Brocade Fabric OS Encryption Administrator’s Guide Support Uživatelský manuál

Procházejte online nebo si stáhněte Uživatelský manuál pro Počítačové příslušenství Brocade Fabric OS Encryption Administrator’s Guide Support. Brocade Fabric OS Encryption Administrator’s Guide Supporting Key Management Interoperability Protocol (KMIP) Key-Compliant Environments (Supporting Fabric OS v7.1.0) User Manual [es] Uživatelská příručka

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 322
  • Tabulka s obsahem
  • ŘEŠENÍ PROBLÉMŮ
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků

Shrnutí obsahu

Strany 1 - Fabric OS Encryption

53-1002747-0225 March 2013®53-1002747-02Fabric OS EncryptionAdministrator’s Guide Supporting Key Management Interoperability Protocol (KMIP) Key-Compl

Strany 2 - Document History

x Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Rekeying best practices and policies. . . . . . . . . . . . . . . . . . . . . . . .238

Strany 3 - Contents

82 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Adding target disk LUNs for encryption2Adding target disk LUNs for encryptionYou can

Strany 4

Fabric OS Encryption Administrator’s Guide (KMIP) 8353-1002747-02Adding target disk LUNs for encryption2• Encryption Mode• Encrypt Existing Data• Key

Strany 5

84 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Adding target disk LUNs for encryption2FIGURE 75 Select Initiator Port dialog boxThe

Strany 6

Fabric OS Encryption Administrator’s Guide (KMIP) 8553-1002747-02Adding target disk LUNs for encryption2FIGURE 76 Select LUN dialog box The dialog box

Strany 7

86 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Adding target disk LUNs for encryption2NOTEWith the introduction of Fabric OS v7.1.0,

Strany 8

Fabric OS Encryption Administrator’s Guide (KMIP) 8753-1002747-02Adding target tape LUNs for encryption2Configuring storage arraysThe Storage Array co

Strany 9

88 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Adding target tape LUNs for encryption2FIGURE 78 Encryption Targets dialog box3. Sele

Strany 10 - 53-1002747-02

Fabric OS Encryption Administrator’s Guide (KMIP) 8953-1002747-02Adding target tape LUNs for encryption2FIGURE 80 Add Encryption Target Tape LUNs dial

Strany 11

90 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Moving Targets2• Enable Read Ahead: When selected, enables read pre-fetching on this

Strany 12

Fabric OS Encryption Administrator’s Guide (KMIP) 9153-1002747-02Configuring encrypted tape storage in a multi-path environment2Configuring encrypted

Strany 13 - About This Document

Fabric OS Encryption Administrator’s Guide (KMIP) xi53-1002747-02General encryption troubleshooting . . . . . . . . . . . . . . . . . . . . . . . .26

Strany 14 - Document conventions

92 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Tape LUN write early and read ahead2Tape LUN write early and read aheadThe tape LUN w

Strany 15 - Notes, cautions, and warnings

Fabric OS Encryption Administrator’s Guide (KMIP) 9353-1002747-02Tape LUN statistics2FIGURE 82 Encryption Target Tape LUNs dialog box - Setting tape L

Strany 16 - Additional information

94 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Tape LUN statistics2Viewing and clearing tape container statisticsYou can view LUN st

Strany 17 - Getting technical help

Fabric OS Encryption Administrator’s Guide (KMIP) 9553-1002747-02Tape LUN statistics2• Tape Session #: The number of the ongoing tape session.• Uncomp

Strany 18 - Document feedback

96 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Tape LUN statistics2FIGURE 85 Target Tape LUNs dialog box4. Select the LUN or LUNs fo

Strany 19 - Encryption Overview

Fabric OS Encryption Administrator’s Guide (KMIP) 9753-1002747-02Tape LUN statistics2• A Refresh button updates the statistics on the display since th

Strany 20 - Terminology

98 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encryption engine rebalancing2FIGURE 88 Tape LUN Statistics dialog boxThe dialog box

Strany 21

Fabric OS Encryption Administrator’s Guide (KMIP) 9953-1002747-02Master keys2During rebalancing operations, be aware of the following:• You might noti

Strany 22 - The Brocade Encryption Switch

100 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Master keys2The new master key cannot be used (no new data encryption keys can be cr

Strany 23 - Performance licensing

Fabric OS Encryption Administrator’s Guide (KMIP) 10153-1002747-02Master keys2Refer to the following procedures for more information:- “Saving the mas

Strany 24 - Usage limitations

xii Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02

Strany 25 - FIGURE 2 Encryption overview

102 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Master keys2FIGURE 89 Backup Destination (to file) dialog box4. Select File as the B

Strany 26 - FIGURE 3 Frame redirection

Fabric OS Encryption Administrator’s Guide (KMIP) 10353-1002747-02Master keys2FIGURE 90 Backup Destination (to key vault) dialog box4. Select Key Vaul

Strany 27 - IO Sync LAN

104 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Master keys2FIGURE 91 Backup Destination (to smart cards) dialog box4. Select A Reco

Strany 28 - FIGURE 5 DEK life cycle

Fabric OS Encryption Administrator’s Guide (KMIP) 10553-1002747-02Master keys2Saving a master key to a smart card set - OverviewA card reader must be

Strany 29 - Support for virtual fabrics

106 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Master keys2FIGURE 92 Select a Master Key to Restore (from file) dialog box4. Choose

Strany 30

Fabric OS Encryption Administrator’s Guide (KMIP) 10753-1002747-02Master keys2FIGURE 93 Select a Master Key to Restore (from key vault) dialog box4. C

Strany 31

108 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Master keys2FIGURE 94 Select a Master Key to Restore (from a recovery set of smart c

Strany 32 - Encryption Center features

Fabric OS Encryption Administrator’s Guide (KMIP) 10953-1002747-02Security Settings2Security Settings Security settings help you identify if system ca

Strany 33 - Encryption user privileges

110 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Zeroizing an encryption engine2NOTEZeroizing an engine affects the I/Os, but all tar

Strany 34 - Smart card usage

Fabric OS Encryption Administrator’s Guide (KMIP) 11153-1002747-02Using the Encryption Targets dialog box2Using the Encryption Targets dialog boxThe E

Strany 35

Fabric OS Encryption Administrator’s Guide (KMIP) xiii53-1002747-02About This DocumentIn this chapter•How this document is organized . . . . . . . .

