Brocade Fabric OS Encryption Administrator’s Guide Support Instrukcja Użytkownika

Przeglądaj online lub pobierz Instrukcja Użytkownika dla Akcesoria komputerowe Brocade Fabric OS Encryption Administrator’s Guide Support. Brocade Fabric OS Encryption Administrator’s Guide Supporting Key Management Interoperability Protocol (KMIP) Key-Compliant Environments (Supporting Fabric OS v7.1.0) User Manual [es] Instrukcja obsługi

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj

Podsumowanie treści

Strona 1 - Fabric OS Encryption

53-1002747-0225 March 2013®53-1002747-02Fabric OS EncryptionAdministrator’s Guide Supporting Key Management Interoperability Protocol (KMIP) Key-Compl

Strona 2 - Document History

x Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Rekeying best practices and policies. . . . . . . . . . . . . . . . . . . . . . . .238

Strona 3 - Contents

82 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Adding target disk LUNs for encryption2Adding target disk LUNs for encryptionYou can

Strona 4

Fabric OS Encryption Administrator’s Guide (KMIP) 8353-1002747-02Adding target disk LUNs for encryption2• Encryption Mode• Encrypt Existing Data• Key

Strona 5

84 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Adding target disk LUNs for encryption2FIGURE 75 Select Initiator Port dialog boxThe

Strona 6

Fabric OS Encryption Administrator’s Guide (KMIP) 8553-1002747-02Adding target disk LUNs for encryption2FIGURE 76 Select LUN dialog box The dialog box

Strona 7

86 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Adding target disk LUNs for encryption2NOTEWith the introduction of Fabric OS v7.1.0,

Strona 8

Fabric OS Encryption Administrator’s Guide (KMIP) 8753-1002747-02Adding target tape LUNs for encryption2Configuring storage arraysThe Storage Array co

Strona 9

88 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Adding target tape LUNs for encryption2FIGURE 78 Encryption Targets dialog box3. Sele

Strona 10 - 53-1002747-02

Fabric OS Encryption Administrator’s Guide (KMIP) 8953-1002747-02Adding target tape LUNs for encryption2FIGURE 80 Add Encryption Target Tape LUNs dial

Strona 11

90 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Moving Targets2• Enable Read Ahead: When selected, enables read pre-fetching on this

Strona 12

Fabric OS Encryption Administrator’s Guide (KMIP) 9153-1002747-02Configuring encrypted tape storage in a multi-path environment2Configuring encrypted

Strona 13 - About This Document

Fabric OS Encryption Administrator’s Guide (KMIP) xi53-1002747-02General encryption troubleshooting . . . . . . . . . . . . . . . . . . . . . . . .26

Strona 14 - Document conventions

92 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Tape LUN write early and read ahead2Tape LUN write early and read aheadThe tape LUN w

Strona 15 - Notes, cautions, and warnings

Fabric OS Encryption Administrator’s Guide (KMIP) 9353-1002747-02Tape LUN statistics2FIGURE 82 Encryption Target Tape LUNs dialog box - Setting tape L

Strona 16 - Additional information

94 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Tape LUN statistics2Viewing and clearing tape container statisticsYou can view LUN st

Strona 17 - Getting technical help

Fabric OS Encryption Administrator’s Guide (KMIP) 9553-1002747-02Tape LUN statistics2• Tape Session #: The number of the ongoing tape session.• Uncomp

Strona 18 - Document feedback

96 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Tape LUN statistics2FIGURE 85 Target Tape LUNs dialog box4. Select the LUN or LUNs fo

Strona 19 - Encryption Overview

Fabric OS Encryption Administrator’s Guide (KMIP) 9753-1002747-02Tape LUN statistics2• A Refresh button updates the statistics on the display since th

Strona 20 - Terminology

98 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encryption engine rebalancing2FIGURE 88 Tape LUN Statistics dialog boxThe dialog box

Strona 21

Fabric OS Encryption Administrator’s Guide (KMIP) 9953-1002747-02Master keys2During rebalancing operations, be aware of the following:• You might noti

Strona 22 - The Brocade Encryption Switch

100 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Master keys2The new master key cannot be used (no new data encryption keys can be cr

Strona 23 - Performance licensing

Fabric OS Encryption Administrator’s Guide (KMIP) 10153-1002747-02Master keys2Refer to the following procedures for more information:- “Saving the mas

Strona 24 - Usage limitations

xii Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02

Strona 25 - FIGURE 2 Encryption overview

102 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Master keys2FIGURE 89 Backup Destination (to file) dialog box4. Select File as the B

Strona 26 - FIGURE 3 Frame redirection

Fabric OS Encryption Administrator’s Guide (KMIP) 10353-1002747-02Master keys2FIGURE 90 Backup Destination (to key vault) dialog box4. Select Key Vaul

Strona 27 - IO Sync LAN

104 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Master keys2FIGURE 91 Backup Destination (to smart cards) dialog box4. Select A Reco

Strona 28 - FIGURE 5 DEK life cycle

Fabric OS Encryption Administrator’s Guide (KMIP) 10553-1002747-02Master keys2Saving a master key to a smart card set - OverviewA card reader must be

Strona 29 - Support for virtual fabrics

106 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Master keys2FIGURE 92 Select a Master Key to Restore (from file) dialog box4. Choose

Strona 30

Fabric OS Encryption Administrator’s Guide (KMIP) 10753-1002747-02Master keys2FIGURE 93 Select a Master Key to Restore (from key vault) dialog box4. C

Strona 31

108 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Master keys2FIGURE 94 Select a Master Key to Restore (from a recovery set of smart c

Strona 32 - Encryption Center features

Fabric OS Encryption Administrator’s Guide (KMIP) 10953-1002747-02Security Settings2Security Settings Security settings help you identify if system ca

Strona 33 - Encryption user privileges

110 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Zeroizing an encryption engine2NOTEZeroizing an engine affects the I/Os, but all tar

Strona 34 - Smart card usage

Fabric OS Encryption Administrator’s Guide (KMIP) 11153-1002747-02Using the Encryption Targets dialog box2Using the Encryption Targets dialog boxThe E

Strona 35

Fabric OS Encryption Administrator’s Guide (KMIP) xiii53-1002747-02About This DocumentIn this chapter•How this document is organized . . . . . . . .

