Administration & Maintenance - HTL
You should already have confirmed NTLS binding to the correct interface/address on your Luna SA appliance, with ntls bind
command.
C:\Program Files\SafeNet\LunaClient>
C:\Program Files\SafeNet\LunaClient>PSCP.EXE admin@myLuna:server.pem .
admin@myLuna’s password:
server.pem | 1 kB | 1.1 kB/s | ETA: 00:00:00 | 100%
C:\Program Files\SafeNet\LunaClient>
C:\Program Files\SafeNet\LunaClient>VTL.exe addserver –n <SA hostname-or-IPaddress> -c “C:\Program Files\SafeNet\LunaClient\cert\server\server.pem” –htl
New server <SA hostname or IPaddress> successfully added to server list.
C:\Program Files\SafeNet\LunaClient> VTL.exe createCert –n <clientHostname-or-IPaddress>
----------------- Example -------------------------
C:\Program Files\SafeNet\LunaClient>VTL.exe createCert –n myClient
Private Key created and written to: C:\Program Files\SafeNet\LunaClient\cert\client\myClientKey.pem
Certificate created and written to: C:\Program Files\SafeNet\LunaClient\cert\client\myClient.pem
C:\Program Files\SafeNet\LunaClient>PSCP.EXE “C:\Program Files\SafeNet\LunaClient\cert\client\myClient.pem”
admin@LunaSA:
admin@LunaSA’s password:
myClient.pem | 1 kB | 1.1 kB/s | ETA: 00:00:00 | 100%
lunash:>client register –c MyClient –ip 192.76.20.10 -requireHtl
‘client register’ successful.
Command Result : 0 (Success)
lunash:>
lunash:>client register –c MyClient –hostname myfirstclient -requireHtl
‘client register’ successful.
Command Result : 0 (Success)
lunash:>
lunash:>htl generateOtt –client MyClient
One-time token for client MyClient is ready to use.
Filename is MyClient.ott
Command Result : 0 (Success)
lunash:>
C:\Program Files\SafeNet\LunaClient>PSCP.EXE admin@<LunaSA>:MyClient.ott .
admin@LunaSA's password:
MyClient.ott | 0 kB | 0.0 kB/s | ETA: 00:00:00 | 100%
After the OTT has been transferred to your client, the final step is to make the token available.
1. Move the token to the htl directory on the client, renaming it with the ip address OR hostname of your Luna SA appliance:
Move <clientname.ott> “C:\Program Files\SafeNet\LunaClient\htl\<SAhostname-or-IPaddress.ott>”
---------------- Example --------------------------
C:\Program Files\SafeNet\LunaClient>move MyClient.ott "C:\Program Files\SafeNet\LunaClient\htl\myLunaSA.ott"
1 file(s) moved.
C:\Program Files\SafeNet\LunaClient>
You must rename the token file (see above). It is easiest to change the filename during the "move" operation.
After the token has been moved to its correct location and renamed to reflect the Luna SA hostname or IP, it will be used during the next HTL polling interval. This happens automatically.
On the Luna SA appliance, you can confirm the status of the Host Trust Link with the ‘htl show’ command. The HTL Status changes to "Up" and the OTT Status changes to "In use" after the client has successfully established a Host Trust Link
lunash:>htl show HTL Grace period : 60 seconds Default OTT expiry : 300 seconds Client Name HTL Status OTT Status OTT Expiry Time ----------------------------------------------------------------- MyClient Up In Use 300 (default) Command Result : 0 (Success) lunash:>