Strany 36

112 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Redirection zones2Redirection zonesIt is recommended that you configure the host and

Strany 37

Fabric OS Encryption Administrator’s Guide (KMIP) 11353-1002747-02Disk device decommissioning2Provided that the crypto configuration is not left uncom

Strany 38

114 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Disk device decommissioning2In order to delete keys from the key vault, you need to

Strany 39 - Using system cards

Fabric OS Encryption Administrator’s Guide (KMIP) 11553-1002747-02Rekeying all disk LUNs manually2Displaying Universal IDsIn order to delete keys from

Strany 40

116 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Rekeying all disk LUNs manually2Setting disk LUN Re-key AllTo rekey all disk LUNs on

Strany 41 - Tracking smart cards

Fabric OS Encryption Administrator’s Guide (KMIP) 11753-1002747-02Rekeying all disk LUNs manually2.FIGURE 99 Pending manual rekey operations Viewing d

Strany 42

118 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Rekeying all disk LUNs manually2FIGURE 100 Encryption Target Disk LUNs dialog box4.

Strany 43 - Editing smart cards

Fabric OS Encryption Administrator’s Guide (KMIP) 11953-1002747-02Rekeying all disk LUNs manually2Viewing the progress of manual rekey operationsTo mo

Strany 44 - Network connections

120 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Thin provisioned LUNs2• Current LBA: The Logical Block Address (LBA) of the block th

Strany 45 - Blade processor links

Fabric OS Encryption Administrator’s Guide (KMIP) 12153-1002747-02Viewing time left for auto rekey2• If you are running a Fabric OS version earlier th

Strany 46 - (KAC) certificate

xiv Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02• Chapter 6, “Maintenance and Troubleshooting,” provides information on troubleshoot

Strany 47

122 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Viewing and editing switch encryption properties2The Encryption Target Disk LUNs dia

Strany 48

Fabric OS Encryption Administrator’s Guide (KMIP) 12353-1002747-02Viewing and editing switch encryption properties2FIGURE 103 Encryption Switch Proper

Strany 49

124 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Viewing and editing switch encryption properties2• Encryption Group: The name of the

Strany 50

Fabric OS Encryption Administrator’s Guide (KMIP) 12553-1002747-02Viewing and editing switch encryption properties2• Online• Set State To: Identifies

Strany 51

126 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Viewing and editing encryption group properties2FIGURE 104 Import Signed Certificate

Strany 52

Fabric OS Encryption Administrator’s Guide (KMIP) 12753-1002747-02Viewing and editing encryption group properties2The Encryption Group Properties dial

Strany 53

128 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Viewing and editing encryption group properties2General tabThe General tab (Figure 1

Strany 54 - -----BEGIN CERTIFICATE

Fabric OS Encryption Administrator’s Guide (KMIP) 12953-1002747-02Viewing and editing encryption group properties2When the first encryption engine com

Strany 55

130 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Viewing and editing encryption group properties2• Not responding• Failed authenticat

Strany 56

Fabric OS Encryption Administrator’s Guide (KMIP) 13153-1002747-02Viewing and editing encryption group properties2• Connection Status: The switch’s co

Strany 57

Fabric OS Encryption Administrator’s Guide (KMIP) xv53-1002747-02Command syntax conventionsCommand syntax in this manual follows these conventions:Not

Strany 58

132 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Viewing and editing encryption group properties2Members tab Remove buttonYou can cli

Strany 59

Fabric OS Encryption Administrator’s Guide (KMIP) 13353-1002747-02Viewing and editing encryption group properties2A warning message is displayed when

Strany 60

134 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Viewing and editing encryption group properties2FIGURE 108 Encryption Group Properti

Strany 61

Fabric OS Encryption Administrator’s Guide (KMIP) 13553-1002747-02Viewing and editing encryption group properties2• Registered Authentication Cards ta

Strany 62

136 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Viewing and editing encryption group properties2• Right- and Left-arrow buttons: You

Strany 63

Fabric OS Encryption Administrator’s Guide (KMIP) 13753-1002747-02Viewing and editing encryption group properties2Tape Pools tabTape pools are managed

Strany 64

138 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Viewing and editing encryption group properties2All encryption engines in the encryp

Strany 65

Fabric OS Encryption Administrator’s Guide (KMIP) 13953-1002747-02Viewing and editing encryption group properties24. Based on your selection, do one o

Strany 66

140 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encryption-related acronyms in log messages2FIGURE 113 Encryption Group Properties D

Strany 67 - Encryption preparation

Fabric OS Encryption Administrator’s Guide (KMIP) 14153-1002747-02Chapter3Configuring Encryption Using the CLIIn this chapter•Overview. . . . . . . .

Strany 68 - Creating an encryption group

xvi Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Key termsFor definitions specific to Brocade and Fibre Channel, see the technical gl

Strany 69

142 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Overview3OverviewThis chapter explains how to use the command line interface (CLI) t

Strany 70

Fabric OS Encryption Administrator’s Guide (KMIP) 14353-1002747-02Command RBAC permissions and AD types34. PortMember: allows all control operations o

Strany 71

144 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Command RBAC permissions and AD types3createhaclusterNOMN N N OMN NDisallowedcreatet

Strany 72

Fabric OS Encryption Administrator’s Guide (KMIP) 14553-1002747-02Cryptocfg Help command output3Cryptocfg Help command outputAll encryption operations

Strany 73 - Protocol (KMIP)

146 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Management LAN configuration3switch:admin> cryptocfg --help -nodecfgUsage: crypto

Strany 74

Fabric OS Encryption Administrator’s Guide (KMIP) 14753-1002747-02Configuring cluster links3The following example configures a static IP address and g

Strany 75

148 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Setting encryption node initialization3IP Address change of a node within an encrypt

