Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products

Dell PowerFlex Appliance with PowerFlex 3.x Administration Guide

PDF

Extract and add the MDM certificate

Use this procedure to add MDM certificate.

About this task

The MDM certificate must be exchanged between the replicating clusters to protect from possible security attacks. This procedure is performed using the PowerFlex scli. On each system, a certificate is created and sent to the other host in the replicated pair.

Prerequisites

NOTE:This procedure can only be completed when the secondary site is active.

Steps

  1. Log in to the primary MDM, by using the SSH on source and destination.
  2. Run command: scli --login --username admin on the scli command and provide the MDM cluster password, when prompted.
    See the following example to extract the certificate on source and destination primary MDM.
    • Example for source: scli --extract_root_ca --certificate_file /tmp/Source.crt
    • Example for destination: scli --extract_root_ca --certificate_file /tmp/destination.crt
  3. Copy the extracted certificated of source (primary MDM) to destination (primary MDM) using the SCP and vice versa.
    See the following example to add the copied certificate:
    • Example for source: scli --add_trusted_ca --certificate_file /tmp/destination.crt --comment destination_crt
    • Example for destination: scli --add_trusted_ca --certificate_file /tmp/source.crt --comment source_crt
  4. Run scli --list_trusted_ca to verify the added certificate.
  5. Once all the Journal Capacity is set, log in to the primary DM using SSH, and log in to scli using scli --login --username admin for adding the Peer.
    Logged in. User role is SuperUser. System ID is 2e6ccfd208ef120f
    Note the system ID.
  6. Add a peer system on the primary site: scli --add_replication_peer_system --peer_system_ip.
  7. Add a peer system on the remote site: scli --add_replication_peer_system --peer_system_ip (primary master mdm Mgmt ip,primary slave mdm Mgmt ip) --peer_system_id ( id of primary site ) --peer_system_name (primary sitename).
    NOTE:
    • For a three node cluster, add two management IP addresses (primary and secondary).
    • For a five node cluster, add three management IP addresses (primary, secondary1, and secondary2).

Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\