40
Drive Security with Full Disk Encryption
The hot spare must be the same type of drive as the drive that failed (for example, a
Serial Advanced Technology Attachment [SATA] hot spare cannot replace a Fibre
Channel hot spare).
You can assign drives to act as hot spares manually or have the script commands
automatically assign hot spares. If you manually assign a drive to be a hot spare, you
must identify the drive by tray ID and slot ID. When you let the script commands
automatically assign hot spares, you must enter the number of hot spares that you
want in the storage array.
Drive Security
with Full Disk
Encryption
Drive Security is a premium feature that prevents unauthorized access to the data on a
drive that is physically removed from the storage array. Controllers in the storage
array have a
security key
. Secure drives provide access to data only through a
controller that has the correct security key. Drive Security is a premium feature of the
storage management software and must be enabled either by you or your storage
vendor.
The Drive Security premium feature requires
security capable
drives. A security
capable drive encrypts data during writes and decrypts data during reads. Each
security capable drive has a unique drive encryption key.
When you create a
secure volume group
from security capable drives, the drives in
that volume group become security enabled. When a security capable drive has been
security enabled, the drive requires the correct security key from a controller to read
or write the data. All of the drives and controllers in a storage array share the same
security key. The shared security key provides read access and write access to the
drives, while the drive encryption key on each drive is used to encrypt the data. A
security capable drive works like any other drive until it is security enabled.
Whenever the power is turned off and turned on again, all of the security-enabled
drives change to a
security locked
state. In this state, the data is inaccessible until the
correct security key is provided by a controller.
You can view the Drive Security status of any drive in the storage array from the
Drive Properties
dialog. The drive can have one of these capabilities:
Security Capable
Secure – Security enabled or disabled
Read/Write Accessible – Security locked or unlocked
You can view the Drive Security status of any volume group in the storage array by
using the
show volume group
command. The volume group can have one of
these capabilities:
Security Capable
Secure
The following table shows how to interpret the security properties status of a volume
group.
Summary of Contents for InfiniteStorage 4000 Series
Page 34: ...22 ExitStatus ...
Page 48: ...36 Adding Comments to a Script File ...
Page 110: ...98 Starting Stopping and Resuming a Snapshot Legacy Rollback ...
Page 168: ...156 Interaction with Other Premium Features ...
Page 182: ...170 Interaction with Other Premium Features ...
Page 192: ...180 SSD Cache Management Tasks ...
Page 216: ...204 RecoveryOperations ...
Page 218: ...206 Show Storage Array ...
Page 219: ...Appendix A Examples of Information Returned by the Show Commands 207 ...
Page 220: ...208 Show Storage Array ...
Page 221: ...Appendix A Examples of Information Returned by the Show Commands 209 ...
Page 222: ...210 Show Storage Array ...
Page 223: ...Appendix A Examples of Information Returned by the Show Commands 211 ...
Page 224: ...212 Show Storage Array ...
Page 225: ...Appendix A Examples of Information Returned by the Show Commands 213 ...
Page 226: ...214 Show Storage Array ...
Page 227: ...Appendix A Examples of Information Returned by the Show Commands 215 ...
Page 228: ...216 Show Storage Array ...
Page 229: ...Appendix A Examples of Information Returned by the Show Commands 217 ...
Page 230: ...218 Show Storage Array ...
Page 231: ...Appendix A Examples of Information Returned by the Show Commands 219 ...
Page 233: ...Appendix A Examples of Information Returned by the Show Commands 221 ...
Page 234: ...222 Show Controller NVSRAM ...
Page 253: ...Appendix A Examples of Information Returned by the Show Commands 241 ...
Page 254: ...242 ShowDrive ...
Page 255: ...Appendix A Examples of Information Returned by the Show Commands 243 ...
Page 256: ...244 ShowDrive ...
Page 257: ...Appendix A Examples of Information Returned by the Show Commands 245 ...
Page 258: ...246 ShowDrive ...
Page 268: ...256 ConfigurationUtility ...
Page 275: ......
Page 276: ...Copyright 2012 NetApp Inc All rights reserved ...