
• The certificate must be added to the Default Trusted CA List in one of the Key Managers. For
information on how to do this, see the NonStop Volume Level Encryption Guide.
• OSM can only validate up to 128 bit certificates. If you copy and paste from certificates with
higher bit counts, those certificates will neither pass nor fail the Check Certificate Validity step
– the guided procedure displays a “?” (question mark) rather than a red “X” or a green check
mark – but allows you to continue with the procedure and use those certificates to register a
CLIMs.
NOTE: In such cases, OSM also displays a message instructing how you can (optionally)
download a java library required in order for OSM to validate those certificates. This process
requires you to restart the OSM Service Connection and the guided procedure. It is necessary
only if you wish to have OSM validate those certificates with a bit count higher than 128; it
is not required to continue with the guided procedure and use those unvalidated certificates
to register CLIMs.
To provide OSM with the certificate information for each CLIM listed, locate and open your signed
X.509 certificate, then in this guided procedure dialog box, perform the following steps:
1. From the list of CLIMs in the left box, click to select a CLIM.
2. Copying from your own signed X.509 certificate, paste (or type) the appropriate information
into the boxes titled:
• X.509 client certificate
• Private Key
• Passphrase (the input for this field will be echoed back as "*******")
3. Select another CLIM, by clicking on it or by using the Next or Previous buttons, and repeat
step 2 for that CLIM's client certificate. A circle is displayed in the left column for CLIMs in
which the required three fields have been completed. Continue the process until the information
is provided for each CLIM in the list.
4. Once the fields have been completed for all CLIMs, the Check Certificate Validity button
becomes active. Upon clicking it, the guided procedure checks to make sure that the
combination of certificate, key, and passphrase are correct for each of the CLIMs. If the
verification passes, a green check mark is placed next to the CLIM name (replacing the circle
icon). If the verification fails, a red "X" is placed next to the CLIM name. If OSM is unable to
verify (as in the case of certificates with a bit count over 128, for example) a "?" (question
mark) is placed next to the CLIM name. The Continue button becomes active only after the
validity check for all CLIM client certificates has completed. If errors are reported, you can go
back and click on the CLIM reporting the error and alter the appropriate input box (errors are
304 Register CLIMs with Key Managers Guided Procedure Online Help
Kommentare zu diesen Handbüchern