DD - Vormetric integration.
Summary: Integrating DSM server with DD.
Instructions
Note: confirm DD system is running following DDOS Version
Data Domain OS 6.2.0.012-629552
Step 1:
Configuring KMIP on the Data Domain system
Complete the following steps to configure KMIP on the Data Domain system.
Procedure
1. Set the "system passphrase."
A strong passphrase is required in order for the KMIP feature to work and must
contain:
A minimum of nine characters,
A minimum of one lowercase character,
A minimum of one uppercase character,
A minimum of one digit, and
A minimum of one special character.
a. In DDSH, run
#system passphrase set.
Type passphrase: *********
Re-enter passphrase: *********
Note:
- A weak passphrase that does not comply with the guidelines will cause the KMIP feature to fail.
- No spaces are allowed in passphrase.
- If a weak passphrase was previously set, update the system passphrase according to the guidelines previously listed.
- Please save the passphrase in a secure place, if the passphrase is misplaced or forgotten then there is no way to recover the data, the system need to be reimaged at which time all data will be lost.
Step 2:
Generate the CSR on DDR.
#adminaccess certificate cert-signing-request generate <add parameters>
Step 3:
Confirm the certificate creation.
#adminaccess certificate show
Subject Type Application Valid From Valid Until Fingerprint
---------------------------------- ------------- ----------- ------------------------ ------------------------ ------------------------------------------------------------
maaddvor001.ti.census.gov host https Mon Sep 3 02:25:59 2018 Fri Sep 2 09:25:59 2022 ED:2A:29:19:A4:6B:12:FB:BA:1E:F3:B6:96:5B:67:93:C8:51:95:A3
maaddvor001.ti.census.gov ca trusted-ca Mon Sep 3 09:25:59 2018 Sun Sep 1 09:25:59 2024 FD:71:4E:0D:CF:65:F7:68:D5:7D:8B:87:BF:52:34:10:98:FA:E9:73
---------------------------------- ------------- ----------- ------------------------ ------------------------ ------------------------------------------------------------
Certificate signing request (CSR) exists at /ddvar/certificates/CertificateSigningRequest.csr
Step 4:
Verify the CSR certificate in /ddr/var/certificate
!!!! maaddvor001 YOUR DATA IS IN DANGER !!!! # ls -l /ddr/var/certificates
total 12
-rw-r--r-- 1 root admin 1501 Oct 7 11:27 -notext
-rw-r--r-- 1 root admin 1050 Oct 2 12:04 CertificateSigningRequest.csr
Step 5:
Copy the csr certicate and get it signed by KeySecure CA.
Step 6:
Copy the signed cert back to /ddr/var/certificate and verify the copied "crt" certificate
!!!! maaddvor001 YOUR DATA IS IN DANGER !!!! # cd /ddr/var/certificates
