28
EMC ® Unisphere 360 for VMAX ® Version 8.2.0 Installation Guide REV 01

EMC Unisphere 360 for VMAX Installation Guide

  • Upload
    phamque

  • View
    297

  • Download
    5

Embed Size (px)

Citation preview

Page 1: EMC Unisphere 360 for VMAX Installation Guide

EMC® Unisphere™ 360 forVMAX®Version 8.2.0

Installation GuideREV 01

Page 2: EMC Unisphere 360 for VMAX Installation Guide

Copyright © 2014-2016 EMC Corporation. All rights reserved. Published in the USA.

Published March, 2016

EMC believes the information in this publication is accurate as of its publication date. The information is subject to changewithout notice.

The information in this publication is provided as is. EMC Corporation makes no representations or warranties of any kind withrespect to the information in this publication, and specifically disclaims implied warranties of merchantability or fitness for aparticular purpose. Use, copying, and distribution of any EMC software described in this publication requires an applicablesoftware license.

EMC², EMC, and the EMC logo are registered trademarks or trademarks of EMC Corporation in the United States and othercountries. All other trademarks used herein are the property of their respective owners.

For the most up-to-date regulatory document for your product line, go to EMC Online Support (https://support.emc.com).

EMC CorporationHopkinton, Massachusetts 01748-91031-508-435-1000 In North America 1-866-464-7381www.EMC.com

2 EMC Unisphere 360 for VMAX 8.2.0 Installation Guide

Page 3: EMC Unisphere 360 for VMAX Installation Guide

5

About this content 7

Pre-installation considerations 11

Before you begin........................................................................................... 12Server operating system requirements.......................................................... 12Server hardware requirements.......................................................................12Client operating system requirements........................................................... 12Client browser requirements......................................................................... 13Setting up the PostgreSQL user on Linux....................................................... 13

Installing Unisphere 360 15

Installing Unisphere 360 on a Windows system.............................................16Installing Unisphere 360 on a Linux system...................................................17Launching Unisphere 360............................................................................. 18Starting and stopping the Unisphere 360 server............................................18

Starting and stopping the Unisphere 360 server on Windows........... 18Starting and stopping the Unisphere 360 server on Linux.................19

Configuring security settings 21

Using Lightweight Directory Access Protocol or Active Directory..................... 22Secure communication between Unisphere 360 and Unisphere for VMAX..... 22Obtaining the Unisphere 360 trust store password........................................22Obtaining a Unisphere for VMAX certificate for use in Unisphere 360............ 23Obtaining an eManagement certificate for use in Unisphere 360................... 23Importing CA-signed certificates into the Unisphere 360 trust store...............24Importing CA or self-signed certificates from Unisphere for VMAX into theUnisphere 360 trust store..............................................................................25Replacing the Unisphere 360 and CA server certificates................................ 26Configuring Certificate Revocation List for X.509 certificate-basedauthentication...............................................................................................27Disabling secure communication between Unisphere 360 and Unisphere forVMAX............................................................................................................ 28

Tables

Chapter 1

Chapter 2

Chapter 3

CONTENTS

EMC Unisphere 360 for VMAX 8.2.0 Installation Guide 3

Page 4: EMC Unisphere 360 for VMAX Installation Guide

CONTENTS

4 EMC Unisphere 360 for VMAX 8.2.0 Installation Guide

Page 5: EMC Unisphere 360 for VMAX Installation Guide

Typographical conventions used in this content...............................................................8Unisphere 360 server hardware requirements................................................................12

12

TABLES

EMC Unisphere 360 for VMAX 8.2.0 Installation Guide 5

Page 6: EMC Unisphere 360 for VMAX Installation Guide

TABLES

6 EMC Unisphere 360 for VMAX 8.2.0 Installation Guide

Page 7: EMC Unisphere 360 for VMAX Installation Guide

About this content

As part of an effort to improve its product lines, EMC periodically releases revisions of itssoftware and hardware. Therefore, some functions described in this document might notbe supported by all versions of the software or hardware currently in use. The productrelease notes provide the most up-to-date information on product features.