Strona 36

112 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Redirection zones2Redirection zonesIt is recommended that you configure the host and

Strona 37

Fabric OS Encryption Administrator’s Guide (KMIP) 11353-1002747-02Disk device decommissioning2Provided that the crypto configuration is not left uncom

Strona 38

114 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Disk device decommissioning2In order to delete keys from the key vault, you need to

Strona 39 - Using system cards

Fabric OS Encryption Administrator’s Guide (KMIP) 11553-1002747-02Rekeying all disk LUNs manually2Displaying Universal IDsIn order to delete keys from

Strona 40

116 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Rekeying all disk LUNs manually2Setting disk LUN Re-key AllTo rekey all disk LUNs on

Strona 41 - Tracking smart cards

Fabric OS Encryption Administrator’s Guide (KMIP) 11753-1002747-02Rekeying all disk LUNs manually2.FIGURE 99 Pending manual rekey operations Viewing d

Strona 42

118 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Rekeying all disk LUNs manually2FIGURE 100 Encryption Target Disk LUNs dialog box4.

Strona 43 - Editing smart cards

Fabric OS Encryption Administrator’s Guide (KMIP) 11953-1002747-02Rekeying all disk LUNs manually2Viewing the progress of manual rekey operationsTo mo

Strona 44 - Network connections

120 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Thin provisioned LUNs2• Current LBA: The Logical Block Address (LBA) of the block th

Strona 45 - Blade processor links

Fabric OS Encryption Administrator’s Guide (KMIP) 12153-1002747-02Viewing time left for auto rekey2• If you are running a Fabric OS version earlier th

Strona 46 - (KAC) certificate

xiv Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02• Chapter 6, “Maintenance and Troubleshooting,” provides information on troubleshoot

Strona 47

122 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Viewing and editing switch encryption properties2The Encryption Target Disk LUNs dia

Strona 48

Fabric OS Encryption Administrator’s Guide (KMIP) 12353-1002747-02Viewing and editing switch encryption properties2FIGURE 103 Encryption Switch Proper

Strona 49

124 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Viewing and editing switch encryption properties2• Encryption Group: The name of the

Strona 50

Fabric OS Encryption Administrator’s Guide (KMIP) 12553-1002747-02Viewing and editing switch encryption properties2• Online• Set State To: Identifies

Strona 51

126 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Viewing and editing encryption group properties2FIGURE 104 Import Signed Certificate

Strona 52

Fabric OS Encryption Administrator’s Guide (KMIP) 12753-1002747-02Viewing and editing encryption group properties2The Encryption Group Properties dial

Strona 53

128 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Viewing and editing encryption group properties2General tabThe General tab (Figure 1

Strona 54 - -----BEGIN CERTIFICATE

Fabric OS Encryption Administrator’s Guide (KMIP) 12953-1002747-02Viewing and editing encryption group properties2When the first encryption engine com

Strona 55

130 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Viewing and editing encryption group properties2• Not responding• Failed authenticat

Strona 56

Fabric OS Encryption Administrator’s Guide (KMIP) 13153-1002747-02Viewing and editing encryption group properties2• Connection Status: The switch’s co

Strona 57

Fabric OS Encryption Administrator’s Guide (KMIP) xv53-1002747-02Command syntax conventionsCommand syntax in this manual follows these conventions:Not

Strona 58

132 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Viewing and editing encryption group properties2Members tab Remove buttonYou can cli

Strona 59

Fabric OS Encryption Administrator’s Guide (KMIP) 13353-1002747-02Viewing and editing encryption group properties2A warning message is displayed when

Strona 60

134 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Viewing and editing encryption group properties2FIGURE 108 Encryption Group Properti

Strona 61

Fabric OS Encryption Administrator’s Guide (KMIP) 13553-1002747-02Viewing and editing encryption group properties2• Registered Authentication Cards ta

Strona 62

136 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Viewing and editing encryption group properties2• Right- and Left-arrow buttons: You

Strona 63

Fabric OS Encryption Administrator’s Guide (KMIP) 13753-1002747-02Viewing and editing encryption group properties2Tape Pools tabTape pools are managed

Strona 64

138 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Viewing and editing encryption group properties2All encryption engines in the encryp

Strona 65

Fabric OS Encryption Administrator’s Guide (KMIP) 13953-1002747-02Viewing and editing encryption group properties24. Based on your selection, do one o

Strona 66

140 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encryption-related acronyms in log messages2FIGURE 113 Encryption Group Properties D

Strona 67 - Encryption preparation

Fabric OS Encryption Administrator’s Guide (KMIP) 14153-1002747-02Chapter3Configuring Encryption Using the CLIIn this chapter•Overview. . . . . . . .

Strona 68 - Creating an encryption group

xvi Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Key termsFor definitions specific to Brocade and Fibre Channel, see the technical gl

Strona 69

142 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Overview3OverviewThis chapter explains how to use the command line interface (CLI) t

Strona 70

Fabric OS Encryption Administrator’s Guide (KMIP) 14353-1002747-02Command RBAC permissions and AD types34. PortMember: allows all control operations o

Strona 71

144 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Command RBAC permissions and AD types3createhaclusterNOMN N N OMN NDisallowedcreatet

Strona 72

Fabric OS Encryption Administrator’s Guide (KMIP) 14553-1002747-02Cryptocfg Help command output3Cryptocfg Help command outputAll encryption operations

Strona 73 - Protocol (KMIP)

146 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Management LAN configuration3switch:admin> cryptocfg --help -nodecfgUsage: crypto

Strona 74

Fabric OS Encryption Administrator’s Guide (KMIP) 14753-1002747-02Configuring cluster links3The following example configures a static IP address and g

Strona 75

148 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Setting encryption node initialization3IP Address change of a node within an encrypt

Strona 76

Fabric OS Encryption Administrator’s Guide (KMIP) 14953-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)3From the standpoint of

