HP 3PAR StoreServ 7200 2-node HP 3PAR Command Line Interface Administrator& - Page 113

Restrictions, Using Self-encrypting Disks, Taking Ownership

Page 113 highlights

To view the license using the HP 3PAR CLI, issue the showlicense command: cli%showlicense License key was generated on Thu May 23 16:29:37 2013 License features currently enabled: ... Data Encryption ... To view the license using the HP 3PAR MC, navigate to the Software tab. Restrictions These restrictions apply to the first release of data encryption (HP 3PAR OS 3.1.2 MU2): • Data encryption is available only with the purchase of a new HP 3PAR StoreServ system. • Data encryption cannot be enabled on an HP StoreServ storage system earlier than HP 3PAR OS 3.1.2 MU2. • Data encryption is not supported on any HP 3PAR encrypted storage array with mixed configurations of SEDs and non-SEDs; the array must contain only SEDs. • A single authentication key is used to unlock all the drives in the array for reading and writing to media. • Authentication keys are managed using a local key manager (LKM) in the storage system. • The controlencryption commands (or GUI call) are recorded in the HP 3PAR OS eventlog, but the filename and password contents are not. For example: Time : 2013-05-28 13:52:20 PDT Severity : Informational Type : CLI command executed Message : {3parsvc super all {{0 8}} -1 127.0.0.1 9534} {controlencryption enable_start } {} Message : {3paradm super all {{0 8}} -1 16.94.229.83 9706} {controlencryption status_details} {} Message : {3paradm super all {{0 8}} -1 16.94.229.83 30353} {controlencryption rekey_finish} {} • A user with Super authority is responsible for physical security of a backup copy of the authentication keys and for remembering the password. • Encryption should be enabled before writing data to the array. The system will function, and the same data can be accessed before and after encryption is enabled, but it will not be secure (no DAR) until encryption is enabled. Using Self-encrypting Disks Taking Ownership Ownership means changing the authentication key and locking state of an SED from its default settings, so that the data on the drive is secure. To enable the SED, issue the admitpd [option] [...] command. Options are: • -nold: Do not use the physical disk (as identifed by the WWN specifier) for LD allocation. Specify the -nold option when adding a physical disk to replace a failed disk whose chunklets Restrictions 113

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204

To view the license using the HP 3PAR CLI, issue the
showlicense
command:
cli%
showlicense
License key was generated on Thu May 23 16:29:37 2013
License features currently enabled:
...
Data Encryption
...
To view the license using the HP 3PAR MC, navigate to the
Software
tab.
Restrictions
These restrictions apply to the first release of data encryption (HP 3PAR OS 3.1.2 MU2):
Data encryption is available only with the purchase of a new HP 3PAR StoreServ system.
Data encryption cannot be enabled on an HP StoreServ storage system earlier than HP 3PAR
OS 3.1.2 MU2.
Data encryption is not supported on any HP 3PAR encrypted storage array with mixed
configurations of SEDs and non-SEDs; the array must contain only SEDs.
A single authentication key is used to unlock all the drives in the array for reading and writing
to media.
Authentication keys are managed using a local key manager (LKM) in the storage system.
The
controlencryption
commands (or GUI call) are recorded in the HP 3PAR OS eventlog,
but the filename and password contents are not. For example:
Time
: 2013-05-28 13:52:20 PDT
Severity : Informational
Type
: CLI command executed
Message
: {3parsvc super all {{0 8}} -1 127.0.0.1 9534} {controlencryption
enable_start <password > <secret>} {}
Message
: {3paradm super all {{0 8}} -1 16.94.229.83 9706} {controlencryption
status_details} {}
Message
: {3paradm super all {{0 8}} -1 16.94.229.83 30353} {controlencryption
rekey_finish} {}
A user with Super authority is responsible for physical security of a backup copy of the
authentication keys and for remembering the password.
Encryption should be enabled
before
writing data to the array. The system will function, and
the same data can be accessed before and after encryption is enabled, but it will not be
secure (no DAR) until encryption is enabled.
Using Self-encrypting Disks
Taking Ownership
Ownership means changing the authentication key and locking state of an SED from its default
settings, so that the data on the drive is secure.
To enable the SED, issue the
admitpd [option] [<WWN>...]
command. Options are:
-nold
: Do not use the physical disk (as identifed by the WWN specifier) for LD allocation.
Specify the
nold
option when adding a physical disk to replace a failed disk whose chunklets
Restrictions
113