Administrator's Guide Supporting NetApp Lifetime Key Manager (LKM) and KeySecure Storage Secure Key Manager (SSKM) Environments (Supporting Fabric OS v7.2.0) User Manual
278 Fabric OS Encryption Administrator’s Guide (LKM/SSKM)
53-1002925-01
Index
152
, 153
configuring for first-time encryption
, 166
configuring for multi-path example
, 154
configuring policies using the CLI
, 147
force-enabling for encryption
, 160, 161
impact of policy changes
, 153
modifying parameters using the CLI
, 152
multi-path configuration requirements
, 140
policy for DF-compatibility disk LUNs
, 267
policy for DF-compatibility tape LUNs
, 271
policy for DF-compatibility tape pools
, 271
policy parameters
, 152
removing Crypto LUN to CryptoTarget container
, 151
setting policy for automatic re-keying
, 170
LUN mapping
tape device
, 207
M
management console
launching
, 29
manual command, --manual_rekey
, 171
manual rekey
, 204
manual rekey operations
viewing progress
, 90
members tab
, 100
modify commands
--modify -LUN
, 151, 152, 166, 170
--modify -tapepool
, 165
move commands, --move -container
, 144
multi-path
configuring Crypto LUN
configuring
for multi-path, 153
LUN configuration example
, 154
LUN configuration warning
, 152, 153
multi-path configuration for encrypted storage using the
Management application
, 60
multi-path LUN configuration requirements
, 140
multi-path LUN configuration warning
, 139, 141, 143,
145, 147, 151
N
NetApp Lifetime Key Manager (LKM), description of, 29,
121
NetApp LKM key vaults
effects of zeroizing
, 81
NetBackup labeling
, 163
network connections
requirements
, 27
NetWorker labeling
, 163
P
PID failover, 203
policies
configuration examples
, 135
for Crypto LUN
, 147
impact of LUN policy changes
, 153
impact of tape pool policy changes
, 165
modifying for LUNs using the CLI
, 152
setting for LUN re-keying
, 170
privileges, user
, 15
procedure
adding tape pools
, 109
adding target disk luns for encryption
, 64
adding target tape luns
, 69
connecting to an appliance
, 29
decommissioning disk luns
, 84
displaying and deleting decommissioned key IDs
, 85
rebalancing an EE
, 80
setting zeroization
, 81
procedures
adding a switch to an encryption group
, 44
adding an encryption target
, 54
configuring hosts for encryption targets
, 62
configuring KV settings
, 38
creating an encryption group
, 34
creating HA clusters
, 51
invoking failback
, 53
removing engines from an HA cluster
, 52
replacing an EE in an encryption group
, 49
viewing and editing switch encryption properties
, 93
public key certificate
importing from properties
, 96
public key CSR
exporting from properties
, 96
R
redirection zones, 83, 202
register commands
--reg -membernode
, 131, 220
--regEE
, 220
regEE
, 123
rekey and Brocade native mode
, 204