Strona 77

150 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)36. Configure the KMIP s

Strona 78 - --initnode command

Fabric OS Encryption Administrator’s Guide (KMIP) 15153-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)33. Verify the cluster s

Strona 79 - --reg keyvault

Fabric OS Encryption Administrator’s Guide (KMIP) xvii53-1002747-02For information about the Key Management Interoperability Protocol standard, visit

Strona 80

152 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Configuring the Brocade Encryption Switch key vault setup (SafeNet KeySecure)3h. Aft

Strona 81

Fabric OS Encryption Administrator’s Guide (KMIP) 15353-1002747-02Configuring the Brocade Encryption Switch key vault setup (SafeNet KeySecure)3Signin

Strona 82

154 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Configuring the Brocade Encryption Switch key vault setup (SafeNet KeySecure)33. Und

Strona 83

Fabric OS Encryption Administrator’s Guide (KMIP) 15553-1002747-02Configuring the Brocade Encryption Switch key vault setup (SafeNet KeySecure)32. On

Strona 84 - Error Instructions dialog box

156 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Configuring the Brocade Encryption Switch key vault setup (SafeNet KeySecure)3Regist

Strona 85

Fabric OS Encryption Administrator’s Guide (KMIP) 15753-1002747-02Configuring the Brocade Encryption Switch key vault setup (SafeNet KeySecure)3Time o

Strona 86

158 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Configuring the Brocade Encryption Switch key vault setup (SafeNet KeySecure)3Notify

Strona 87 - Creating HA clusters

Fabric OS Encryption Administrator’s Guide (KMIP) 15953-1002747-02Configuring the Brocade Encryption Switch key vault setup (SafeNet KeySecure)3The fo

Strona 88

160 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Adding a member node to an encryption group3 Server SDK Version:

Strona 89 - Invoking failback

Fabric OS Encryption Administrator’s Guide (KMIP) 16153-1002747-02Adding a member node to an encryption group3CAUTIONAfter adding the member node to t

Strona 90 - Adding an encryption target

xviii Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-023. World Wide Name (WWN)Use the licenseIdShow command to display the WWN of the ch

Strona 91 - 4. Click Next

162 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Adding a member node to an encryption group3NOTEIf the maximum number of certificate

Strona 92

Fabric OS Encryption Administrator’s Guide (KMIP) 16353-1002747-02Generating and backing up the master key3Additional Secondary Key Vault Information:

Strona 93

164 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02High availability clusters32. Export the master key to the key vault. Make a note of

Strona 94

Fabric OS Encryption Administrator’s Guide (KMIP) 16553-1002747-02High availability clusters3• It is recommended that the HA cluster configuration be

Strona 95

166 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02High availability clusters3Adding an encryption engine to an HA cluster1. Log in to

Strona 96

Fabric OS Encryption Administrator’s Guide (KMIP) 16753-1002747-02High availability clusters3Number of HA Clusters: 1HA cluster name: dthac - 2 EE ent

Strona 97 - FIGURE 70 Next Steps screen

168 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02High availability clusters3Policy Configuration ExamplesThe following examples illus

Strona 98

Fabric OS Encryption Administrator’s Guide (KMIP) 16953-1002747-02Re-exporting a master key3Re-exporting a master keyYou can export master keys to the

Strona 99

170 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Re-exporting a master key3Exporting an additional key IDExample: Subsequent master k

Strona 100

Fabric OS Encryption Administrator’s Guide (KMIP) 17153-1002747-02Re-exporting a master key3e3:ae:aa:89:ec:12:0c:04:29:61:9c:99:44:a3:9b:9ae3:ae:aa:89

Strona 101

Fabric OS Encryption Administrator’s Guide (KMIP) 153-1002747-02Chapter1Encryption OverviewIn this chapter•Host and LUN considerations . . . . . . . .

Strona 102

172 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Enabling the encryption engine3Enabling the encryption engineEnable the encryption e

Strona 103

Fabric OS Encryption Administrator’s Guide (KMIP) 17353-1002747-02Zoning considerations3 No HA cluster membership EE Attributes: Media T

Strona 104

174 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Zoning considerations3Frame redirection zoningName Server-based frame redirection en

Strona 105 - Configuring storage arrays

Fabric OS Encryption Administrator’s Guide (KMIP) 17553-1002747-02Zoning considerations3 Redirect: No The Local Name Server has 1 entry }The nsshow co

Strona 106

176 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02CryptoTarget container configuration37. Create a zone that includes the initiator an

Strona 107

Fabric OS Encryption Administrator’s Guide (KMIP) 17753-1002747-02CryptoTarget container configuration3FIGURE 118 Relationship between initiator, virt

Strona 108 - Moving Targets

178 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02CryptoTarget container configuration3• When removing an existing disk or tape target

Strona 109

Fabric OS Encryption Administrator’s Guide (KMIP) 17953-1002747-02CryptoTarget container configuration3FabricAdmin:switch> cryptocfg --create -cont

Strona 110

180 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02CryptoTarget container configuration3zone: red_______base 00:00:00:00:00:00:00:01;

Strona 111 - Tape LUN statistics

Fabric OS Encryption Administrator’s Guide (KMIP) 18153-1002747-02CryptoTarget container configuration3Deleting a CryptoTarget containerYou may delete

Strona 112

Copyright © 2012- 2013 Brocade Communications Systems, Inc. All Rights Reserved.Brocade, Brocade Assurance, the B-wing symbol, BigIron, DCX, Fabric OS

Strona 113

2 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Terminology1TerminologyThe following are definitions of terms used extensively in this

Strona 114

182 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Crypto LUN configuration3NOTEIf a CryptoTarget container is moved in a configuration

Strona 115

Fabric OS Encryption Administrator’s Guide (KMIP) 18353-1002747-02Crypto LUN configuration3Discovering a LUNWhen adding a LUN to a CryptoTarget contai

Strona 116 - Encryption engine rebalancing

184 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Crypto LUN configuration3NOTEThere is a maximum of 512 disk LUNs per Initiator in a

