Note: Installing the ISO file will delete all existing data on the disk.

  1. Mount the CSP Vault installation ISO in the media browser.

  2. Make sure to change the one time boot option to CD/DVD by selecting F12 in the boot screen.

  3. Start the installation.

  4. When prompted, select the primary network interface for the installation.

  5. Enter a password for the Cryptographic Security Platform Vault system administration account htadmin and press Enter. Password requirements are configured by an Cryptographic Security Platform Vault administrator in the System Settings.
    This password controls access to the Entrust Cryptographic Security Platform Vault System Console that allows users to perform some Cryptographic Security Platform Vault administration tasks. It does not permit a Cryptographic Security Platform Vault user to access the full OS.
    Important: Make sure you keep this password in a secure place. If you lose the password, you will need to contact Entrust Support. For security reasons, Cryptographic Security Platform Vault does not provide a user-accessible password recovery mechanism.

  6. If you want to configure a bonded interface, press Yes to enable bonding on the primary interface. Otherwise, press No.
    If you selected Yes, complete the following to configure the system with the bonded network interface: 

    1. Choose the desired network bonding mode based on your network requirements, and press OK.

    2. Add the additional network interfaces that will participate in the bond and press OK.

    3. Enter any optional bonding parameters, such as link monitoring or failover settings, and press OK.

  7. On the Confirm Network Configuration page, enter the appropriate network information for the CSP Vault node. When you are done, press Enter to save this information.
  8. On the System Configuration page, review the configuration settings and press Yes if you are ready to configure the node.
    The installer configures Cryptographic Security Platform Vault and then starts the appropriate services. This process will take a few minutes to complete. When the installer has finished, Cryptographic Security Platform Vault displays a confirmation dialog stating that the setup was completed successfully.

  9. Review the confirmation dialog that provides the URL of the Cryptographic Security Platform Vault webGUI (also known as the Management IP Address). You will need this URL in the next step.
    When you are done, press Enter to finish the installation. Cryptographic Security Platform Vault displays the Oracle Linux login prompt.

  10. After the configuration is complete, unmount the ISO from the media browser, and ensure that the boot order is reset.
  11. To initialize the Cryptographic Security Platform Vault webGUI and finish the configuration of the first node, do the following:

    1. Use a web browser to navigate to https://node-ip-address, where node-ip-address is the Management IP address. For security reasons, you must explicitly specify https:// in the URL.

    2. If prompted, add a security exception for the Cryptographic Security Platform Vault IP address and proceed to the Cryptographic Security Platform Vault Management webGUI.
      Cryptographic Security Platform Vault uses its own Root Certificate Authority to create its security certificate, which means that certificate will not be recognized by the browser. For details, see CSP Vault Certificates.

    3. On the Entrust Cryptographic Security Platform Vault Management login page, enter secroot for both the username and password.
    4. Review the EULA (end user license agreement). When you are done, click I Agree to accept the license terms.
    5. On the Welcome to Cryptographic Security Platform Vault screen, click Continue as a Standalone Node.
    6. On the Change Password page, enter a new password for the secroot account and click Update Password.

    7. On the Configure E-Mail and Mail Server Settings page, specify your email settings.
      If you specify an email address, Cryptographic Security Platform Vault sends an email with the Admin Key for the new node. It also sends system alerts to this email address.
      To disable alerts, select the Disable e-mail notifications checkbox. You are then prompted to download the Admin Key.

    8. When you are done, click Continue.

    9. On the Download Admin Key page, click the Download button to save the admin key locally. Please keep the admin key in a safe place for later use. When Cryptographic Security Platform Vault prompts for an admin key to recover your Cryptographic Security Platform Vault system, you must provide this admin key to proceed. If you do not have your admin key, you may lose your data.
      Note: Whenever the admin key is regenerated, Cryptographic Security Platform Vault forces you to download the admin key.

    10. When you are finished, click Continue.
      Cryptographic Security Platform Vault displays the Cryptographic Security Platform Vault Management webGUI. For details about the tasks you can perform from the webGUI, see the CSP Vault Management webGUI Page Reference.

  12. If you would like to add an additional NIC or a bonded interface, you can configure it in the CSP Vault System Console by doing the following: 

    1. From the System Console, navigate to Manage Network Settings and select Manage Interfaces and IP Address Settings.

    2. Choose one of the available unconfigured network interfaces and press OK.

    3. Select Configure as secondary or bonded secondary interface and press OK.

    4. Select Yes if you want to configure a bonded secondary interface, or select No if you want to configure an unbonded secondary interface.

    5. If you selected a bonded secondary interface, select the appropriate network bonding mode based on your network setup requirements and press OK.
      Note: If you selected unbonded, this step will not appear.

    6. If you selected a bonded secondary interface, add the additional interfaces that you want to be included in the secondary bond and press OK.
      Note: If you selected unbonded, this step will not appear.

    7. If you selected a bonded secondary interface, add any additional options for the bond, or leave blank if there are no additional options, and press OK.
      Note: If you selected unbonded, this step will not appear.

    8. When prompted to configure the selected interface, click Yes.

    9. Configure the secondary network and press OK.

    10. Verify that the secondary interface or network bond is successfully created and operational.

What to Do Next