Strany 76

Fabric OS Encryption Administrator’s Guide (KMIP) 14953-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)3From the standpoint of

Strany 77

150 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)36. Configure the KMIP s

Strany 78 - --initnode command

Fabric OS Encryption Administrator’s Guide (KMIP) 15153-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)33. Verify the cluster s

Strany 79 - --reg keyvault

Fabric OS Encryption Administrator’s Guide (KMIP) xvii53-1002747-02For information about the Key Management Interoperability Protocol standard, visit

Strany 80

152 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Configuring the Brocade Encryption Switch key vault setup (SafeNet KeySecure)3h. Aft

Strany 81

Fabric OS Encryption Administrator’s Guide (KMIP) 15353-1002747-02Configuring the Brocade Encryption Switch key vault setup (SafeNet KeySecure)3Signin

Strany 82

154 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Configuring the Brocade Encryption Switch key vault setup (SafeNet KeySecure)33. Und

Strany 83

Fabric OS Encryption Administrator’s Guide (KMIP) 15553-1002747-02Configuring the Brocade Encryption Switch key vault setup (SafeNet KeySecure)32. On

Strany 84 - Error Instructions dialog box

156 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Configuring the Brocade Encryption Switch key vault setup (SafeNet KeySecure)3Regist

Strany 85

Fabric OS Encryption Administrator’s Guide (KMIP) 15753-1002747-02Configuring the Brocade Encryption Switch key vault setup (SafeNet KeySecure)3Time o

Strany 86

158 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Configuring the Brocade Encryption Switch key vault setup (SafeNet KeySecure)3Notify

Strany 87 - Creating HA clusters

Fabric OS Encryption Administrator’s Guide (KMIP) 15953-1002747-02Configuring the Brocade Encryption Switch key vault setup (SafeNet KeySecure)3The fo

Strany 88

160 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Adding a member node to an encryption group3 Server SDK Version:

Strany 89 - Invoking failback

Fabric OS Encryption Administrator’s Guide (KMIP) 16153-1002747-02Adding a member node to an encryption group3CAUTIONAfter adding the member node to t

Strany 90 - Adding an encryption target

xviii Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-023. World Wide Name (WWN)Use the licenseIdShow command to display the WWN of the ch

Strany 91 - 4. Click Next

162 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Adding a member node to an encryption group3NOTEIf the maximum number of certificate

Strany 92

Fabric OS Encryption Administrator’s Guide (KMIP) 16353-1002747-02Generating and backing up the master key3Additional Secondary Key Vault Information:

Strany 93

164 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02High availability clusters32. Export the master key to the key vault. Make a note of

Strany 94

Fabric OS Encryption Administrator’s Guide (KMIP) 16553-1002747-02High availability clusters3• It is recommended that the HA cluster configuration be

Strany 95

166 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02High availability clusters3Adding an encryption engine to an HA cluster1. Log in to

Strany 96

Fabric OS Encryption Administrator’s Guide (KMIP) 16753-1002747-02High availability clusters3Number of HA Clusters: 1HA cluster name: dthac - 2 EE ent

Strany 97 - FIGURE 70 Next Steps screen

168 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02High availability clusters3Policy Configuration ExamplesThe following examples illus

Strany 98

Fabric OS Encryption Administrator’s Guide (KMIP) 16953-1002747-02Re-exporting a master key3Re-exporting a master keyYou can export master keys to the

Strany 99

170 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Re-exporting a master key3Exporting an additional key IDExample: Subsequent master k

Strany 100

Fabric OS Encryption Administrator’s Guide (KMIP) 17153-1002747-02Re-exporting a master key3e3:ae:aa:89:ec:12:0c:04:29:61:9c:99:44:a3:9b:9ae3:ae:aa:89

Strany 101

Fabric OS Encryption Administrator’s Guide (KMIP) 153-1002747-02Chapter1Encryption OverviewIn this chapter•Host and LUN considerations . . . . . . . .

Strany 102

172 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Enabling the encryption engine3Enabling the encryption engineEnable the encryption e

Strany 103

Fabric OS Encryption Administrator’s Guide (KMIP) 17353-1002747-02Zoning considerations3 No HA cluster membership EE Attributes: Media T

Strany 104

174 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Zoning considerations3Frame redirection zoningName Server-based frame redirection en

Strany 105 - Configuring storage arrays

Fabric OS Encryption Administrator’s Guide (KMIP) 17553-1002747-02Zoning considerations3 Redirect: No The Local Name Server has 1 entry }The nsshow co

Strany 106

176 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02CryptoTarget container configuration37. Create a zone that includes the initiator an

Strany 107

Fabric OS Encryption Administrator’s Guide (KMIP) 17753-1002747-02CryptoTarget container configuration3FIGURE 118 Relationship between initiator, virt

Strany 108 - Moving Targets

178 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02CryptoTarget container configuration3• When removing an existing disk or tape target

Strany 109

Fabric OS Encryption Administrator’s Guide (KMIP) 17953-1002747-02CryptoTarget container configuration3FabricAdmin:switch> cryptocfg --create -cont

Strany 110

180 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02CryptoTarget container configuration3zone: red_______base 00:00:00:00:00:00:00:01;

Strany 111 - Tape LUN statistics

Fabric OS Encryption Administrator’s Guide (KMIP) 18153-1002747-02CryptoTarget container configuration3Deleting a CryptoTarget containerYou may delete

Strany 112

Copyright © 2012- 2013 Brocade Communications Systems, Inc. All Rights Reserved.Brocade, Brocade Assurance, the B-wing symbol, BigIron, DCX, Fabric OS

Strany 113

2 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Terminology1TerminologyThe following are definitions of terms used extensively in this

Strany 114

182 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Crypto LUN configuration3NOTEIf a CryptoTarget container is moved in a configuration

Strany 115

Fabric OS Encryption Administrator’s Guide (KMIP) 18353-1002747-02Crypto LUN configuration3Discovering a LUNWhen adding a LUN to a CryptoTarget contai

Strany 116 - Encryption engine rebalancing

184 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Crypto LUN configuration3NOTEThere is a maximum of 512 disk LUNs per Initiator in a