Contact your EMC technical support professional if a product does not function properlyor does not function as described in this document.

This document was accurate at publication time. New versions of this document might bereleased on the EMC Online Support website. Check the EMC Online Support site https://support.EMC.com to ensure that you are using the latest version of this document.

PurposeThis document describes how to configure and use Unisphere for VMAX.

Related documentationThe following EMC publications provide additional information:

l EMC Unisphere for VMAX Release Notes

l EMC Unisphere for VMAX Online Help

l EMC Unisphere 360 Online Help

l EMC Solutions Enabler Installation Guide

l EMC Solutions Enabler Release Notes

l EMC Solutions Enabler SRM CLI Product Guide

l EMC Solutions Enabler CLI Command Reference

l EMC VMAX Family Security Configuration Guide

Special notice conventions used in this documentEMC uses the following conventions for special notices:

DANGER

Indicates a hazardous situation which, if not avoided, will result in death or seriousinjury.

WARNING

Indicates a hazardous situation which, if not avoided, could result in death or seriousinjury.

CAUTION

Indicates a hazardous situation which, if not avoided, could result in minor or moderateinjury.

NOTICE

Addresses practices not related to personal injury.

About this content 7

Page 8: EMC Unisphere 360 for VMAX Installation Guide

Note

Presents information that is important, but not hazard-related.

Typographical conventionsEMC uses the following type style conventions in this document:

Table 1 Typographical conventions used in this content

Bold Used for names of interface elements, such as names of windows,dialog boxes, buttons, fields, tab names, key names, and menu paths(what the user specifically selects or clicks)

Italic Used for full titles of publications referenced in text

Monospace Used for:

l System code

l System output, such as an error message or script

l Pathnames, filenames, prompts, and syntax

l Commands and options

Monospace italic Used for variables

Monospace bold Used for user input

[ ] Square brackets enclose optional values

| Vertical bar indicates alternate selections - the bar means “or”

{ } Braces enclose content that the user must specify, such as x or y or z

... Ellipses indicate nonessential information omitted from the example

About this content

8 EMC Unisphere 360 for VMAX 8.2.0 Installation Guide

Page 9: EMC Unisphere 360 for VMAX Installation Guide

Where to get helpEMC support, product, and licensing information can be obtained as follows:

Product information

EMC support, product, and licensing information can be obtained on the EMC OnlineSupport site asdescribed next.To open a service request through the EMC Online Support site, you must have avalid support agreement. Contact your EMC sales representative for details aboutobtaining a valid support agreement or to answer any questions about your account.

Technical support

EMC offers a variety of support options.

Support by Product — EMC offers consolidated, product-specific information on theWeb at: https://support.EMC.com/products.

The Support by Product web pages offer quick links to Documentation, White Papers,Advisories (such as frequently used Knowledgebase articles), and Downloads, aswell as more dynamic content, such as presentations, discussion, relevant CustomerSupport Forum entries, and a link to EMC Live Chat.

EMC Live Chat — Open a Chat or instant message session with an EMC SupportEngineer.

eLicensing support

To activate your entitlements and obtain your VMAX license files, visit the ServiceCenter on https://support.EMC.com, as directed on your License Authorization Code(LAC) letter emailed to you.

For help with missing or incorrect entitlements after activation (that is, expectedfunctionality remains unavailable because it is not licensed), contact your EMCAccount Representative or Authorized Reseller.

For help with any errors applying license files through Solutions Enabler, contact theEMC Customer Support Center.

If you are missing a LAC letter, or require further instructions on activating yourlicenses through the Online Support site, contact EMC's worldwide Licensing team [email protected] or call:

◆ North America, Latin America, APJK, Australia, New Zealand: SVC4EMC(800-782-4362) and follow the voice prompts.

