Brocade Fabric OS Encryption Administrator’s Guide Support Uživatelský manuál Strana 1

Procházejte online nebo si stáhněte Uživatelský manuál pro Počítačové příslušenství Brocade Fabric OS Encryption Administrator’s Guide Support. Brocade Fabric OS Encryption Administrator’s Guide Supporting HP Secure Key Manager (SKM) and HP Enterprise Secure Key Manager (ESKM) Environments (Supporting Fabric OS v7.2.0) User Manual Uživatelská příručka

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 324
  • Tabulka s obsahem
  • ŘEŠENÍ PROBLÉMŮ
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků

Shrnutí obsahu

Strany 1 - Administrator’s Guide

53-1002923-0126 July 2013®Fabric OS Encryption Administrator’s Guide Supporting HP Secure Key Manager (SKM) and HP Enterprise Secure Key Manager (ESKM

Strany 2 - Document History

viii Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Crypto LUN configuration . . . . . . . . . . . . . . . . . . . . . . . . . . .

Strany 3 - Document Title iii

80 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Tape LUN write early and read ahead2FIGURE 53 Encryption Targets dialog box3. Sel

Strany 4

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 8153-1002923-01Tape LUN statistics2NOTEYou can also select a group, switch, or engine from the E

Strany 5 - Contents

82 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Tape LUN statistics2FIGURE 56 Tape LUN Statistics dialog boxThe dialog box contai

Strany 6

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 8353-1002923-01Tape LUN statistics23. Select a tape target storage device, then click LUNs.The T

Strany 7

84 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Tape LUN statistics2• Compressed Bytes: The number of compressed bytes written to

Strany 8

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 8553-1002923-01Encryption engine rebalancing2FIGURE 60 Tape LUN Statistics dialog boxThe dialog

Strany 9

86 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Master keys2During rebalancing operations, be aware of the following:• You might

Strany 10 - 53-1002923-01

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 8753-1002923-01Master keys2The new master key cannot be used (no new data encryption keys can be

Strany 11

88 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Master keys2Master key actionsNOTEMaster keys belong to the group and are managed

Strany 12

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 8953-1002923-01Master keys23. Select Backup Master Key as the Master Key Action.The Master Key B

Strany 13

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) ix53-1002923-01Multiple paths, one DEK cluster, and two HA clusters . . . . . . . . . .208Multip

Strany 14

90 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Master keys23. Select Backup Master Key as the Master Key Action.The Backup Maste

Strany 15 - About This Document

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 9153-1002923-01Master keys2FIGURE 63 Master key backup dialog box - Backup Destination (to smart

Strany 16 - Document conventions

92 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Master keys2Overview of Saving a master key to a smart card set A card reader mus

Strany 17 - Notes, cautions, and warnings

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 9353-1002923-01Master keys2FIGURE 64 Restore Master Key for Encryption Group dialog box - Restor

Strany 18 - Additional information

94 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Master keys2FIGURE 65 Restore Master Key for Encryption Group dialog box - Restor

Strany 19 - Getting technical help

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 9553-1002923-01Master keys2FIGURE 66 Restore Master Key for Encryption Group dialog box - Restor

Strany 20 - Document feedback

96 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Security settings2Security settings Security settings help you identify if system

Strany 21 - Encryption Overview

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 9753-1002923-01Zeroizing an encryption engine2NOTEZeroizing an engine affects the I/Os, but all

Strany 22 - Terminology

98 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Using the Encryption Targets dialog box2Using the Encryption Targets dialog boxTh

Strany 23

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 9953-1002923-01Redirection zones2Redirection zonesIt is recommended that you configure the host

Strany 24 - The Brocade Encryption Switch

x Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Rekeying best practices and policies. . . . . . . . . . . . . . . . . . . . . . .

Strany 25 - The FS8-18 blade

100 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Disk device decommissioning2Provided that the crypto configuration is not left u

Strany 26 - Usage limitations

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 10153-1002923-01Disk device decommissioning2If a rekey operation is currently in progress on a s

Strany 27 - FIGURE 2 Encryption overview

102 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Rekeying all disk LUNs manually23. Click Delete All to delete the decommissioned

Strany 28 - FIGURE 3 Frame redirection

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 10353-1002923-01Rekeying all disk LUNs manually2The following conditions must be satisfied for t

Strany 29 - IO Sync LAN

104 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Rekeying all disk LUNs manually2.FIGURE 72 Pending manual rekey operations Viewi

Strany 30 - FIGURE 5 DEK life cycle

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 10553-1002923-01Rekeying all disk LUNs manually2FIGURE 73 Encryption Target Disk LUNs dialog box

Strany 31 - Support for virtual fabrics

106 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Rekeying all disk LUNs manually2Viewing the progress of manual rekey operationsT

Strany 32

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 10753-1002923-01Thin provisioned LUNs2• Current LBA: The Logical Block Address (LBA) of the bloc