Strany 117 - Master keys

Fabric OS Encryption Administrator’s Guide (KMIP) 18553-1002747-02Crypto LUN configuration3VT: 20:00:00:05:1e:41:4e:1d 20:01:00:05:1e:41:4e:1dNumber o

Strany 118 - Alternate master key

186 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Crypto LUN configuration3TABLE 6 LUN parameters and policies Policy name Command pa

Strany 119

Fabric OS Encryption Administrator’s Guide (KMIP) 18753-1002747-02Crypto LUN configuration3Configuring a tape LUNThis example shows how to configure a

Strany 120 - ATTENTION

188 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Crypto LUN configuration3LUN serial number:Key ID state: Key ID not Applicab

Strany 121

Fabric OS Encryption Administrator’s Guide (KMIP) 18953-1002747-02Crypto LUN configuration3FabricAdmin:switch> cryptocfg --remove -LUN my_disk_tgt

Strany 122

190 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Crypto LUN configuration3CAUTIONWhen configuring a LUN with multiple paths, do not c

Strany 123

Fabric OS Encryption Administrator’s Guide (KMIP) 19153-1002747-02Impact of tape LUN configuration changes3Impact of tape LUN configuration changesLUN

Strany 124

Fabric OS Encryption Administrator’s Guide (KMIP) 353-1002747-02Terminology1Opaque Key VaultA storage location that provides untrusted key management

Strany 125

192 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Configuring a multi-path Crypto LUN3Multi-path LUN configuration exampleFigure 119 o

Strany 126 - Creating a master key

Fabric OS Encryption Administrator’s Guide (KMIP) 19353-1002747-02Configuring a multi-path Crypto LUN3c. Create a CryptoTarget container (CTC2) for ta

Strany 127 - Security Settings

194 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Configuring a multi-path Crypto LUN3b. Add the same LUN to the CryptoTarget containe

Strany 128 - Setting zeroization

Fabric OS Encryption Administrator’s Guide (KMIP) 19553-1002747-02Decommissioning LUNs3Decommissioning LUNsA disk device needs to be decommissioned wh

Strany 129

196 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Decommissioning LUNs33. Enter cryptocfg --show -decommissionedkeyids to obtain a lis

Strany 130 - Disk device decommissioning

Fabric OS Encryption Administrator’s Guide (KMIP) 19753-1002747-02Decommissioning replicated LUNs3Decommissioning replicated LUNsThe following scenari

Strany 131 - Decommissioning disk LUNs

198 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Force-enabling a decommissioned disk LUN for encryption3NOTEDo not delete the key fr

Strany 132

Fabric OS Encryption Administrator’s Guide (KMIP) 19953-1002747-02Force-enabling a disabled disk LUN for encryption37. En a bl e th e LU N .FabricAd

Strany 133 - Displaying Universal IDs

200 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Tape pool configuration3Tape pool configurationTape pools are used by tape backup ap

Strany 134 - Setting disk LUN Re-key All

Fabric OS Encryption Administrator’s Guide (KMIP) 20153-1002747-02Tape pool configuration3CommVault Galaxy labelingCommVault uses a storage policy for

Strany 135

4 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02The Brocade Encryption Switch1The Brocade Encryption SwitchThe Brocade Encryption Swit

Strany 136

202 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Tape pool configuration3Creating a tape poolTake the following steps to create a tap

Strany 137

Fabric OS Encryption Administrator’s Guide (KMIP) 20353-1002747-02Tape pool configuration3Deleting a tape poolThis command does not issue a warning if

Strany 138 - Thin provisioned LUNs

204 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02First-time encryption3First-time encryptionFirst-time encryption, also referred to a

Strany 139 - Thin provisioning support

Fabric OS Encryption Administrator’s Guide (KMIP) 20553-1002747-02Thin provisioned LUNs3Thin provisioned LUNsWith the introduction of Fabric OS 7.1.0,

Strany 140

206 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Thin provisioned LUNs3Encryption algorithm: AES256-XTSKey ID state: Read

Strany 141

Fabric OS Encryption Administrator’s Guide (KMIP) 20753-1002747-02Data rekeying3• Because windows host utility “sdelete –c” sends WRITE command with z

Strany 142

208 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Data rekeying3Configuring a LUN for automatic rekeyingRekeying options are configure

Strany 143

Fabric OS Encryption Administrator’s Guide (KMIP) 20953-1002747-02Data rekeying3Initiating a manual rekey sessionYou can initiate a rekeying session m

Strany 144

210 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Data rekeying3Current LBA: 488577Operation succeeded.Suspension and resum

Strany 145

Fabric OS Encryption Administrator’s Guide (KMIP) 21153-1002747-02Chapter4Deployment ScenariosIn this chapter•Single encryption switch, two paths from

Strany 146 - General tab

Fabric OS Encryption Administrator’s Guide (KMIP) 553-1002747-02The FS8-18 blade1The FS8-18 bladeThe FS8-18 blade provides the same features and funct

Strany 147

212 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Single encryption switch, two paths from host to target4Single encryption switch, tw

Strany 148 - Members tab

Fabric OS Encryption Administrator’s Guide (KMIP) 21353-1002747-02Single fabric deployment - HA cluster4Single fabric deployment - HA clusterFigure 12

Strany 149

214 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Single fabric deployment - DEK cluster4In Figure 121, the two encryption switches pr

Strany 150 - Members tab Remove button

Fabric OS Encryption Administrator’s Guide (KMIP) 21553-1002747-02Dual fabric deployment - HA and DEK cluster4In Figure 122, two encryption switches a

Strany 151 - Security tab

216 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Multiple paths, one DEK cluster, and two HA clusters4failover for the encryption pat

Strany 152

Fabric OS Encryption Administrator’s Guide (KMIP) 21753-1002747-02Multiple paths, one DEK cluster, and two HA clusters4The configuration details shown

Strany 153 - HA Clusters tab

218 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Multiple paths, DEK cluster, no HA cluster4Multiple paths, DEK cluster, no HA cluste

