LSI Corporation
- 42 -
12Gb/s MegaRAID SAS Software User Guide
March 2014
Chapter 3: SafeStore Disk Encryption
Workflow
Table 19 Terminology used in FDE
3.2
Workflow
3.2.1
Enable Security
You can enable security on the controller. After you enable security, you have the option to create secure virtual drives
using a security key.
There are three procedures you can perform to create secure virtual drives using a security key:
Create the security key identifier
Create the security key
Create a password (optional)
Create the Security Key Identifier
The security key identifier appears when you enter the security key. If you have multiple security keys, the identifier
helps you determine which security key to enter. The controller provides a default identifier for you. You can use the
default setting or enter your own identifier.
Create the Security Key
You need to enter the security key to perform certain operations. You can choose a strong security key that the
controller suggests.
CAUTION
If you forget the security key, you will lose access to your data.
Create a Password
The password provides additional security. The password must be different from the security key. You can select a
setting in the utilities so that you must enter the password whenever you boot your server.
CAUTION
If you forget the password, you will lose access to your data.
Option
Description
Authenticated Mode
The RAID configuration is keyed to a user password. The password must be provided on system boot
to authenticate the user and facilitate unlocking the configuration for user access to the encrypted
data.
Key backup
You need to provide the controller with a lock key if the controller is replaced or if you choose to
migrate secure virtual disks. To do this task, you must back up the security key.
Password
An optional authenticated mode is supported in which you must provide a password on each boot to
make sure the system boots only if the user is authenticated. Firmware uses the user password to
encrypt the security key.
Re-provisioning
Re-provisioning disables the security system of a device. For a controller, it involves destroying the
security key. For SafeStore encrypted drives, when the drive lock key is deleted, the drive is unlocked
and any user data on the drive is securely deleted. This situation does not apply to
controller-encrypted drives, because deleting the virtual disk destroys the encryption keys and
causes a secure erase. See
, for information about the instant secure erase
feature.
Security Key
A key based on a user-provided string. The controller uses the security key to lock and unlock access
to the secure user data. If the security key is unavailable, user data is irretrievably lost. You must take
all precautions to never lose the security key.
Un-Authenticated Mode
This mode allows controller to boot and unlock access to user configuration without user
intervention.
Содержание ThinkServer RD650
Страница 1: ...ThinkServer 12 Gb s MegaRAID SAS Software User Guide ...
Страница 417: ......
Страница 418: ......