1.0 Working in CCM - Administration
In the Fortanix Confidential Computing Manager (CCM), you can perform administration tasks such as signing up, logging in, creating an account, managing your application deployment, assign access, and handle approval requests. You can also view the nodes in your cluster and their attestation status, tasks, and audit logs of cluster events. To get started, sign up.
1.1 Sign Up
- Visit https://ccm.fortanix.com/ to get started.
- Click the SIGN UP button on the top-right corner of the page. Figure 1: Sign Up
- Fill the Sign Up form and enter the necessary details such as Email, First name, Last name, Create password, Retype password.
Figure 2: Sign Up Form
- Select the check box “I’m not a robot” and click SIGN UP.
Figure 3: Sign Up
- After you sign up, the administrator will receive an email to approve this request. After the administrator approves it, you will receive an email notification regarding the approval of the request.
- You will also review an email to verify your email address. Click CONFIRM EMAIL in the email to verify your email. You will be redirected to the CCM UI. Click PROCEED in the CCM UI.
Figure 4: Email Confirmed
- After signing up, the user can log in successfully to the CCM.
1.2 Log In
- Fortanix CCM account.
- A user added in Fortanix CCM with relevant permissions to access the functionality of this service.
- Visit https://ccm.fortanix.com/.
- Enter your E-mail and Password.
- If you have set up Single Sign-On (SSO) for your account then click LOG IN WITH SSO.
Figure 5: Logging In For more details on how to enable SSO using Azure Active Directory refer to Azure AD Authentication Guide.
- Click LOG IN to log in to Fortanix CCM.
- After you log in, create an account using the CCM Accounts page to proceed.
Figure 6: Accounts Page To create an account, refer to the “Create Account” section below.
1.3 Change Password
- In the CCM UI, click the drop-down menu associated with the user's name on the top-right of the UI.
- From the menu, click My profile.
Figure 7: My Profile
- On the My profile page, click the CHANGE PASSWORD button.
Figure 8: Change Password
- Enter the Current Password and type the New Password two times.
Figure 9: New Password
- Click CHANGE PASSWORD button to save changes.
1.4 Create an Account
A CCM account is the top-level container for applications, images, and nodes. An account is generally associated with an organization, rather than an individual. Different accounts are fully isolated from each other. A user can either create a new account or join an existing account. To join an account, an account administrator must invite a user using the user’s email address through the Invite User workflow explained in the User’s Guide: Invite Users. The user needs to contact the account administrator to join an existing account. Upon accepting the invitation to join the account, the user will be added to it.
1.4.1 Disable Fortanix CCM Attestation
If you have a server or laptop that is unable to attest to Intel’s IAS attestation service, but you still want Fortanix CCM to pass attestation so that your compute node can be successfully enrolled to Fortanix CCM, you can create an account with the "test-only deployment" policy. This policy allows the compute nodes to bypass the IAS attestation service, thereby enabling the enrollment of compute nodes that do not fully qualify for the IAS attestation. Refer to step 3 below to bypass IAS attestation.
You need to be an account administrator for the account.
- After you sign up and log in, you will be taken to the Accounts page. Click ADD ACCOUNT to create a new account.
Figure 10: Create an Account
- Enter a name for the new account and optionally add a custom logo for the account.
- To allow compute nodes to bypass Intel's IAS attestation and successfully enroll regardless of attestation failing, click the check box “This is a test-only deployment”.
- Click CREATE ACCOUNT to complete the account creation.
Figure 11: Create Account Complete
- The account is now successfully created.
Figure 12: Account Created Successfully
- Click SELECT ACCOUNT to select the newly created account. Click GO TO ACCOUNT to enter the account and start enrolling the compute nodes and creating applications.
- If you disabled the attestation for compute nodes, you would see a warning in the Fortanix CCM dashboard “Test-only deployment: Compute nodes can be enrolled into Fortanix CCM without attesting to Intel’s IAS attestation service”.
Figure 13: Test-Only Deployment
Figure 14: Customize Account
1.5 Leave an Account
A user has the option to leave an account.
To leave an account:
- Click the overflow menu on the account card.
Figure 15: Leave an Account
- Click LEAVE ACCOUNT to leave an account that you had previously joined.