Importing CA Certificates of Devices

To enhance system security, you are advised to import all the CA certificates of devices before adding devices or system components to eReplication. If CA certificates of devices are not imported, the communication between eReplication and devices and system communication are not affected. However, the system may encounter spoofing risks. After CA certificates are imported, you need to restart eReplication to make the certificates take effect. You are advised to restart eReplication in off-peak hours.

Prerequisites

Context

  • The eReplication Server provides key store bcm.keystore. You need to import CA certificates to the key store. The fixed save path of the key store is /opt/BCManager/Runtime/LegoRuntime/certs in Linux.
  • The eReplication Server has preset CA certificates of the Agent. Therefore, you do not need to import the CA certificates of the Agent (bcmagentca).
  • Note the following when importing CA certificates to the eReplication Server:
    • If there are CA certificates of multiple levels, import all the CA certificates.
    • If multiple devices use a same CA certificate, import the CA certificate once only.
  • If the system reports a certificate alarm, restart the eReplication Server after CA certificates are imported.
  • Stop the eReplication Server only when no protection tasks or recovery plans are being executed in eReplication.

If no CA certificate is imported or the device certificate expires, eReplication generates a certificate alarm by default. You can disable certificate alarming if you do not want eReplication to generate certificate alarms. For details about how to disable certificate alarming, see Disabling Certificate Alarming.

Procedure

----End

Follow-up Procedure

If CA certificates of devices are updated, you need to delete original CA certificates and import new CA certificates. Before performing 6 (in Linux), perform the following operations:


Copyright © Huawei Technologies Co., Ltd.