Nonstop Volume Level Encryption Guide

a. If you did not do so during the ESKM installation, create local CA NSVLECA (the name
used in this example) and use it to sign the server certificate:
1) Log onto the Secure Key Manager GUI as admin. Login name is case sensitive.
2) On the Security tab, select Local CAs.
3) Enter information to create a local certificate authority:
4) Click Create.
You can use the local CA to sign both server and client certificates. You must
download this CA to the NonStop system.
If a customer wants to use their own CA, they can import a known CA. See the Enterprise
Secure Key Manager Users Guide for details.
b. Set up the local Certificate Authority
1) Create the ESKM server certificate
2) Enable SSL on the Key Management System (KMS) Server
4. Establish a cluster
Installation steps 17