- 修改“kmsagent.conf”中的IP参数值为上述命令查询到的AI-GUARD网络的Gateway地址。并配置Crypto_fs服务所用的端口(可选,默认1024),具体命令为:
/usr/local/Ascend/driver/tools/kmsagent -c /var/kmsagentd/kmsagent.conf -k /var/kmsagentd/kmsconf.ksf -s SERVER_FOR_CFS -n IP -v {ip}
/usr/local/Ascend/driver/tools/kmsagent -c /var/kmsagentd/kmsagent.conf -k /var/kmsagentd/kmsconf.ksf -s SERVER_FOR_CFS -n Port -v {port}
- 修改配置文件中的“SERVER_FOR_CFS”下TlsCertPath和TlsBackupCertPath的路径。(若TlsCertPath和TlsBackupCertPath参数设置的目录已存在,且目录属主为HwHiAiUser用户,可跳过此步骤。)
/usr/local/Ascend/driver/tools/kmsagent -c /var/kmsagentd/kmsagent.conf -k /var/kmsagentd/kmsconf.ksf -s SERVER_FOR_CFS -n TlsCertPath -v {HwHiAiUser用户所属的目录}
/usr/local/Ascend/driver/tools/kmsagent -c /var/kmsagentd/kmsagent.conf -k /var/kmsagentd/kmsconf.ksf -s SERVER_FOR_CFS -n TlsBackupCertPath -v {HwHiAiUser用户所属的目录}
- 下载Crypto_fs所用设备证书的CA证书。配置Crypto_fs所用设备证书的CA证书路径,该路径不能在任意的“TlsCertPath”下,此处以{path-to-rsa.trust.pem}为例代指具体路径,且该文件路径仅为kmsagent运行属主可访问(如HwHiAiUser)且其他用户无法读写,则具体命令为:
/usr/local/Ascend/driver/tools/kmsagent -c /var/kmsagentd/kmsagent.conf -k /var/kmsagentd/kmsconf.ksf -s SERVER_FOR_CFS -n CaPath -v {path-to-rsa.trust.pem}
示例如下:
# /usr/local/Ascend/driver/tools/kmsagent -c /var/kmsagentd/kmsagent.conf -k /var/kmsagentd/kmsconf.ksf -s SERVER_FOR_CFS -n CaPath -v /home/HwHiAiUser/cfs_ca_path/cfsca.pem
Modify config successfully.
- 配置AI-VAULT服务所用的IP和端口,具体命令为:
/usr/local/Ascend/driver/tools/kmsagent -c /var/kmsagentd/kmsagent.conf -k /var/kmsagentd/kmsconf.ksf -s CLIENT_FOR_AIVAULT -n ConnectIP -v {ip}
/usr/local/Ascend/driver/tools/kmsagent -c /var/kmsagentd/kmsagent.conf -k /var/kmsagentd/kmsconf.ksf -s CLIENT_FOR_AIVAULT -n ConnectPort -v {port}
- 修改配置文件中的“CLIENT_FOR_AIVAULT”下TlsCertPath和TlsBackupCertPath的路径。(若TlsCertPath和TlsBackupCertPath参数设置的目录已存在,且目录属主为HwHiAiUser用户,可跳过此步骤。)
/usr/local/Ascend/driver/tools/kmsagent -c /var/kmsagentd/kmsagent.conf -k /var/kmsagentd/kmsconf.ksf -s CLIENT_FOR_AIVAULT -n TlsCertPath -v {HwHiAiUser用户所属的目录}
/usr/local/Ascend/driver/tools/kmsagent -c /var/kmsagentd/kmsagent.conf -k /var/kmsagentd/kmsconf.ksf -s CLIENT_FOR_AIVAULT -n TlsBackupCertPath -v {HwHiAiUser用户所属的目录}
- 配置AI-VAULT所用设备证书的CA证书路径,该路径不能在任意的“TlsCertPath”下,此处以{path-to-rsa.trust.pem}为例代指具体路径,且该文件路径仅为kmsagent运行属主可访问(如HwHiAiUser)且其他用户无法读写,则具体命令为:
/usr/local/Ascend/driver/tools/kmsagent -c /var/kmsagentd/kmsagent.conf -k /var/kmsagentd/kmsconf.ksf -s CLIENT_FOR_AIVAULT -n CaPath -v {path-to-rsa.trust.pem}