Brocade Network Advisor SAN User Manual v12.0.0 (53-1002696-01, April 2013)

Brocade Network Advisor SAN User Manual 671
53-1002696-01
Master keys
20
Refer to the following procedures for more information:
“Saving the master key to a file” on page 671
“Saving a master key to a key vault” on page 672
“Saving a master key to a smart card set” on page 673
You must back up the master key when the status is Created but not backed up.
Restore master key: Enabled when no master key exists or the previous master key has been
backed up. This option is also enabled when using a DPM key vault.
When this option is selected, the Restore Master Key for Encryption Group dialog box displays,
from which you can restore a master key from a file, key vault, or smart card set. Refer to the
following procedures for more information:
“Restoring a master key from a file” on page 675
“Restoring a master key from a key vault” on page 676
“Restoring a master key from a smart card set” on page 677
Create new master key: Enabled when no master key exists, or the previous master key has
been backed up. Refer to “Creating a new master key” on page 678.
You must create a new master key when the status is Required but not created.
NOTE
If a master key was not created, Not Used is displayed as the status and the Master Key
Actions list is grayed out. In this case, you must create a new master key. Additional master key
statuses are: Backed up but not propagated and Created and backed up.
Saving the master key to a file
Use the following procedure to save the master key to a file.
1. Select Configure > Encryption from the menu task bar to display the Encryption Center
dialog box (Refer to Figure 185 on page 526).
2. Select a group from the Encryption Center Devices table, then select Group > Security from the
menu task bar.
The Encryption Group Properties dialog box displays with the Security tab selected.
3. Select Backup Master Key as the Master Key Action.
The Master Key Backup dialog box displays (Figure 312), but only if the master key has already
been generated.