Strany 154

Fabric OS Encryption Administrator’s Guide (KMIP) 21953-1002747-02Multiple paths, DEK cluster, no HA cluster4The configuration details are as follows:

Strany 155 - Tape Pools tab

220 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Deployment in Fibre Channel routed fabrics4Deployment in Fibre Channel routed fabric

Strany 156 - Adding tape pools

Fabric OS Encryption Administrator’s Guide (KMIP) 22153-1002747-02Deployment in Fibre Channel routed fabrics4The following is a summary of steps for c

Strany 157 - Engine Operations tab

6 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Recommendation for connectivity1Recommendation for connectivityIn order to achieve hig

Strany 158 - TABLE 3 Encryption acronyms

222 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Deployment as part of an edge fabric4Deployment as part of an edge fabricIn this dep

Strany 159 - In this chapter

Fabric OS Encryption Administrator’s Guide (KMIP) 22353-1002747-02Deployment with FCIP extension switches4Deployment with FCIP extension switchesEncry

Strany 160 - Command validation checks

224 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02VMware ESX server deployments4VMware ESX server deploymentsVMware ESX servers may ho

Strany 161

Fabric OS Encryption Administrator’s Guide (KMIP) 22553-1002747-02VMware ESX server deployments4Figure 131 shows a VMware ESX server with two guest op

Strany 162 - (Continued)

226 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02VMware ESX server deployments4

Strany 163 - Cryptocfg Help command output

Fabric OS Encryption Administrator’s Guide (KMIP) 22753-1002747-02Chapter5Best Practices and Special TopicsIn this chapter•Firmware upgrade and downgr

Strany 164 - Configuring cluster links

228 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Firmware upgrade and downgrade considerations5Firmware upgrade and downgrade conside

Strany 165

Fabric OS Encryption Administrator’s Guide (KMIP) 22953-1002747-02Firmware upgrade and downgrade considerations5• Guidelines for firmware upgrade of e

Strany 166 - Node is a member node

230 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Configuration upload and download considerations58. Check that CryptoTarget Containe

Strany 167

Fabric OS Encryption Administrator’s Guide (KMIP) 23153-1002747-02Configuration upload and download considerations5• Certificates generated internally

Strany 168 - Creating a cluster

Fabric OS Encryption Administrator’s Guide (KMIP) 753-1002747-02Brocade encryption solution overview1Brocade encryption solution overviewThe loss of s

Strany 169 - Adding a node to the cluster

232 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02HP-UX considerations5Steps after configuration downloadFor all opaque key vaults, re

Strany 170 - KeySecure)

Fabric OS Encryption Administrator’s Guide (KMIP) 23353-1002747-02AIX Considerations5Best practices are as follows:• Create a cryptoTarget container f

Strany 171

234 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Tape metadata5Tape metadataOne kilobyte of metadata is added per tape block for both

Strany 172

Fabric OS Encryption Administrator’s Guide (KMIP) 23553-1002747-02Tape block zero handling5Tape pool configuration is used only when labeling of tape

Strany 173

236 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Redirection zones5• Before committing CryptoTarget container or LUN configurations o

Strany 174 - Verify connectivity

Fabric OS Encryption Administrator’s Guide (KMIP) 23753-1002747-02Deployment with Admin Domains (AD)5Deployment with Admin Domains (AD)Virtual devices

Strany 175 - • Node CP certificate

238 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02PID failover5PID failover Virtual device PIDs do not persist upon failover within a

Strany 176

Fabric OS Encryption Administrator’s Guide (KMIP) 23953-1002747-02KAC certificate registration expiry5Allow rekey to complete before deleting a contai

Strany 177

240 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Changing IP addresses in encryption groups5Changing IP addresses in encryption group

Strany 178 - • cryptocfg --enableEE

Fabric OS Encryption Administrator’s Guide (KMIP) 24153-1002747-02Best practices for host clusters in an encryption environment5FIGURE 132 Fan-in rati

Strany 179

8 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Brocade encryption solution overview1Data flow from server to storageThe Brocade Encry

Strany 180

242 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02HA Cluster deployment considerations and best practices5• For AIX-based Power HA Sys

Strany 181

Fabric OS Encryption Administrator’s Guide (KMIP) 24353-1002747-02Chapter6Maintenance and TroubleshootingIn this chapter•Encryption group and HA clust

Strany 182 - High availability clusters

244 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encryption group and HA cluster maintenance6Encryption group and HA cluster maintena

Strany 183 - Creating an HA cluster

Fabric OS Encryption Administrator’s Guide (KMIP) 24553-1002747-02Encryption group and HA cluster maintenance6FIGURE 133 Removing a node from an encry

Strany 184

246 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encryption group and HA cluster maintenance6 IP Address: 10.32.33

Strany 185

Fabric OS Encryption Administrator’s Guide (KMIP) 24753-1002747-02Encryption group and HA cluster maintenance6Deleting an encryption groupYou can dele

Strany 186 - Policy Configuration Examples

248 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encryption group and HA cluster maintenance6Displaying the HA cluster configurationN

Strany 187 - Re-exporting a master key

Fabric OS Encryption Administrator’s Guide (KMIP) 24953-1002747-02Encryption group and HA cluster maintenance6Replacing an HA cluster member1. Log in

Strany 188 - Viewing the master key IDs

250 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encryption group and HA cluster maintenance6FIGURE 134 Replacing a failed encryption

Strany 189

Fabric OS Encryption Administrator’s Guide (KMIP) 25153-1002747-02Encryption group and HA cluster maintenance6Case 2: Replacing a “live” encryption en

Strany 190

Fabric OS Encryption Administrator’s Guide (KMIP) 953-1002747-02Data encryption key life cycle management1Data encryption key life cycle managementDat

Strany 191 - Zoning considerations

252 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encryption group and HA cluster maintenance6Performing a manual failback of an encry

Strany 192 - Frame redirection zoning

Fabric OS Encryption Administrator’s Guide (KMIP) 25353-1002747-02Encryption group merge and split use cases6• After the failback completes, the crypt

Strany 193

254 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encryption group merge and split use cases6NOTEWhen attempting to reclaim a failed B

Strany 194

Fabric OS Encryption Administrator’s Guide (KMIP) 25553-1002747-02Encryption group merge and split use cases6RecoveryIf auto failback policy is set, n

Strany 195

256 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encryption group merge and split use cases6• The isolation of N3 from the group lead

Strany 196 - Gathering information

Fabric OS Encryption Administrator’s Guide (KMIP) 25753-1002747-02Encryption group merge and split use cases6Recovery1. Restore the connection between

Strany 197

258 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encryption group merge and split use cases6NOTEThe collective time allowed (the hear

Strany 198

Fabric OS Encryption Administrator’s Guide (KMIP) 25953-1002747-02Encryption group merge and split use cases6NOTEIf one or more EG status displays as

Strany 199

260 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encryption group merge and split use cases6Display the encryption group state again.

