Enabling the security certificate to configure data encryption over wire for VVR replication
book
Article ID: 100048252
calendar_today
Updated On:
Description
Setting up the certificate authority (CA) certificates in /etc/vx/vvr/cacert.pem
The /etc/vx/vvr/cacert.pem file must include the CA certificate.
In case of self-signed node certificates, the /etc/vx/vvr/cacert.pem file should include the certificates from each of the signing nodes. In case of a root CA-signed certificate, this file should include the certificate issued by the root CA.
However, there may exist a chain of CAs where one or more intermediate CAs are trusted by the top-most root CA to sign certificates on their behalf. In such cases, you must perform the following steps to set up the certificates under /etc/vx/vvr/cacert.pem.
- Obtain the certificates from all CAs in the chain of trust up to the top-most root CA.
- Copy the certificates of the complete chain of CAs.
If a node certificate is signed by an intermediate CA (CA3) under a chain of CAs—for example, Root CA > Intermediate CA1 > Intermediate CA2 > Intermediate CA3—the certificates should be added or appended to the cacert.pem file in the following order:
- Intermediate CA3 certificate
- Intermediate CA2 certificate
- Intermediate CA1 certificate
- Root CA certificate
Note: Do not add the node certificate to this list because it is already included in the /etc/vx/vvr/cert.pem file.
- Ensure that the certificates of all CAs in the chain, including the root CA, are installed and present under the list of trusted CA certificates on each node.
- Validate the certificates and the basic OpenSSL connections with the updated certificate files using the standard OpenSSL commands.
- Verify that the VVR daemon SSL connections are done by using the messages logged in the daemon log files.
| VVR daemon |
Log file |
SSL connection related log messages |
| vradmind |
/var/vx/vras/log/vradmind_log_A |
Primary
Client IpmHandle:: SSL_new state succeeded
Client IpmHandle:: SSL_connect succeeded
client IpmHandle:: SSL_show Cert. succeeded
Secondary
Server IpmHandle:: SSL_new state succeeded
Server IpmHandle:: SSL_accept succeeded
Server IpmHandle:: SSL_show Cert. succeeded
|
| /var/log/messages |
Primary/Secondary
vradmind: VVR_SSL_SOCK: SSL initialization succeeded. |
| vxrsyncd |
/var/log/messages |
Primary/Secondary
in.vxrsyncd: VVR_SSL_SOCK: SSL initialization succeeded.
|
Issue/Introduction
Enabling the security certificate to configure data encryption over wire for VVR replication
Was this article helpful?
thumb_up
Yes
thumb_down
No