Strona 117 - Master keys

Fabric OS Encryption Administrator’s Guide (KMIP) 18553-1002747-02Crypto LUN configuration3VT: 20:00:00:05:1e:41:4e:1d 20:01:00:05:1e:41:4e:1dNumber o

Strona 118 - Alternate master key

186 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Crypto LUN configuration3TABLE 6 LUN parameters and policies Policy name Command pa

Strona 119

Fabric OS Encryption Administrator’s Guide (KMIP) 18753-1002747-02Crypto LUN configuration3Configuring a tape LUNThis example shows how to configure a

Strona 120 - ATTENTION

188 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Crypto LUN configuration3LUN serial number:Key ID state: Key ID not Applicab

Strona 121

Fabric OS Encryption Administrator’s Guide (KMIP) 18953-1002747-02Crypto LUN configuration3FabricAdmin:switch> cryptocfg --remove -LUN my_disk_tgt

Strona 122

190 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Crypto LUN configuration3CAUTIONWhen configuring a LUN with multiple paths, do not c

Strona 123

Fabric OS Encryption Administrator’s Guide (KMIP) 19153-1002747-02Impact of tape LUN configuration changes3Impact of tape LUN configuration changesLUN

Strona 124

Fabric OS Encryption Administrator’s Guide (KMIP) 353-1002747-02Terminology1Opaque Key VaultA storage location that provides untrusted key management

Strona 125

192 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Configuring a multi-path Crypto LUN3Multi-path LUN configuration exampleFigure 119 o

Strona 126 - Creating a master key

Fabric OS Encryption Administrator’s Guide (KMIP) 19353-1002747-02Configuring a multi-path Crypto LUN3c. Create a CryptoTarget container (CTC2) for ta

Strona 127 - Security Settings

194 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Configuring a multi-path Crypto LUN3b. Add the same LUN to the CryptoTarget containe

Strona 128 - Setting zeroization

Fabric OS Encryption Administrator’s Guide (KMIP) 19553-1002747-02Decommissioning LUNs3Decommissioning LUNsA disk device needs to be decommissioned wh

Strona 129

196 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Decommissioning LUNs33. Enter cryptocfg --show -decommissionedkeyids to obtain a lis

Strona 130 - Disk device decommissioning

Fabric OS Encryption Administrator’s Guide (KMIP) 19753-1002747-02Decommissioning replicated LUNs3Decommissioning replicated LUNsThe following scenari

Strona 131 - Decommissioning disk LUNs

198 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Force-enabling a decommissioned disk LUN for encryption3NOTEDo not delete the key fr

Strona 132

Fabric OS Encryption Administrator’s Guide (KMIP) 19953-1002747-02Force-enabling a disabled disk LUN for encryption37. En a bl e th e LU N .FabricAd

Strona 133 - Displaying Universal IDs

200 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Tape pool configuration3Tape pool configurationTape pools are used by tape backup ap

Strona 134 - Setting disk LUN Re-key All

Fabric OS Encryption Administrator’s Guide (KMIP) 20153-1002747-02Tape pool configuration3CommVault Galaxy labelingCommVault uses a storage policy for

Strona 135

4 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02The Brocade Encryption Switch1The Brocade Encryption SwitchThe Brocade Encryption Swit

Strona 136

202 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Tape pool configuration3Creating a tape poolTake the following steps to create a tap

Strona 137

Fabric OS Encryption Administrator’s Guide (KMIP) 20353-1002747-02Tape pool configuration3Deleting a tape poolThis command does not issue a warning if

Strona 138 - Thin provisioned LUNs

204 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02First-time encryption3First-time encryptionFirst-time encryption, also referred to a

Strona 139 - Thin provisioning support

Fabric OS Encryption Administrator’s Guide (KMIP) 20553-1002747-02Thin provisioned LUNs3Thin provisioned LUNsWith the introduction of Fabric OS 7.1.0,

Strona 140

206 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Thin provisioned LUNs3Encryption algorithm: AES256-XTSKey ID state: Read

Strona 141

Fabric OS Encryption Administrator’s Guide (KMIP) 20753-1002747-02Data rekeying3• Because windows host utility “sdelete –c” sends WRITE command with z

Strona 142

208 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Data rekeying3Configuring a LUN for automatic rekeyingRekeying options are configure

Strona 143

Fabric OS Encryption Administrator’s Guide (KMIP) 20953-1002747-02Data rekeying3Initiating a manual rekey sessionYou can initiate a rekeying session m

Strona 144

210 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Data rekeying3Current LBA: 488577Operation succeeded.Suspension and resum

Strona 145

Fabric OS Encryption Administrator’s Guide (KMIP) 21153-1002747-02Chapter4Deployment ScenariosIn this chapter•Single encryption switch, two paths from

Strona 146 - General tab

Fabric OS Encryption Administrator’s Guide (KMIP) 553-1002747-02The FS8-18 blade1The FS8-18 bladeThe FS8-18 blade provides the same features and funct

Strona 147

212 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Single encryption switch, two paths from host to target4Single encryption switch, tw

Strona 148 - Members tab

Fabric OS Encryption Administrator’s Guide (KMIP) 21353-1002747-02Single fabric deployment - HA cluster4Single fabric deployment - HA clusterFigure 12

Strona 149

214 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Single fabric deployment - DEK cluster4In Figure 121, the two encryption switches pr

Strona 150 - Members tab Remove button

Fabric OS Encryption Administrator’s Guide (KMIP) 21553-1002747-02Dual fabric deployment - HA and DEK cluster4In Figure 122, two encryption switches a

Strona 151 - Security tab

216 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Multiple paths, one DEK cluster, and two HA clusters4failover for the encryption pat

Strona 152

Fabric OS Encryption Administrator’s Guide (KMIP) 21753-1002747-02Multiple paths, one DEK cluster, and two HA clusters4The configuration details shown

Strona 153 - HA Clusters tab

218 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Multiple paths, DEK cluster, no HA cluster4Multiple paths, DEK cluster, no HA cluste

