‘Configuring the Integration’¶
ImplementingtheCipherTrustTransparentEncryption(CTE)solutionrequiresthefollowingcomponents:
Postgres server installed and operational. - CipherTrust Manager installed and operational. - A CTE agent installed on the Postgres host registered to the CipherTrust Manager.
ThefollowingdiagramshowsthebasicflowoftheCTEsolution:
Prerequisites¶
Postgres Host¶
Ensure that the Postgres server is installed and running.
For CentOS 7, you need to install the following repository:
sudo yum install -y lsof
CipherTrust Manager¶
Ensure CipherTrust Manager is installed and running.
Configuring CipherTrust Manager Logon to the CipherTrust Manager (CM) Web GUI and perform the following steps:¶
Create a registration token.
Navigate to KeyandAccessManagement and select RegistrationTokens . This token is used for the CTE agent enrollment to CM.
Select NewRegistrationToken to create a new registration token.
The following screenshot shows a registration token created with the name edb .
Create user sets.
Navigate to CTE and select Policies, Policy Elements and then User Sets.
Select Create User Set to create a new user set.
Create the Postgres, EnterpriseDB and Barman user sets as shown in the following screenshots.
CreatePolicies
Navigate back to Policies and select CreatePolicy .
ThefollowingscreenshotsshowLiveDataTransformation(LDT)policiespostgres-policy,epas-policyandbarman-policy.
Note
The policies include the User Sets Postgres and EnterpriseDB respectively created in Step 2 and the same Key Rule for the policies:
Installing CTE Agent¶
Refer to the following guides from Thales for installing the CTE agent on the Postgres host:
CTE Agent Advanced Installation Guide
Note
You will need the Registration Token and host address of the CipherTrust Manager during the installation.
After the CTE agent is successfully installed, verify the Postgres host is registered with CM.
Log on to the CM Web GUI and navigate to CTE .
Select Clients . The client status should appear as Healthy as shown below (you may have to wait a few seconds for the status to get updated).
The following screenshot shows clients registered with the CipherTrust Manager.