◆ EMEA: +353 (0) 21 4879862 and follow the voice prompts.

Your commentsYour suggestions help us improve the accuracy, organization, and overall quality of thedocumentation. Send your comments and feedback to: [email protected]

About this content

9

Page 10: EMC Unisphere 360 for VMAX Installation Guide

About this content

10 EMC Unisphere 360 for VMAX 8.2.0 Installation Guide

Page 11: EMC Unisphere 360 for VMAX Installation Guide

CHAPTER 1

Pre-installation considerations

This chapter lists some points to consider before installing Unisphere 360:

l Before you begin................................................................................................... 12l Server operating system requirements.................................................................. 12l Server hardware requirements...............................................................................12l Client operating system requirements................................................................... 12l Client browser requirements..................................................................................13l Setting up the PostgreSQL user on Linux............................................................... 13

Pre-installation considerations 11

Page 12: EMC Unisphere 360 for VMAX Installation Guide

Before you beginThe following section contains information to consider before beginning the installation.

l The Unisphere 360 installer is for a use with a fresh install only. Upgrading is notsupported for V8.2.0.

l The user performing the installation must have operating system administratorpermissions on the system.

l On Linux systems, before starting the installation procedure, create the postgresuser and group. For more information about how to do this, see Setting up thePostgreSQL user on Linux on page 13.

Server operating system requirementsWindowsThe following Windows versions are supported:

l Windows Server 2012 R2

l Windows Server 2008 R2 (64-bit only)

LinuxThe following Linux versions are supported:

l Red Hat Enterprise Linux 6.7 (64-bit)

l Red Hat Enterprise Linux 7.2 (64-bit)

l SUSE Linux Enterprise Server 11 (64-bit)

l SUSE Linux Enterprise Server 12 (64-bit)

Server hardware requirementsThe following hardware requirements apply for Unisphere 360:

Table 2 Unisphere 360 server hardware requirements

Operating system Windows Linux

Minimum processor 2-core 1.8 GHz processor 2-core 1.8 GHz processor

Minimum available memory 16 GB 16 GB

Minimum available diskspace

120 GB 120 GB

Client operating system requirementsThe following client operating systems are supported:

l Windows 7

l Windows 8

l Windows 10

Pre-installation considerations

12 EMC Unisphere 360 for VMAX 8.2.0 Installation Guide

Page 13: EMC Unisphere 360 for VMAX Installation Guide

Client browser requirementsThe following browsers are supported:

l Firefox version 40

l Chrome version 45.0

l Internet Explorer 11.0.23

Setting up the PostgreSQL user on LinuxBefore starting a new installation of Unisphere for VMAX or Unisphere 360 on Linux, thePostgreSQL user (postgres) and group (postgres), must be present. In addition, theuser must be a member of the postgres group.

Use the following commands to create the postgres group and add the postgresuser to the postgres group:

groupadd postgresuseradd -g postgres postgres

Pre-installation considerations

Client browser requirements 13

Page 14: EMC Unisphere 360 for VMAX Installation Guide

Pre-installation considerations

14 EMC Unisphere 360 for VMAX 8.2.0 Installation Guide

Page 15: EMC Unisphere 360 for VMAX Installation Guide

CHAPTER 2

Installing Unisphere 360

This chapter explains how to install Unisphere 360:

l Installing Unisphere 360 on a Windows system.....................................................16l Installing Unisphere 360 on a Linux system...........................................................17l Launching Unisphere 360..................................................................................... 18l Starting and stopping the Unisphere 360 server....................................................18

Installing Unisphere 360 15

Page 16: EMC Unisphere 360 for VMAX Installation Guide

Installing Unisphere 360 on a Windows systemThe default installation method for Windows is the wizard, but you can launch theconsole mode using the following command:

./UNISPHERE360_version_WINDOWS_X86_64.exe -i consoleTo install Unisphere 360:

Procedure

1. To run the installer, double click the executable file.

2. In the Introduction page, click Next.

3. In the Choose Install Folder page, do one of the following:

l In the Where Would You Like to Install field, type the installation path.

l Click Choose and navigate to the installation path.