Strany 33

108 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Viewing time left for auto rekey2• If you are running a Fabric OS version earlie

Strany 34 - Encryption Center features

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 10953-1002923-01Viewing and editing switch encryption properties2The Encryption Target Disk LUNs

Strany 35 - Encryption user privileges

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) xi53-1002923-01Encryption group database manual operations . . . . . . . . . . . . . . .259Manua

Strany 36 - Smart card usage

110 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Viewing and editing switch encryption properties2FIGURE 76 Encryption Switch Pro

Strany 37

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 11153-1002923-01Viewing and editing switch encryption properties2• Discovering• Not a member- En

Strany 38

112 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Viewing and editing switch encryption properties2• need master/link key• Online-

Strany 39

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 11353-1002923-01Viewing and editing encryption group properties2FIGURE 77 Import Signed Certific

Strany 40

114 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Viewing and editing encryption group properties2The Encryption Group Properties

Strany 41 - Using system cards

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 11553-1002923-01Viewing and editing encryption group properties2General tabThe General tab is vi

Strany 42

116 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Viewing and editing encryption group properties2When the first encryption engine

Strany 43 - Tracking smart cards

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 11753-1002923-01Viewing and editing encryption group properties2Members tabThe Members tab lists

Strany 44

118 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Viewing and editing encryption group properties2The Members table might not matc

Strany 45

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 11953-1002923-01Viewing and editing encryption group properties2Table 2 explains the impact of r

Strany 46 - Editing smart cards

xii Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01

Strany 47 - Blade processor links

120 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Viewing and editing encryption group properties2FIGURE 81 Encryption Group Prope

Strany 48 - (KAC) certificate

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 12153-1002923-01Viewing and editing encryption group properties2• Registered Authentication Card

Strany 49

122 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Viewing and editing encryption group properties2FIGURE 82 Encryption Group Prope

Strany 50

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 12353-1002923-01Viewing and editing encryption group properties2• Configure Blade Processor Link

Strany 51

124 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Viewing and editing encryption group properties2Tape pools overviewTape cartridg

Strany 52

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 12553-1002923-01Viewing and editing encryption group properties2FIGURE 85 Add Tape Pool by numbe

Strany 53

126 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Encryption-related acronyms in log messages2NOTEYou can also select a group from

Strany 54

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 12753-1002923-01Chapter3Configuring Encryption Using the CLI•Overview. . . . . . . . . . . . . .

Strany 55

128 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Overview3OverviewThis chapter explains how to use the command line interface (CL

Strany 56

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 12953-1002923-01Command RBAC permissions and AD types34. PortMember: allows all control operatio

Strany 57

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) xiii53-1002923-01About This DocumentIn this chapter•How this document is organized . . . . . .

Strany 58 - <primary

130 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Command RBAC permissions and AD types3createhaclusterNOMN N N OMN NDisallowedcre

Strany 59

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 13153-1002923-01Command RBAC permissions and AD types3rebalanceNOMN N N OMN NDisallowedreclaimNO

Strany 60 - Encryption preparation

132 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Cryptocfg Help command output3Cryptocfg Help command outputAll encryption operat

Strany 61 - Creating an encryption group

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 13353-1002923-01Configuring cluster links3Configuring cluster linksEach encryption switch or FS8

Strany 62

134 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Configuring cluster links3DHCP: Offeth0: 10.33.54.208/20eth1: none/noneGateway:

Strany 63

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 13553-1002923-01Setting encryption node initialization34. Reboot the member node (the node on wh

Strany 64

136 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Steps for connecting to an SKM or ESKM appliance3Steps for connecting to an SKM

Strany 65 - (ESKM/SKM)

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 13753-1002923-01Steps for connecting to an SKM or ESKM appliance313. Select Save.The Brocade use

Strany 66

138 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Steps for connecting to an SKM or ESKM appliance3FIGURE 87 Creating an HP SKM/ES

Strany 67

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 13953-1002923-01Steps for connecting to an SKM or ESKM appliance3Creating and installing the SKM

Strany 68

xiv Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Supported hardware and software. The following hardware platforms support data e

Strany 69

140 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Steps for connecting to an SKM or ESKM appliance317. Select the server certifica

Strany 70 - --reg keyvault command

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 14153-1002923-01Steps for connecting to an SKM or ESKM appliance34. Click Edit. A warning messag

Strany 71

142 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Steps for connecting to an SKM or ESKM appliance33. Select the name of the local

Strany 72

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 14353-1002923-01Steps for connecting to an SKM or ESKM appliance320. Create and install an SKM/E

Strany 73

144 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Steps for connecting to an SKM or ESKM appliance35. Initialize the encryption en

Strany 74

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 14553-1002923-01Steps for connecting to an SKM or ESKM appliance310. Allow Certificate Duration

Strany 75

146 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Steps for connecting to an SKM or ESKM appliance3The following example creates t

Strany 76

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 14753-1002923-01Steps for connecting to an SKM or ESKM appliance3Server SDK Version:

