542
Brocade Network Advisor SAN User Manual
53-1002696-01
Supported encryption key manager appliances
20
HA support should be set before you register the key vault. Three settings are supported; however,
certain settings are determined by the compliant key vault type that is being used:
•
Transparent: The client assumes the entire HA is implemented on the key vault. Key archival
and retrieval is performed without any additional hardening checks.
•
Opaque: The primary and secondary key vaults are both registered on the Fabric OS encryption
switch. The client archives the key to a single (primary) key vault. For disk operations, an
additional hardening check is done on the secondary key vault before the key is used for
encryption.
•
None: If no HA is selected, the primary and secondary key vaults are both registered on the
Fabric OS encryption switch. The client archives keys to both key vaults and ensures that the
archival succeeds before the key is used for encryption.
Username authentication can be defined after TLS connectivity to a client device is requested.
Three modes are available:
•
User Name: Only a user name is required to identify the client device.
•
User Name and Password: Both a user name and a password are required to identify the client
device.
•
None: No authentication is required.
The TLS certificates used between the Fabric OS encryption switch and the key vault are be either
Self -Signed or CA Signed.
Table 66
identifies the supported KMIP key vault configurations and certificate formats.
IP
Supported encryption key manager appliances
As stated under
“Network connections”
on page 539, a supported key management appliance
must be connected on the same LAN as the management port of the encryption switches, or of the
Backbone Chassis Control Processors (CPs) in the case of the encryption blade.
Secure communication between encryption nodes in an encryption group, and between encryption
nodes and key manager appliances requires an exchange of certificates that are used for mutual
authentication. Each supported key manager appliance has unique requirements for setting up a
secure connection and exchanging certificates.
TABLE 66
KMIP key vault configurations and certificate formats
Key vault type
HA mode
KAC certificate
Username
authentication
after TLS
Certificate
format
TKLM
No HA
•
Self signed
•
CA signed
No
DER
TEKA
No HA
CA signed
No
PEM
ESKM/SKM
HA Opaque
CA signed
No
PEM
DPM
•
HA Transparent with IPLB
1
•
HA Opaque without IPLB
1.
IPLB = IP Load Balancer.
CA signed
No
PEM
Содержание Network Advisor 12.0.0
Страница 36: ...xxxvi Brocade Network Advisor SAN User Manual 53 1002696 01...
Страница 82: ...34 Brocade Network Advisor SAN User Manual 53 1002696 01 License downgrade 2...
Страница 86: ...38 Brocade Network Advisor SAN User Manual 53 1002696 01 Uninstalling a patch 3...
Страница 122: ...74 Brocade Network Advisor SAN User Manual 53 1002696 01 VM Manager discovery 4...
Страница 184: ...136 Brocade Network Advisor SAN User Manual 53 1002696 01 Fabric tracking 5...
Страница 214: ...166 Brocade Network Advisor SAN User Manual 53 1002696 01 User profiles 6...
Страница 236: ...188 Brocade Network Advisor SAN User Manual 53 1002696 01 Searching for an assigned event filter 7...
Страница 284: ...236 Brocade Network Advisor SAN User Manual 53 1002696 01 User defined performance monitors 8...
Страница 320: ...272 Brocade Network Advisor SAN User Manual 53 1002696 01 Grouping on the topology 9...
Страница 336: ...288 Brocade Network Advisor SAN User Manual 53 1002696 01 Microsoft System Center Operations Manager SCOM plug in 10...
Страница 434: ...386 Brocade Network Advisor SAN User Manual 53 1002696 01 Port Auto Disable 12...
Страница 442: ...394 Brocade Network Advisor SAN User Manual 53 1002696 01 Exporting Host port mapping 13...
Страница 450: ...402 Brocade Network Advisor SAN User Manual 53 1002696 01 Exporting storage port mapping 14...
Страница 536: ...488 Brocade Network Advisor SAN User Manual 53 1002696 01 Virtual FCoE port configuration 16...
Страница 552: ...504 Brocade Network Advisor SAN User Manual 53 1002696 01 Security configuration deployment 17...
Страница 878: ...830 Brocade Network Advisor SAN User Manual 53 1002696 01 Removing thresholds 24...
Страница 922: ...874 Brocade Network Advisor SAN User Manual 53 1002696 01 VLAN routing 26...
Страница 990: ...942 Brocade Network Advisor SAN User Manual 53 1002696 01 SAN Connection utilization 29...
Страница 998: ...950 Brocade Network Advisor SAN User Manual 53 1002696 01 Removing a frame monitor from a switch 30...
Страница 1138: ...1090 Brocade Network Advisor SAN User Manual 53 1002696 01 Call Home Event Tables B...
Страница 1144: ...1096 Brocade Network Advisor SAN User Manual 53 1002696 01 IP Performance monitoring events C...
Страница 1186: ...1138 Brocade Network Advisor SAN User Manual 53 1002696 01 Regular Expressions F...
Страница 1486: ...1438 Brocade Network Advisor SAN User Manual 53 1002696 01 Views H...