Integration with CipherTrust Manager
This section outlines the steps to integrate Cloud ONTAP with the CipherTrust Manager.
Integrate CipherTrust Manager with ONTAP
Connect to the ONTAP instance using SSH. The ONTAP shell appears. Perform the following steps on the ONTAP shell:
Install Client Certificate for KMIP Server.
Note
Here, the client certificate and key are the ones that you have generated in Creating the Client Certificate section.
Install the
server-ca
certificate for KMIP server.Note
Here, the server-ca belongs to the Certificate Authority which is used for signing the certs.
Install and enable the external key-management setup.
Here,
CipherTrust-Manager-private-ip refers to the IP of CipherTrust Manager.
Client_Common_Name refers to the certificate's generated name received after uploading client certificate and key on ONTAP shell.
ServerCA_Common_Name refers to the certificate's generated name received after uploading CA on ONTAP Shell.
Verify that external key-management is configured, and its status is available.
If the status is set to available it means that the CipherTrust Manager is now configured as the external KMS for the ONTAP.