File Share Encryption

 View Only
  • 1.  Changing expired certificate on PGP US cluster environment

    Posted Jun 23, 2016 05:18 AM
      |   view attached

    Do I need to change any settings on the server PGP when replacing an expiring certificate, for example unplugging and re-join the cluster ?



  • 2.  RE: Changing expired certificate on PGP US cluster environment
    Best Answer

    Broadcom Employee
    Posted Jul 08, 2016 09:50 AM

    No.

    For communication with SED clients: you only need to ensure that the key is trusted in the client. The trust chain must be valid for the OS or the Desktop client; the server must be able to build the trust chain (root certificate and intermediate certificate must be in the Trusted Keys before assigning the SSL certificate to the interface).

    For Web Email Protection: the server must be able to build the trust chain (root certificate and intermediate certificate must be in the Trusted Keys before assigning the SSL certificate to the interface) and the web browser needs to be able to trust the root certificate

    For the cluster interface: the server must be able to build the trust chain (the self-signed certificate or the root certificate and intermediate certificate must be in the Trusted Keys before assigning the SSL certificate to the interface). The Trusted Keys are replicated across the cluster.

     

    Re-joining a cluster is a big no. When joining a cluster all unique data in the database of the server that is joining will be overwritten. It means that unique data that a server might have will disapear. It is not possible to "merge" that data.