Strany 200 - Crypto LUN configuration

Fabric OS Encryption Administrator’s Guide (KMIP) 26153-1002747-02Encryption group merge and split use cases6If you now perform a cryptocfg --show -gr

Strany 201 - Configuring a Crypto LUN

10 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Data encryption key life cycle management1FIGURE 5 DEK life cycle

Strany 202

262 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encryption group merge and split use cases66. Verify your encryption group is re-con

Strany 203

Fabric OS Encryption Administrator’s Guide (KMIP) 26353-1002747-02Encryption group database manual operations6Encryption group database manual operati

Strany 204 - LUN parameters and policies

264 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Key vault diagnostics6Use the --sync -securitydb command to distribute the security

Strany 205 - Configuring a tape LUN

Fabric OS Encryption Administrator’s Guide (KMIP) 26553-1002747-02Measuring encryption performance6• Key class and format on the KV configured for the

Strany 206

266 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Measuring encryption performance6FabricAdmin:switch> cryptocfg --perfshow [slot]

Strany 207

Fabric OS Encryption Administrator’s Guide (KMIP) 26753-1002747-02General encryption troubleshooting6General encryption troubleshootingTable 9 lists t

Strany 208

268 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02General encryption troubleshooting6A backup fails because the LUN is always in the i

Strany 209

Fabric OS Encryption Administrator’s Guide (KMIP) 26953-1002747-02General encryption troubleshooting6A performance drop occurs when using DPM on a Mic

Strany 210

270 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Troubleshooting examples using the CLI6Troubleshooting examples using the CLIEncrypt

Strany 211

Fabric OS Encryption Administrator’s Guide (KMIP) 27153-1002747-02Troubleshooting examples using the CLI6Encryption Disabled CryptoTarget LUNIf the LU

Strany 212

Fabric OS Encryption Administrator’s Guide (KMIP) 1153-1002747-02Master key management1Master key managementCommunications with opaque key vaults are

Strany 213 - Decommissioning LUNs

272 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Management application encryption wizard troubleshooting6Management application encr

Strany 214

Fabric OS Encryption Administrator’s Guide (KMIP) 27353-1002747-02Management application encryption wizard troubleshooting6Errors related to adding a

Strany 215

274 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Management application encryption wizard troubleshooting6General errors related to t

Strany 216

Fabric OS Encryption Administrator’s Guide (KMIP) 27553-1002747-02LUN policy troubleshooting6LUN policy troubleshootingTable 14 may be used as an aid

Strany 217

276 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Loss of encryption group leader after power outage6Loss of encryption group leader a

Strany 218 - Tape pool configuration

Fabric OS Encryption Administrator’s Guide (KMIP) 27753-1002747-02MPIO and internal LUN states65. Synchronize the crypto configurations across all mem

Strany 219 - NetWorker labeling

278 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02FS8-18 blade removal and replacement61. Enter the cryptocfg --resume_rekey command,

Strany 220 - Creating a tape pool

Fabric OS Encryption Administrator’s Guide (KMIP) 27953-1002747-02FS8-18 blade removal and replacement63. If the replaced FS8-18 blade is in member no

Strany 221 - Modifying a tape pool

280 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02FS8-18 blade removal and replacement6NOTEBecause the FS8-18 blade was inserted in th

Strany 222 - First-time encryption

Fabric OS Encryption Administrator’s Guide (KMIP) 28153-1002747-02Brocade Encryption Switch removal and replacement611. If a master key is not present

Strany 223

Fabric OS Encryption Administrator’s Guide (KMIP) iii53-1002747-02ContentsAbout This DocumentIn this chapter . . . . . . . . . . . . . . . . . . . . .

Strany 224 - Space reclamation

12 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Cisco Fabric Connectivity support1Cisco Fabric Connectivity supportThe Brocade Encryp

Strany 225 - Data rekeying

282 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Brocade Encryption Switch removal and replacement68. Power on the new Brocade Encryp

Strany 226

Fabric OS Encryption Administrator’s Guide (KMIP) 28353-1002747-02Brocade Encryption Switch removal and replacement621. Import the signed CSR/Cert ont

Strany 227

284 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Brocade Encryption Switch removal and replacement631. If HA cluster membership for t

Strany 228

Fabric OS Encryption Administrator’s Guide (KMIP) 28553-1002747-02Brocade Encryption Switch removal and replacement611. Invoke the following command t

Strany 229 - Deployment Scenarios

286 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Reclaiming the WWN base of a failed Brocade Encryption Switch627. Verify that defzon

Strany 230

Fabric OS Encryption Administrator’s Guide (KMIP) 28753-1002747-02Removing stale rekey information for a LUN6NOTEWhen attempting to reclaim a failed B

Strany 231 - Virtual

288 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Splitting an encryption group into two encryption groups6NOTEYou should not join a F

Strany 232

Fabric OS Encryption Administrator’s Guide (KMIP) 28953-1002747-02Moving an encryption blade from one EG to another in the same fabric6a. Create the g

Strany 233

290 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Moving an encryption switch from one EG to another in the same fabric6Moving an encr

Strany 234

Fabric OS Encryption Administrator’s Guide (KMIP) 29153-1002747-02AppendixAState and Status InformationIn this appendix•Encryption engine security pro