4. Click Next.

5. In the Ports Configuration page, do the following:

a. In the HTTPS Port No field, type the HTTPS port number, or accept the default valueof 8470.

b. In the DB Port No field, type the database port number, or accept the default valueof 3424.

c. Click Next.

6. In the X.509 Certificate-based Client Authentication page, do one of the following:

Note

Enable X.509 certificate-based authentication only if it is enabled on the Unispherefor VMAX instance. Otherwise, enrollment of the Unisphere for VMAX instance will fail.

l To continue installing without configuring X.509 certificate-based authentication,click Next.

l To configure X.509 certificate-based authentication, complete the following steps:

a. Select Enable certificate based client authentication.

b. Specify whether to use the CN or UPN of the client's identify.

Note that instances of the following special characters are stripped from thealias: @:?;|<>[]+=,*/\

c. In the Admin User Name field, specify the admin user name.The admin user name must match CN/UPN of the X.509 certificate (minus anyspecial characters that are stripped out) as configured in step 6.b on page 16.

This user is created in Unisphere 360 and assigned administration privileges tobootstrap administration of the system.

d. Click Next.

7. In the Pre-Installation Summary page, review the summary information and clickInstall.

The installation operation completes.

8. In the Install Complete page, click Done.

Installing Unisphere 360

16 EMC Unisphere 360 for VMAX 8.2.0 Installation Guide

Page 17: EMC Unisphere 360 for VMAX Installation Guide

After you finish

The installation operation creates a shortcut on the Windows desktop. Double-click thisshortcut to launch Unisphere 360.

Installing Unisphere 360 on a Linux systemThe default installation method for Linux is the console mode, but you can launch thewizard mode using the following command:

./UNISPHERE360_version_LINUX_X86_64.exe -i swingTo install Unisphere 360:

Procedure

1. To run the installer, run the following command:

./UNISPHERE360_version_LINUX_X86_64.exe -i console

2. In the Introduction panel, press Enter.

3. In the Choose Install Folder panel, do one of the following:

l Type the installation path and press Enter.

l Press Enter to accept the default installation path.

4. In the Ports Configuration panel, do the following:

a. Type the database port number and press Enter, or press Enter to accept thedefault value of 3424.

b. Type the HTTPS port number and press Enter, or press Enter to accept the defaultvalue of 8470.

5. In the X.509 Certificate-based Client Authentication panel, do one of the following:

Note

Enable X.509 certificate-based authentication only if it is enabled on the Unispherefor VMAX instance. Otherwise, enrollment of the Unisphere for VMAX instance will fail.

l To continue installing without configuring X.509 certificate-based authentication,type 1.

l To configure X.509 certificate-based authentication, type 2 and complete thefollowing steps:

a. Do one of the following:

n To use the CN of the client's identity, type 1.

n To use the UPN of the client's identity, type 2.

Note that instances of the following special characters are stripped from thealias: @:?;|<>[]+=,*/\

b. Type the admin user name and press Enter.The admin user name must match CN/UPN of the X.509 certificate (minus anyspecial characters that are stripped out) as configured in step 5.a on page 17.

This user is created in Unisphere 360 and assigned administration privileges tobootstrap administration of the system.

Installing Unisphere 360

Installing Unisphere 360 on a Linux system 17

Page 18: EMC Unisphere 360 for VMAX Installation Guide

6. In the Pre-Installation Summary panel, review the summary information and pressEnter.

The installation operation completes.

