Establishing secure communication within the global cluster (optional)

A global cluster is created in non-secure mode by default. You may continue to allow the global cluster to run in non-secure mode or choose to establish secure communication between clusters.

The following prerequisites are required for establishing secure communication within a global cluster:

The following information is required for adding secure communication to a global cluster:

Adding secure communication involves the following tasks:

To take the ClusterService-Proc (wac) resource offline on all clusters

  1. From Cluster Monitor, log on to a cluster in the global cluster.
  2. In the Service Groups tab of the Cluster Explorer configuration tree, expand the ClusterService group and the Process agent.
  3. Right-click the ClusterService-Proc resource, click Offline, and click the appropriate system from the menu.
  4. Repeat all the previous steps for the additional clusters in the global cluster.

To add the -secure option to the StartProgram resource

  1. In the Service Groups tab of the Cluster Explorer configuration tree, right-click the ClusterService-Proc resource under the Process type in the ClusterService group.
  2. Click View > Properties view.
  3. Click the Edit icon to edit the StartProgram attribute.
  4. In the Edit Attribute dialog box, add -secure switch to the path of the executable Scalar Value.

    For example:

    "C:\Program Files\Veritas\Cluster Server\bin\wac.exe" -secure
  5. Repeat the previous step for each system in the cluster.
  6. Click OK to close the Edit Attribute dialog box.
  7. Click the Save and Close Configuration icon in the tool bar.
  8. Repeat all the previous steps for each cluster in the global cluster.

To establish trust between root brokers if there is more than one root broker

To bring the ClusterService-Proc (wac) resource online on all clusters

  1. In the Service Groups tab of the Cluster Explorer configuration tree, expand the ClusterService group and the Process agent.
  2. Right-click the ClusterService-Proc resource, click Online, and click the appropriate system from the menu.
  3. Repeat all the previous steps for the additional clusters in the global cluster.