HP 8/8 Fabric OS Encryption Administrator's Guide v6.4.0 (53-1001864-01, June - Page 234

encryption, format, LUN state, LUN policy, Encrypt existing data, Key ID, Metadata, on LUN, Results

Page 234 highlights

B DF-compatibility support for disk LUNs TABLE 20 LUN encryption format Support matrix for disk LUNs for various configuration and modify options LUN state LUN policy Encrypt existing data Key ID Metadata Results on LUN Native Encrypted Encrypt NA when NA Yes (Brocade) LUN State = encrypt Native Encrypted Encrypt (Brocade) NA when LUN State = encrypt None No Native (Brocade) Native (Brocade) Encrypted Encrypt Encrypted Cleartext NA when LUN State = encrypt NA when LUN State = encrypt Provided No NA Yes Native (Brocade) Native (Brocade) Encrypted Cleartext Encrypted Cleartext NA when LUN State = encrypt NA when LUN State = encrypt None No Provided No Native Cleartext Encrypt Yes (Brocade) NA Yes Native Cleartext Encrypt Yes (Brocade) Native Cleartext Encrypt Yes (Brocade) None No Provided No No error. If the LUN was previously DF-encrypted, the LUN is set to Read Only until you either remove the LUN and add it back with the native Brocade encryption format, or issue the runtime CLI command to force the change. The data encryption key is retrieved from the key vault based on the LUN serial number, and used for further encryption and decryption. An attempt is made to write the metadata. If the key cannot be retrieved for this LUN based on the LUN serial number, then the LUN is disabled for encryption. You need to either modify the LUN state to cleartext or provide the key ID in the LUN setup. You can also use the runtime cryptocfg --enable -LUN command to force the change, in which case a new key is generated and an attempt is made to write metadata. No error. The LUN is disabled for encryption. Metadata is present on the LUN and the LUN is in encrypted state. You need to either modify the LUN policy to encrypt, or use the runtime cryptocfg --enable -LUN command to force the change from encrypt to cleartext. No error. The KeyID is not valid when this combination is used in cryptocfg --modify -LUN. When issuing cryptocfg --add -LUN, this is an invalid combination The LUN is disabled for encryption. Metadata is present on the LUN and the LUN is in encrypted state. You need to either modify the LUN state to "encrypted" or use the runtime cryptocfg --enable -LUN command to force the change from the current state of the LUN to encrypt. No error. First time encryption started to convert the LUN from cleartext to encrypt. No Error. Key ID is ignored. 216 Fabric OS Encryption Administrator's Guide 53-1001864-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248

216
Fabric OS Encryption Administrator’s Guide
53-1001864-01
DF-compatibility support for disk LUNs
B
TABLE 20
Support matrix for disk LUNs for various configuration and modify options
LUN
encryption
format
LUN state
LUN policy
Encrypt existing data
Key ID
Metadata
on LUN
Results
Native
(Brocade)
Encrypted
Encrypt
NA when
LUN State = encrypt
NA
Yes
No error. If the LUN was previously
DF-encrypted, the LUN is set to Read Only until
you either remove the LUN and add it back
with the native Brocade encryption format, or
issue the runtime CLI command to force the
change.
Native
(Brocade)
Encrypted
Encrypt
NA when
LUN State = encrypt
None
No
The data encryption key is retrieved from the
key vault based on the LUN serial number, and
used for further encryption and decryption. An
attempt is made to write the metadata. If the
key cannot be retrieved for this LUN based on
the LUN serial number, then the LUN is
disabled for encryption. You need to either
modify the LUN state to cleartext or provide
the key ID in the LUN setup. You can also use
the runtime
cryptocfg
--
enable -LUN
command to force the change, in which case a
new key is generated and an attempt is made
to write metadata.
Native
(Brocade)
Encrypted
Encrypt
NA when
LUN State = encrypt
Provided
No
No error.
Native
(Brocade)
Encrypted
Cleartext
NA when
LUN State = encrypt
NA
Yes
The LUN is disabled for encryption. Metadata
is present on the LUN and the LUN is in
encrypted state. You need to either modify the
LUN policy to encrypt, or use the runtime
cryptocfg
--
enable -LUN
command to force
the change from encrypt to cleartext.
Native
(Brocade)
Encrypted
Cleartext
NA when
LUN State = encrypt
None
No
No error.
Native
(Brocade)
Encrypted
Cleartext
NA when
LUN State = encrypt
Provided
No
The KeyID is not valid when this combination
is used in
cryptocfg
--
modify -LUN.
When
issuing
cryptocfg
--
add -LUN,
this is an invalid
combination
Native
(Brocade)
Cleartext
Encrypt
Yes
NA
Yes
The LUN is disabled for encryption. Metadata
is present on the LUN and the LUN is in
encrypted state. You need to either modify the
LUN state to “encrypted” or use the runtime
cryptocfg
--
enable -LUN
command to force
the change from the current state of the LUN
to encrypt.
Native
(Brocade)
Cleartext
Encrypt
Yes
None
No
No error. First time encryption started to
convert the LUN from cleartext to encrypt.
Native
(Brocade)
Cleartext
Encrypt
Yes
Provided
No
No Error. Key ID is ignored.