HP 3PAR StoreServ 7400 2-node HP 3PAR Command Line Interface Administrator& - Page 115

Backing up the Authentication Key File, Restoring the Key File, Rekeying the Authentication Key

Page 115 highlights

Backing up the Authentication Key File To back up the authentication key file, issue the controlencryption backup command. For example: cli% controlencryption backup backup1 The keystore must be backed up to prevent total loss of data. You will be prompted to twice for the password for the backup file. The same password must be supplied on restore. Restoring the Key File Restoration of a key file is necessary only if there is a catastrophic problem and the key-files on all nodes are destroyed or corrupted. Restore the key-file from an external source to the controller nodes in the StoreServ system. To restore the key file, issue the controlencryption restore command. For example: cli% controlencryption restore backup1 Rekeying the Authentication Key To change the authentication key and back up the authentication key file, issue the controlencryption rekey command. You can rekey the array at any time. You can also save and back up a new copy of the authentication key file at any time. In the event of a recovery action requiring restoration of the key file, the correct key file must be available; otherwise the data will be lost. Showing Data Encryption Status To see the status of data encryption, issue the following command: controlencryption status Optionally, issue the command with the -d option to show disks that are failed or not SED-capable. #$ controlencryption status Licensed Enabled BackupSaved State SeqNum yes yes yes normal 2 #$ controlencryption status -d Licensed Enabled BackupSaved State SeqNum Non-SEDs FailedDisks yes yes yes normal 2 0 0 Data encryption states (as seen under the State column in the foregoing example) are shown in Table 7 (page 115). Table 7 Data Encryption States System Encryption State initializing normal recovery_needed Description The data-encryption service is in the process of starting up. Data encryption is in a normal state Re-run the previous operation after addressing the reason why the previous operation failed (this is most likely to have been a failed drive). in_progress An encryption operation is in progress. A task is generated for the associated operations; the task can be reviewed in Task Manager. Using Self-encrypting Disks 115

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204

Backing up the Authentication Key File
To back up the authentication key file, issue the
controlencryption backup
command. For
example:
cli%
controlencryption backup backup1
The keystore must be backed up to prevent total loss of data. You will be prompted to twice for
the password for the backup file. The same password must be supplied on restore.
Restoring the Key File
Restoration of a key file is necessary only if there is a catastrophic problem and the key-files on all
nodes are destroyed or corrupted. Restore the key-file from an external source to the controller
nodes in the StoreServ system.
To restore the key file, issue the
controlencryption restore
command. For example:
cli%
controlencryption restore backup1
Rekeying the Authentication Key
To change the authentication key and back up the authentication key file, issue the
controlencryption rekey
command.
You can rekey the array at any time. You can also save and back up a new copy of the
authentication key file at any time. In the event of a recovery action requiring restoration of the
key file, the correct key file must be available; otherwise the data will be lost.
Showing Data Encryption Status
To see the status of data encryption, issue the following command:
controlencryption status
Optionally, issue the command with the
-d
option to show disks that are failed or not SED-capable.
#$
controlencryption status
Licensed Enabled BackupSaved State
SeqNum
yes
yes
yes
normal
2
#$
controlencryption status -d
Licensed Enabled BackupSaved State
SeqNum Non-SEDs FailedDisks
yes
yes
yes
normal
2
0
0
Data encryption states (as seen under the
State
column in the foregoing example) are shown in
Table 7 (page 115)
.
Table 7 Data Encryption States
Description
System Encryption State
The data-encryption service is in the process of starting up.
initializing
Data encryption is in a normal state
normal
Re-run the previous operation after addressing the reason
why the previous operation failed (this is most likely to have
been a failed drive).
recovery_needed
An encryption operation is in progress. A task is generated
for the associated operations; the task can be reviewed in
Task Manager.
in_progress
Using Self-encrypting Disks
115