hosts.inv, sets the configuration properties for the installation. The Zettaset software includes an annotated sample file, hosts.inv.example. This section provides additional information.
All Nodes
None
- encrypted_blockdev: Enter the block device to be encrypted (such as
/dev/sdb1). Disk partition name is expected. To use disk partition labels, setuse_labels=true. - encrypted_mountpoint: Enter a mount point for the device (such as
/data1). The mount point must exist before the installation. - encrypted_mountnames: Enter a partition name. Each name must be unique for each partition on the node. (such as
crypt1) - encrypted_preserve: Use one of the following values:
- y: Preserves existing data. Mount the file system before performing the installation. If the partition is not mounted, the data is overwritten. The partition must also be unmountable. If a process prevents the unmount, encryption cannot start. Only ext file systems can be preserved.
- n: Does not preserve existing data. You must unmount the partition.
- w: Securely wipes the partition before the new encrypted file system is created. You must unmount the partition.
- fstype: Must be set to the type of file system to make when encrypted_preserve is y or w. Must be set to the existing file system type when encrypted_preserve=n. Typical file system types include ext4 and xfs.
- newfsargs: A string of arguments to pass to the MKFS command. If spaces exist between multiple arguments, surround the string in double quotes (for example,
"-b 2048 -d su=64k,sw=4"). When no arguments are to be passed, set this value to none. - mountargs: A string of mount options to pass to the crypt_mount.sh script. If spaces exist between multiple arguments, surround the string in double quotes (for example,
"noatime,inode64,allocsize=16m"). When no arguments are to be passed, set this value to none. - kmip_client_jks: The location of the keystore that contains the client certificate. The keystore must be in this location on the installer node before installation.
- kmip_client_jks_password: The password for the jks file.
- newfsargs: Use colons to separate values. Include values for all settings. For example:
None
Product Name
None
Software License
None
FIPS Mode
None
true to enable FIPS 140 mode. All ZTS processes run in FIPS mode. fips_mode set to true is currently only supported for OS versions 7.x and later.
Disk Labels
None
CA Configuration
None
pem file in external_ca_cert_source. This is the location of the CA pem file on the installer node.
While using an external CA, you can ignore the ca_org_* values.
KMIP Server Configuration
None
300000.
When using an external KMIP server, use kmip_client_jks_test and kmip_client_jks_passwd to enter the jks path and password and check the KMIP server connectivity before installing XCrypt. These values install a KMIP client on the installation node. Leave these values blank if you do not need to check external KMIP connectivity or install a KMIP client on the installation node.
HSM Configuration
None
- hsm_so_pin and hsm_user_pin: Password for the identity created on the KMES Series 3 and set inside the Futurex PKCS #11 (FXPKCS11) configuration file.
- hsm_slot: Slot number configured in the FXPKCS11 configuration file,
fxpkcs11.cfg. The slot number is 0 by default. - hsm_lib_cfg_env_var: Specify
COMPAT_MODE=3. - hsm_lib_file: Path and filename for the FXPKCS11 module.
Node Functions
None
- [ca_master]: The node that stores licenses and generates the CA. If using an external CA, set this value to a node within the cluster.
- [kmip]: List of the KMIP server and backup server nodes. The first entry must be the kmip_master. Comment out when using an external KMIP server.
- [kmip_master]: The KMIP master node. Must be the same as kmip_master_ip. Comment out when using an external KMIP server.
- [slave]: List of the nodes that have encrypted partitions.
- [license_server]: List of the nodes where you plan to install the License server. Must not intersect with [kmip] or [slave] nodes.
- [zookeeper]: List of the zookeeper nodes used when you enable KMIP HA. List at least three nodes. These nodes cannot be members of the [kmip] group.

