Sign the Host Certificate using ESKM

See section Create a Data Domain Host Certificate and complete all related steps before performing the steps below. 

  1. Copy the host certificate signing request (CertificateSigningRequest.csr) from the Dell DD for signing with the ESKM local CA. The following command can copy the CSR to a Linux machine.

$scp sysadmin@<DDServerIP>:/ddvar/certificates/CertificateSigningRequest.csr

  1. Open the ESKM Management Console, click the Security tab, and then click on the Local CAs link in the Certificates & CAs section.

  2. Select the previously created CA certificate name from the Sign with Certificate Authority.

  3. Select the radio button Client in the Certificate Purpose section. 

  4. Copy the host certificate content to the Certificate Request box. 

image-20250627-081055.png

Sign Certificate Request

  1. Click on the Sign Request button. 

image-20250627-081217.png

Signed Host Certificate Details

  1. Note down the common name and copy the signed certificate content to create a KMIP user.

  2. Click on the Download button to download the signed host certificate file.