Strany 77

148 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Steps for connecting to an SKM or ESKM appliance3• The user name and password mu

Strany 78 - Creating HA clusters

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 14953-1002923-01Steps for connecting to an SKM or ESKM appliance3cluster fails, an error is logg

Strany 79

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) xv53-1002923-01Notes, cautions, and warningsThe following notices and statements are used in thi

Strany 80 - Invoking failback

150 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Steps for connecting to an SKM or ESKM appliance3When the secondary SKM/ESKM is

Strany 81 - Adding an encryption target

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 15153-1002923-01Steps for connecting to an SKM or ESKM appliance35. Use the cryptocfg --import c

Strany 82 - 4. Click Next

152 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Generating and backing up the master key3Node Name: 10:00:00:05

Strany 83

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 15353-1002923-01Generating and backing up the master key33. Save the master key to a file.Securi

Strany 84

154 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01High availability clusters3Group Leader Node Name: 10:00:00:05:1e:41:9a:7eEn

Strany 85

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 15553-1002923-01High availability clusters3NOTEIn Fabric OS 6.3.0 and later, HA cluster creation

Strany 86

156 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01High availability clusters3NOTEAn HA cluster configuration must have two encrypt

Strany 87

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 15753-1002923-01High availability clusters3<<old node WWN> [old slot number]><<

Strany 88 - FIGURE 42 Next Steps screen

158 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01High availability clusters3Policy Configuration ExamplesThe following examples i

Strany 89

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 15953-1002923-01Re-exporting a master key3Re-exporting a master keyWith the introduction of Fabr

Strany 90

xvi Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Key termsFor definitions specific to Brocade and Fibre Channel, see the technica

Strany 91

160 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Re-exporting a master key3The exported key ID is displayed with the master key I

Strany 92

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 16153-1002923-01Re-exporting a master key3The following example lists the exported master key ID

Strany 93

162 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Enabling the encryption engine3Enabling the encryption engineEnable the encrypti

Strany 94

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 16353-1002923-01Zoning considerations3 No HA cluster membership EE Attributes: Med

Strany 95 - Configuring storage arrays

164 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Zoning considerations3Frame redirection zoningName Server-based frame redirectio

Strany 96

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 16553-1002923-01Zoning considerations3 The Local Name Server has 1 entry }The nsshow command sho

Strany 97

166 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01CryptoTarget container configuration37. Create a zone that includes the initiato

Strany 98

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 16753-1002923-01CryptoTarget container configuration3FIGURE 89 Relationship between initiator, v

Strany 99 - Moving targets

168 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01CryptoTarget container configuration3To determine if rebalancing is recommended

Strany 100

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 16953-1002923-01CryptoTarget container configuration3Creating a CryptoTarget container1. Log in

Strany 101 - Tape LUN statistics

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) xvii53-1002923-01For information about the Key Management Interoperability Protocol standard, vi

Strany 102

170 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01CryptoTarget container configuration3Number of LUN(s): 0Operation Succeeded6

Strany 103

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 17153-1002923-01CryptoTarget container configuration3CAUTIONWhen configuring a multi-path LUN, y

Strany 104

172 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01CryptoTarget container configuration3CAUTIONWhen configuring a multi-path LUN, y

Strany 105 - Encryption engine rebalancing

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 17353-1002923-01Crypto LUN configuration3Crypto LUN configurationA Crypto LUN is the LUN of a ta

Strany 106 - Master keys

174 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Crypto LUN configuration3CAUTIONWhen configuring a LUN with multiple paths, perf

Strany 107 - Alternate master key

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 17553-1002923-01Crypto LUN configuration3NOTEIf you are using VMware virtualization software or

Strany 108 - Master key actions

176 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Crypto LUN configuration3Crypto LUN parameters and policies Table 6 shows the en

Strany 109 - ATTENTION

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 17753-1002923-01Crypto LUN configuration3Configuring a tape LUNThis example shows how to configu

Strany 110

178 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Crypto LUN configuration3b. Add an initiator to the CryptoTarget container “my_t

Strany 111

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 17953-1002923-01Crypto LUN configuration3Encryption format: DF_compatibleTape type:

Strany 112

Copyright © 2012 - 2013 Brocade Communications Systems, Inc. All Rights Reserved.ADX, AnyIO, Brocade, Brocade Assurance, the B-wing symbol, DCX, Fabri

Strany 113

xviii Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01If you cannot use the licenseIdShow command because the switch is inoperable,

Strany 114

180 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Crypto LUN configuration3Modifying Crypto LUN parameters You can modify one or m

Strany 115 - Creating a master key

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 18153-1002923-01Impact of tape LUN configuration changes3For tape LUNs, the -enable_encexistingd

Strany 116 - Security settings

182 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Configuring a multi-path Crypto LUN3To avoid the risk of data corruption, you mu