Strona 154

Fabric OS Encryption Administrator’s Guide (KMIP) 21953-1002747-02Multiple paths, DEK cluster, no HA cluster4The configuration details are as follows:

Strona 155 - Tape Pools tab

220 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Deployment in Fibre Channel routed fabrics4Deployment in Fibre Channel routed fabric

Strona 156 - Adding tape pools

Fabric OS Encryption Administrator’s Guide (KMIP) 22153-1002747-02Deployment in Fibre Channel routed fabrics4The following is a summary of steps for c

Strona 157 - Engine Operations tab

6 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Recommendation for connectivity1Recommendation for connectivityIn order to achieve hig

Strona 158 - TABLE 3 Encryption acronyms

222 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Deployment as part of an edge fabric4Deployment as part of an edge fabricIn this dep

Strona 159 - In this chapter

Fabric OS Encryption Administrator’s Guide (KMIP) 22353-1002747-02Deployment with FCIP extension switches4Deployment with FCIP extension switchesEncry

Strona 160 - Command validation checks

224 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02VMware ESX server deployments4VMware ESX server deploymentsVMware ESX servers may ho

Strona 161

Fabric OS Encryption Administrator’s Guide (KMIP) 22553-1002747-02VMware ESX server deployments4Figure 131 shows a VMware ESX server with two guest op

Strona 162 - (Continued)

226 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02VMware ESX server deployments4

Strona 163 - Cryptocfg Help command output

Fabric OS Encryption Administrator’s Guide (KMIP) 22753-1002747-02Chapter5Best Practices and Special TopicsIn this chapter•Firmware upgrade and downgr

Strona 164 - Configuring cluster links

228 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Firmware upgrade and downgrade considerations5Firmware upgrade and downgrade conside

Strona 165

Fabric OS Encryption Administrator’s Guide (KMIP) 22953-1002747-02Firmware upgrade and downgrade considerations5• Guidelines for firmware upgrade of e

Strona 166 - Node is a member node

230 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Configuration upload and download considerations58. Check that CryptoTarget Containe

Strona 167

Fabric OS Encryption Administrator’s Guide (KMIP) 23153-1002747-02Configuration upload and download considerations5• Certificates generated internally

Strona 168 - Creating a cluster

Fabric OS Encryption Administrator’s Guide (KMIP) 753-1002747-02Brocade encryption solution overview1Brocade encryption solution overviewThe loss of s

Strona 169 - Adding a node to the cluster

232 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02HP-UX considerations5Steps after configuration downloadFor all opaque key vaults, re

Strona 170 - KeySecure)

Fabric OS Encryption Administrator’s Guide (KMIP) 23353-1002747-02AIX Considerations5Best practices are as follows:• Create a cryptoTarget container f

Strona 171

234 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Tape metadata5Tape metadataOne kilobyte of metadata is added per tape block for both

Strona 172

Fabric OS Encryption Administrator’s Guide (KMIP) 23553-1002747-02Tape block zero handling5Tape pool configuration is used only when labeling of tape

Strona 173

236 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Redirection zones5• Before committing CryptoTarget container or LUN configurations o

Strona 174 - Verify connectivity

Fabric OS Encryption Administrator’s Guide (KMIP) 23753-1002747-02Deployment with Admin Domains (AD)5Deployment with Admin Domains (AD)Virtual devices

Strona 175 - • Node CP certificate

238 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02PID failover5PID failover Virtual device PIDs do not persist upon failover within a

Strona 176

Fabric OS Encryption Administrator’s Guide (KMIP) 23953-1002747-02KAC certificate registration expiry5Allow rekey to complete before deleting a contai

Strona 177

240 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Changing IP addresses in encryption groups5Changing IP addresses in encryption group

Strona 178 - • cryptocfg --enableEE

Fabric OS Encryption Administrator’s Guide (KMIP) 24153-1002747-02Best practices for host clusters in an encryption environment5FIGURE 132 Fan-in rati

Strona 179

8 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Brocade encryption solution overview1Data flow from server to storageThe Brocade Encry

Strona 180

242 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02HA Cluster deployment considerations and best practices5• For AIX-based Power HA Sys

Strona 181

Fabric OS Encryption Administrator’s Guide (KMIP) 24353-1002747-02Chapter6Maintenance and TroubleshootingIn this chapter•Encryption group and HA clust

Strona 182 - High availability clusters

244 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encryption group and HA cluster maintenance6Encryption group and HA cluster maintena

Strona 183 - Creating an HA cluster

Fabric OS Encryption Administrator’s Guide (KMIP) 24553-1002747-02Encryption group and HA cluster maintenance6FIGURE 133 Removing a node from an encry

Strona 184

246 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encryption group and HA cluster maintenance6 IP Address: 10.32.33

Strona 185

Fabric OS Encryption Administrator’s Guide (KMIP) 24753-1002747-02Encryption group and HA cluster maintenance6Deleting an encryption groupYou can dele

Strona 186 - Policy Configuration Examples

248 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encryption group and HA cluster maintenance6Displaying the HA cluster configurationN

Strona 187 - Re-exporting a master key

Fabric OS Encryption Administrator’s Guide (KMIP) 24953-1002747-02Encryption group and HA cluster maintenance6Replacing an HA cluster member1. Log in

Strona 188 - Viewing the master key IDs

250 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encryption group and HA cluster maintenance6FIGURE 134 Replacing a failed encryption

Strona 189

Fabric OS Encryption Administrator’s Guide (KMIP) 25153-1002747-02Encryption group and HA cluster maintenance6Case 2: Replacing a “live” encryption en

Strona 190

Fabric OS Encryption Administrator’s Guide (KMIP) 953-1002747-02Data encryption key life cycle management1Data encryption key life cycle managementDat

Strona 191 - Zoning considerations

252 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encryption group and HA cluster maintenance6Performing a manual failback of an encry

Strona 192 - Frame redirection zoning

Fabric OS Encryption Administrator’s Guide (KMIP) 25353-1002747-02Encryption group merge and split use cases6• After the failback completes, the crypt

Strona 193

254 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encryption group merge and split use cases6NOTEWhen attempting to reclaim a failed B

Strona 194

Fabric OS Encryption Administrator’s Guide (KMIP) 25553-1002747-02Encryption group merge and split use cases6RecoveryIf auto failback policy is set, n

Strona 195

256 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encryption group merge and split use cases6• The isolation of N3 from the group lead

Strona 196 - Gathering information

Fabric OS Encryption Administrator’s Guide (KMIP) 25753-1002747-02Encryption group merge and split use cases6Recovery1. Restore the connection between

Strona 197

258 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encryption group merge and split use cases6NOTEThe collective time allowed (the hear

Strona 198

Fabric OS Encryption Administrator’s Guide (KMIP) 25953-1002747-02Encryption group merge and split use cases6NOTEIf one or more EG status displays as

Strona 199

260 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encryption group merge and split use cases6Display the encryption group state again.

