Follow this procedure if you are configuring the first Cryptographic Security Platform Vault node in the cluster. If you are adding the node to an existing cluster, see Configuring Additional GCP Nodes.
Before You Begin
Make sure you have the following information:
The instance ID for the Cryptographic Security Platform Vault instance. This is located in the Basic Information section on the Details page of the instance.
The External IP associated with the instance.
Procedure
To initialize Cryptographic Security Platform Vault for this cluster, do the following:
Use a web browser to navigate to
https://node-ip-address, wherenode-ip-addressis the External IP address. For security reasons, you must explicitly specifyhttps://in the URL.If prompted, add a security exception for the Cryptographic Security Platform Vault IP address and proceed to the Cryptographic Security Platform Vault Management webGUI.
Cryptographic Security Platform Vault uses its own Root Certificate Authority to create its security certificate, which means that certificate will not be recognized by the browser. For details, see CSP Vault Certificates.
On the Entrust Cryptographic Security Platform Vault Management login page, enter
secrootfor the username and the Instance ID for the password.Click Login.
- Review the EULA (end user license agreement). When you are done, click I Agree to accept the license terms.
- On the Welcome to Appliance Management screen, click Continue as a Standalone Node.
On the Change Password page, enter a new password for the
secrootaccount and click Update Password.On the Configure E-Mail and Mail Server Settings page, specify your email settings.
If you specify an email address, Cryptographic Security Platform Vault sends an email with the Admin Key for the new node. It also sends system alerts to this email address.
To disable alerts, select the Disable e-mail notifications checkbox. You are then prompted to download the Admin Key.
When you are done, click Continue.
On the Download Admin Key page, click the Download button to save the admin key locally. Please keep the admin key in a safe place for later use. When Cryptographic Security Platform Vault prompts for an admin key to recover your Cryptographic Security Platform Vault system, you must provide this admin key to proceed. If you do not have your admin key, you may lose your data.
Note: Whenever the admin key is regenerated, Cryptographic Security Platform Vault forces you to download the admin key.
When you are finished, click Continue.
Cryptographic Security Platform Vault displays the Cryptographic Security Platform Vault Management webGUI. For details about the tasks you can perform from the webGUI, see the Administration Guide.
What to Do Next
If you want to add another Cryptographic Security Platform Vault node to this cluster, create another instance as described in Deploying the First CSP Vault Node in GCP and then configure it as described in Configuring Additional GCP Nodes.