Strany 117 - Setting zeroization

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 18353-1002923-01Configuring a multi-path Crypto LUN33. On the group leader encryption switch (sw

Strany 118

184 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Configuring a multi-path Crypto LUN3c. Review the output of the LUN discovery to

Strany 119 - Disk device decommissioning

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 18553-1002923-01Decommissioning LUNs3Make sure the LUNs in previously committed LUN configuratio

Strany 120 - Decommissioning Disk LUNs

186 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Decommissioning LUNs3If a LUN is removed when undergoing decommission or is in a

Strany 121

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 18753-1002923-01Decommissioning replicated LUNs3Decommissioning replicated LUNsThe following sce

Strany 122 - Displaying Universal IDs

188 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Force-enabling a decommissioned disk LUN for encryption3NOTEDo not delete the ke

Strany 123 - Setting disk LUN Re-key All

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 18953-1002923-01Force-enabling a disabled disk LUN for encryption37. En a b le t h e L UN .Fabr

Strany 124

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 153-1002923-01Chapter1Encryption OverviewIn this chapter•Host and LUN considerations . . . . . .

Strany 125

190 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Tape pool configuration3Tape pool configurationTape pools are used by tape backu

Strany 126

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 19153-1002923-01Tape pool configuration3CommVault Galaxy labelingCommVault uses a storage policy

Strany 127 - Thin provisioned LUNs

192 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Tape pool configuration3Creating a tape poolTake the following steps to create a

Strany 128 - Thin provisioning support

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 19353-1002923-01Tape pool configuration3Deleting a tape poolThis command does not issue a warnin

Strany 129

194 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01First-time encryption3First-time encryptionFirst-time encryption, also referred

Strany 130

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 19553-1002923-01Thin provisioned LUNs3Thin provisioned LUNsWith the introduction of Fabric OS 7.

Strany 131

196 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Thin provisioned LUNs3Encryption format: nativeEncrypt existing data: disa

Strany 132

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 19753-1002923-01Data rekeying3• The WRITE_SAME command will not be supported for the unmap opera

Strany 133

198 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Data rekeying3• Rekey temporarily uses the last 512 blocks. As a result, these b

Strany 134

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 19953-1002923-01Data rekeying31. Log in to the group leader as FabricAdmin. 2. Enable automatic

Strany 135 - General tab

2 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Terminology1TerminologyThe following are definitions of terms used extensively in

Strany 136

200 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Data rekeying3Target: 50:06:01:60:30:20:db:34 50:06:01:60:b0:20:

Strany 137 - Members tab

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 20153-1002923-01Data rekeying32. Check the status of the resumed rekey session.FabricAdmin:switc

Strany 138 - Members tab Remove button

202 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Data rekeying3

Strany 139 - Security tab

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 20353-1002923-01Chapter4Deployment ScenariosIn this chapter•Single encryption switch, two paths

Strany 140

204 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Single encryption switch, two paths from host to target4Single encryption switch

Strany 141 - HA Clusters tab

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 20553-1002923-01Single fabric deployment - HA cluster4Single fabric deployment - HA clusterFigur

Strany 142

206 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Single fabric deployment - DEK cluster4In Figure 92, the two encryption switches

Strany 143 - Tape Pools tab

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 20753-1002923-01Dual fabric deployment - HA and DEK cluster4In Figure 93, two encryption switche

Strany 144 - Adding tape pools

208 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Multiple paths, one DEK cluster, and two HA clusters4failover for the encryption

Strany 145 - Engine Operations tab

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 20953-1002923-01Multiple paths, DEK cluster, no HA cluster4The configuration details shown in Fi

Strany 146 - TABLE 3 Encryption acronyms

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 353-1002923-01Terminology1Opaque Key VaultA storage location that provides untrusted key managem

Strany 147

210 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Multiple paths, DEK cluster, no HA cluster4The configuration details are as foll

Strany 148 - Command validation checks

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 21153-1002923-01Deployment in Fibre Channel routed fabrics4Deployment in Fibre Channel routed fa

Strany 149

212 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Deployment in Fibre Channel routed fabrics4The following is a summary of steps f

Strany 150 - (Continued)

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 21353-1002923-01Deployment as part of an edge fabric4Deployment as part of an edge fabricIn this

Strany 151

214 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Deployment as part of an edge fabric4• The encryption device creates the frame r

Strany 152 - Management LAN configuration

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 21553-1002923-01Deployment with FCIP extension switches4Deployment with FCIP extension switchesE

Strany 153 - Configuring cluster links

216 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01VMware ESX server deployments4VMware ESX server deploymentsVMware ESX servers ma

Strany 154 - Node is a member node

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 21753-1002923-01VMware ESX server deployments4FIGURE 101 VMware ESX server, One HBA per guest OS

Strany 155 - • Node CP certificate

218 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01VMware ESX server deployments4Figure 102 shows a VMware ESX server with two gues

Strany 156 - Configuring a Brocade group

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 21953-1002923-01VMware ESX server deployments4FIGURE 102 VMware ESX server, One HBA shared by tw