Strona 200 - Crypto LUN configuration

Fabric OS Encryption Administrator’s Guide (KMIP) 26153-1002747-02Encryption group merge and split use cases6If you now perform a cryptocfg --show -gr

Strona 201 - Configuring a Crypto LUN

10 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Data encryption key life cycle management1FIGURE 5 DEK life cycle

Strona 202

262 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encryption group merge and split use cases66. Verify your encryption group is re-con

Strona 203

Fabric OS Encryption Administrator’s Guide (KMIP) 26353-1002747-02Encryption group database manual operations6Encryption group database manual operati

Strona 204 - LUN parameters and policies

264 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Key vault diagnostics6Use the --sync -securitydb command to distribute the security

Strona 205 - Configuring a tape LUN

Fabric OS Encryption Administrator’s Guide (KMIP) 26553-1002747-02Measuring encryption performance6• Key class and format on the KV configured for the

Strona 206

266 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Measuring encryption performance6FabricAdmin:switch> cryptocfg --perfshow [slot]

Strona 207

Fabric OS Encryption Administrator’s Guide (KMIP) 26753-1002747-02General encryption troubleshooting6General encryption troubleshootingTable 9 lists t

Strona 208

268 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02General encryption troubleshooting6A backup fails because the LUN is always in the i

Strona 209

Fabric OS Encryption Administrator’s Guide (KMIP) 26953-1002747-02General encryption troubleshooting6A performance drop occurs when using DPM on a Mic

Strona 210

270 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Troubleshooting examples using the CLI6Troubleshooting examples using the CLIEncrypt

Strona 211

Fabric OS Encryption Administrator’s Guide (KMIP) 27153-1002747-02Troubleshooting examples using the CLI6Encryption Disabled CryptoTarget LUNIf the LU

Strona 212

Fabric OS Encryption Administrator’s Guide (KMIP) 1153-1002747-02Master key management1Master key managementCommunications with opaque key vaults are

Strona 213 - Decommissioning LUNs

272 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Management application encryption wizard troubleshooting6Management application encr

Strona 214

Fabric OS Encryption Administrator’s Guide (KMIP) 27353-1002747-02Management application encryption wizard troubleshooting6Errors related to adding a

Strona 215

274 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Management application encryption wizard troubleshooting6General errors related to t

Strona 216

Fabric OS Encryption Administrator’s Guide (KMIP) 27553-1002747-02LUN policy troubleshooting6LUN policy troubleshootingTable 14 may be used as an aid

Strona 217

276 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Loss of encryption group leader after power outage6Loss of encryption group leader a

Strona 218 - Tape pool configuration

Fabric OS Encryption Administrator’s Guide (KMIP) 27753-1002747-02MPIO and internal LUN states65. Synchronize the crypto configurations across all mem

Strona 219 - NetWorker labeling

278 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02FS8-18 blade removal and replacement61. Enter the cryptocfg --resume_rekey command,

Strona 220 - Creating a tape pool

Fabric OS Encryption Administrator’s Guide (KMIP) 27953-1002747-02FS8-18 blade removal and replacement63. If the replaced FS8-18 blade is in member no

Strona 221 - Modifying a tape pool

280 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02FS8-18 blade removal and replacement6NOTEBecause the FS8-18 blade was inserted in th

Strona 222 - First-time encryption

Fabric OS Encryption Administrator’s Guide (KMIP) 28153-1002747-02Brocade Encryption Switch removal and replacement611. If a master key is not present

Strona 223

Fabric OS Encryption Administrator’s Guide (KMIP) iii53-1002747-02ContentsAbout This DocumentIn this chapter . . . . . . . . . . . . . . . . . . . . .

Strona 224 - Space reclamation

12 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Cisco Fabric Connectivity support1Cisco Fabric Connectivity supportThe Brocade Encryp

Strona 225 - Data rekeying

282 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Brocade Encryption Switch removal and replacement68. Power on the new Brocade Encryp

Strona 226

Fabric OS Encryption Administrator’s Guide (KMIP) 28353-1002747-02Brocade Encryption Switch removal and replacement621. Import the signed CSR/Cert ont

Strona 227

284 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Brocade Encryption Switch removal and replacement631. If HA cluster membership for t

Strona 228

Fabric OS Encryption Administrator’s Guide (KMIP) 28553-1002747-02Brocade Encryption Switch removal and replacement611. Invoke the following command t

Strona 229 - Deployment Scenarios

286 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Reclaiming the WWN base of a failed Brocade Encryption Switch627. Verify that defzon

Strona 230

Fabric OS Encryption Administrator’s Guide (KMIP) 28753-1002747-02Removing stale rekey information for a LUN6NOTEWhen attempting to reclaim a failed B

Strona 231 - Virtual

288 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Splitting an encryption group into two encryption groups6NOTEYou should not join a F

Strona 232

Fabric OS Encryption Administrator’s Guide (KMIP) 28953-1002747-02Moving an encryption blade from one EG to another in the same fabric6a. Create the g

Strona 233

290 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Moving an encryption switch from one EG to another in the same fabric6Moving an encr

Strona 234

Fabric OS Encryption Administrator’s Guide (KMIP) 29153-1002747-02AppendixAState and Status InformationIn this appendix•Encryption engine security pro