Strany 235

Fabric OS Encryption Administrator’s Guide (KMIP) 1353-1002747-02Chapter2Configuring Encryption Using the Management ApplicationIn this chapter•Encryp

Strany 236

292 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Security processor KEK statusASecurity processor KEK statusTable 19 lists security p

Strany 237

Fabric OS Encryption Administrator’s Guide (KMIP) 29353-1002747-02Encrypted LUN statesALUN_1ST_TIME_REKEY_IN_PROG First time rekey is in progress.LUN_

Strany 238

294 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encrypted LUN statesALUN_DIS_WR_META_DONE_ERR Disabled (Write metadata done with fai

Strany 239 - --rdcreate [host wwn]

Fabric OS Encryption Administrator’s Guide (KMIP) 29553-1002747-02Encrypted LUN statesATABLE 21 Tape LUN statesInternal Names Console String Explanati

Strany 240

296 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encrypted LUN statesALUN_ENCRYPT Encryption enabled The tape medium is present, and

Strany 241 - FIGURE 129 FCIP deployment

Fabric OS Encryption Administrator’s Guide (KMIP) 29753-1002747-02IndexAadd commands--add -haclustermember, 166--add -initiator, 179, 187, 193--add -L

Strany 242 - VMware ESX server deployments

298 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Crypto LUNadding to CryptoTarget container using the CLI, 182configuring, 182, 183mo

Strany 243

Fabric OS Encryption Administrator’s Guide (KMIP) 29953-1002747-02disk lunsdecommissioning, 113rekeying manually, 115setting rekey all, 116viewing rek

Strany 244

300 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02encryption nodesetting initialization, 28encryption nodessetting initialization, 148

Strany 245

Fabric OS Encryption Administrator’s Guide (KMIP) 30153-1002747-02Iimport commands, --import, 161initialize commands--initEE, 254initEE, 158--initnode

Strany 246 - General guidelines

14 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encryption Center features2•Viewing and editing encryption group properties . . . . .

Strany 247

302 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02member nodesadding to an encryption group, 160members tab, 130remove button, 132modi

Strany 248

Fabric OS Encryption Administrator’s Guide (KMIP) 30353-1002747-02set commands--set -failback, 168--set -keyvault LKM, 159show commands--show, 162, 17

Strany 249

304 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02troubleshootingcfgshow command, 267configshow, 267cryptocfg --show -groupcfg command

Strany 250 - HP-UX considerations

Fabric OS Encryption Administrator’s Guide (KMIP) 1553-1002747-02Encryption user privileges2Encryption user privilegesIn BNA, resource groups are assi

Strany 251 - Disk metadata

16 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Smart card usage2Smart card usageSmart Cards are credit card-sized cards that contain

Strany 252 - Tape pools

Fabric OS Encryption Administrator’s Guide (KMIP) 1753-1002747-02Smart card usage2• Establishing a trusted link with the NetApp LKM key vault.• Decomm

Strany 253 - Tape key expiry

18 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Smart card usage23. Locate the Authentication Card Quorum Size and select the quorum

Strany 254

Fabric OS Encryption Administrator’s Guide (KMIP) 1953-1002747-02Smart card usage2Registering authentication cards from the databaseSmart cards that a

Strany 255

20 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Smart card usage2Deregistering an authentication cardAuthentication cards can be remo

Strany 256 - PID failover

Fabric OS Encryption Administrator’s Guide (KMIP) 2153-1002747-02Smart card usage2Using system cardsSystem cards are smart cards that can be used to c

Strany 257

iv Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Support for virtual fabrics. . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Strany 258

22 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Smart card usage2Enabling or disabling the system card requirementTo use a system car

Strany 259

Fabric OS Encryption Administrator’s Guide (KMIP) 2353-1002747-02Smart card usage2Deregistering system cardsSystem cards can be removed from the datab

Strany 260 - Tape Device LUN Mapping

24 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Smart card usage2FIGURE 12 Smart Card asset tracking dialog boxThe Smart Cards table

Strany 261

Fabric OS Encryption Administrator’s Guide (KMIP) 2553-1002747-02Smart card usage2• Save As button: Saves the entire list of smart cards to a file. Th

Strany 262

26 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Network connections22. Insert the smart card into the card reader.3. After the card’s

Strany 263

Fabric OS Encryption Administrator’s Guide (KMIP) 2753-1002747-02Blade processor links2Blade processor linksEach encryption switch or blade has two Gb

Strany 264

28 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Encryption node initialization and certificate generation23. Enter the link IP addres

Strany 265 - Removing an HA cluster member

Fabric OS Encryption Administrator’s Guide (KMIP) 2953-1002747-02Key Management Interoperability Protocol2Key Management Interoperability Protocol The

Strany 266

30 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2NOTEIf you are configuri

Strany 267

Fabric OS Encryption Administrator’s Guide (KMIP) 3153-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2Setting FIPS compliance1

Strany 268

Fabric OS Encryption Administrator’s Guide (KMIP) v53-1002747-02High availability (HA) clusters . . . . . . . . . . . . . . . . . . . . . . . . . . .

Strany 269 - Deleting an HA cluster member

32 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2Creating a local CA1. Fr

Strany 270 - Failover/failback example

Fabric OS Encryption Administrator’s Guide (KMIP) 3353-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2Creating a server certif

Strany 271 - Recovery

34 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2FIGURE 19 KeySecure Cert

Strany 272

Fabric OS Encryption Administrator’s Guide (KMIP) 3553-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)25. Copy the certificate

Strany 273

36 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)28. Select Server as the

Strany 274

Fabric OS Encryption Administrator’s Guide (KMIP) 3753-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2FIGURE 24 KeySecure Cert

Strany 275

38 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2Creating a cluster1. Fro

Strany 276 - -hbmisses and -hbtimeout

Fabric OS Encryption Administrator’s Guide (KMIP) 3953-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2FIGURE 27 KeySecure Clus

Strany 277

40 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2Configuring a Brocade gr

Strany 278

Fabric OS Encryption Administrator’s Guide (KMIP) 4153-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2Registering the KeySecur

Strany 279

vi Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Disk device decommissioning . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Strany 280

42 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2Signing the encryption n

