Brocade Network Advisor SAN User Manual v12.0.0 (53-1002696-01, April 2013)

Brocade Network Advisor SAN User Manual 527
53-1002696-01
Encryption user privileges
20
“Blade processor links” on page 539 describes the steps for interconnecting encryption
switches or blades in an encryption group through a dedicated LAN. This must be done before
the encryption engines are enabled. Security parameters and certificates cannot be
exchanged if these links are not configured and active.
“Encryption node initialization and certificate generation” on page 540 lists the security
parameters and certificates that are generated when an encryption node is initialized.
“Supported encryption key manager appliances” on page 542 lists the supported key manager
appliances, and lists topics that provide additional detail.
Encryption user privileges
In the Management application, resource groups are assigned privileges, roles, and fabrics.
Privileges are not directly assigned to users; users get privileges because they belong to a role in a
resource group. A user can only belong to one resource group at a time.
The Management application provides three pre-configured roles:
Storage encryption configuration
Storage encryption key operations
Storage encryption security
Table 65 lists the associated roles and their read/write access to specific operations. The functions
are enabled from the Encryption Center dialog box:
TABLE 65 Encryption privileges
Privilege Read/Write
Storage Encryption
Configuration
Launch the Encryption center dialog box.
View switch, group, or engine properties.
View the Encryption Group Properties Security tab.
View encryption targets, hosts, and LUNs.
View LUN centric view
View all rekey sessions
Add/remove paths and edit LUN configuration on LUN centric view
Rebalance encryption engines.
Clear tape LUN statistics
Create a new encryption group or add a switch to an existing encryption group.
Edit group engine properties (except for the Security tab)
Add targets.
Select encryption targets and LUNs to be encrypted or edit LUN encryption settings.
Edit encryption target hosts configuration.
Show tape LUN statistics.
Storage Encryption Key
Operations
Launch the Encryption center dialog box.
View switch, group, or engine properties,
View the Encryption Group Properties Security tab.
View encryption targets, hosts, and LUNs.
View LUN centric view.
View all rekey sessions.
Initiate manual rekeying of all disk LUNs.
Initiate refresh DEK.
Enable and disable an encryption engine.
Decommission LUNs.
Zeroize an encryption engine.
Restore a master key.
Edit key vault credentials.
Show tape LUN statistics.