Brocade Network Advisor SAN User Manual
541
53-1002696-01
Key Management Interoperability Protocol
20
Setting encryption node initialization
Encryption nodes are initialized by the Configure Switch Encryption wizard when you confirm a
configuration. Encryption nodes may also be initialized from the Encryption Center dialog box.
1. Select a switch from the Encryption Center Devices table, then select Switch > Init Node from
the menu task bar.
2. Select Yes after reading the warning message to initialize the node.
Key Management Interoperability Protocol
The Key Management Interoperability Protocol (KMIP) standardizes the communication between
an Enterprise key management system and a client, thus replacing the use of vendor-specific key
vault servers with KMIP-compatible servers. Currently, KMIP versions 1.0 and 1.1 are supported.
NOTE
Currently, only KMIP with SafeNet KeySecure 6.1 for key management (SSKM) native hosting LKM
is supported.
Any KMIP-compliant server can be registered as a key vault on the Fabric OS encryption switch
after setting the key vault type to KMIP. With the introduction of Fabric OS 7.1.0, TKLM key vaults
can be reregistered as KMIP key vaults without losing older keys that were created with earlier
versions of Fabric OS. For other supported key vaults, only new installations are allowed to use the
KMIP key vault type. KMIP will work for any key server supporting KMIP 1.0 and 1.1 protocols.
Currently, the following key vault types can be configured as KMIP servers on the Fabric OS
encryption switch:
•
HP ESKM, which is allowed for new installations only. It is not backwards compatible with keys
created using Fabric OS versions prior to v7.1.0.
•
IBM TKLM, which is backwards compatible with keys created using earlier Fabric OS versions
(v6.41 - v7.0.1)
•
Thales TEKA, which is allowed for new installations only. It is not backwards compatible with
keys created using Fabric OS versions prior to v7.1.0.
•
RSA DPM, which is allowed for new installations only. It is not backwards compatible with keys
created using Fabric OS versions prior to v7.1.0.
Although KMIP support is available from multiple key vault types, each key vault implementation
differs in terms of HA clustering, certificate exchange, and authentication. The KMIP adapter
simplifies this implementation by providing a single client SDK that is interoperable with any
KMIP-compliant key server.
The KMIP KAC adapter provides configurable HA support.
NOTE
The KMIP client does not implement HA. Implementation is done either at the KAC adapter level, or
transparently on the server.
Содержание Network Advisor 12.0.0
Страница 36: ...xxxvi Brocade Network Advisor SAN User Manual 53 1002696 01...
Страница 82: ...34 Brocade Network Advisor SAN User Manual 53 1002696 01 License downgrade 2...
Страница 86: ...38 Brocade Network Advisor SAN User Manual 53 1002696 01 Uninstalling a patch 3...
Страница 122: ...74 Brocade Network Advisor SAN User Manual 53 1002696 01 VM Manager discovery 4...
Страница 184: ...136 Brocade Network Advisor SAN User Manual 53 1002696 01 Fabric tracking 5...
Страница 214: ...166 Brocade Network Advisor SAN User Manual 53 1002696 01 User profiles 6...
Страница 236: ...188 Brocade Network Advisor SAN User Manual 53 1002696 01 Searching for an assigned event filter 7...
Страница 284: ...236 Brocade Network Advisor SAN User Manual 53 1002696 01 User defined performance monitors 8...
Страница 320: ...272 Brocade Network Advisor SAN User Manual 53 1002696 01 Grouping on the topology 9...
Страница 336: ...288 Brocade Network Advisor SAN User Manual 53 1002696 01 Microsoft System Center Operations Manager SCOM plug in 10...
Страница 434: ...386 Brocade Network Advisor SAN User Manual 53 1002696 01 Port Auto Disable 12...
Страница 442: ...394 Brocade Network Advisor SAN User Manual 53 1002696 01 Exporting Host port mapping 13...
Страница 450: ...402 Brocade Network Advisor SAN User Manual 53 1002696 01 Exporting storage port mapping 14...
Страница 536: ...488 Brocade Network Advisor SAN User Manual 53 1002696 01 Virtual FCoE port configuration 16...
Страница 552: ...504 Brocade Network Advisor SAN User Manual 53 1002696 01 Security configuration deployment 17...
Страница 878: ...830 Brocade Network Advisor SAN User Manual 53 1002696 01 Removing thresholds 24...
Страница 922: ...874 Brocade Network Advisor SAN User Manual 53 1002696 01 VLAN routing 26...
Страница 990: ...942 Brocade Network Advisor SAN User Manual 53 1002696 01 SAN Connection utilization 29...
Страница 998: ...950 Brocade Network Advisor SAN User Manual 53 1002696 01 Removing a frame monitor from a switch 30...
Страница 1138: ...1090 Brocade Network Advisor SAN User Manual 53 1002696 01 Call Home Event Tables B...
Страница 1144: ...1096 Brocade Network Advisor SAN User Manual 53 1002696 01 IP Performance monitoring events C...
Страница 1186: ...1138 Brocade Network Advisor SAN User Manual 53 1002696 01 Regular Expressions F...
Страница 1486: ...1438 Brocade Network Advisor SAN User Manual 53 1002696 01 Views H...