Note: Installing the ISO file will delete all existing data on the disk.
Mount the CSP Vault installation ISO in the media browser.
Make sure to change the one time boot option to CD/DVD by selecting F12 in the boot screen.
Start the installation.
When prompted, select the primary network interface for the installation.
Enter a password for the Cryptographic Security Platform Vault system administration account
htadminand press Enter. Password requirements are configured by an Cryptographic Security Platform Vault administrator in the System Settings.
This password controls access to the Entrust Cryptographic Security Platform Vault System Console that allows users to perform some Cryptographic Security Platform Vault administration tasks. It does not permit a Cryptographic Security Platform Vault user to access the full OS.
Important: Make sure you keep this password in a secure place. If you lose the password, you will need to contact Entrust Support. For security reasons, Cryptographic Security Platform Vault does not provide a user-accessible password recovery mechanism.If you want to configure a bonded interface, press Yes to enable bonding on the primary interface. Otherwise, press No.
If you selected Yes, complete the following to configure the system with the bonded network interface:Choose the desired network bonding mode based on your network requirements, and press OK.
Add the additional network interfaces that will participate in the bond and press OK.
Enter any optional bonding parameters, such as link monitoring or failover settings, and press OK.
- On the Confirm Network Configuration page, enter the appropriate network information for the Cryptographic Security Platform Vault node. When you are done, press Enter to save this information.
On the System Configuration page, review the configuration settings and press Yes if you are ready to configure the node.
The installer configures Cryptographic Security Platform Vault and then starts the appropriate services. This process will take a few minutes to complete. When the installer has finished, Cryptographic Security Platform Vault displays a confirmation dialog stating that the setup was completed successfully.Review the confirmation dialog that provides the URL of the Cryptographic Security Platform Vault webGUI (also known as the Management IP Address). You will need this URL in the next step.
When you are done, press Enter to finish the installation. Cryptographic Security Platform Vault displays the Oracle Linux login prompt.- After the configuration is complete, unmount the ISO from the media browser, and ensure that the boot order is reset.
Log into the webGUI on the CSP Vault node you want to join with the cluster using
secrootfor both the name and the password.On the Welcome to Cryptographic Security Platform Vault screen, click Join an Existing Cluster.
The Join Existing Cluster window displays.On the Get Started page, review the overview information to determine that you are ready to begin. This includes:
Access to the cluster you are joining the node to. We recommend that you open the webGUI for the cluster in a different tab or browser window.
Permissions on both this node and the cluster node so you can download and import the required certificates and files.
A passphrase to use during the joining process. Passphrase requirements are configured by a CSP Vault administrator in the System Settings. This phrase is a temporary string used to encrypt the initial communication between this node and the existing cluster.
Verifying that both this node and the cluster node are running the same Cryptographic Security Platform Vault version and build. The version number for the cluster node is on the Settings > System Upgrade page.
Click Continue.
On the Download CSR page, click Generate and Download CSR.
Click Continue.
Switch to one of the existing nodes in the cluster and navigate to the Cluster page.
Select Actions > Add a Node.
Click Save and Download Bundle to download the certificate bundle from the cluster node.
The certificate bundle is a .zip file you must unpack. It contains both an encrypted SSL certificate in .p12 format and a CA certificate in .pem format.Click OK to close the Add a Node window.
Return to the new node and click Continue.
On the Node page, upload the encrypted SSL certificate and CA certificate that you downloaded from the cluster node, enter the private IP address of any node in the existing cluster, and enter the passphrase that you selected.
Note: Cryptographic Security Platform Vault uses the private IP address of its cluster members for cluster communication, such as heartbeat and object store synchronization.Click Join.
During the joining process, a status page is displayed on the new node. Do not refresh the browser while this is in process.
The cluster will automatically be placed in maintenance mode. The node will restart after the join is complete.When the node has successfully restarted, click Login.