HP 1606 Fabric OS Encryption Administrator's Guide v6.4.0 (53-1001864-01, June - Page 214

TABLE 10, General encryption troubleshooting I, General errors and conditions

Page 214 highlights

6 General encryption troubleshooting I TABLE 10 Problem General errors and conditions Resolution LUN state for some LUNS remains in "initialize" state on the passive path. This is expected behavior. The LUNs exposed through Passive paths of the target array will be in either Initialize or LUN Discovery Complete state so long as the paths remain n passive condition. When the passive path becomes active, the LUN changes to Encryption Enabled. Use the --show -LUN command with the -stat option to check the LUN state. A backup fails because the LUN is always in the initialize state for the tape container. Tape media is encrypted and gets a key which is archived in the key vault. The key is encrypted with a master key. At a later point in time you generate a new master key. You decide to use this tape media to back up other data. You rewind the tape, erase the tape, relabel the tape, and start a backup from the start of the tape. When the first command comes from the host, the key vault is queried for the tape media based on the media serial number. Since this tape media was used previously, the key is already present in the key vault for this media serial number but this key is encrypted with the old master key and that master key is not present in the switch. You cannot create a new key for this tape media because, per policy, there can be only one key per media. Use one of two resolutions: • Load the old master key on the switch at an alternate location. The key for the tape media can then be decrypted. • Delete the key for the tape media from the key vault. This forces the switch to create a new key for the tape media. Until you start the backup, the LUN remains in "initialize" state. "Invalid certificate" error message received when doing a KAC certificate exchange between the Brocade Encryption Switch and a key management system appliance. This error is due to the Brocade Encryption Switch time being ahead of the appliance time. Use one of two resolutions: • Change the appliance time to match the start period of the KAC certificate. • Change the Brocade Encryption Switch time to synchronize with the appliance time. Upon completion, regenerate the KAC certificate and then do another KAC certificate exchange with the appliance. "Temporarily out of resources" message received during re-key or first time encryption. Re-key or first time encryption sessions are pending due to resource unavailability. A maximum of twelve sessions including rekey (manual or auto) and first time encryption sessions are supported per encryption switch or blade and two sessions per target. The system checks once every hour to determine, if there are any re-key or first time encryption sessions pending. If resources are available, the next session in the queue is processed. There may be up to an hour lag before the next session in the queue is processed. It is therefore recommended that you do not schedule more than 12 re-key or first time encryption sessions. HA cluster creation fails with error, Create HA cluster status: The IO link IP address of the EE (online) is not configured, even though both the addresses are set and accessible. The IP addresses for the I/O link ports should be configured before enabling the EE. Failure to do so results in unsuccessful HA Cluster creation. If the IP addresses for these ports were configured after the EE is enabled, reboot the encryption switch or slotpoweroff/slotpoweron the encryption blade to sync up the IP address information to the EE. Re-keying fails with error "Disabled (Key not in sync)". cryptocfg --commit fails with message "Default zone set to all access at one of nodes in EG." Re-keying was started on a remote EE but the local EE is not capable of starting re-key because the key returned from key vault does not match with the Key ID used by remote EE. You will need to re-enable the LUN after the keys are synced between two key vaults properly using the needs to cryptocfg --discoverLUN command. Default zoning must be set to no access. 196 Fabric OS Encryption Administrator's Guide 53-1001864-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248

196
Fabric OS Encryption Administrator’s Guide
53-1001864-01
General encryption troubleshooting I
6
LUN state for some LUNS remains in "initialize" state on the
passive path.
This is expected behavior. The LUNs exposed through Passive paths of the
target array will be in either Initialize or LUN Discovery Complete state so long
as the paths remain n passive condition. When the passive path becomes
active, the LUN changes to Encryption Enabled. Use the
--
show -LUN
command with the
-stat
option to check the LUN state.
A backup fails because the LUN is always in the initialize
state for the tape container.
Tape media is encrypted and gets a key which is archived in
the key vault. The key is encrypted with a master key. At a
later point in time you generate a new master key. You
decide to use this tape media to back up other data. You
rewind the tape, erase the tape, relabel the tape, and start
a backup from the start of the tape. When the first
command comes from the host, the key vault is queried for
the tape media based on the media serial number. Since
this tape media was used previously, the key is already
present in the key vault for this media serial number but
this key is encrypted with the old master key and that
master key is not present in the switch. You cannot create a
new key for this tape media because, per policy, there can
be only one key per media.
Use one of two resolutions:
Load the old master key on the switch at an alternate location. The key
for the tape media can then be decrypted.
Delete the key for the tape media from the key vault. This forces the
switch to create a new key for the tape media.
Until you start the backup, the LUN remains in “initialize” state.
“Invalid certificate” error message received when doing a
KAC certificate exchange between the Brocade Encryption
Switch and a key management system appliance. This
error is due to the Brocade Encryption Switch time being
ahead of the appliance time.
Use one of two resolutions:
Change the appliance time to match the start period of the KAC
certificate.
Change the Brocade Encryption Switch time to synchronize with the
appliance time.
Upon completion, regenerate the KAC certificate and then do another KAC
certificate exchange with the appliance.
“Temporarily out of resources” message received during
re-key or first time encryption.
Re-key or first time encryption sessions are pending due to resource
unavailability. A maximum of twelve sessions including rekey (manual or auto)
and first time encryption sessions are supported per encryption switch or
blade and two sessions per target. The system checks once every hour to
determine, if there are any re-key or first time encryption sessions pending. If
resources are available, the next session in the queue is processed. There
may be up to an hour lag before the next session in the queue is processed. It
is therefore recommended that you do not schedule more than 12 re-key or
first time encryption sessions.
HA cluster creation fails with error, Create HA cluster
status: The IO link IP address of the EE (online) is not
configured, even though both the addresses are set and
accessible.
The IP addresses for the I/O link ports should be configured before enabling
the EE. Failure to do so results in unsuccessful HA Cluster creation. If the IP
addresses for these ports were configured after the EE is enabled, reboot the
encryption switch or slotpoweroff/slotpoweron the encryption blade to sync
up the IP address information to the EE.
Re-keying fails with error “Disabled (Key not in sync)”.
Re-keying was started on a remote EE but the local EE is not capable of
starting re-key because the key returned from key vault does not match with
the Key ID used by remote EE. You will need to re-enable the LUN after the
keys are synced between two key vaults properly using the needs to
cryptocfg
--discoverLUN <Container Name>
command.
cryptocfg
--
commit
fails with message “Default zone set
to all access at one of nodes in EG.”
Default zoning must be set to no access.
TABLE 10
General errors and conditions
Problem
Resolution