!!!! maaddvor001 YOUR DATA IS IN DANGER !!!! # ls
-notext CertificateSigningRequest.csr abccdsm01.ti.census.gov.cer maaddvor001.bdc.ti.census.gov.crt
Step 7:
Run the following command
!!! maaddvor001 YOUR DATA IS IN DANGER !!!! # openssl s_client -connect 10.253.210.7:5696 -showcerts
CONNECTED(00000005)
depth=1 CN = CG CA S on abccdsm01.ti.census.gov, OU = TI, O = U.S. Census Bureau, L = Washington, ST = DC, C = US
verify error:num=19:self signed certificate in certificate chain
---
Certificate chain
0 s:/CN=abccdsm01.ti.census.gov
i:/CN=CG CA S on abccdsm01.ti.census.gov/OU=TI/O=U.S. Census Bureau/L=Washington/ST=DC/C=US
-----BEGIN CERTIFICATE-----
MIIDpjCCAo6gAwIBAgIGCBPjOgHiMA0GCSqGSIb3DQEBDAUAMIGGMSswKQYDVQQD
EyJDRyBDQSBTIG9uIGFiY2Nkc20wMS50aS5jZW5zdXMuZ292MQswCQYDVQQLEwJU
STEbMBkGA1UEChMSVS5TLiBDZW5zdXMgQnVyZWF1MRMwEQYDVQQHEwpXYXNoaW5n
dG9uMQswCQYDVQQIEwJEQzELMAkGA1UEBhMCVVMwHhcNMTcxMTAxMTM0NzE0WhcN
MjcxMTAyMTM0NzE0WjAiMSAwHgYDVQQDDBdhYmNjZHNtMDEudGkuY2Vuc3VzLmdv
djCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALBbTjMf7OKQ4jsKZ8f3
SWbduQqmO1mgGSnlf8x4JuVtNVNbUwSexrQf9L+bU8Y1KROjzzz3pKqrQHT2AauJ
eUu16Arbjs4WrYgme/fediWCU3jSNilnNA63uRqsZIiY6l3mHJhApU/n1c2uRVFj
WsP+VKy7+2mT7m/5wrPS8CZbH0zQt14oQP9klp92+X45fuUfAWQWqRbTlLGqEJjA
YM8WS5hv6LR+BJrB04hjfcsxcyCGAzzl/gbA9kxNYyk4RvvrSRLrW+clRNB53TRX
9GDucz/GPnf6WDnj0Yi1cK8LBFXiPTEPl4d8Mpqvjy0zcnVL/imlwiUUwuTdMiva
FUcCAwEAAaN9MHswEwYDVR0lBAwwCgYIKwYBBQUHAwEwDAYDVR0TAQH/BAIwADAO
BgNVHQ8BAf8EBAMCA6gwHQYDVR0OBBYEFD74MtHTq2Bd0lAMhYe8MGliQ8hpMCcG
A1UdIwQgMB6AFJWWUH7Y5MYwFs8BGxcSHCVW50PKggYAs6GOtbowDQYJKoZIhvcN
AQEMBQADggEBAFN6mBFVznpnVINaL1uA/a2iPiVORtAXwwf8/biHOLoDXlrgVkNM
LnUGmE+k2qaX0+ljV9Z5UEsh7doOd8YcGfiOs68hCYqNiT6/AABH2eC1B9oTn5sS
Cg6dbuUJgvQ33k/Bx1CN0qsxak78hNdiXpJ3Qe4QXwRxib9qfOWOYiUCEPZKh6zf
KR46uXHKTjqg6utq0udngrMBGzLYA64VUuYuboQ4TbllbSdq37eqb19UEGtI1Rwp
u2A18gVfA+O5KpHrOpqBb9hU9waULUb0KAgE4mnf6ghD9NGzgijN8K8OjSqhWtiU
jfziDSE3uWGR0hy7pLIL6umIdaXC0Wje+sY=
-----END CERTIFICATE-----
1 s:/CN=CG CA S on abccdsm01.ti.census.gov/OU=TI/O=U.S. Census Bureau/L=Washington/ST=DC/C=US
i:/CN=CG CA S on abccdsm01.ti.census.gov/OU=TI/O=U.S. Census Bureau/L=Washington/ST=DC/C=US
-----BEGIN CERTIFICATE-----
MIID/DCCAuSgAwIBAgIGALOhjrW6MA0GCSqGSIb3DQEBDAUAMIGGMSswKQYDVQQD
EyJDRyBDQSBTIG9uIGFiY2Nkc20wMS50aS5jZW5zdXMuZ292MQswCQYDVQQLEwJU
STEbMBkGA1UEChMSVS5TLiBDZW5zdXMgQnVyZWF1MRMwEQYDVQQHEwpXYXNoaW5n
dG9uMQswCQYDVQQIEwJEQzELMAkGA1UEBhMCVVMwHhcNMTcxMTAxMTM0NjM0WhcN
MjcxMTAzMTM0NjM0WjCBhjErMCkGA1UEAxMiQ0cgQ0EgUyBvbiBhYmNjZHNtMDEu
dGkuY2Vuc3VzLmdvdjELMAkGA1UECxMCVEkxGzAZBgNVBAoTElUuUy4gQ2Vuc3Vz
