2.3.5 Provision a User and Associated Wallet

For maximum security, an Exascale user should create and manage their own user credentials, which are stored in a digital key store, also known as a wallet. This enables the user to maintain complete control of their private key.

However, an Exascale administrator can provision an Exascale user and associated wallet. Later, if required, the user can change the keys to regain complete control of their private key.

The following procedure outlines a typical sequence of Exascale Command Line Interface (ESCLI) commands to provision an Exascale user and associated wallet.

The procedure brings together tasks described in Administer Exascale Users and Administer Exascale User Credentials. Refer to the detailed tasks for additional information.

The command examples contain placeholder values for various command arguments, including privatekey.pem, NEWUSER01, and newuser.wallet. Replace these and any other placeholder values in the commands with your own valid values as needed.

To provision a new Exascale user along with an associated wallet:

  1. Create a new public/private key pair.

    For example:

    @> mkkey --private-key-file privatekey.pem --public-key-file publickey.pem

    See also Create User Keys.

  2. Create the Exascale user.

    For example:

    @> mkuser NEWUSER --attributes id=NEWUSER01
    User created with ID: NEWUSER01

    See also Create a User.

  3. Associate the new Exascale user with the public key.

    For example:

    @> chuser NEWUSER01 --public-key-file1 publickey.pem
    User attributes changed successfully.

    See also Create a User.

  4. Provision the new Exascale user with the desired privileges.

    For example, to grant Exascale cluster administration privileges to the new user:

    @> chuser NEWUSER01 --privilege cl_admin
    User attributes changed successfully.
  5. Create a new empty wallet.

    For example:

    @> mkwallet --wallet newuser.wallet
    Wallet created.
  6. Associate the wallet with the new Exascale user.

    For example:

    @> chwallet --wallet newuser.wallet --attributes user=NEWUSER01
    Set user ID to NEWUSER01
    
  7. Put the Exascale user's private key into the wallet.

    For example:

    @> chwallet --wallet newuser.wallet --private-key-file privatekey.pem
    Successfully put private key in wallet.
  8. Add the URL for the Exascale control services endpoint into the wallet.

    For example:

    @> chwallet --wallet newuser.wallet --attributes restEndPoint=exa01ers.example.com:5052
    Default ExaCTRL server address set to exa01ers.example.com:5052.

Related Topics