Strona 235

Fabric OS Encryption Administrator’s Guide (KMIP) 1353-1002747-02Chapter2Configuring Encryption Using the Management ApplicationIn this chapter•Encryp

Strona 236

292 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Security processor KEK statusASecurity processor KEK statusTable 19 lists security p

Strona 237

Fabric OS Encryption Administrator’s Guide (KMIP) 29353-1002747-02Encrypted LUN statesALUN_1ST_TIME_REKEY_IN_PROG First time rekey is in progress.LUN_

Strona 238

294 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encrypted LUN statesALUN_DIS_WR_META_DONE_ERR Disabled (Write metadata done with fai

Strona 239 - --rdcreate [host wwn]

Fabric OS Encryption Administrator’s Guide (KMIP) 29553-1002747-02Encrypted LUN statesATABLE 21 Tape LUN statesInternal Names Console String Explanati

Strona 240

296 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encrypted LUN statesALUN_ENCRYPT Encryption enabled The tape medium is present, and

Strona 241 - FIGURE 129 FCIP deployment

Fabric OS Encryption Administrator’s Guide (KMIP) 29753-1002747-02IndexAadd commands--add -haclustermember, 166--add -initiator, 179, 187, 193--add -L

Strona 242 - VMware ESX server deployments

298 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Crypto LUNadding to CryptoTarget container using the CLI, 182configuring, 182, 183mo

Strona 243

Fabric OS Encryption Administrator’s Guide (KMIP) 29953-1002747-02disk lunsdecommissioning, 113rekeying manually, 115setting rekey all, 116viewing rek

Strona 244

300 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02encryption nodesetting initialization, 28encryption nodessetting initialization, 148

Strona 245

Fabric OS Encryption Administrator’s Guide (KMIP) 30153-1002747-02Iimport commands, --import, 161initialize commands--initEE, 254initEE, 158--initnode

Strona 246 - General guidelines

14 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encryption Center features2•Viewing and editing encryption group properties . . . . .

Strona 247

302 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02member nodesadding to an encryption group, 160members tab, 130remove button, 132modi

Strona 248

Fabric OS Encryption Administrator’s Guide (KMIP) 30353-1002747-02set commands--set -failback, 168--set -keyvault LKM, 159show commands--show, 162, 17

Strona 249

304 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02troubleshootingcfgshow command, 267configshow, 267cryptocfg --show -groupcfg command

Strona 250 - HP-UX considerations

Fabric OS Encryption Administrator’s Guide (KMIP) 1553-1002747-02Encryption user privileges2Encryption user privilegesIn BNA, resource groups are assi

Strona 251 - Disk metadata

16 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Smart card usage2Smart card usageSmart Cards are credit card-sized cards that contain

Strona 252 - Tape pools

Fabric OS Encryption Administrator’s Guide (KMIP) 1753-1002747-02Smart card usage2• Establishing a trusted link with the NetApp LKM key vault.• Decomm

Strona 253 - Tape key expiry

18 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Smart card usage23. Locate the Authentication Card Quorum Size and select the quorum

Strona 254

Fabric OS Encryption Administrator’s Guide (KMIP) 1953-1002747-02Smart card usage2Registering authentication cards from the databaseSmart cards that a

Strona 255

20 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Smart card usage2Deregistering an authentication cardAuthentication cards can be remo

Strona 256 - PID failover

Fabric OS Encryption Administrator’s Guide (KMIP) 2153-1002747-02Smart card usage2Using system cardsSystem cards are smart cards that can be used to c

Strona 257

iv Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Support for virtual fabrics. . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Strona 258

22 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Smart card usage2Enabling or disabling the system card requirementTo use a system car

Strona 259

Fabric OS Encryption Administrator’s Guide (KMIP) 2353-1002747-02Smart card usage2Deregistering system cardsSystem cards can be removed from the datab

Strona 260 - Tape Device LUN Mapping

24 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Smart card usage2FIGURE 12 Smart Card asset tracking dialog boxThe Smart Cards table

Strona 261

Fabric OS Encryption Administrator’s Guide (KMIP) 2553-1002747-02Smart card usage2• Save As button: Saves the entire list of smart cards to a file. Th

Strona 262

26 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Network connections22. Insert the smart card into the card reader.3. After the card’s

Strona 263

Fabric OS Encryption Administrator’s Guide (KMIP) 2753-1002747-02Blade processor links2Blade processor linksEach encryption switch or blade has two Gb

Strona 264

28 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encryption node initialization and certificate generation23. Enter the link IP addres

Strona 265 - Removing an HA cluster member

Fabric OS Encryption Administrator’s Guide (KMIP) 2953-1002747-02Key Management Interoperability Protocol2Key Management Interoperability Protocol The

Strona 266

30 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2NOTEIf you are configuri

Strona 267

Fabric OS Encryption Administrator’s Guide (KMIP) 3153-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2Setting FIPS compliance1

Strona 268

Fabric OS Encryption Administrator’s Guide (KMIP) v53-1002747-02High availability (HA) clusters . . . . . . . . . . . . . . . . . . . . . . . . . . .

Strona 269 - Deleting an HA cluster member

32 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2Creating a local CA1. Fr

Strona 270 - Failover/failback example

Fabric OS Encryption Administrator’s Guide (KMIP) 3353-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2Creating a server certif

Strona 271 - Recovery

34 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2FIGURE 19 KeySecure Cert

Strona 272

Fabric OS Encryption Administrator’s Guide (KMIP) 3553-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)25. Copy the certificate

Strona 273

36 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)28. Select Server as the

Strona 274

Fabric OS Encryption Administrator’s Guide (KMIP) 3753-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2FIGURE 24 KeySecure Cert

Strona 275

38 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2Creating a cluster1. Fro

Strona 276 - -hbmisses and -hbtimeout

Fabric OS Encryption Administrator’s Guide (KMIP) 3953-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2FIGURE 27 KeySecure Clus

Strona 277

40 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2Configuring a Brocade gr

Strona 278

Fabric OS Encryption Administrator’s Guide (KMIP) 4153-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2Registering the KeySecur

