Preparing to configure the clusters in secure mode

You can set up Symantec Product Authentication Service (AT) for the cluster during or after the Storage Foundation configuration.

If you want to enable or disable AT in a cluster that is online, run the following command:

# /opt/VRTS/install/installsf -security

See the Veritas Cluster Server Administrator's Guide for instructions.

The prerequisites to configure a cluster in secure mode are as follows:

The installsf provides the following configuration modes:

Automatic mode

The external root broker system must allow rsh or ssh passwordless login to use this mode.

Semi-automatic mode

This mode requires encrypted files (BLOB files) from the AT administrator to configure a cluster in secure mode.

The nodes in the cluster must allow rsh or ssh passwordless login.

Manual mode

This mode requires root_hash file and the root broker information from the AT administrator to configure a cluster in secure mode.

The nodes in the cluster must allow rsh or ssh passwordless login.

Figure: Workflow to configure Storage Foundation cluster in secure mode depicts the flow of configuring Storage Foundation cluster in secure mode.

Figure: Workflow to configure Storage Foundation cluster in secure mode

Workflow to configure Storage Foundation cluster in secure mode

Table: Preparatory tasks to configure a cluster in secure mode (with an external root broker) lists the preparatory tasks in the order which the AT and VCS administrators must perform. These preparatory tasks apply only when you use an external root broker system for the cluster.

Table: Preparatory tasks to configure a cluster in secure mode (with an external root broker)

Tasks

Who performs this task

Decide one of the following configuration modes to set up a cluster in secure mode:

  • Automatic mode

  • Semi-automatic mode

  • Manual mode

VCS administrator

Install the root broker on a stable system in the enterprise.

AT administrator

To use the semi-automatic mode or the manual mode, on the root broker system, create authentication broker accounts for each node in the cluster.

See Creating authentication broker accounts on root broker system.

AT administrator requires the following information from the VCS administrator:

  • Node names that are designated to serve as authentication brokers

  • Password for each authentication broker

AT administrator

To use the semi-automatic mode, create the encrypted files (BLOB files) for each node and provide the files to the VCS administrator.

AT administrator requires the following additional information from the VCS administrator:

  • Administrator password for each authentication broker

    Typically, the password is the same for all nodes.

AT administrator

To use the manual mode, provide the root_hash file (/opt/VRTSat/bin/root_hash) from the root broker system to the VCS administrator.

AT administrator

Copy the files that are required to configure a cluster in secure mode to the system from where you plan to install and configure Storage Foundation.

See Preparing the installation system for the security infrastructure.

VCS administrator

More Information

Installing the root broker for the security infrastructure

Installing the root broker for the security infrastructure

Creating encrypted files for the security infrastructure