Brocade Fabric OS Encryption Administrator's Guide v7.1.0 (53-1002721-01, March 2013)

Table Of Contents
110 Fabric OS Encryption Administrators Guide (SKM/ESKM)
53-1002721-01
Viewing and editing switch encryption properties
2
Encryption Group Status: Status options are:
OK/Converged: the group leader can communicate with all members.
Degraded: the group leader cannot communicate with one or more members. The
following operations are not allowed: key vault changes, master key operations,
enable/disable encryption engines, Failback mode changes, HA Cluster creation or
addition (removal is allowed), tape pool changes, and any configuration changes for
storage targets, hosts, and LUNs.
Unknown: The group leader is in an unmanaged fabric.
Fabric: The name of the fabric to which the switch belongs.
Domain ID: The domain ID of the selected switch.
Key Vault type
Firmware Version: The current encryption firmware on the switch.
Primary Key Vault Link Key Status/Backup Key Vault Link Key Status: (LKM/SSKM key
vault only.) Shown as Not Used.
Primary Key Vault Connection Status/Backup Key Vault Connection Status: Whether the
primary key vault link is connected. Options are:
Unknown/Busy
Key Vault Not Configured
No Response
Failed authentication
Connected.
Key Vault User Name button: (TEKA key vault only). Shown as inactive.
Public Key Certificate Request text box: The switch’s KAC certificate signing request, which
must be signed by a certificate authority (CA). The signed certificate must then be
imported onto the switch and onto the primary and backup key vaults.
Export button: Exports the public key certificate in CSR format to an external file for signing
by a certificate authority (CA).
Import button: Imports a signed public key certificate.
Encryption Engine Properties table: The properties for the encryption engine. There may
be 0 to 4 slots, one for each encryption engine in the switch.
Current Status: The status of the encryption engine. Many possible values exist. Common
options are:
Not Available (the engine is not initialized)
Disabled
Operational
need master/link key
Online
Set State To: Identifies if the state is enabled or disabled. You can click the line item in the
table to change the value, then click OK to apply the change.
Total Targets: The number of encrypted target devices.
HA Cluster Peer: The name and location of the high-availability (HA) cluster peer (another
encryption engine in the same group), if in an HA configuration. If no peer is configured, No
Peer is displayed.