Strona 279

vi Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Disk device decommissioning . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Strona 280

42 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2Signing the encryption n

Strona 281

Fabric OS Encryption Administrator’s Guide (KMIP) 4353-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2FIGURE 31 Certificate an

Strona 282 - Key vault diagnostics

44 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2FIGURE 32 Import Signed

Strona 283 - -portperfshow

Fabric OS Encryption Administrator’s Guide (KMIP) 4553-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2FIGURE 34 Backup and Res

Strona 284

46 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2Configuring the KMIP ser

Strona 285 - Problem Resolution

Fabric OS Encryption Administrator’s Guide (KMIP) 4753-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2Adding a node to the clu

Strona 286 - General errors and conditions

48 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2FIGURE 38 KeySecure Clus

Strona 287

Fabric OS Encryption Administrator’s Guide (KMIP) 4953-1002747-02Encryption preparation28. Under Restore Backup, select Upload from browser, then ente

Strona 288

50 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Creating an encryption group2• An external host is available on the LAN to facilitate

Strona 289

Fabric OS Encryption Administrator’s Guide (KMIP) 5153-1002747-02Creating an encryption group25. Select Security Settings.6. Confirm the configuration

Strona 290

Fabric OS Encryption Administrator’s Guide (KMIP) vii53-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure). . . . . . . . . . . .

Strona 291

52 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Creating an encryption group2FIGURE 43 Designate Switch Membership dialog box 5. For

Strona 292

Fabric OS Encryption Administrator’s Guide (KMIP) 5353-1002747-02Creating an encryption group2The dialog box contains the following information:• Encr

Strona 293 - LUN policy troubleshooting

54 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Creating an encryption group2Using this dialog box, you can select a key vault for th

Strona 294

Fabric OS Encryption Administrator’s Guide (KMIP) 5553-1002747-02Creating an encryption group2Configuring key vault settings for Key Management Intero

Strona 295 - MPIO and internal LUN states

56 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Creating an encryption group24. (Optional) Enter a Backup Key Vault IP address or hos

Strona 296 - Multi-node EG replacement

Fabric OS Encryption Administrator’s Guide (KMIP) 5753-1002747-02Creating an encryption group2FIGURE 48 Specify Master Key File Name dialog box9. Ente

Strona 297

58 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Creating an encryption group2FIGURE 49 Select Security Settings dialog box12. Set quo

Strona 298 - Single-node EG replacement

Fabric OS Encryption Administrator’s Guide (KMIP) 5953-1002747-02Creating an encryption group2FIGURE 50 Confirm Configuration dialog box14. Confirm th

Strona 299 - Multi-node EG Case

60 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Creating an encryption group2All configuration items have green check marks if the co

Strona 300

Fabric OS Encryption Administrator’s Guide (KMIP) 6153-1002747-02Adding a switch to an encryption group23. Register the key vault. BNA registers the k

Strona 301

viii Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Crypto LUN configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Strona 302 - Single-node EG Replacement

62 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Adding a switch to an encryption group2FIGURE 53 Configure Switch Encryption wizard -

Strona 303

Fabric OS Encryption Administrator’s Guide (KMIP) 6353-1002747-02Adding a switch to an encryption group2The dialog box contains the following informat

Strona 304

64 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Adding a switch to an encryption group2FIGURE 56 Specify Public Key Certificate (KAC)

Strona 305

Fabric OS Encryption Administrator’s Guide (KMIP) 6553-1002747-02Adding a switch to an encryption group2FIGURE 58 Configuration Status dialog boxAll c

Strona 306 - Encryption group Nodes

66 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Adding a switch to an encryption group2FIGURE 59 Error Instructions dialog box8. Revi

Strona 307

Fabric OS Encryption Administrator’s Guide (KMIP) 6753-1002747-02Replacing an encryption engine in an encryption group2Replacing an encryption engine

Strona 308

68 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02High availability (HA) clusters2High availability (HA) clusters A high availability (

Strona 309 - State and Status Information

Fabric OS Encryption Administrator’s Guide (KMIP) 6953-1002747-02High availability (HA) clusters2Creating HA clusters For the initial encryption node,

Strona 310 - Encrypted LUN states

70 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02High availability (HA) clusters23. Click the right arrow to add the encryption engine

Strona 311

Fabric OS Encryption Administrator’s Guide (KMIP) 7153-1002747-02Configuring encryption storage targets2Failback optionThe Failback option determines

Strona 312

Fabric OS Encryption Administrator’s Guide (KMIP) ix53-1002747-02Deployment in Fibre Channel routed fabrics. . . . . . . . . . . . . . . . . .220Deplo

Strona 313 - TABLE 21 Tape LUN states

72 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Configuring encryption storage targets26. Configuration Status7. Important Instructio

Strona 314

Fabric OS Encryption Administrator’s Guide (KMIP) 7353-1002747-02Configuring encryption storage targets2FIGURE 63 Configure Storage Encryption welcome

Strona 315

74 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Configuring encryption storage targets2The dialog box contains the following informat

Strona 316

Fabric OS Encryption Administrator’s Guide (KMIP) 7553-1002747-02Configuring encryption storage targets26. Select a target from the list. (The Target

Strona 317

76 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Configuring encryption storage targets2NOTENote: You must enter the host node world w

Strona 318

Fabric OS Encryption Administrator’s Guide (KMIP) 7753-1002747-02Configuring encryption storage targets2FIGURE 67 Name Container dialog box10. Enter t

Strona 319

78 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Configuring encryption storage targets2The screen contains the following information:

Strona 320

Fabric OS Encryption Administrator’s Guide (KMIP) 7953-1002747-02Configuring encryption storage targets213. Review any post-configuration instructions

Strona 321

80 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Configuring hosts for encryption targets2Configuring hosts for encryption targetsUse

Strona 322

Fabric OS Encryption Administrator’s Guide (KMIP) 8153-1002747-02Configuring hosts for encryption targets2FIGURE 72 Encryption Target Hosts dialog box

Komentarze do niniejszej Instrukcji

Brak uwag