3 Prerequisites
Customers deploy OCLM from a supplied VMDK image. The image contains the OCLM service payload, service launcher scripts, systemd service configuration, log configuration, and runtime directory structure.
The OCLM service should be started only after Operator CA configuration, initial CMP identity files, and required trust files are installed.
Before starting, patching, or upgrading the OCLM node, collect the following site-specific inputs from the virtualization, networking, PKI, and DSD/SDS teams.
Table 3-1 Prerequisites
| Input | Required Information |
|---|---|
| VM image | Approved OCLM image artifact |
| Administrative access | Initial VM login method and approved password rotation procedure. |
| Operator CA endpoint | CMP server URL, port, path, recipient DN, and timeout policy |
| Operator CA trust | Root and intermediate CA certificate files used to verify issued certificates. |
| Operator CA TLS trust | TLS issuing CA for the Operator CA HTTPS endpoint, if TLS validation is enabled. |
| Initial OCLM identity | Initial CMP client certificate and matching private key for signature-protected CMP requests. |