LSI Corporation
- 44 -
12Gb/s MegaRAID SAS Software User Guide
March 2014
Chapter 3: SafeStore Disk Encryption
Instant Secure Erase
3.2.4
Import a Foreign Configuration
After you create a security key, you can run a scan for a foreign configuration and import a locked configuration. (You
can import unsecured or unlocked configurations when security is disabled.) A foreign configuration is a RAID
configuration that already exists on a replacement set of drives that you install in a computer system. WebBIOS
Configuration Utility and the MegaRAID Storage Manager software allows you to import the existing configuration to
the RAID controller or clear the configuration so you can create a new one.
See
Importing or Clearing a Foreign Configuration
, for the procedure in the MegaRAID Storage Manager software.
To import a foreign configuration, you must first enable security to allow importation of locked foreign drives. If the
drives are locked and the controller security is disabled, you cannot import the foreign drives. Only unlocked drives
can be imported when security is disabled.
After you enable the security, you can import the locked drives. To import the locked drives, you must provide the
security key used to secure them. Verify whether any drives are left to import as the locked drives can use different
security keys. If there are any drives left, repeat the import process for the remaining drives. After all of the drives are
imported, there is no configuration to import.
3.3
Instant Secure Erase
Instant Secure Erase is a feature used to erase data from encrypted drives. After the initial investment for an encrypted
disk, there is no additional cost in dollars or time to erase data using the Instant Secure Erase feature.
You can change the encryption key for all MegaRAID RAID controllers that are connected to encrypted drives. All
encrypted drives, whether locked or unlocked, always have an encryption key. This key is set by the drive and is always
active. When the drive is unlocked, the data to host from the drive (on reads) and from the host to the drive cache (on
writes) is always provided. However, when resting on the drive platters, the data is always encrypted by the drive.
You might not want to lock your drives because you have to manage a password if they are locked. Even if you do not
lock the drives, there is still a benefit to using encrypted disks.
If you are concerned about data theft or other security issues, you might already invest in drive disposal costs, and
there are benefits to using SafeStore encryption over other technologies that exist today, both in terms of the security
provided and time saved.
If the encryption key on the drive changes, the drive cannot decrypt the data on the platters, effectively erasing the
data on the disks. The National Institute of Standards and Technology
) values this type of data
erasure above secure erase and below physical destruction of the device.
Consider the following reasons for using instant secure erase.
To repurpose the hard drive for a different application
You might need to move the drive to another server to expand storage elsewhere, but the drive is in use. The data on
the drive might contain sensitive data including customer information that, if lost or divulged, could cause an
embarrassing disclosure of a security hole. You can use the instant secure erase feature to effectively erase the data so
that the drive can be moved to another server or area without concern that old data could be found.
To replace drives
If the amount of data has outgrown the storage system, and there is no room to expand capacity by adding drives,
you might choose to purchase upgrade drives. If the older drives support encryption, you can erase the data instantly
so the new drives can be used.
To return a disk for warranty activity
Summary of Contents for ThinkServer RD650
Page 1: ...ThinkServer 12 Gb s MegaRAID SAS Software User Guide ...
Page 417: ......
Page 418: ......