Administration & Maintenance - HTL
You should already have confirmed NTLS binding to the correct interface address on your Luna SA appliance, with ntls bind
command.
/usr/safenet/lunaclient/bin
scp admin@LunaSA:server.pem .
admin@LunaSA’s password
server.pem 100% 1164 1.1KB/s 00:00
# ./vtl addServer –n LunaSA –c server.pem –htl
New server LunaSA successfully added to server list.
# ./vtl createCert –n MyClient
Private Key created and written to: /usr/safenet/lunaclient/cert/client/MyClientKey.pem
Certificate created and written to: /usr/safenet/lunaclient/cert/client/MyClient.pem
# scp /usr/safenet/lunaclient/cert/client/MyClient.pem admin@LunaSA:
admin@LunaSA's password:
MyClient.pem 100% 1164 1.1KB/s 00:00
lunash:>client register –c MyClient –ip 192.76.20.10 -requireHtl
‘client register’ successful.
Command Result : 0 (Success)
lunash:>
lunash:>client register –c MyClient –hostname myfirstclient -requireHtl
‘client register’ successful.
Command Result : 0 (Success)
lunash:>
htl generateOtt -client MyClient
One-time token for client MyClient is ready to use.
Filename is MyClient.ott
Command Result : 0 (Success)
lunash:>
# scp admin@10.2.87.61:MyClient2.ott .
admin@10.2.87.61's password:
MyClient2.ott 100% 32 0.0KB/s 00:00
# scp admin@10.2.87.61:MyClient2.ott .
admin@MyLunaSA's password:
MyClient2.ott 100% 32 0.0KB/s 00:00
After the OTT has been transferred to your client, the final step is to make the token available.
You must rename the token file (see above). It is easiest to change the filename during the "move" operation.
After the token has been moved to its correct location, it will be used during the next HTL polling interval. This happens automatically.
On the Luna SA appliance, you can confirm the status of the Host Trust Link with the ‘htl show’ command. The HTL Status changes to "Up" and the OTT Status changes to "In use" after the client has successfully established a Host Trust Link
htl show HTL Grace period : 60 seconds Default OTT expiry : 300 seconds Client Name HTL Status OTT Status OTT Expiry Time ----------------------------------------------------------------- MyClient Down No file 300 (default) MyClient2 Up In use 300 (default) Command Result : 0 (Success)