User Guide
DDOC0099-000-AH
DTS1 CSfC
5 - 8
Encryption
© 2020 Curtiss-Wright Defense Solutions
Revision 6.0
Example
5.4
Software Layer Encryption
CAUTION
DATA SECURITY. Be sure to CLOSE the SSH session after initializing or entering the software
encryption layer. Leaving the SSH session open can expose the passphrase to unauthorized
access.
CAUTION
DATA SECURITY. Only SSH session may be used for configuring software encryption layer. The
console or serial port cannot be used for setting up software encryption as the passphrase is not
cleared from memory as required.
NOTE
The RMC module must have services assigned before the software encryption layer can be initial
-
ized / entered.
The rmcctl -C command allows the user to view and alter the DTS1 disk encryption options. The
software encryption layer uses containers to hold the data. Creation of a container requires the use
of a password or passphrase. Refer to paragraph 5.1.2
5.4.1
Unpartitioned Disk
Disks cannot be partitioned after software encryption has been performed.
5.4.1.1
Initialize Container (Unpartitioned Disk)
CAUTION
DATA LOSS. Initializing SWE will overwrite / destroy any existing data on the disk. As a result the -
-force option must be used.
Initialize a Software Encryption (SWE) container on an RMC module as follows:
1. Type
rmcctl --force -C
and press E
NTER
key.
NOTE
After the above command has be issued, the user must acknowledge that all data on the disk will
be overwritten
2. At the overwrite query prompt type
YES
and press E
NTER
key.
NOTE
Refer to paragraph 5.1.2
Software Layer Passwords / Passphrases
for requirements.
3. Enter a password / passphrase that complies with the password / passphrase requirements
and press E
NTER
key.
4. Reenter the password / passphrase and press E
NTER
key.
If the passphrase is entered correctly both times and meets the requirements the following
message will be displayed:
RMC_C0; action=cryp status=OK
.
Example of RMC Module Status
cw_dts>
cmkey --del [0 thru 31]
[cmkey]
CMKEY: action=del status=OK
[!cmkey] OK
cw_dts>
rmcctl
[rmcctl]
RMC_S#:
ins hcryp osdr p#
size
serv scryp osdm
fmt mnt rem mntpoint
*********************************************************************************
RMC_S0:
1
1
1
-- 100GB
NAS
1
0
na
na
0
rmc0
[!rmcctl] OK