HP 8/8 Fabric OS Encryption Administrator's Guide v6.4.0 (53-1001864-01, June - Page 189

HP-UX considerations, Enable of a disabled LUN, Disk metadata, Tape metadata

Page 189 highlights

HP-UX considerations 5 HP-UX considerations The HP-UX OS requires LUN 0 to be present. LUNs are scanned differently based on the type value returned for LUN 0 by the target device. • If the type is 0, then HP-UX only scans LUNs from 0 to 7. That is the maximum limit allowed by HP-UX for device type for type 0. • If the type is 0xC, then HP-UX scans all LUNs. Best practices are as follows: • Create a cryptoTarget container for the target WWN. • Add the HP-UX initiator WWN to the container. • Issue the discover LUN CLI command on the container to discover the LUNs present in the target. • Based on the LUN list returned as part of LUN discovery, add the LUN 0 if LUN 0 is present in the target (which is usually the case). Enable of a disabled LUN When Metadata is found on the LUN, but current LUN state is indicated as cleartext or is being converted from encrypt to cleartext, the LUN is disabled and the LUN status displayed by the LUN Show CLI command is Encryption Disabled . The disabled LUN can be enabled by the enable LUN command. cryptocfg --enable -LUN Disk metadata If possible, thirty-two bytes of metadata are added to every block in LBA range 1 to 16 for both the native Brocade format and DF-compatible formats. This metadata is not visible to the host. The Host I/Os for the metadata region of the LUN are handled in the encryption switch software, and some additional latency should be expected. Tape metadata One kilobyte of metadata is added per tape block for both the native Brocade format and DF-compatible formats. Tape block size (as configured by host) is modified by the encryption device to accommodate 1K metadata per block. A given tape can have a mix of compressed and uncompressed blocks. Block lengths are as follows. Encrypted/Compressed Compressed and encrypted tape block data + 1K metadata + ASCII 0 pad = block Tape Block Format length of tape. Encrypted Tape Block Encrypted tape block data + 1K metadata = block length of tape. Format (No Compression) Fabric OS Encryption Administrator's Guide 171 53-1001864-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248

Fabric OS Encryption Administrator’s Guide
171
53-1001864-01
HP-UX considerations
5
HP-UX considerations
The HP-UX OS requires LUN 0 to be present. LUNs are scanned differently based on the type value
returned for LUN 0 by the target device.
If the type is 0, then HP-UX only scans LUNs from 0 to 7. That is the maximum limit allowed by
HP-UX for device type for type 0.
If the type is 0xC, then HP-UX scans all LUNs.
Best practices are as follows:
Create a cryptoTarget container for the target WWN.
Add the HP-UX initiator WWN to the container.
Issue the discover LUN CLI command on the container to discover the LUNs present in the
target.
Based on the LUN list returned as part of LUN discovery, add the LUN 0 if LUN 0 is present in
the target (which is usually the case).
Enable of a disabled LUN
When Metadata is found on the LUN, but current LUN state is indicated as cleartext or is being
converted from encrypt to cleartext, the LUN is disabled and the LUN status displayed by the LUN
Show CLI command is
Encryption Disabled <Reason Code>
.
The disabled LUN can be enabled by the enable LUN command.
cryptocfg --enable -LUN <crypto target container name> <LUN Num> <InitiatorPWWN>
Disk metadata
If possible, thirty-two bytes of metadata are added to every block in LBA range 1 to 16 for both the
native Brocade format and DF-compatible formats. This metadata is not visible to the host. The
Host I/Os for the metadata region of the LUN are handled in the encryption switch software, and
some additional latency should be expected.
Tape metadata
One kilobyte of metadata is added per tape block for both the native Brocade format and
DF-compatible formats. Tape block size (as configured by host) is modified by the encryption device
to accommodate 1K metadata per block. A given tape can have a mix of compressed and
uncompressed blocks. Block lengths are as follows.
Encrypted/Compressed
Tape Block Format
Compressed and encrypted tape block data + 1K metadata + ASCII 0 pad = block
length of tape.
Encrypted Tape Block
Format (No Compression)
Encrypted tape block data + 1K metadata = block length of tape.