You can link CloudAdvisor with HyTrust KeyControl so that CloudAdvisor can access and monitor the VMs registered with the KeyControl cluster and encrypted by the HyTrust DataControl Policy Agent.
Note: | If you are using a third party application to encrypt your VMs and are only using KeyControl to manage your encryption keys, CloudAdvisor cannot access or monitor your encrypted VMs even if you link to the KeyControl cluster. CloudAdvisor only supports monitoring VMs that have been encrypted by the DataControl Policy Agent. |
If you have multiple KeyControl clusters, you need to create a separate link between CloudAdvisor and at least one KeyControl node in each cluster.
Before You Begin
If you want CloudAdvisor to verify the KeyControl root CA certificate every time it connects to KeyControl, make sure that the SSL certificate installed in KeyControl includes the entire certificate chain, starting from the root CA certificate. When SSL Verify is enabled, CloudAdvisor verifies the root CA certificate when it communicates with KeyControl.
Procedure
Generate the one-time App Link code in KeyControl.
Log into the CloudAdvisor interface.
In the Create App Link dialog box, specify the options you want to use.
Field |
Description |
|||
---|---|---|---|---|
Name | A user-defined name for the app link. | |||
Description |
A user-defined description for the app link. |
|||
Server |
The hostname or IP address and port number for the KeyControl server. When connecting to the server, CloudAdvisor automatically prepends If you have multiple KeyControl nodes in the cluster, enter as many of the node IP addresses as you want. If the first node is not available, CloudAdvisor will try each node in turn when it attempts to contact KeyControl in order to decrypt and analyze a VM. |
|||
Server Type |
Select HyTrust KeyControl. |
|||
SSL Verify |
If this option is enabled, the certificate for the KeyControl server is verified every time a connection between CloudAdvisor and KeyControl is established. If the KeyControl certificate changes, the connection will fail. This is the default. If this option is not enabled, the KeyControl server certificate is never checked by CloudAdvisor.
|
|||
One Time Code |
The App Link code generated in KeyControl. |
If the connection information is correct and you have enabled the SSL Verify option, CloudAdvisor displays the available KeyControl certificates. Verify that the certificates are correct and that the link is going to the expected server. If the information is correct, click Yes.
If desired, repeat this procedure to link CloudAdvisor to another KeyControl server.