12.07.2015 Views

Installation and User's Guide

Installation and User's Guide

Installation and User's Guide

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

If you use a self-signed certificateEach Tivoli Storage Manager server generates its own certificate. The certificate hasa fixed file name of cert.arm, <strong>and</strong> it is stored on the server workstation in theserver instance directory. For example: c:\program files\tivoli\tsm\server1\cert.arm. If this file does not exist, when the SSLTCPPORT orSSLTCPADMINPORT server options are specified in dsmserv.opt, the file is createdwhen you restart the server with these options. Also, a self-signed SSL certificate isgenerated <strong>and</strong> stored in the server instance directory.Follow these steps to set up the SSL connection to a server:1. Obtain the certificate, the cert.arm file, from the server administrator.2. Import the certificate into the local-client key database, <strong>and</strong> enable trust to thecertificate by placing the certificate file, cert.arm, on your client workstation.After you place the certificate file on your workstation, run the followingcomm<strong>and</strong>:gsk8capicmd -cert -add -db dsmcert.kdb -pw -label "TSM server self-signed key"-file -format ascii -trust enableIf you use a certificate issued by a CAIf the certificate was issued by a Certificate Authority (CA) such as VeriSign orThawte, the client is ready for SSL <strong>and</strong> you can skip the following steps. See“Certificate Authorities root certificates” on page 30 for the preinstalled list of theroot certificates of the external Certificate Authorities.If the certificate was not issued by one of the well-known Certificate Authorities,follow these steps:1. Obtain the root certificate of the signing CA.2. Import the root certificate into the local-client key database file, <strong>and</strong> enabletrust to the certificate by placing the certificate file on your client workstation.After you place the certificate file on your workstation, run the followingcomm<strong>and</strong>:gsk8capicmd -cert -add -db dsmcert.kdb -pw -label "XYZ Certificate Authority" -file -format ascii -trust enableImportant:1. An arbitrary password provided by you is used to encrypt the key database.The password is automatically stored encrypted in the stash file (dsmcert.sth).The stash file is used by the Tivoli Storage Manager client to retrieve the keydatabase password.2. More than one server certificate can be added to the client key database file sothat the client can connect to different servers. Different certificates must havedifferent labels. The label names are not important, but use meaningful names.Also, more than one CA root certificate can be added to the client key database.3. If you do not run the preceding comm<strong>and</strong>s from the Tivoli Storage Managerclient directory, you must copy dsmcert.kdb <strong>and</strong> dsmcert.sth into thatdirectory.4. On a 64-bit platform, GSKit is installed in \Program files\IBM\gsk8_64. TheGSKit location can vary, so check the registry key. For a 64-bit platform, use thegsk8capicmd_64 comm<strong>and</strong>.Chapter 2. Configure the Tivoli Storage Manager client 29

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!