evfsfile.1 (2010 09)

e
evfsfile(1) evfsfile(1)
(EVFS Software Required)
NAME
evfsfile - manage EVFS encrypted files and directories
SYNOPSIS
evfsfile add -r file
evfsfile assign -r recovkey_file -u user
-g group file
evfsfile assign -r recovkey_file {
-u user | -g group} file
evfsfile decrypt file
evfsfile encrypt [-c cipher ] file
evfsfile list file | directory
evfsfile rekey [-c cipher ] file
evfsfile set [-c cipher | -d] directory
evfsfile sync file | directory
DESCRIPTION
The
evfsfile command enables users to manage HP-UX EVFS encrypted files and directory created in
a disk or volume in file-level encryption mode.
With
evfsfile, users can enable/disable a directory or a file system for encryption, list the encryption
attributes of an encrypted file or a directory configured for encryption. Users can also convert a clear-text
file in an Encrypted File System to an encrypted file, an encrypted file to clear-text file and change the file
symmetric key (rekey) of an encrypted file. This command can be used to add/replace a recovery key
record of an encrypted file. evfsfile command can also be used to synchronize the file UNIX DAC per-
missions with the EVFS access permissions of an encrypted file in case there is any mismatch.
The
evfsfile command requires the optional HP-UX Encrypted Volume and File System (EVFS)
software.
Subcommands
evfsfile recognizes the following subcommands:
add Add/Replace a recovery key record (key envelope) of an encrypted file. If the recovery key
record already exists in the encrypted file, then this command replaces the existing
recovery key record with the key record of the recovery key loaded in the system. The
recovery key should be already loaded in the system to add/replace the recovery key
record. Use the evfspkey loadkey command to load the recovery key. See evfsp-
key(1).
Only the owner of an encrypted file, being in secure session, can perform this operation.
assign Change file owner, group, or both for an encrypted file. The current owner’s key record
in the encrypted file is replaced by the new owner’s key record. The current group’s key
record in the encrypted file is replaced by the new group’s key record if it is specified.
Only the system admin or the owner of the encrypted file can perform this operation.
decrypt Convert an encrypted file to clear-text file. A file in conversion is not accessible until the
operation is successful.
Only the owner of the file, being in secure session, can perform this operation. Users
must login to secure session using the
evfsauth login command. See evfsauth (1).
encrypt Convert the clear-text file to an encrypted file. Users can specify the cipher with which
the data to be encrypted. A file in conversion is not accessible until the operation is suc-
cessful.
Only the owner of the file, being in secure session, can perform this operation. Users
must login to secure session using the
evfsauth login command. See evfsauth (1).
list List the encryption parameters of an encrypted file or a directory enabled for encryption.
A user with valid UNIX DAC permissions can perform this operation.
rekey Change the symmetric key of an encrypted file. Users can specify the cipher with which
the data to be re-encrypted. A file in conversion is not accessible until the operation is
HP-UX 11i Version 3: September 2010 1 Hewlett-Packard Company 1

Summary of content (4 pages)