7. In the Install Complete panel, press Enter to exit the installer.

Launching Unisphere 360Consider the following points when launching Unisphere 360:

l When using X.509 certificate-based authentication, ensure that the certificate forUnisphere 360 is imported into the trust store for each Unisphere for VMAX to beenrolled. For more information about this, refer to Secure communication betweenUnisphere 360 and Unisphere for VMAX on page 22.

l When using Lightweight Directory Access Protocol (LDAP) or Active Directory (AD),ensure that you use the same user names as when signing in to Unisphere for VMAXusing LDAP/AD. For more information about this, refer to Using Lightweight DirectoryAccess Protocol or Active Directory on page 22.

To launch Unisphere 360:

Procedure

1. Type the following URL in a browser:

https://host_IP|host_name:port_number/unisphere360

The port number is configured during installation. The default HTTPS port number is8470.

If the host IP address is an IPv6 address, surround the IP address with squarebrackets, for example:

https://[2001:db8:ffff:ffff:ffff:ffff:ffff:ffff]:8470/unisphere360If the host IP address is an IPv4 address, type the IP address as normal, for example:

https://198.51.100.255:8470/unisphere360

2. Do one of the following:

l At the login window, type the Unisphere Initial Setup User username andpassword.

The default username for the Unisphere Initial Setup User in Unisphere 360 isadmin and the default password is admin.

l If X.509 certificate-based user authentication is configured on the server, the UseX.509 Client Certificate checkbox is automatically selected.

3. Click Login.

Starting and stopping the Unisphere 360 serverIf required to do so, you can start and stop the Unisphere 360 server manually.

Starting and stopping the Unisphere 360 server on WindowsTo start or stop the Unisphere 360 server in Windows, use the Services panel. ClickControl Panel > Administrative Tools > Services to open the Services panel.

Installing Unisphere 360

18 EMC Unisphere 360 for VMAX 8.2.0 Installation Guide

Page 19: EMC Unisphere 360 for VMAX Installation Guide

Right-click on the EMCUnisphere360Server service. Select Start, Stop, or Restart, asappropriate.

Alternatively, you can use the following commands to start or stop the Windows servicesusing the CLI:

net start " EMCUnisphere360Server"net stop " EMCUnisphere360Server"

Starting and stopping the Unisphere 360 server on LinuxTo start or stop the Unisphere 360 server in Linux, change to this directory: /etc/init.d and use the following commands:

Action Command

Start server ./cirrus start

Stop server ./cirrus stop

Restart server ./cirrus restart

Installing Unisphere 360

Starting and stopping the Unisphere 360 server on Linux 19

Page 20: EMC Unisphere 360 for VMAX Installation Guide

Installing Unisphere 360

20 EMC Unisphere 360 for VMAX 8.2.0 Installation Guide

Page 21: EMC Unisphere 360 for VMAX Installation Guide

CHAPTER 3

Configuring security settings

This chapter explains how to configure security settings for Unisphere 360:

l Using Lightweight Directory Access Protocol or Active Directory............................. 22l Secure communication between Unisphere 360 and Unisphere for VMAX............. 22l Obtaining the Unisphere 360 trust store password................................................22l Obtaining a Unisphere for VMAX certificate for use in Unisphere 360.................... 23l Obtaining an eManagement certificate for use in Unisphere 360........................... 23l Importing CA-signed certificates into the Unisphere 360 trust store.......................24l Importing CA or self-signed certificates from Unisphere for VMAX into the Unisphere

360 trust store...................................................................................................... 25l Replacing the Unisphere 360 and CA server certificates........................................ 26l Configuring Certificate Revocation List for X.509 certificate-based authentication

............................................................................................................................. 27l Disabling secure communication between Unisphere 360 and Unisphere for VMAX

............................................................................................................................. 28

Configuring security settings 21

Page 22: EMC Unisphere 360 for VMAX Installation Guide

Using Lightweight Directory Access Protocol or Active DirectoryWhen using Lightweight Directory Access Protocol (LDAP) or Active Directory (AD)complete the following steps:

Procedure

1. Configure LDAP or AD for a Unisphere for VMAX instance.

2. Enroll that Unisphere for VMAX in Unisphere 360.

3. Add users as external users to ensure that they can login to Unisphere 360.

When signing in to Unisphere for VMAX, specify the user name in the following format:

l AD users sign in specifying "domain\name".

l LDAP and local users sign in specifying "name".

