Install prerequisites online
Perform the following steps on each target node in your deployment to install prerequisites online:Confirm that the operating system is either CentOS or RHEL 6.x - 9.0 by viewing
/etc/redhat-release:Shell
If encrypting an xfs file system, install the xfsprogs and xfsdump libraries on the node running xfs. You must unmount the xfs partitions before installing Zettaset XCrypt Full Disk.
Open the ports used by your Key Manager. For example, when using the Zettaset software-based Key Manager, open ports 6666 and 8789:When using iptables, run the following commands:When using firewalld, run the following commands:If using an external, third-party Key Manager, ensure that the necessary ports are open in your cluster.
Shell
Shell
When enabling KMIP HA on CentOS or RHEL 7.x, open ports 2181, 2888, and 3888 on the [zookeeper] nodes to establish communication between those devices. For example, if using firewalld, run the following commands:Then, run the following commands to open port 24007 and one port per [kmip] node starting from 49152 on the [kmip] nodes.
Shell
Shell
Open the port used by the Futurex PKCS #11 (FXPKCS11) library to connect to the KMES Series 3. The default Excrypt/Production port on our HSMs is port 9100.When using iptables, run the following commands:When using firewalld, run the following commands:
Shell
Shell
Install the Java Cryptography Extension (JCE) unlimited strength jurisdiction policy files:Download the file from
https://www.oracle.com/technetwork/java/javase/downloads/jce-7-download-432124.htmlorhttps://www.oracle.com/technetwork/java/javase/downloads/jce8-download-2133166.htmlThen, extract the jar files and install them in
$JAVA_HOME/lib/security.We support FIPS mode only in CentOS or RHEL 7.x and later. If you set fips_mode to
true, confirm that the FIPS version openssl installed on all nodes is at least version 1.0.1.e-fips.Establish SSH trust between the installer node and all target nodes. This prevents errors when running SSH commands. To create an SSH trust, run the following command to generate an SSH key for the installer, if not already present:Distribute the key to each target node:
Shell
Shell
Install prerequisites offline
When deploying Zettaset XCrypt Full Disk to a cluster that does not have access to the internet or a central package repository, use the Zettaset pre-installer to install the required RPMs. To use the pre-installer:Copy the
tar.gz file to all nodes on which the Zettaset software is deployed and the node that serves as the Zettaset XCrypt Full Disk installer node.Prepare the installer node by executing the following command:This command installs the RPMs needed to run the Zettaset XCrypt Full Disk installation.
Shell

