670
Brocade Network Advisor SAN User Manual
53-1002696-01
Master keys
20
The new master key cannot be used (no new data encryption keys can be created, so no new
encrypted LUNs can be configured), until you back up the new master key. After you have backed
up the new master key, it is strongly recommended that all encrypted disk LUNs be rekeyed.
rekeying causes a new data encryption key to be created and encrypted using the new active
master key, thereby removing any dependency on the old master key. Refer to
“Creating a new
master key”
on page 678 for more information.
Master key actions are disabled if they are unavailable. For example:
•
The user does not have Storage Encryption Security permissions.
•
The group leader is not discovered or managed by the Management application.
NOTE
It is important to back up the master key because if the master key is lost, none of the data
encryption keys can be restored and none of the encrypted data can be decrypted.
Active master key
The active master key is used to encrypt newly created data encryption keys (DEKs) prior to sending
them to a key vault to be stored. You can restore the active master key under the following
conditions:
•
The active master key has been lost, which happens if all encryption engines in the group have
been zeroized or replaced with new hardware at the same time.
•
You want multiple encryption groups to share the same active master key. Groups should share
the same master key if the groups share the same key vault and if tapes (or disks) are going to
be exchanged regularly between the groups.
Alternate master key
The alternate master key is used to decrypt data encryption keys that were not encrypted with the
active master key. Restore the alternate master key for the following reasons:
•
To read an old tape that was created when the group used a different active master key.
•
To read a tape (or disk) from a different encryption group that uses a different active
master key.
Master key actions
NOTE
Master keys belong to the group and are managed from Group Properties.
Master key actions are as follows:
•
Backup master key: Enabled any time a master key exists. Selecting this option launches the
Backup Master Key for Encryption Group dialog box.
You can back up the master key to a file, to a key vault, or to a smart card. You can back up the
master key multiple times to any of these media in case you forget the passphrase you
originally used to back up the master key, or if multiple administrators each needs a
passphrase for recovery.
Содержание Network Advisor 12.0.0
Страница 36: ...xxxvi Brocade Network Advisor SAN User Manual 53 1002696 01...
Страница 82: ...34 Brocade Network Advisor SAN User Manual 53 1002696 01 License downgrade 2...
Страница 86: ...38 Brocade Network Advisor SAN User Manual 53 1002696 01 Uninstalling a patch 3...
Страница 122: ...74 Brocade Network Advisor SAN User Manual 53 1002696 01 VM Manager discovery 4...
Страница 184: ...136 Brocade Network Advisor SAN User Manual 53 1002696 01 Fabric tracking 5...
Страница 214: ...166 Brocade Network Advisor SAN User Manual 53 1002696 01 User profiles 6...
Страница 236: ...188 Brocade Network Advisor SAN User Manual 53 1002696 01 Searching for an assigned event filter 7...
Страница 284: ...236 Brocade Network Advisor SAN User Manual 53 1002696 01 User defined performance monitors 8...
Страница 320: ...272 Brocade Network Advisor SAN User Manual 53 1002696 01 Grouping on the topology 9...
Страница 336: ...288 Brocade Network Advisor SAN User Manual 53 1002696 01 Microsoft System Center Operations Manager SCOM plug in 10...
Страница 434: ...386 Brocade Network Advisor SAN User Manual 53 1002696 01 Port Auto Disable 12...
Страница 442: ...394 Brocade Network Advisor SAN User Manual 53 1002696 01 Exporting Host port mapping 13...
Страница 450: ...402 Brocade Network Advisor SAN User Manual 53 1002696 01 Exporting storage port mapping 14...
Страница 536: ...488 Brocade Network Advisor SAN User Manual 53 1002696 01 Virtual FCoE port configuration 16...
Страница 552: ...504 Brocade Network Advisor SAN User Manual 53 1002696 01 Security configuration deployment 17...
Страница 878: ...830 Brocade Network Advisor SAN User Manual 53 1002696 01 Removing thresholds 24...
Страница 922: ...874 Brocade Network Advisor SAN User Manual 53 1002696 01 VLAN routing 26...
Страница 990: ...942 Brocade Network Advisor SAN User Manual 53 1002696 01 SAN Connection utilization 29...
Страница 998: ...950 Brocade Network Advisor SAN User Manual 53 1002696 01 Removing a frame monitor from a switch 30...
Страница 1138: ...1090 Brocade Network Advisor SAN User Manual 53 1002696 01 Call Home Event Tables B...
Страница 1144: ...1096 Brocade Network Advisor SAN User Manual 53 1002696 01 IP Performance monitoring events C...
Страница 1186: ...1138 Brocade Network Advisor SAN User Manual 53 1002696 01 Regular Expressions F...
Страница 1486: ...1438 Brocade Network Advisor SAN User Manual 53 1002696 01 Views H...