HP 8/8 Fabric OS Encryption Administrator's Guide v6.4.0 (53-1001864-01, June - Page 158

Deleting a tape pool, Impact of tape pool configuration changes, while data is written to or

Page 158 highlights

3 Tape pool configuration Deleting a tape pool This command does not issue a warning if the tape pool being deleted has tape media or volumes that are currently accessed by the host. Be sure the tape media is not currently in use. 1. Log into the group leader as FabricAdmin. 2. Enter the cryptocfg --delete -tapepool command followed by a tape pool label or number. Use cryptocfg --show -tapepool -all to display all configured tape pool names and numbers. FabricAdmin:switch>cryptocfg --delete -tapepool -label my_tapepool Operation succeeded. 3. Commit the transaction FabricAdmin:switch>cryptocfg --commit Operation succeeded. Modifying a tape pool 1. Log into the group leader as FabricAdmin. 2. Enter the cryptocfg --modify -tapepool command followed by a tape pool label or number. Then specify a new policy, encryption format, or both. The following example changes the encryption format from Brocade native to DF-compatible. FabricAdmin:switch>cryptocfg --modify -tapepool -label my_tapepool -encryption_format DF_compatible Operation succeeded. 3. Commit the transaction. FabricAdmin:switch>cryptocfg --commit Operation succeeded. Impact of tape pool configuration changes Tape pool-level policies overrule policy configurations at the LUN level, when no policies are configured at the tape pool level. The following restrictions apply when modifying tape pool-level configuration parameters: • If you change the tape pool policy from encrypt to cleartext or from cleartext to encrypt or if you change the encryption format from Brocade native to DF-compatible while data is written to or read from a tape backup device, the policy change is not enforced until the current process completes and the tape is unmounted, rewound, or overwritten. This mechanism prevents the mixing of cleartext data to cipher-text data on the tape. • You cannot modify the tape pool label or the key lifespan value. If you wish to modify these tape pool attributes, delete the tape pool and create a new tape pool with a different label and key lifespan. Key lifespan values only apply to native-mode pools. When in DF-compatible mode, every new media receives a unique key, matching DataFort behavior. 140 Fabric OS Encryption Administrator's Guide 53-1001864-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248

140
Fabric OS Encryption Administrator’s Guide
53-1001864-01
Tape pool configuration
3
Deleting a tape pool
This command does not issue a warning if the tape pool being deleted has tape media or volumes
that are currently accessed by the host. Be sure the tape media is not currently in use.
1.
Log into the group leader as FabricAdmin.
2.
Enter the
cryptocfg
--
delete -tapepool
command followed by a tape pool label or number. Use
cryptocfg
--
show -tapepool -all t
o display all configured tape pool names and numbers.
FabricAdmin:switch>
cryptocfg --delete -tapepool -label my_tapepool
Operation succeeded.
3.
Commit the transaction
FabricAdmin:switch>
cryptocfg --commit
Operation succeeded.
Modifying a tape pool
1.
Log into the group leader as FabricAdmin.
2.
Enter the
cryptocfg
--
modify -tapepool
command followed by a tape pool label or number.
Then specify a new policy, encryption format, or both. The following example changes the
encryption format from Brocade native to DF-compatible.
FabricAdmin:switch>
cryptocfg --modify -tapepool -label my_tapepool
-encryption_format DF_compatible
Operation succeeded.
3.
Commit the transaction.
FabricAdmin:switch>
cryptocfg --commit
Operation succeeded.
Impact of tape pool configuration changes
Tape pool-level policies overrule policy configurations at the LUN level, when no policies are
configured at the tape pool level. The following restrictions apply when modifying tape pool-level
configuration parameters:
If you change the tape pool policy from
encrypt
to
cleartext
or from
cleartext
to
encrypt
or if you
change the encryption format from Brocade
native
to
DF-compatible
while data is written to or
read from a tape backup device, the policy change is not enforced until the current process
completes and the tape is unmounted, rewound, or overwritten. This mechanism prevents the
mixing of cleartext data to cipher-text data on the tape.
You cannot modify the tape pool label or the key lifespan value. If you wish to modify these tape
pool attributes, delete the tape pool and create a new tape pool with a different label and key
lifespan.
Key lifespan values only apply to native-mode pools. When in DF-compatible mode,
every new media receives a unique key, matching DataFort behavior.