IEJ1cmVhdTETMBEGA1UEBxMKV2FzaGluZ3RvbjELMAkGA1UECBMCREMxCzAJBgNV
BAYTAlVTMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA8I7GB+2X8aFi
6wTyVAuWcrJbCkEqQYRCw7EM4vy1iAANil7o0jAP2kTKMcDEFwA67iB8GrtQYta0
j7HgyOjgTp7O39RfUfxzzVwqGjoqouxltPjFGXX3hkGNu2fvowfgJZRW+xSUOzFV
Qu1jPIoBqlZWptTRXgCtZkfeztShJwH0yGzyxSQvp2TTnuSSQxRBmQonFccYl+Qo
HI5akgfBrdVoklHhsiksbmgy3K/+YXPwI0m59BQ+kofQvX9rvqrgxflgCXnaYWeX
M785ticfWa1qA2ukjbtYij/UQam59SXQJi4j45h+pbOXioo0w0yQfz2gHTO8NZFs
x5JL55+hvwIDAQABo24wbDASBgNVHRMBAf8ECDAGAQH/AgEAMA4GA1UdDwEB/wQE
AwIBBjAdBgNVHQ4EFgQUlZZQftjkxjAWzwEbFxIcJVbnQ8owJwYDVR0jBCAwHoAU
lZZQftjkxjAWzwEbFxIcJVbnQ8qCBgCzoY61ujANBgkqhkiG9w0BAQwFAAOCAQEA
i8HUfFMXpFUYra+v+fPFELeTq/m9RJFavjYUtlApIXPVIIaznmFSiJ51mI/M/HNg
bohaCDme9+kU95eDC/xU0Gkej1c+HNNlMh1gSz3v39xMXmg+6+iDUqKfdSJ8IyaZ
fXqMIJ1waPIE8YADvamZ5d7vNxWBpBORGbvgmiEPJR/R0y6D/Yn/DNyY9RZlWcpr
GB0JcBguI6BoI710KG3Wylf9RR7dwXREtPytWbvkZREuZcijBvchqH5yuOMcRI1Q
8k6JyLslY1H0/pI39Q72FD9Tu3D8OXY1ZzeytN2JgXo9RRPY0MOssyPTPobdE3De
+vFAM1sQX4orZuheXk0ugw==
-----END CERTIFICATE-----
---
Server certificate
subject=/CN=abccdsm01.ti.census.gov
issuer=/CN=CG CA S on abccdsm01.ti.census.gov/OU=TI/O=U.S. Census Bureau/L=Washington/ST=DC/C=US
---
Acceptable client certificate CA names
/CN=CG CA S on abccdsm01.ti.census.gov/OU=TI/O=U.S. Census Bureau/L=Washington/ST=DC/C=US
Client Certificate Types: RSA sign, DSA sign, ECDSA sign
Requested Signature Algorithms: RSA+SHA512:DSA+SHA512:ECDSA+SHA512:RSA+SHA384:DSA+SHA384:ECDSA+SHA384:RSA+SHA256:DSA+SHA256:ECDSA+SHA256:RSA+SHA224:DSA+SHA224:ECDSA+SHA224:RSA+SHA1:DSA+SHA1:ECDSA+SHA1
Shared Requested Signature Algorithms: RSA+SHA512:DSA+SHA512:ECDSA+SHA512:RSA+SHA384:DSA+SHA384:ECDSA+SHA384:RSA+SHA256:DSA+SHA256:ECDSA+SHA256:RSA+SHA224:DSA+SHA224:ECDSA+SHA224:RSA+SHA1:DSA+SHA1:ECDSA+SHA1
Peer signing digest: SHA512
Server Temp Key: ECDH, P-256, 256 bits
---
SSL handshake has read 2800 bytes and written 443 bytes
---
New, TLSv1/SSLv3, Cipher is ECDHE-RSA-AES256-GCM-SHA384
Server public key is 2048 bit
Secure Renegotiation IS supported
Compression: NONE
Expansion: NONE
No ALPN negotiated
SSL-Session:
Protocol : TLSv1.2
Cipher : ECDHE-RSA-AES256-GCM-SHA384
Session-ID: 7C5611F5CAE956CE42764385ECB14BC83FCE949BEB86A7FEA10D5C7F7688CE49
Session-ID-ctx:
Master-Key: 9B2517ECD3BA62426D44E11289768728219BEE29D9E90466F7A57428814D2112AE80FE9E9C76A70396E62FD7562D7DA4
Key-Arg : None
PSK identity: None
PSK identity hint: None
SRP username: None
TLS session ticket lifetime hint: 300 (seconds)
TLS session ticket:
0000 - 44 ab 77 16 fe 1c f4 8b-f7 27 be bf e4 7d 50 c7 D.w......'...}P.
