OceanStor Dorado Documentation

Quorum Server Configuration

Definition

The Quorum Server configuration includes adding the Quorum Server IPs for the connection to the devices, signing the certificates from the storage devices to ensure a safe connection and whitelisting the storage devices in the Quorum.


IP Adding

  1. Access the Quorum Server:

`qsadmin`

  1. Add the IP(s) of the Quorum Server:

`add server_ip ip=XX.XX.XX.XX`

  1. Check for the IPs inside the Quorum Server:

`show server_ip`


Certificate Signing

  1. Access the Storage Device(s) that will connect to the Quorum Server through DeviceManager
  2. Access Settings > Certificates in DeviceManager

QuorumServerConfig 001

  1. Select 'HyperMetro arbitration certificate' and Export Request File

QuorumServerConfig 002

  1. Move the .csr file generated to the Quorum Server VM: /opt/quorum_server/export_import
  2. Give permissions to the file for the Quorum Server:

`chown quorumsvr:quorumsvr FILENAME.csr`

  1. Sign the .csr file and generate the CA .crt file:

`generate tls_cert csr=FILENAME.csr cert_name=FILENAME.crt`

  1. Obtain the CA file (cps_ca.crt) and the signed HyperMetro arbitration certificate (FILENAME.crt) from the /opt/quorum_server/export_import directory
  2. Access Settings > Certificates in DeviceManager for the Storage Device
  3. Select 'HyperMetro arbitration certificate' and Import Certificate

QuorumServerConfig 003

  1. Upload 'Certificate File' as the signed HyperMetro arbitration certificate (FILENAME.crt)
  2. Upload 'CA Certificate File' as the trusted entity signature (cps_ca.crt)

QuorumServerConfig 004

  1. Press OK and finish the certificate signing process

Device Whitelisting

  1. Access the Quorum Server:

`qsadmin`

  1. Query the certificate ID and record the 'Cert id' value:

`show tls_cert` QuorumServerConfig 005

  1. Whitelist the Storage Device(s):

`add white_list sn=xxxxxxxxxxxxx cert_id=0`