ADC
   
    
附录
带有输出的示例命令:
运行脚本
     root@ns# pwd
    /var/safenet/config
    root@ns# sh safenet_config
<!--NeedCopy-->
创建证书
    root@ns# cd /var/safenet/safenet/lunaclient/bin
    root@ns# ./vtl createcert -n 10.102.59.175
    Private Key created and written to: /var/safenet/safenet/lunaclient/cert/client/10.102.59.175Key.pem
    Certificate created and written to: /var/safenet/safenet/lunaclient/cert/client/10.102.59.175.pem
<!--NeedCopy-->
将证书复制到 HSM
    root@ns# scp /var/safenet/safenet/lunaclient/cert/client/10.102.59.175.pem admin@10.217.2.7:
    admin@10.217.2.7's password:
    10.102.59.175.pem          100%  818     0.8KB/s   00:00
<!--NeedCopy-->
将证书和密钥从 HSM 复制到 Citrix ADC 设备
    root@ns# scp admin@10.217.2.7:server.pem /var/Thales Luna/safenet/lunaclient/server.2.7.pem
    admin@10.217.2.7's password:
    server.pem            100% 1164     1.1KB/s   00:01
<!--NeedCopy-->
使用 SSH 连接到泰雷兹 Luna HSM
    ssh admin@10.217.2.7
    Connecting to 10.217.2.7:22...
    Connection established.
    To escape to local shell, press 'Ctrl+Alt+]'.
    Last login: Thu Jun 23 02:20:29 2016 from 10.252.243.11
    Luna SA 5.2.3-1 Command Line Shell - Copyright (c) 2001-2014 SafeNet, Inc. All rights reserved.
    [Safenet1] lunash:>hsm login
      Please enter the HSM Administrators' password:
      > *******
    'hsm login' successful.
    Command Result : 0 (Success)
    [Safenet1] lunash:>
<!--NeedCopy-->
在泰雷兹 Luna HSM 上注册 Citrix ADC
    [Safenet1] lunash:>client register -client ns175 -ip 10.102.59.175
    'client register' successful.
    Command Result : 0 (Success)
    [Safenet1] lunash:>
<!--NeedCopy-->
从分区列表中为客户端分配一个分区
    [Safenet1] lunash:>client assignPartition -client ns175 -partition p2
    'client assignPartition' successful.
    Command Result : 0 (Success)
    [Safenet1] lunash:>
<!--NeedCopy-->
在 Citrix ADC 上使用其证书注册 HSM
    root@ns# ./vtl addserver -n 10.217.2.7 -c /var/safenet/safenet/lunaclient/server.2.7.pem
    New server 10.217.2.7 successfully added to server list.
<!--NeedCopy-->
验证 ADC 和 HSM 之间的网络信任链路 (NTL) 连接
    root@ns# ./vtl verify
    The following Luna SA Slots/Partitions were found:
    Slot        Serial #                  Label
    ====      ================           =====
       0              477877010          p2
<!--NeedCopy-->
保存配置
    root@ns# cp /etc/Chrystoki.conf /var/safenet/config/
<!--NeedCopy-->
在引导时配置 Gateway 关守护进程的自动启动
    touch /var/safenet/safenet_is_enrolled
<!--NeedCopy-->
    已复制!
    失败!