0010 - b4 d4 e3 7a da 5c 8d b3-18 b3 0d 5f 38 27 68 e1 ...z.\....._8'h.
0020 - e7 5d a5 b7 f5 f7 8b 2f-4a d9 2a 19 36 8c 4d 98 .]...../J.*.6.M.
0030 - 4f ff 89 ba 69 e5 01 5d-83 63 85 73 f5 ff 41 c9 O...i..].c.s..A.
0040 - 60 f4 9a 7b 4c bd 87 23-c8 56 00 d8 ef 68 34 07 `..{L..#.V...h4.
0050 - 31 c3 71 fc c9 8f 43 06-f1 c9 d0 5d a4 0e 7d 1e 1.q...C....]..}.
0060 - e8 62 6f 6c 21 39 48 c3-d7 72 d8 58 cf a3 e3 87 .bol!9H..r.X....
0070 - 6d 3f 93 91 1c 47 cc a8-fb 4b 26 84 ad 9b 1d a2 m?...G...K&.....
0080 - 30 0b d3 3f 8b 45 a5 fa-1c 8e 24 f3 68 23 b0 2b 0..?.E....$.h#.+
0090 - cd 02 7a 21 e5 69 e0 07-73 53 2f f6 b9 9e e2 88 ..z!.i..sS/.....
Start Time: 1570475077
Timeout : 300 (sec)
Verify return code: 19 (self signed certificate in certificate chain)
---
Step: 8
create "cacert.pem" file under /ddr/var/certificate and add the following content from above output.
!!!! maaddvor001 YOUR DATA IS IN DANGER !!!! # vi cacert.pem
-----BEGIN CERTIFICATE-----
MIID/DCCAuSgAwIBAgIGALOhjrW6MA0GCSqGSIb3DQEBDAUAMIGGMSswKQYDVQQD
EyJDRyBDQSBTIG9uIGFiY2Nkc20wMS50aS5jZW5zdXMuZ292MQswCQYDVQQLEwJU
STEbMBkGA1UEChMSVS5TLiBDZW5zdXMgQnVyZWF1MRMwEQYDVQQHEwpXYXNoaW5n
dG9uMQswCQYDVQQIEwJEQzELMAkGA1UEBhMCVVMwHhcNMTcxMTAxMTM0NjM0WhcN
MjcxMTAzMTM0NjM0WjCBhjErMCkGA1UEAxMiQ0cgQ0EgUyBvbiBhYmNjZHNtMDEu
dGkuY2Vuc3VzLmdvdjELMAkGA1UECxMCVEkxGzAZBgNVBAoTElUuUy4gQ2Vuc3Vz
IEJ1cmVhdTETMBEGA1UEBxMKV2FzaGluZ3RvbjELMAkGA1UECBMCREMxCzAJBgNV
BAYTAlVTMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA8I7GB+2X8aFi
6wTyVAuWcrJbCkEqQYRCw7EM4vy1iAANil7o0jAP2kTKMcDEFwA67iB8GrtQYta0
j7HgyOjgTp7O39RfUfxzzVwqGjoqouxltPjFGXX3hkGNu2fvowfgJZRW+xSUOzFV
Qu1jPIoBqlZWptTRXgCtZkfeztShJwH0yGzyxSQvp2TTnuSSQxRBmQonFccYl+Qo
HI5akgfBrdVoklHhsiksbmgy3K/+YXPwI0m59BQ+kofQvX9rvqrgxflgCXnaYWeX
M785ticfWa1qA2ukjbtYij/UQam59SXQJi4j45h+pbOXioo0w0yQfz2gHTO8NZFs
x5JL55+hvwIDAQABo24wbDASBgNVHRMBAf8ECDAGAQH/AgEAMA4GA1UdDwEB/wQE
AwIBBjAdBgNVHQ4EFgQUlZZQftjkxjAWzwEbFxIcJVbnQ8owJwYDVR0jBCAwHoAU