Strany 157

4 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01The Brocade Encryption Switch1The Brocade Encryption SwitchThe Brocade Encryption

Strany 158

220 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01VMware ESX server deployments4

Strany 159

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 22153-1002923-01Chapter5Best Practices and Special Topics•Firmware upgrade and downgrade conside

Strany 160 - • Allow Key Export

222 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Firmware upgrade and downgrade considerations5Firmware upgrade and downgrade con

Strany 161

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 22353-1002923-01Firmware upgrade and downgrade considerations5• When doing a firmware upgrade to

Strany 162

224 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Firmware upgrade and downgrade considerations5• Do not try registering a node ru

Strany 163

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 22553-1002923-01Configuration upload and download considerations5Configuration upload and downlo

Strany 164

226 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Configuration upload and download considerations5Steps before configuration down

Strany 165

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 22753-1002923-01HP-UX considerations53. If there are containers that belonged to the old encrypt

Strany 166

228 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01AIX Considerations5NOTEWhen an EMC-CX3 storage array is used with HP-UX the CX3

Strany 167

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 22953-1002923-01Tape data compression5Tape data compressionData is compressed by the encryption

Strany 168 - Data Encryption Keys

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 553-1002923-01The FS8-18 blade1The FS8-18 bladeThe FS8-18 blade provides the same features and f

Strany 169 - Tape LUN support

230 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Tape block zero handling5Tape block zero handlingThe block zero of the tape medi

Strany 170 - • cryptocfg --enableEE

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 23153-1002923-01Redirection zones5• To enable host MPIO, LUNs must also be available through a s

Strany 171

232 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Ensure uniform licensing in HA clusters5Ensure uniform licensing in HA clustersL

Strany 172

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 23353-1002923-01Turn off compression on extension switches5Turn off compression on extension swi

Strany 173

234 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01KAC certificate registration expiry5Do not change LUN configuration while rekeyi

Strany 174 - High availability clusters

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 23553-1002923-01Disabling the encryption engine5Disabling the encryption engineThe disable encry

Strany 175 - Creating an HA cluster

236 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Best practices for host clusters in an encryption environment5The fan-in ratio f

Strany 176

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 23753-1002923-01Tape device LUN mapping5Tape device LUN mapping When performing LUN mapping, ens

Strany 177

238 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Special notes for HP Data Protector backup and restore application5

Strany 178 - Policy Configuration Examples

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 23953-1002923-01Chapter6Maintenance and Troubleshooting•Encryption group and HA cluster maintena

Strany 179 - Re-exporting a master key

6 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Recommendation for connectivity1Recommendation for connectivityIn order to achieve

Strany 180 - Viewing the master key IDs

240 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Encryption group and HA cluster maintenance6Encryption group and HA cluster main

Strany 181

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 24153-1002923-01Encryption group and HA cluster maintenance6FIGURE 104 Removing a node from an e

Strany 182

242 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Encryption group and HA cluster maintenance6 IP Address: 10.3

Strany 183 - Zoning considerations

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 24353-1002923-01Encryption group and HA cluster maintenance6Deleting an encryption groupYou can

Strany 184 - Frame redirection zoning

244 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Encryption group and HA cluster maintenance6Displaying the HA cluster configurat

Strany 185

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 24553-1002923-01Encryption group and HA cluster maintenance6Replacing an HA cluster member1. Log

Strany 186

246 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Encryption group and HA cluster maintenance6FIGURE 105 Replacing a failed encryp

Strany 187

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 24753-1002923-01Encryption group and HA cluster maintenance6Case 2: Replacing a “live” encryptio

Strany 188 - Gathering information

248 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Encryption group and HA cluster maintenance6Performing a manual failback of an e

Strany 189

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 24953-1002923-01Encryption group merge and split use cases6• After the failback completes, the c

Strany 190

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 753-1002923-01Brocade encryption solution overview1Brocade encryption solution overviewThe loss

Strany 191

250 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Encryption group merge and split use cases6NOTEWhen attempting to reclaim a fail

Strany 192

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 25153-1002923-01Encryption group merge and split use cases6RecoveryIf auto failback policy is se

Strany 193 - Crypto LUN configuration

252 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Encryption group merge and split use cases6• The isolation of N3 from the group

Strany 194 - Configuring a Crypto LUN

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 25353-1002923-01Encryption group merge and split use cases6Recovery1. Restore the connection bet

Strany 195

254 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Encryption group merge and split use cases6NOTEThe collective time allowed (the

Strany 196

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 25553-1002923-01Encryption group merge and split use cases6NOTEIf one or more EG status displays

Strany 197 - Configuring a tape LUN

256 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Encryption group merge and split use cases6Display the encryption group state ag

Strany 198

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 25753-1002923-01Encryption group merge and split use cases6If you now perform a cryptocfg --show

Strany 199

258 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Encryption group merge and split use cases66. Verify your encryption group is re