Strany 281

Fabric OS Encryption Administrator’s Guide (KMIP) 4353-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2FIGURE 31 Certificate an

Strany 282 - Key vault diagnostics

44 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2FIGURE 32 Import Signed

Strany 283 - -portperfshow

Fabric OS Encryption Administrator’s Guide (KMIP) 4553-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2FIGURE 34 Backup and Res

Strany 284

46 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2Configuring the KMIP ser

Strany 285 - Problem Resolution

Fabric OS Encryption Administrator’s Guide (KMIP) 4753-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2Adding a node to the clu

Strany 286 - General errors and conditions

48 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure)2FIGURE 38 KeySecure Clus

Strany 287

Fabric OS Encryption Administrator’s Guide (KMIP) 4953-1002747-02Encryption preparation28. Under Restore Backup, select Upload from browser, then ente

Strany 288

50 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Creating an encryption group2• An external host is available on the LAN to facilitate

Strany 289

Fabric OS Encryption Administrator’s Guide (KMIP) 5153-1002747-02Creating an encryption group25. Select Security Settings.6. Confirm the configuration

Strany 290

Fabric OS Encryption Administrator’s Guide (KMIP) vii53-1002747-02Steps for connecting to a KMIP appliance (SafeNet KeySecure). . . . . . . . . . . .

Strany 291

52 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Creating an encryption group2FIGURE 43 Designate Switch Membership dialog box 5. For

Strany 292

Fabric OS Encryption Administrator’s Guide (KMIP) 5353-1002747-02Creating an encryption group2The dialog box contains the following information:• Encr

Strany 293 - LUN policy troubleshooting

54 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Creating an encryption group2Using this dialog box, you can select a key vault for th

Strany 294

Fabric OS Encryption Administrator’s Guide (KMIP) 5553-1002747-02Creating an encryption group2Configuring key vault settings for Key Management Intero

Strany 295 - MPIO and internal LUN states

56 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Creating an encryption group24. (Optional) Enter a Backup Key Vault IP address or hos

Strany 296 - Multi-node EG replacement

Fabric OS Encryption Administrator’s Guide (KMIP) 5753-1002747-02Creating an encryption group2FIGURE 48 Specify Master Key File Name dialog box9. Ente

Strany 297

58 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Creating an encryption group2FIGURE 49 Select Security Settings dialog box12. Set quo

Strany 298 - Single-node EG replacement

Fabric OS Encryption Administrator’s Guide (KMIP) 5953-1002747-02Creating an encryption group2FIGURE 50 Confirm Configuration dialog box14. Confirm th

Strany 299 - Multi-node EG Case

60 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Creating an encryption group2All configuration items have green check marks if the co

Strany 300

Fabric OS Encryption Administrator’s Guide (KMIP) 6153-1002747-02Adding a switch to an encryption group23. Register the key vault. BNA registers the k

Strany 301

viii Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Crypto LUN configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Strany 302 - Single-node EG Replacement

62 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Adding a switch to an encryption group2FIGURE 53 Configure Switch Encryption wizard -

Strany 303

Fabric OS Encryption Administrator’s Guide (KMIP) 6353-1002747-02Adding a switch to an encryption group2The dialog box contains the following informat

Strany 304

64 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Adding a switch to an encryption group2FIGURE 56 Specify Public Key Certificate (KAC)

Strany 305

Fabric OS Encryption Administrator’s Guide (KMIP) 6553-1002747-02Adding a switch to an encryption group2FIGURE 58 Configuration Status dialog boxAll c

Strany 306 - Encryption group Nodes

66 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Adding a switch to an encryption group2FIGURE 59 Error Instructions dialog box8. Revi

Strany 307

Fabric OS Encryption Administrator’s Guide (KMIP) 6753-1002747-02Replacing an encryption engine in an encryption group2Replacing an encryption engine

Strany 308

68 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02High availability (HA) clusters2High availability (HA) clusters A high availability (

Strany 309 - State and Status Information

Fabric OS Encryption Administrator’s Guide (KMIP) 6953-1002747-02High availability (HA) clusters2Creating HA clusters For the initial encryption node,

Strany 310 - Encrypted LUN states

70 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02High availability (HA) clusters23. Click the right arrow to add the encryption engine

Strany 311

Fabric OS Encryption Administrator’s Guide (KMIP) 7153-1002747-02Configuring encryption storage targets2Failback optionThe Failback option determines

Strany 312

Fabric OS Encryption Administrator’s Guide (KMIP) ix53-1002747-02Deployment in Fibre Channel routed fabrics. . . . . . . . . . . . . . . . . .220Deplo

Strany 313 - TABLE 21 Tape LUN states

72 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Configuring encryption storage targets26. Configuration Status7. Important Instructio

Strany 314

Fabric OS Encryption Administrator’s Guide (KMIP) 7353-1002747-02Configuring encryption storage targets2FIGURE 63 Configure Storage Encryption welcome

Strany 315

74 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Configuring encryption storage targets2The dialog box contains the following informat

Strany 316

Fabric OS Encryption Administrator’s Guide (KMIP) 7553-1002747-02Configuring encryption storage targets26. Select a target from the list. (The Target

Strany 317

76 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Configuring encryption storage targets2NOTENote: You must enter the host node world w

Strany 318

Fabric OS Encryption Administrator’s Guide (KMIP) 7753-1002747-02Configuring encryption storage targets2FIGURE 67 Name Container dialog box10. Enter t

Strany 319

78 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Configuring encryption storage targets2The screen contains the following information:

Strany 320

Fabric OS Encryption Administrator’s Guide (KMIP) 7953-1002747-02Configuring encryption storage targets213. Review any post-configuration instructions

Strany 321

80 Fabric OS Encryption Administrator’s Guide (KMIP)53-1002747-02Configuring hosts for encryption targets2Configuring hosts for encryption targetsUse

Strany 322

Fabric OS Encryption Administrator’s Guide (KMIP) 8153-1002747-02Configuring hosts for encryption targets2FIGURE 72 Encryption Target Hosts dialog box

Komentáře k této Příručce

Žádné komentáře