The section describes the steps and information needed for the new installation of a Security Manager. The overall installation process includes the following steps.
-
If needed, download the Security Manager documentation, especially the Security manager Operations Guide and Security Manager Administration User Guide.
-
Prepare for installation of a new Security Manager, which includes collecting the installation and configuration data required.
-
Make sure to disable any anti-virus software during the installation process.
-
Install one of the supported LDAP-compliant directories for storing Certification Authority (CA) certificates, certificate revocation lists (CRLs) and user information. The recommendation is that you create a directory before proceeding to the installation of the Security Manager.
-
Optionally, install the hardware security modules (HSMs). The Security Manager (requires 64-bit HSM drivers) supports storing of the keys on the PKCS#11 version 2 HSMs.
-
Install the PostgreSQL as the Security Manager database provided by Entrust, which stores information about the Certification Authority, the X.509 users and the EAC entities.
-
Install the Security Manager software. Note that before the installation, people with administrative roles (e.g.: Site Planner, Directory Administrator, Database Administrator, Master User and First Officer) should be selected. For more information about the Security Manager roles, see the Security Manager Administration User Guide.
-
Configure the Security Manager.
-
Optionally, customize the Security Manager files, in which you can configure some of the important settings.
-
Initialize the Security Manager. This step is mandatory before using the PKI system.