Strany 200

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 25953-1002923-01Encryption group database manual operations6Encryption group database manual ope

Strany 201

8 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Brocade encryption solution overview1Data flow from server to storageThe Brocade E

Strany 202

260 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Key vault diagnostics6Use the --sync -securitydb command to distribute the secur

Strany 203

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 26153-1002923-01Measuring encryption performance6• Key class and format on the KV configured for

Strany 204

262 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Measuring encryption performance6For example:FabricAdmin:switch> cryptocfg --

Strany 205 - Decommissioning LUNs

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 26353-1002923-01Measuring encryption performance6b. The user port on which a particular virtual

Strany 206

264 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Measuring encryption performance6In a DCX Backbone, the slot number is also disp

Strany 207

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 26553-1002923-01General encryption troubleshooting6General encryption troubleshootingTable 9 lis

Strany 208

266 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01General encryption troubleshooting6A backup fails because the LUN is always in t

Strany 209

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 26753-1002923-01General encryption troubleshooting6A performance drop occurs when using DPM on a

Strany 210 - Tape pool configuration

268 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Troubleshooting examples using the CLI6Troubleshooting examples using the CLIEnc

Strany 211 - NetWorker labeling

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 26953-1002923-01Troubleshooting examples using the CLI6Encryption Disabled CryptoTarget LUNIf th

Strany 212 - Creating a tape pool

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 953-1002923-01Data encryption key life cycle management1Data encryption key life cycle managemen

Strany 213 - Modifying a tape pool

270 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Management application encryption wizard troubleshooting6Management application

Strany 214 - First-time encryption

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 27153-1002923-01Management application encryption wizard troubleshooting6Errors related to addin

Strany 215

272 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Management application encryption wizard troubleshooting6General errors related

Strany 216 - Space reclamation

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 27353-1002923-01LUN policy troubleshooting6LUN policy troubleshootingTable 14 may be used as an

Strany 217 - Data rekeying

274 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Loss of encryption group leader after power outage6Loss of encryption group lead

Strany 218 - Rekeying modes

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 27553-1002923-01MPIO and internal LUN states65. Synchronize the crypto configurations across all

Strany 219

276 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01FS8-18 blade removal and replacement61. Enter the cryptocfg --resume_rekey comma

Strany 220

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 27753-1002923-01FS8-18 blade removal and replacement63. If the replaced FS8-18 blade is in membe

Strany 221

278 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01FS8-18 blade removal and replacement6NOTEBecause the FS8-18 blade was inserted i

Strany 222

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 27953-1002923-01Brocade Encryption Switch removal and replacement611. If a master key is not pre

Strany 223 - Deployment Scenarios

Document Title iii53-1002923-01

Strany 224

10 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Data encryption key life cycle management1FIGURE 5 DEK life cycle

Strany 225

280 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Brocade Encryption Switch removal and replacement66. Replace the old Brocade Enc

Strany 226

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 28153-1002923-01Brocade Encryption Switch removal and replacement621. Import the signed CSR/Cert

Strany 227

282 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Brocade Encryption Switch removal and replacement631. If HA cluster membership f

Strany 228

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 28353-1002923-01Brocade Encryption Switch removal and replacement612. Recreate the EG with the s

Strany 229

284 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Reclaiming the WWN base of a failed Brocade Encryption Switch6b. Issue commit. A

Strany 230

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 28553-1002923-01Removing stale rekey information for a LUN6Removing stale rekey information for

Strany 231

286 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Fabric OS and ESKM compatibility matrix6NOTEWhen disabling the firmware consiste

Strany 232 - --rdcreate [host wwn]

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 28753-1002923-01Splitting an encryption group into two encryption groups6Splitting an encryption

Strany 233

288 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Moving an encryption blade from one EG to another in the same fabric6When prompt

Strany 234

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 28953-1002923-01Moving an encryption switch from one EG to another in the same fabric6Moving an

Strany 235 - FIGURE 100 FCIP deployment

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 1153-1002923-01Master key management1Master key managementCommunications with opaque key vaults

Strany 236 - VMware ESX server deployments

290 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Moving an encryption switch from one EG to another in the same fabric6

Strany 237

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 29153-1002923-01AppendixAState and Status InformationIn this appendix•Encryption engine security

Strany 238

292 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Security processor KEK statusASecurity processor KEK statusTable 20 lists securi

Strany 239

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 29353-1002923-01Encrypted LUN statesALUN_1ST_TIME_REKEY_IN_PROG First time rekey is in progress.