lZZQftjkxjAWzwEbFxIcJVbnQ8qCBgCzoY61ujANBgkqhkiG9w0BAQwFAAOCAQEA
i8HUfFMXpFUYra+v+fPFELeTq/m9RJFavjYUtlApIXPVIIaznmFSiJ51mI/M/HNg
bohaCDme9+kU95eDC/xU0Gkej1c+HNNlMh1gSz3v39xMXmg+6+iDUqKfdSJ8IyaZ
fXqMIJ1waPIE8YADvamZ5d7vNxWBpBORGbvgmiEPJR/R0y6D/Yn/DNyY9RZlWcpr
GB0JcBguI6BoI710KG3Wylf9RR7dwXREtPytWbvkZREuZcijBvchqH5yuOMcRI1Q
8k6JyLslY1H0/pI39Q72FD9Tu3D8OXY1ZzeytN2JgXo9RRPY0MOssyPTPobdE3De
+vFAM1sQX4orZuheXk0ugw==
-----END CERTIFICATE-----
!!!! maaddvor001 YOUR DATA IS IN DANGER !!!! # ls -l
total 20
-rw-r--r-- 1 root admin 1501 Oct 7 11:27 -notext
-rw-r--r-- 1 root admin 1050 Oct 2 12:04 CertificateSigningRequest.csr
-rwxr--r-- 1 root admin 1916 Oct 7 12:02 abccdsm01.ti.census.gov.cer
-rw-r--r-- 1 root admin 1444 Oct 7 12:06 cacert.pem
Step:9
Import the "cacert.pem" certificate
Welcome to Data Domain OS 6.2.0.012-629552
------------------------------------------
SE@maaddvor001## adminaccess certificate import ca application dsm file cacert.pem
The SHA1 fingerprint for the imported CA certificate is
88:82:8D:20:17:C8:50:A7:B7:D7:F1:97:D2:9E:83:5C:DF:23:D8:18
Do you want to import this certificate? (yes|no) [yes]: yes
CA certificate imported for application(s) : "dsm".
Step 10:
Get a "crt" file from DSM and copy it to /ddr/var/certificate
!!!! maaddvor001 YOUR DATA IS IN DANGER !!!! # ls -l
total 20
-rw-r--r-- 1 root admin 1501 Oct 7 11:27 -notext
-rw-r--r-- 1 root admin 1050 Oct 2 12:04 CertificateSigningRequest.csr
-rwxr--r-- 1 root admin 1916 Oct 7 12:02 abccdsm01.ti.census.gov.cer
-rw-r--r-- 1 root admin 1444 Oct 7 12:06 cacert.pem
-rwxr--r-- 1 root admin 1524 Oct 7 11:41 maaddvor001.bdc.ti.census.gov.crt
Step 11:
SE@maaddvor001## adminaccess certificate import host application dsm file maaddvor001.bdc.ti.census.gov.crt
The SHA1 fingerprint for the imported host certificate is
34:BD:FB:7F:4F:A9:C8:9C:38:CA:A2:8F:01:74:DE:B1:F4:61:9B:25
Do you want to import this certificate? (yes|no) [yes]: yes
Host certificate imported for applications(s) : "dsm".
