HP 1606 Fabric OS Encryption Administrator's Guide v6.4.0 (53-1001864-01, June - Page 33

Encryption user privileges

Page 33 highlights

Encryption user privileges 2 Encryption user privileges In the Management application, resource groups are assigned privileges, roles, and fabrics. Privileges are not directly assigned to users; users get privileges because they belong to a role in a resource group. A user can only belong to one resource group at a time. The Management application provides three pre-configured roles: • Storage encryption configuration. • Storage encryption key operations. • Storage encryption security. Table lists the associated roles and their read/write access to specific operations. Privilege Read/Write Storage Encryption Configuration Storage Encryption Key Operations Storage Encryption Security Enables the following functions from the Encryption Center dialog box: • Launch the Configure Encryption dialog. • View switch, group, or engine properties. • View the Encryption Group Properties Security tab. • View encryption targets, hosts, and LUNs. • View LUN centric view • View all re-key sessions • Add/remove paths and edit LUN configuration on LUN centric view • Rebalance encryption engines. • Decommission LUNs • Edit smart card • Create a new encryption group or add a switch to an existing encryption group. • Edit group engine properties (except for the Security tab) • Add targets. • Select encryption targets and LUNs to be encrypted or edit LUN encryption settings. • Edit encryption target hosts configuration. Enables the following functions from the Encryption Center dialog box: • Launch the Configure Encryption dialog. • View switch, group, or engine properties, • View the Encryption Group Properties Security tab. • View encryption targets, hosts, and LUNs. • Initiate manual LUN re-keying. • Enable and disable an encryption engine. • Zeroize an encryption engine. • Restore a master key. • Edit key vault credentials. Enables the following functions from the Encryption Center dialog box: • Launch the Configure Encryption dialog. • View switch, group, or engine properties. • View encryption targets, hosts, and LUNs. • Create a master key. • Backup a master key. • View and modify settings on the Encryption Group Properties Security tab (quorum size, authentication cards list and system card requirement). • Establish link keys for LKM key managers. Fabric OS Encryption Administrator's Guide 15 53-1001864-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248

Fabric OS Encryption Administrator’s Guide
15
53-1001864-01
Encryption user privileges
2
Encryption user privileges
In the Management application, resource groups are assigned privileges, roles, and fabrics.
Privileges are not directly assigned to users; users get privileges because they belong to a role in a
resource group. A user can only belong to one resource group at a time.
The Management application provides three pre-configured roles:
Storage encryption configuration.
Storage encryption key operations.
Storage encryption security.
Table
lists the associated roles and their read/write access to specific operations.
Privilege
Read/Write
Storage Encryption
Configuration
Enables the following functions from the
Encryption Center
dialog box:
Launch the Configure Encryption dialog.
View switch, group, or engine properties.
View the Encryption Group Properties Security tab.
View encryption targets, hosts, and LUNs.
View LUN centric view
View all re-key sessions
Add/remove paths and edit LUN configuration on LUN centric view
Rebalance encryption engines.
Decommission LUNs
Edit smart card
Create a new encryption group or add a switch to an existing encryption group.
Edit group engine properties (except for the Security tab)
Add targets.
Select encryption targets and LUNs to be encrypted or edit LUN encryption settings.
Edit encryption target hosts configuration.
Storage Encryption Key
Operations
Enables the following functions from the
Encryption Center
dialog box:
Launch the Configure Encryption dialog.
View switch, group, or engine properties,
View the Encryption Group Properties Security tab.
View encryption targets, hosts, and LUNs.
Initiate manual LUN re-keying.
Enable and disable an encryption engine.
Zeroize an encryption engine.
Restore a master key.
Edit key vault credentials.
Storage Encryption
Security
Enables the following functions from the
Encryption Center
dialog box:
Launch the Configure Encryption dialog.
View switch, group, or engine properties.
View encryption targets, hosts, and LUNs.
Create a master key.
Backup a master key.
View and modify settings on the Encryption Group Properties Security tab (quorum size,
authentication cards list and system card requirement).
Establish link keys for LKM key managers.