Secure communication between Unisphere 360 and Unispherefor VMAX

By default, each Unisphere 360 and Unisphere for VMAX pair need to establish a TLSconnection before communicating. Therefore, Unisphere 360 needs to have alreadytrusted a certificate from Unisphere for VMAX before enrollment can succeed.

For more information about importing certificates into the Unisphere 360 trust store, referto the following topics:

l Importing CA or self-signed certificates from Unisphere for VMAX into the Unisphere360 trust store on page 25

l Importing CA-signed certificates into the Unisphere 360 trust store on page 24

Obtaining the Unisphere 360 trust store passwordProcedure

1. Open the application.properties file.

For Linux:

install_dir\Unisphere360\config\application.properties

For Windows:

install_dir/Unisphere360/config/application.properties

2. Search for the following string:

tls.trust-store-password="

3. Take note of the value of the password attribute.

Configuring security settings

22 EMC Unisphere 360 for VMAX 8.2.0 Installation Guide

Page 23: EMC Unisphere 360 for VMAX Installation Guide

Obtaining a Unisphere for VMAX certificate for use in Unisphere360

Procedure

1. Using either Internet Explorer or Chrome, launch Unisphere for VMAX:

https://host_IP:port_number

2. Do one of the following:

For Internet Explorer:

a. In the address bar, click Certificate error.

b. In the Untrusted Certificate dialog box, click View certificates.

For Chrome:

a. Click the crossed out padlock icon.

b. In the Connection tab of the dialog box, click Certificate information.

The Certificate dialog box displays.

3. In the Details tab, click Copy to File.

4. In the Welcome to the Certificate Export Wizard page, click Next.

5. In the Export File Format page, select Base-64 encoded X.509(.CER). Click Next.

6. In the File to Export page, do one of the following:

l Type the path and name of the file to export, for example C:\Users\Administrator\Desktop\u4v.cer.

l Click Browse to navigate to the folder. Type the name of the file, if required.

7. Click Next.

8. In the Completing the Certificate Export Wizard page, review the information and clickFinish.

After you finish

The newly saved certificate can be imported into Unisphere 360. For more information,refer to Importing CA or self-signed certificates from Unisphere for VMAX into theUnisphere 360 trust store on page 25.

Obtaining an eManagement certificate for use in Unisphere 360Procedure

1. Launch the vApp Manager for Embedded Management (eManagement):

https://host_IP:5480

2. In the Network Info panel, take note of the assigned IP address, either IPv4 or IPv6.

3. Click Operations > Certificate Management for Unisphere Server.

The Certificate Management for Unisphere Server wizard displays.

Configuring security settings

Obtaining a Unisphere for VMAX certificate for use in Unisphere 360 23

Page 24: EMC Unisphere 360 for VMAX Installation Guide

4. In the Welcome to certificate management for Unisphere Server page, click Next.

5. In the Choose appropriate option page, select Certificate Import/Delete and clickNext.

6. In the Certificate Import/Delete page, select the Unisphere server certificate and clickDelete.

7. When the operation completes, click Cancel to close the wizard.

8. Click Operations > Certificate Management for Unisphere Server.

The Certificate Management for Unisphere Server wizard displays.

9. In the Welcome to certificate management for Unisphere Server page, click Next.

10. In the Choose appropriate option page, select Generate Self Signed Certificate forUnisphere Server and click Next.

11. In the Generate Self Sign Certificate page, type appropriate values for each field. Inthe CN field, type the assigned IP address you noted in step 2 on page 23.

12. Click Next.

13. When the operation completes. click Cancel to close the wizard.

eManagement reboots and regenerates the keystore to contain the new certificate.

