JgXo9RRPY0MOssyPTPobdE3De
+vFAM1sQX4orZuheXk0ugw==
-----END CERTIFICATE-----


!!!! maaddvor001 YOUR DATA IS IN DANGER !!!! # ls -l
total 20
-rw-r--r-- 1 root admin 1501 Oct  7 11:27 -notext
-rw-r--r-- 1 root admin 1050 Oct  2 12:04 CertificateSigningRequest.csr
-rwxr--r-- 1 root admin 1916 Oct  7 12:02 abccdsm01.ti.census.gov.cer
-rw-r--r-- 1 root admin 1444 Oct  7 12:06 cacert.pem


Step:9
Import the "cacert.pem" certificate

Welcome to Data Domain OS 6.2.0.012-629552
------------------------------------------
SE@maaddvor001
## adminaccess certificate import ca application dsm file cacert.pem

The SHA1 fingerprint for the imported CA certificate is
88:82:8D:20:17:C8:50:A7:B7:D7:F1:97:D2:9E:83:5C:DF:23:D8:18

        Do you want to import this certificate? (yes|no) [yes]: yes
CA certificate imported for application(s) : "dsm".

Step 10: 
Get a "crt" file from DSM and copy it to
/ddr/var/certificate

!!!! maaddvor001 YOUR DATA IS IN DANGER !!!! # ls -l
total 20
-rw-r--r-- 1 root admin 1501 Oct  7 11:27 -notext
-rw-r--r-- 1 root admin 1050 Oct  2 12:04 CertificateSigningRequest.csr
-rwxr--r-- 1 root admin 1916 Oct  7 12:02 abccdsm01.ti.census.gov.cer
-rw-r--r-- 1 root admin 1444 Oct  7 12:06 cacert.pem
-rwxr--r-- 1 root admin 1524 Oct  7 11:41 maaddvor001.bdc.ti.census.gov.crt

Step 11:
SE@maaddvor001#
# adminaccess certificate import host application dsm file maaddvor001.bdc.ti.census.gov.crt

The SHA1 fingerprint for the imported host certificate is
34:BD:FB:7F:4F:A9:C8:9C:38:CA:A2:8F:01:74:DE:B1:F4:61:9B:25

        Do you want to import this certificate? (yes|no) [yes]: yes
Host certificate imported for applications(s) : "dsm".

Step 12:
Verify the certificates
SE@maaddvor001#
# adminaccess certificate show imported-host application dsm
Subject                         Type            Application   Valid From                 Valid Until                Fingerprint
-----------------------------   -------------   -----------   ------------------------   ------------------------   ------------------------------------------------------------
maaddvor001.bdc.ti.census.gov   imported-host   dsm           Mon Oct  7 11:26:33 2019   Wed Oct  6 11:26:33 2021   34:BD:FB:7F:4F:A9:C8:9C:38:CA:A2:8F:01:74:DE:B1:F4:61:9B:25
-----------------------------   -------------   -----------   ------------------------   ------------------------   ------------------------------------------------------------
Certificate signing request (CSR) exists at
/ddvar/certificates/CertificateSigningRequest.csr

SE@maaddvor001## adminaccess certificate show
Subject                              Type            Application   Valid From                 Valid Until                Fingerprint
----------------------------------   -------------   -----------   ------------------------   ------------------------   ------------------------------------------------------------
maaddvor001.ti.census.gov            host            https         Mon Sep  3 02:25:59 2018   Fri Sep  2 09:25:59 2022   ED:2A:29:19:A4:6B:12:FB:BA:1E:F3:B6:96:5B:67:93:C8:51:95:A3
maaddvor001.ti.census.gov            ca              trusted-ca    Mon Sep  3 09:25:59 2018   Sun Sep  1 09:25:59 2024   FD:71:4E:0D:CF:65:F7:68:D5:7D:8B:87:BF:52:34:10:98:FA:E9:73
maaddvor001.bdc.ti.census.gov        imported-host   dsm           Mon Oct  7 11:26:33 2019   Wed Oct  6 11:26:33 2021   34:BD:FB:7F:4F:A9:C8:9C:38:CA:A2:8F:01:74:DE:B1:F4:61:9B:25
CG CA S on abccdsm01.ti.census.gov   imported-ca     dsm           Wed Nov  1 06:46:34 2017   Wed Nov  3 06:46:34 2027   88:82:8D:20:17:C8:50:A7:B7:D7:F1:97:D2:9E:83:5C:DF:23:D8:18
----------------------------------   -------------   -----------   ------------------------   ------------------------   ------------------------------------------------------------
Certificate signing request (CSR) exists at
/ddvar/certificates/CertificateSigningRequest.csr

Step 13:

Import the certificate on DSM server and confirm.

Step 14:
Verify the connectiviy with DSM server

SE@maaddvor001#
# filesys encryption key-manager set server 10.253.210.7 port 5696 fips-mode enabled server-type dsm key-class test kmip-user maaddvor001.bdc.ti.census.gov
The current key-manager configuration is:
Key Manager:                                Disabled
Server Type:                                DSM
Server:                                     10.253.210.7
Port:                                       5696
Fips-mode:                                  enabled
Status:                                     Online
Key-class:                                  test
KMIP-user:                                  maaddvor001.bdc.ti.census.gov
Key rotation period:                        not-configured
Last key rotation date:                     N/A
Next key rotation date:                     N/A
SE@maaddvor001## filesys encryption key-manager enable
Key manager is enabled.
The filesystem must be restarted to effect this change.

SE@maaddvor001## filesys encryption keys show
Active Tier:
        Key   Key                                    State                  Size
        Id    MUID                                                          post-comp
        ---   ------------------------------------   --------------------   ---------
        0.1   4a5                                    Activated-RW **        58.50 MiB
        0.2   a16358a7-3405-4e41-b1d4-f0973764fe12   Pending-Activated **   0
        ---   ------------------------------------   --------------------   ---------
        * Post-comp size is based on last cleaning of Tue Oct  1 06:03:18 2019.
        * For these keys, key manager state and local system state are different.
        * Restart the filesystem for the 'Pending-Activated' key to become 'Activated-RW'.

Step 15: 
Restart filesystem

SE@maaddvor001#
# filesys restart

This action will restart the file system.
Applications may experience interruptions
while the file system is restarted.
        Are you sure? (yes|no) [no]: ye
yes or no, please try again
        Are you sure? (yes|no) [no]: yes

ok, proceeding.

Disabling filesystem:
Please wait.........
The filesystem is now disabled.

After filesystem gets enabled

Step 16:
Confirm encryption key is activated.


sysadmin@maaddvor001# filesys encryption keys show
Active Tier:
        Key   Key                                    State          Size
        Id    MUID                                                  post-comp
        ---   ------------------------------------   ------------   ---------
        0.1   fd8                                    Deactivated    -
        0.2   a16358a7-3405-4e41-b1d4-f0973764fe12   Activated-RW   -
        ---   ------------------------------------   ------------   ---------
        * Post-comp size will be updated after next cleaning cycle.

Step 17:
Confirm the key in DSM server matches the key listed in "
filesys encryption keys show" output.


 

Affected Products

Data Domain

Products

Data Domain, DD OS
Article Properties
Article Number: 000021998
Article Type: How To
Last Modified: 07 Sep 2026
Version:  8
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.