Step 12:
Verify the certificates
SE@maaddvor001## adminaccess certificate show imported-host application dsm
Subject Type Application Valid From Valid Until Fingerprint
----------------------------- ------------- ----------- ------------------------ ------------------------ ------------------------------------------------------------
maaddvor001.bdc.ti.census.gov imported-host dsm Mon Oct 7 11:26:33 2019 Wed Oct 6 11:26:33 2021 34:BD:FB:7F:4F:A9:C8:9C:38:CA:A2:8F:01:74:DE:B1:F4:61:9B:25
----------------------------- ------------- ----------- ------------------------ ------------------------ ------------------------------------------------------------
Certificate signing request (CSR) exists at /ddvar/certificates/CertificateSigningRequest.csr
SE@maaddvor001## adminaccess certificate show
Subject Type Application Valid From Valid Until Fingerprint
---------------------------------- ------------- ----------- ------------------------ ------------------------ ------------------------------------------------------------
maaddvor001.ti.census.gov host https Mon Sep 3 02:25:59 2018 Fri Sep 2 09:25:59 2022 ED:2A:29:19:A4:6B:12:FB:BA:1E:F3:B6:96:5B:67:93:C8:51:95:A3
maaddvor001.ti.census.gov ca trusted-ca Mon Sep 3 09:25:59 2018 Sun Sep 1 09:25:59 2024 FD:71:4E:0D:CF:65:F7:68:D5:7D:8B:87:BF:52:34:10:98:FA:E9:73
maaddvor001.bdc.ti.census.gov imported-host dsm Mon Oct 7 11:26:33 2019 Wed Oct 6 11:26:33 2021 34:BD:FB:7F:4F:A9:C8:9C:38:CA:A2:8F:01:74:DE:B1:F4:61:9B:25
CG CA S on abccdsm01.ti.census.gov imported-ca dsm Wed Nov 1 06:46:34 2017 Wed Nov 3 06:46:34 2027 88:82:8D:20:17:C8:50:A7:B7:D7:F1:97:D2:9E:83:5C:DF:23:D8:18
---------------------------------- ------------- ----------- ------------------------ ------------------------ ------------------------------------------------------------
Certificate signing request (CSR) exists at /ddvar/certificates/CertificateSigningRequest.csr
Step 13:
Import the certificate on DSM server and confirm.
Step 14:
Verify the connectiviy with DSM server
SE@maaddvor001## filesys encryption key-manager set server 10.253.210.7 port 5696 fips-mode enabled server-type dsm key-class test kmip-user maaddvor001.bdc.ti.census.gov
The current key-manager configuration is:
Key Manager: Disabled
Server Type: DSM
Server: 10.253.210.7
Port: 5696
Fips-mode: enabled
Status: Online
Key-class: test
KMIP-user: maaddvor001.bdc.ti.census.gov
Key rotation period: not-configured
Last key rotation date: N/A
Next key rotation date: N/A
SE@maaddvor001## filesys encryption key-manager enable
Key manager is enabled.
The filesystem must be restarted to effect this change.
SE@maaddvor001## filesys encryption keys show
Active Tier:
Key Key State Size
Id MUID post-comp
--- ------------------------------------ -------------------- ---------
0.1 4a5 Activated-RW ** 58.50 MiB
0.2 a16358a7-3405-4e41-b1d4-f0973764fe12 Pending-Activated ** 0
--- ------------------------------------ -------------------- ---------
* Post-comp size is based on last cleaning of Tue Oct 1 06:03:18 2019.
* For these keys, key manager state and local system state are different.
* Restart the filesystem for the 'Pending-Activated' key to become 'Activated-RW'.
Step 15:
Restart filesystem
SE@maaddvor001## filesys restart
This action will restart the file system.
Applications may experience interruptions
while the file system is restarted.
Are you sure? (yes|no) [no]: ye
yes or no, please try again
Are you sure? (yes|no) [no]: yes
ok, proceeding.
Disabling filesystem:
Please wait.........
The filesystem is now disabled.
After filesystem gets enabled
Step 16:
Confirm encryption key is activated.
sysadmin@maaddvor001# filesys encryption keys show
Active Tier:
Key Key State Size
Id MUID post-comp
--- ------------------------------------ ------------ ---------
0.1 fd8 Deactivated -
0.2 a16358a7-3405-4e41-b1d4-f0973764fe12 Activated-RW -
--- ------------------------------------ ------------ ---------
* Post-comp size will be updated after next cleaning cycle.
Step 17:
Confirm the key in DSM server matches the key listed in "filesys encryption keys show" output.