12.07.2015 Views

Installation and User's Guide

Installation and User's Guide

Installation and User's Guide

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

v A certificate that is self-signed by Tivoli Storage Managerv A certificate that is issued by a Certificate Authority (CA). The CA can be from acompany such as VeriSign or Thawte, or an internal CA, maintained within yourcompany.Follow these steps to enable SSL communication with a self-signed certificate:1. Obtain the Tivoli Storage Manager server self-signed certificate.2. Configure the clientsv To use SSL, each client must import the self-signed server certificate. Youcan do this using the GSKit comm<strong>and</strong>-line utility, gsk8capicmd.3. For a disaster recovery of the Tivoli Storage Manager server, if the certificatehas been lost, a new one is automatically generated by the server. Each clientmust obtain <strong>and</strong> import the new certificate.Follow these steps to enable SSL communication with a CA-signed certificate:1. Obtain the CA root certificate.2. Configure the clients.v To use SSL, each client must import the root certificate of the CA. You c<strong>and</strong>o this using the GSKit comm<strong>and</strong>-line utility, gsk8capicmd.Tip: After you have completed this step, if the server gets a new certificatesigned by the same CA, the client does not need to import the root certificateagain.3. If you are recovering the Tivoli Storage Manager as part of disaster recovery,you must install the SSL certificate on the server again. If the certificate waslost, you must get a new one. You do not need to reconfigure the client if thenew certificate has been signed by a CA.The gsk8capicmd comm<strong>and</strong> is provided by Global Security Kit (GSKit). TivoliStorage Manager automatically installs GSKit in \Program Files\IBM\gsk8.However, if GSKit has been installed prior to Tivoli Storage Manager installation, itis possible that it is in some other location. You might have to obtain the GSKitlocation from the following registry key:HKLM\SOFTWARE\IBM\gsk8\CurrentVersion\InstallPathBefore you set up the server certificate on the client, follow these steps:1. Open a comm<strong>and</strong> window <strong>and</strong> change the directory to your Tivoli StorageManager client directory, for example: cd "c:\Program Files\Tivoli\TSM\baclient"2. Add the GSKit binary path <strong>and</strong> library path to the PATH environment variable,for example:set PATH=C:\Program Files\IBM\gsk8\bin;C:\Program Files\IBM\gsk8\lib;%PATH%||If you are configuring SSL on the Tivoli Storage Manager client for the first time,you need to create the client local key database, dsmcert.kdb. To create the clientlocal key database, run the following comm<strong>and</strong> from the Tivoli Storage Managerclient directory:gsk8capicmd -keydb -create -populate-db dsmcert.kdb -pw password -stashAfter you create the local key database, you must import the server certificate, orthe CA root certificate.28 IBM Tivoli Storage Manager for Windows Backup-Archive Clients: <strong>Installation</strong> <strong>and</strong> <strong>User's</strong> <strong>Guide</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!