HP 8/8 Fabric OS Encryption Administrator's Guide v6.4.0 (53-1001864-01, June - Page 228

Security processor KEK status, Encrypted LUN states

Page 228 highlights

A Security processor KEK status Security processor KEK status Table 16 lists security processor KEK status information. TABLE 16 KEK type Security processor KEK status KEK status1 Description Primary KEK (current MK or None primary KV link key) Mismatch Primary KEK is not configured. Primary KEK mismatch between the CP and the SP. Match/Valid Primary KEK at CP matches the one in the SP and is valid. Secondary KEK (alternate None MK or secondary KV link key) Mismatch Secondary KEK is not configured. Secondary KEK mismatch between the CP and the SP. Match/Valid Secondary KEK at CP matches the one in the SP and is valid. Group KEK None Group KEK is not configured. Mismatch Group KEK mismatch between the CP and the SP. Match/Valid Group KEK at the CP matches the one in the SP and is valid. 1. Only valid in the "encryption engine awaiting encryption group" state and the "encryption engine online" state. Encrypted LUN states Table 17 lists encrypted LUN states. Table 18 lists LUN states that are specific to tape LUNs. TABLE 17 LUN state Encrypted LUN states String displayed UNKNOWN LUN_STATE_UNAVAILABLE LUN_STATE_INIT LUN_DISC_START LUN_DISC_COMPLETE LUN_SETUP_START LUN_CLEAR_TEXT LUN_ENCRYPT LUN_READONLY_1 LUN_READONLY_2 LUN_READONLY_3 LUN_WR_META_IN_PROG Unknown LUN state unavailable. Initialize LUN discovery in progress. LUN discovery complete. LUN setup cleartext encryption enabled. Encryption enabled. Read only (found native metadata while LUN is in DF mode). Read only (found DF metadata while LUN is in native mode). Read only (metadata key is in read-only state). Write metadata is in progress. 210 Fabric OS Encryption Administrator's Guide 53-1001864-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248

210
Fabric OS Encryption Administrator’s Guide
53-1001864-01
Security processor KEK status
A
Security processor KEK status
Table 16
lists security processor KEK status information.
Encrypted LUN states
Table 17
lists encrypted LUN states.
Table 18
lists LUN states that are specific to tape LUNs.
TABLE 16
Security processor KEK status
KEK type
KEK status
1
1.
Only valid in the “encryption engine awaiting encryption group” state and the “encryption engine online” state.
Description
Primary KEK (current MK or
primary KV link key)
None
Primary KEK is not configured.
Mismatch
Primary KEK mismatch between the CP
and the SP.
Match/Valid
Primary KEK at CP matches the one in the
SP and is valid.
Secondary KEK (alternate
MK or secondary KV link key)
None
Secondary KEK is not configured.
Mismatch
Secondary KEK mismatch between the CP
and the SP.
Match/Valid
Secondary KEK at CP matches the one in
the SP and is valid.
Group KEK
None
Group KEK is not configured.
Mismatch
Group KEK mismatch between the CP and
the SP.
Match/Valid
Group KEK at the CP matches the one in
the SP and is valid.
TABLE 17
Encrypted LUN states
LUN state
String displayed
UNKNOWN
Unknown
LUN_STATE_UNAVAILABLE
LUN state unavailable.
LUN_STATE_INIT
Initialize
LUN_DISC_START
LUN discovery in progress.
LUN_DISC_COMPLETE
LUN discovery complete.
LUN_SETUP_START
LUN setup
LUN_CLEAR_TEXT
cleartext encryption enabled.
LUN_ENCRYPT
Encryption enabled.
LUN_READONLY_1
Read only (found native metadata while LUN is in DF mode).
LUN_READONLY_2
Read only (found DF metadata while LUN is in native mode).
LUN_READONLY_3
Read only (metadata key is in read-only state).
LUN_WR_META_IN_PROG
Write metadata is in progress.