Report errors or omissions

 

Add a Gateway Instance

For high availability, add additional Gateway Instances to your exiting Gateway.

Add a Gateway Instance

Click > Resources > Gateways. The Gateways page appears.

Click Add Instance to add a Gateway Instance to your existing Gateway. The Registration Code appears.

Click Copy to Clipboard to copy the Registration Code.

Configure the Gateway.Configure the Gateway.

Configure the Gateway

Power on your the virtual machine.

If the VM is in a network with DHCP disabled, you must log in to the VM and set up the static IP before using the cockpit to register the Gateway as follows:

At the login prompt, enter entrust.

At the password prompt, enter entrust. You are prompted to create a new password.

 At the (current) UNIX password prompt, enter entrust to confirm your existing password.

Enter a new password. The password must meet the following rules:

 Must not be based on any word found in the English dictionary

Cannot contain spaces.

Must contain at least 8 alphanumeric (a-z, A-Z, 0-9) characters.

Must contain at least one special character (for example, ! %*) character.

At the Retype new password prompt, re-enter the password. The Entrust Identity as a Service Gateway Configuration Tool appears.

Setup static IP for the VM

Option one: Run sudo /home/entrust/tools/setup_static_ip.sh and respond to the prompts. The network service restarts.

Option two: Set up the static IP manually according to the needs.

In your Web browser, enter the IP address of your Virtual Machine using port 9090, for example, https://192.168.1.20:9090 and accept the browser self-signed certificate warning. The Identity as a Service Gateway Web Interface opens.

The self-signed certificate is created on VM boot, which is unique to each Enterprise Gateway. If you want to change the certificate for the cockpit (IDaaS Gateway Web interface), replace the file /etc/cockpit/ws-certs.d/0-self-signed.cert which contains both the certificate and the private key. If multiple certificates exist under the /etc/cockpit/ws-certs.d/ folder, the cockpit uses the last file with a .cert or .crt extension in alphabetical order. Use the following command to see which certificate has been used:

sudo remotectl certificate

Note: Internet Explorer is not supported.

At the User Name prompt, enter entrust.

At the password prompt, enter entrust. You are prompted to create a new password.

Follow the prompts to reset the password.

Attention: After you have changed your password, when you log in to the Web Interface, you must select Reuse my password for privileged tasks.

At the (current) UNIX password prompt, enter entrust to confirm your existing password and click Log In.

Enter a new password. The password must meet the following rules:

Must not be based on any word found in the English dictionary

Cannot contain spaces.

It must contain at least 8 alphanumeric (a-z, A-Z, 0-9) characters.

It must contain at least one special character (for example, ! %*) character.

At the Retype new password prompt, re-enter the password. The Identity as a Service Enterprise Gateway Configuration Tool appears.

Click Get Started. The Network Settings page appears.

By default the hostname is entrust-idaas-agent. To change the hostname:

Click the Hostname link. The Hostname dialog box appears.

Enter a new hostname and click Save.

To change the IP Configuration, click the IP Address link.

Select Static or DHCP.

Make the required Network Settings changes. A confirmation dialog box appears.

Click Save.

Click Next. The NTP Settings appear.

Optional: If you want to change any of the NTP Settings, do the following:

On the NTP Settings page, click Edit.

Make the required NTP Settings changes and click Save.

Click Next.

If required, click Configure. The Configure Proxy page appears.

Enter the Proxy server host IP or Proxy host name.

Enter the Proxy port number.

Enter the Proxy username.

Enter the Proxy password.

Click Save.

Click Next. The Registration Parameters appear.

Paste the Registration Code you copied when you created the Gateway.

Click Register.

Recommended. For high availability, add more than one Gateway Instance.

Attention: When making changes to the proxy configuration on the Identity as a Service Gateway the appliance must be restarted in order for the changes to take effect.