
XYGATE
®
Data Protection
™
Reference Manual
Chapter 4. Setting up Tokenization in XDP
XYPRO Technology Corporation
20
Proprietary and Confidential
Add FILEDEF MYFILE to a DPGROUP in order for XDP to use it:
DPGROUP MYACL
DESCRIPTION "My ACL"
FILEDEF MYFILE
<other security settings>
Multiple FILEDEFs can be added to a FILEDEF line in a DPGROUP if the FILEDEF
names are separated by commas. Multiple FILEDEF lines can also be used if needed.
Compile the configuration (assuming that your XDP installation is named XDP):
TACL 50 >
XDP_COMPILE
If XDP is running, you will also have to load the configuration:
TACL 51 >
XDP_LOAD_CONFIG
Rolling the encryption key on the Voltage SecureData Management console
The Voltage SecureData Management console supports the concept of “rolling” the
Voltage SST encryption key on the Voltage SecureData Management console.
Periodic key rolling should be done to help protect the integrity of the data encrypted
on the HPE NonStop server. Currently, if the Voltage SST key is rolled on the Voltage
SecureData Management console, perform the following procedure:
1.
Access the Voltage SecureData Management console and roll the Voltage SST
encryption key.
2.
Produce the Voltage SST data file on the Voltage SecureData Management
console.
3.
Rename the Voltage SST data file on the HPE NonStop system.
4.
Upload the Voltage SST data file to the HPE NonStop system using the same
name as before.
5.
Use the XDP_REFRESH_VOLTCONFIG macro to refresh the new SST file into
the encryption server processes.
Due to the design of the Voltage software there will be a period of time between when
the SST key is rolled on the Voltage console and the XDP_REFRESH_MACRO is
executed on the NonStop system (between steps 2 and 5 above) that XDP can
encounter errors returned from the Voltage key server when attempting encryption
operations. These errors are caused by a mismatch between an encryption key stored
in the SST file on the NonStop system and an encryption key that is stored in the
newly generated SST data that resulted from the key roll. Because of this situation, it
may be a good idea to plan for a brief system outage while the SST key is rolled and
the SST file on the NonStop system is replaced.
Summary of Contents for Trinitron WEGA KV-DZ29M91
Page 2: ......