Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

PowerScale OneFS 9.8.0.0 Web Administration Guide

Import certificate for TLS syslog forwarding

Import client-side certificates for two-way authentication for encrypted syslog forwarding.

TLS syslog forwarding uses the embedded OneFS CA root certificates for server-side authentication during the TLS handshake.

For two-way authentication, you must import the client certificates into OneFS. If the customer uses a common CA for issuing TLS certificates, OneFS may already trust the root certificate for the client certificates. Otherwise, import an accompanying new root certificate in addition to the client certificate and key files. The following steps show how to import first the root certificate and then the certificate and key files.

  1. Copy the root certificate in a known location in /ifs.
  2. Import this root certificate into the OneFS root certificate database using the following command.
    isi certificate authority import /ifs/root_cert.pem
  3. Verify that the root certificate was successfully imported.
  4. For security, delete the root certificate from /ifs after it is successfully imported.
  5. Copy the certificate and the certificate key files into the OneFS file system. The files can be in PEM, DER, or PCKS#12 format.
  6. Import the certificates and key file into the OneFS certificate store.
     isi audit certificates syslog import /ifs/certs/mycertificate.pem /ifs/certs/certkey/mycertificatekey.pem \
       --name config-change-audits
    The system assigns an id to the certificate. It stores the certificate and the key file in the OneFS certificate store.
  7. View the certificate information.
    isi audit certificates syslog view config-change-audits 
    

    The system assigned ID, status, and expiration date are displayed.

  8. For security reasons, delete the key file from the OneFS file system. You may also delete the certificate file.

Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\