After you finish

The newly generated certificate can be saved and imported into Unisphere 360. For moreinformation, refer to Obtaining a Unisphere for VMAX certificate for use in Unisphere360 on page 23 and Importing CA or self-signed certificates from Unisphere for VMAX intothe Unisphere 360 trust store on page 25.

Importing CA-signed certificates into the Unisphere 360 truststore

Procedure

1. Get the Unisphere 360 trust store password.

For more information, refer to Obtaining the Unisphere 360 trust store password onpage 22.

2. Stop the Unisphere 360 server.

For more information, refer to Starting and stopping the Unisphere 360 server on page18.

3. Navigate to the config folder.

l On Windows, enter the following command:

cd install_dir\Unisphere360\config\l On Linux, enter the following command:

cd install_dir/Unisphere360/config/4. For each root CA and intermediate CA certificate, run the import command.

l On Windows, enter the following command on one line:

"install_dir\Unisphere360\jre\bin\keytool.exe"-import -alias alias_name

Configuring security settings

24 EMC Unisphere 360 for VMAX 8.2.0 Installation Guide

Page 25: EMC Unisphere 360 for VMAX Installation Guide

-file rootca_signed_certificate_file-keystore keystore.jks -trustcacerts

l On Linux, enter the following command on one line:

install_dir/Unisphere360/jre/bin/keytool-import -alias alias_name-file rootca_signed_certificate_file-keystore keystore.jks -trustcacerts

In the commands above, alias is a unique, user-defined name for the certificateimported, for example, root.

Note

Ensure that you import all of the intermediate certificates, as well as the rootcertificate.

5. When prompted to do so, enter the keystore password.

6. Start the Unisphere 360 server.

For more information, refer to Starting and stopping the Unisphere 360 server on page18.

Importing CA or self-signed certificates from Unisphere for VMAXinto the Unisphere 360 trust store

Procedure

1. Get the Unisphere 360 trust store password.

For more information, refer to Obtaining the Unisphere 360 trust store password onpage 22.

2. For each Unisphere for VMAX instance, get a Unisphere for VMAX certificate file.

For more information, refer to Obtaining a Unisphere for VMAX certificate for use inUnisphere 360 on page 23.

3. Stop the Unisphere 360 server.

For more information, refer to Starting and stopping the Unisphere 360 server on page18.

4. Navigate to the config folder.

l On Windows, enter the following command:

cd install_dir\Unisphere360\config\l On Linux, enter the following command:

cd install_dir/Unisphere360/config/5. For each certificate, run the import command.

l On Windows, enter the following command on one line:

"install_dir\Unisphere360\jre\bin\keytool.exe"-import -alias alias_name-file u4v_certificate_file-keystore keystore.jks -trustcacerts

Configuring security settings

Importing CA or self-signed certificates from Unisphere for VMAX into the Unisphere 360 trust store 25

Page 26: EMC Unisphere 360 for VMAX Installation Guide

l On Linux, enter the following command on one line:

install_dir/Unisphere360/jre/bin/keytool-import -alias alias_name-file u4v_certificate_file-keystore keystore.jks -trustcacerts

In the commands above, alias is a unique, user-defined name for the certificateimported, for example, u4v1234 which references a unique ID of the Unisphere forVMAX instance.

6. When prompted to do so, enter the keystore password.

7. Start the Unisphere 360 server.

For more information, refer to Starting and stopping the Unisphere 360 server on page18.

Replacing the Unisphere 360 and CA server certificatesProcedure

1. Get the Unisphere 360 trust store password.

For more information, refer to Obtaining the Unisphere 360 trust store password onpage 22.

