Building Disaster Recovery Serviceguard Solutions Using Metrocluster with 3PAR Remote Copy

For each node in the site, there must be at least two alternately routed fibre channel paths to
the local 3PAR storage system.
When you upgrade the HP 3PAR storage system to any of the following 3PAR OS versions,
then it impacts the HP Metrocluster 3PAR package.
2.3.1 MU5 Patch35
3.1.1 MU3 Patch27
3.1.2 MU3 Patch16
After the upgrade to the patches is complete, a new self-signed 2048-bit RSA SSL Certificate
is created on the HP 3PAR Array. The HP 3PAR Remote CLI clients, HP 3PAR Management
Console, 3PAR Recovery Manager, and/or any other client applications communicating to
the HP 3PAR StoreServ Storage System over SSL must be upgraded to enforce certificate
validation.
It is recommended to follow the respective HP 3PAR OS software upgrade instructions to
upgrade your storage. After the upgrade to the patches, get the certificate file or the certificate
exception file saved in the default location. The default location of exception certificate is
$HOME/.hp3par. The HP Metrocluster for 3PAR supports only the default location of the
certificate or the certificate exception file.
You can generate the certificate file by connecting to the HP 3PAR Array through the CLI client.
When the CLI server certificate is not verified by the certificate file ("cert"), the CLI looks for
the certificate information in the certificate exception file. If the certificate is not found, the CLI
prompts the user to accept and save the exception file. Later, the CLI connects to the same CLI
server without prompt.
For Example:
# /opt/3PAR/inform_cli_3.1.2/bin/cli -sys <storage system>
user: user1
password:
The authenticity of the storage system cannot be established.
CLI Server Certificate
Issuer: CN=HP 3PAR InServ F400 1306125
Subject: CN=HP 3PAR InServ F400 1306125
SHA1 fingerprint: <Key>
Validity: Not before: Nov 5 09:31:19 2013 GMT
Not after: Nov 4 09:31:19 2016 GMT
Warning: self signed certificate
Warning: certificate is not yet valid
Continue connecting (yes/no)? yes
Permanently add this certificate as an exception (yes/no)? yes
cli%
For more information about generating the certificate file or certificate exception file, see the
HP 3PAR storage system documentation.
You must generate the certification file, and save it in all the HP Metrocluster 3PAR package
nodes of the cluster. If the inform OS is updated with the latest patch and cert file, or the
certificate exception file is not present in the default location, the following is an impact on
the HP Metrocluster 3PAR package:
There is no successful configuration of a new HP Metrocluster package. The cmcheckconf
and cmapplyconf commands will time out.
The existing HP Metrocluster package fails to start after a failover.
The existing HP Metrocluster device group monitoring does not happen and no RCVG
replication status is notified.
Overview of solution for Metrocluster with 3PAR Remote Copy 9