Skip to main content
After downloading node CSRs from Prism Element, you need to create an equal number of client endpoints inside the Nutanix AOS service in CryptoHub. Endpoints are devices authorized to access the service. Use the Endpoints menu to view and manage these devices.
1
Navigate to the Endpoints menu for the Nutanix AOS service you deployed.
2
In the Manage Endpoints menu, select [ Add New ].
3
In the Add Endpoint dialog:
  • Enter a Name for the endpoint. Use a descriptive name that helps you identify which node CSR this endpoint corresponds to (e.g. “nutanix-node-1”, “nutanix-node-2”, etc.).
  • Leave set the CryptoHub Hostname that is auto-populated.
4
Select [ Add Endpoint ]. The browser prompts you to download a zip file which contains the following files:
Each client endpoint you create corresponds to one node CSR you downloaded from Prism Element. Therefore, you must create the same number of endpoints as CSRs. If you have three CSRs, create three endpoints. If you have four CSRs, create four endpoints, and so on. Keep track of which endpoint corresponds to which node CSR to avoid confusion when signing the CSRs in the next step.
After deploying the client endpoint, CryptoHub creates a Certificate Authority (CA) for the service. This CA is used in the next step to sign the per-node CSRs that Nutanix generates. The CA certificate is also uploaded to Nutanix to establish trust.
The Futurex Test Root CA (ECC).cer or Futurex Test Root SSL CA.cer file from this zip is the KMIP server root CA certificate. You will need this file when configuring the Certificate Authority in Prism Element.