Strany 240

294 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Encrypted LUN statesALUN_DIS_WR_META_DONE_ERR Disabled (Write metadata done with

Strany 241

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 29553-1002923-01Encrypted LUN statesATABLE 22 Tape LUN statesInternal Names Console String Expla

Strany 242

296 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Encrypted LUN statesALUN_ENCRYPT Encryption enabled The tape medium is present,

Strany 243 - General guidelines

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 29753-1002923-01IndexAadd commands--add -haclustermember, 156--add -initiator, 169, 178, 183--ad

Strany 244

298 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01cryptocfg command--add -haclustermember, 156--add -initiator, 169, 178, 183--add

Strany 245

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 29953-1002923-01disk devicesdecommissioning, 99disk lunsdecommissioning, 100rekeying manually, 1

Strany 246 - - CP certificate

12 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Cisco Fabric Connectivity support1Cisco Fabric Connectivity supportThe Brocade En

Strany 247 - HP-UX considerations

300 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01encryption group propertiesediting, 113using the restore master key, 97viewing,

Strany 248 - Tape metadata

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 30153-1002923-01using the CLI, 248removing an encryption engine using the CLI, 243removing engin

Strany 249 - Tape pools

302 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Mmanual command, --manual_rekey, 199manual re-key, 233manual rekeyviewing progre

Strany 250 - Tape key expiry

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 30353-1002923-01remove commands--rem -haclustermember, 241--rem -LUN, 179, 276--remove -hacluste

Strany 251

304 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01tape pools, 229adding, 124CommVault Galaxy labeling using the CLI, 191configurin

Strany 252 - PID failover

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 1353-1002923-01Chapter2Configuring Encryption Using the Management Application•Encryption Center

Strany 253 - Latency in rekey operations

14 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Encryption Center features2Encryption Center featuresThe Encryption Center dialog

Strany 254

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 1553-1002923-01Encryption user privileges2Encryption user privilegesIn Brocade Network Advisor,

Strany 255

16 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Smart card usage2Smart card usageSmart Cards are credit card-sized cards that con

Strany 256 - Key Vault Best Practices

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 1753-1002923-01Smart card usage2• Establishing a trusted link with the NetApp LKM key vault.• De

Strany 257 - Tape device LUN mapping

18 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Smart card usage23. Locate the Authentication Card Quorum Size and select the quo

Strany 258

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 1953-1002923-01Smart card usage2Registering authentication cards from the databaseSmart cards th

Strany 259

iv Document Title53-1002923-01

Strany 260

20 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Smart card usage2Deregistering an authentication cardAuthentication cards can be

Strany 261

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 2153-1002923-01Smart card usage2Using system cardsSystem cards are smart cards that can be used

Strany 262

22 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Smart card usage2Enabling or disabling the system card requirementTo use a system

Strany 263 - Removing an HA cluster member

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 2353-1002923-01Smart card usage2Deregistering system cardsSystem cards can be removed from the d

Strany 264

24 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Smart card usage2FIGURE 7 Smart Card asset tracking dialog boxThe Smart Cards tab

Strany 265

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 2553-1002923-01Smart card usage2NOTEYou can remove smart cards from the table to keep the Smart

Strany 266

26 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Smart card usage2Editing smart cardsSmart cards can be used for user authenticati

Strany 267 - Deleting an HA cluster member

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 2753-1002923-01Network connections2Network connectionsBefore you use the encryption setup wizard

Strany 268 - Failover/failback example

28 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Encryption node initialization and certificate generation2Configuring blade proce

Strany 269 - Recovery

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 2953-1002923-01Steps for connecting to an ESKM/SKM appliance2Setting encryption node initializat

Strany 270

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) iii53-1002923-01ContentsAbout This DocumentIn this chapter . . . . . . . . . . . . . . . . . . .

Strany 271

30 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Steps for connecting to an ESKM/SKM appliance2Configuring a Brocade group on ESKM

Strany 272

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 3153-1002923-01Steps for connecting to an ESKM/SKM appliance2FIGURE 10 Key Vault Credentials dia

Strany 273

32 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Steps for connecting to an ESKM/SKM appliance2Setting up the local Certificate Au

Strany 274 - -hbmisses and -hbtimeout

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 3353-1002923-01Steps for connecting to an ESKM/SKM appliance25. Under Certificates & CAs, se

Strany 275

34 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Steps for connecting to an ESKM/SKM appliance210. Click Sign Request.11. Enter th

Strany 276

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 3553-1002923-01Steps for connecting to an ESKM/SKM appliance2Creating an ESKM/SKM high availabil

Strany 277

36 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Steps for connecting to an ESKM/SKM appliance2Adding ESKM/SKM appliances to the c

Strany 278

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 3753-1002923-01Steps for connecting to an ESKM/SKM appliance2Signing the encryption node KAC cer

Strany 279

38 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Steps for connecting to an ESKM/SKM appliance2Importing a signed KAC certificate

Strany 280 - Key vault diagnostics

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 3953-1002923-01Steps for connecting to an ESKM/SKM appliance2Data Encryption KeysThe following s

Strany 281 - -portperfshow

iv Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Chapter 2 Configuring Encryption Using the Management ApplicationEncryption Cente

Strany 282

40 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Encryption preparation2ESKM/SKM key vault deregistrationDeregistration of either

Strany 283

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 4153-1002923-01Creating an encryption group2Creating an encryption groupThe following steps desc

Strany 284

42 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Creating an encryption group2g. Configuration Status.h. Read Instructions.FIGURE

Strany 285 - Problem Resolution

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 4353-1002923-01Creating an encryption group2FIGURE 15 Designate Switch Membership dialog box 5.

