HP B-series Fabric OS 7.1.1a Release Notes (5697-3023, November 2013 - includes all 7.1.1x versions)

The System Card feature requires a compatible DCFM or HP Network Advisor release that
supports this feature: DCFM 10.4 or later for pre-Fabric OS 7.0.0a and Network Advisor
11.1 or later for Fabric OS 7.0.0a or later. All nodes in the EG must be running Fabric OS
6.3.0 or later for system verification to be properly supported.
The HP StorageWorks Encryption SAN Switch and HP StorageWorks DC Switch Encryption
FC Blade do not support QoS. When using encryption or Frame Redirection, participating
flows should not be included in QoS Zones.
HP SKM/ESKM are supported with Multiple Nodes and Dual SKM/ESKM Key Vaults. Two-way
certificate exchange is supported. See the Encryption Administration Guide for configuration
information. If you are using dual SKM/ESKMs on HP StorageWorks Encryption SAN
Switch/HP StorageWorks DC Switch Encryption FC Blade Encryption Group, then these
SKM/ESKM appliances must be clustered. Failure to cluster results in key creation failure.
Otherwise, register only one SKM/ESKM on the HP StorageWorks Encryption SAN Switch/HP
StorageWorks DC Switch Encryption FC Blade Encryption Group.
Starting with Fabric OS 7.1, SHA256 signatures will be used for the TLS certificates to connect
to the ESKM 3.0 Server using the ESKM 2.0 client. Upgrade from Fabric OS versions
(6.4.x/7.0.x) to Fabric OS 7.1.0 and later requires regeneration and re-registration of CA
and signed KAC certificates to restore connectivity to the key vault. This is also true for
downgrade from Fabric OS 7.1.0 and later to Fabric OS versions 6.4.x/7.0.x. Please refer
to the Encryption Administration Guide for more details on the ESKM/Fabric OS compatibility
matrix.
With Windows and Veritas Volume Manager/Veritas Dynamic Multipathing, when LUN sizes
less than 400 MB are presented to HP StorageWorks Encryption SAN Switch for encryption,
a host panic may occur and this configuration is not supported in the Fabric OS 6.3.1 or later
release.
Hot Code Load from Fabric OS 6.4.1a to Fabric OS 7.0.0a or later is supported.
Cryptographic operations and I/O are disrupted, but other layer 2 FC traffic is not disrupted.
When disk and tape CTCs are hosted on the same encryption engine, re-keying cannot be
done while tape backup or restore operations are running. Re-keying operations must be
scheduled at a time that does not conflict with normal tape I/O operations. The LUNs should
not be configured with the auto rekey option when single EE has disk and tape CTCs.
Fabric OS 7.1.0 introduces support for the disk device decommissioning feature. To use this
feature, all the nodes in the encryption group must be running Fabric OS 7.1.0 or later.
Firmware downgrade will be prevented from Fabric OS 7.1.0 to a lower version if this feature
is in use.
Fabric OS 7.1.0 mandates regular zones for Hosts and Targets must be defined in the effective
configuration before adding an initiator into a crypto container. If the crypto commit operation
is performed without regular zones for the Host and Target, frame redirection zones will not
be created. Hosts and targets must be zoned together by worldwide port name (WWPN)
rather than worldwide node name (WWNN) in configurations where frame redirection will
be used.
In Fabric OS 7.1.0, the encryption FPGA has been upgraded to include parity protection of
lookup memory (ROM) within the AES engine. This change enhances the parity error detection
capability of the FPGA.
20