User Guide
DDOC0099-000-AH
DTS1 CSfC
7 - 6
Operation
© 2020 Curtiss-Wright Defense Solutions
Revision 4.0
7.4
Encryption
The DTS1 uses two layers of encryption:
•
Hardware encryption layer
•
Software encryption Layer
The user is required to use the CLI to issue initialization and key management commands.
7.4.1
Hardware Encryption Layer
Refer to paragraph 5.3
for detailed instructions on how to create /
log into the HWE layer.
7.4.2
Software Encryption Layer
Refer to paragraph 5.4
for detailed instructions on how to create / log
into the SWE layer.
7.4.3
Zeroize / Delete SWE Container / RMC Purge
•
The destruction of the HWE layer key is accomplished via zeroization.
•
The SWE layer passphrase(s) is / are destroyed via deleting the SWE container(s).
•
The RMC module data is destroyed via the rmcpurge command.
Refer to paragraph paragraph 5.5
Zeroize HWE Key / Delete SWE Container / RMC Purge
for
additional information,
7.5
Storage Media
NOTE
The DTS1 must have the hardware encryption layer initialized and open before the RMC module
(storage media) can be accessed.
If desired, the RMC module disk can be used without partitioning. The unpartitioned disk must
have services started and assigned before formatting and mounting. Refer to paragraph 6.6
Services for additional information.
7.5.1
Preparation for Partition
The following steps must be done in sequential order.
1. Stop services.
Commands:
Stop services:
serv -a 0
Stop iSCSI targets:
istarget --stop
Stop PCAP recording:
pcap --stop
2. Unmount drive.
Command
rmcctl -U
3. Erase existing partitions.
Command:
rmcctl -W --force
4. Check drive status.
NOTE
Refer to paragraph 12.3.21
for information regarding the rmcctl status indications.
Command:
rmcctl