Strany 286 - General errors and conditions

44 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Creating an encryption group2The dialog box contains the following information:•

Strany 287

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 4553-1002923-01Creating an encryption group2Using this dialog box, you can select a key vault fo

Strany 288

46 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Creating an encryption group21. Enter the IP address or host name for the primary

Strany 289

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 4753-1002923-01Creating an encryption group2FIGURE 20 Specify Master Key File Name dialog box 9.

Strany 290

48 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Creating an encryption group211. Set quorum size and system card requirements.The

Strany 291

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 4953-1002923-01Creating an encryption group2FIGURE 23 Configuration Status dialog boxAll configu

Strany 292

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) v53-1002923-01High availability clusters . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Strany 293 - LUN policy troubleshooting

50 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Creating an encryption group2FIGURE 24 Next Steps dialog box14. Review post-confi

Strany 294

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 5153-1002923-01Adding a switch to an encryption group27. Back up the master key to a file. (Opaq

Strany 295 - MPIO and internal LUN states

52 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Adding a switch to an encryption group2FIGURE 26 Designate Switch Membership dial

Strany 296 - Multi-node EG replacement

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 5353-1002923-01Adding a switch to an encryption group2FIGURE 27 Add Switch to Existing Encryptio

Strany 297

54 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Adding a switch to an encryption group26. Enter the location where you want to st

Strany 298 - Single-node EG replacement

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 5553-1002923-01Adding a switch to an encryption group2All configuration items have green check m

Strany 299 - Multi-node EG Case

56 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Replacing an encryption engine in an encryption group2Replacing an encryption eng

Strany 300

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 5753-1002923-01High availability clusters2High availability clusters A high availability (HA) cl

Strany 301

58 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01High availability clusters2Creating HA clustersFor the initial encryption node, p

Strany 302 - Single-node EG Replacement

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 5953-1002923-01High availability clusters23. Click the right arrow to add the encryption engine

Strany 303

vi Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Rekeying all disk LUNs manually . . . . . . . . . . . . . . . . . . . . . . . . .

Strany 304

60 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Configuring encryption storage targets2Failback optionThe Failback option determi

Strany 305

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 6153-1002923-01Configuring encryption storage targets25. Confirmation6. Configuration Status7. I

Strany 306 - SKM 1.x ESKM 2.x ESKM 3.x

62 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Configuring encryption storage targets2FIGURE 35 Configure Storage Encryption - w

Strany 307 - Encryption group Nodes

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 6353-1002923-01Configuring encryption storage targets2The dialog box contains the following info

Strany 308

64 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Configuring encryption storage targets26. Select a target from the list. (The Tar

Strany 309

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 6553-1002923-01Configuring encryption storage targets2NOTEYou must enter the host node world wid

Strany 310

66 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Configuring encryption storage targets2FIGURE 39 Name Container dialog box10. Ent

Strany 311 - State and Status Information

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 6753-1002923-01Configuring encryption storage targets2The screen contains the following informat

Strany 312 - Encrypted LUN states

68 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Configuring encryption storage targets213. Review any post-configuration instruct

Strany 313

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 6953-1002923-01Configuring hosts for encryption targets2Configuring hosts for encryption targets

Strany 314

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) vii53-1002923-01Steps for connecting to an SKM or ESKM appliance . . . . . . . . . . .136Configu

Strany 315 - TABLE 22 Tape LUN states

70 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Configuring hosts for encryption targets2FIGURE 44 Encryption Target Hosts dialog

Strany 316

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 7153-1002923-01Adding target disk LUNs for encryption2Adding target disk LUNs for encryptionYou

Strany 317

72 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Adding target disk LUNs for encryption2• Encryption path table: Should be LUN/Pat

Strany 318

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 7353-1002923-01Adding target disk LUNs for encryption24. Select the target port from the Target

Strany 319

74 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Adding target disk LUNs for encryption2FIGURE 48 Select LUN dialog box The dialog

Strany 320

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 7553-1002923-01Adding target disk LUNs for encryption2NOTEThe maximum number of uncommitted conf

Strany 321

76 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Adding target tape LUNs for encryption2NOTEThe controller LUN (LUN 0) must be add

Strany 322

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 7753-1002923-01Adding target tape LUNs for encryption2FIGURE 51 Encryption Target Tape LUNs dial

Strany 323

78 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)53-1002923-01Adding target tape LUNs for encryption2When you select a specific host, only the

Strany 324

Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 7953-1002923-01Moving targets2Moving targetsThe Move Targets dialog box is used to redistribute

Komentáře k této Příručce

Žádné komentáře