2. Navigate to the config folder.

l On Windows, enter the following command:

cd install_dir\Unisphere360\config\l On Linux, enter the following command:

cd install_dir/Unisphere360/config/3. Generate a certificate request.

l On Windows, enter the following command on one line:

"install_dir\Unisphere360\jre\bin\keytool.exe"-certreq -alias tomcat-file tomcatcert.csr-keystore keystore.jks

l On Linux, enter the following command on one line:

install_dir/Unisphere360/jre/bin/keytool-certreq -alias tomcat-file tomcatcert.csr-keystore keystore.jks

A file named tomcatcert.csr is generated. This is the certificate request file.

4. Send the generated certificate file, tomcatcert.csr, to your CA for validation.

After the request file has been validated, you should receive a signed certificate backfrom the CA.

5. Stop the Unisphere 360 server.

For more information, refer to Starting and stopping the Unisphere 360 server on page18.

Configuring security settings

26 EMC Unisphere 360 for VMAX 8.2.0 Installation Guide

Page 27: EMC Unisphere 360 for VMAX Installation Guide

6. Navigate to the config folder.

l On Windows, enter the following command:

cd install_dir\Unisphere360\config\l On Linux, enter the following command:

cd install_dir/Unisphere360/config/7. Import the CA-signed certificate and enter the trust store password when prompted to

do so.

For more information, refer to Importing CA-signed certificates into the Unisphere 360trust store on page 24.If the following error message is returned:

keytool error: java.lang.Exception: Failed to establish chain from reply

then the root CA-signed certificate is not in the trust store.

Import the root CA-signed certificate and then re-attempt to import the new CA-signedcertificate.

8. Start the Unisphere 360 server.

For more information, refer to Starting and stopping the Unisphere 360 server on page18.

Configuring Certificate Revocation List for X.509 certificate-basedauthentication

Unisphere 360 installations with X.509 certificate-based authentication may optionallyconfigure a Certificate Revocation List (CRL) for greater PKI security. The CRL could bereplaced periodically, based on the PKI security requirement set by the enterprise.

Procedure

1. Open the application.properties file:

For Windows:

install_dir\Unisphere360\config\application.properties

For Linux:

install_dir/Unisphere360/config/application.properties

2. Add the following line:

tls.crl-file=absolute_filename_of_the_CRL_file

3. Stop and restart the Unisphere 360 server.

For more information, refer to Starting and stopping the Unisphere 360 server on page18.

Configuring security settings

Configuring Certificate Revocation List for X.509 certificate-based authentication 27

Page 28: EMC Unisphere 360 for VMAX Installation Guide

Disabling secure communication between Unisphere 360 andUnisphere for VMAX

NOTICE

The following section includes a description of the steps to disable securecommunications. EMC does not recommend this activity.

Two properties are used to configure secure communications between Unisphere 360and Unisphere for VMAX.

tls.host-name-verifier-allow-all

When set to true, this property configures Unisphere 360 to not verify the identity ofthe host when communicating with Unisphere for VMAX. Valid values are true andfalse.

tls.trust-self-signed-certs

When set to true, this property configures Unisphere 360 to unconditionally trustself-signed certificates without the need to import them. Valid values are true andfalse.

NOTICE

Unisphere 360 is installed in secure mode by default. By disabling securecommunication between Unisphere 360 and Unisphere for VMAX you are choosing to runUnisphere 360 in an unsecured mode. EMC recommends that Unisphere 360 is run in asecure mode at all times. Choosing to complete the following steps could lead to yourstorage system being compromised.

Procedure

1. Open the application.properties file.

For Windows:

install_dir\Unisphere360\config\application.properties

For Linux:

install_dir/Unisphere360/config/application.properties

2. Do one or both of the following :

l To disable host name (FQDN, IP, DNS entry) verification, add the following line:

tls.host-name-verifier-allow-all=truel To disable trust store verification of self-signed X.509 certificates, as the following

line:

tls.trust-self-signed-certs=true3. Stop and restart the Unisphere 360 server.

For more information, refer to Starting and stopping the Unisphere 360 server on page18.

Configuring security settings

28 EMC Unisphere 360 for VMAX 8.2.0 Installation Guide