HP 8/80 Fabric OS Encryption Administrator's Guide v6.4.0 (53-1001864-01, June - Page 143

Removing an initiator from a CryptoTarget container, Deleting a CryptoTarget container

Page 143 highlights

CryptoTarget container configuration 3 Removing an initiator from a CryptoTarget container You may remove one or more initiators from a given CryptoTarget container. This operation removes the initiators' access to the target port. If the initiator has access to multiple targets and you wish to remove access to all targets, follow the procedure described to remove the initiator from every CryptoTarget container that is configured with this initiator. NOTE Stop all traffic between the initiator you intend to remove and its respective target ports. Failure to do so results in I/O failure between the initiator and the target port. 1. Log into the group leader as Admin or FabricAdmin. 2. Enter the cryptocfg --remove -initiator command. Specify the CryptoTarget container name followed by one or more initiator port WWNs. The following example removes one initiator from the CryptoTarget container "my_disk_tgt". FabricAdmin:switch>cryptocfg --rem -initiator my_disk_tgt 10:00:00:00:c9:2b:c9:3a Operation Succeeded 3. Commit the transaction. FabricAdmin:switch>cryptocfg --commit Operation Succeeded CAUTION When configuring a multi-path LUN, you must remove all initiators from all CryptoTarget containers in sequence before committing the transaction. Failure to do so may result in a potentially catastrophic situation where one path ends up being exposed through the encryption switch and another path has direct access to the device from a host outside the protected realm of the encryption platform. Refer to the section "Configuring a multi-path Crypto LUN" on page 141 for more information. Deleting a CryptoTarget container You may delete a CryptoTarget container to remove the target port from a given encryption switch or blade. Deleting a CryptoTarget container removes the virtual target and all associated LUNs from the fabric. Before deleting a container, be aware of the following: • Stop all traffic to the target port for which the CryptoTarget container is being deleted. Failure to do so will cause data corruption (a mix of encrypted data and cleartext data will be written to the LUN). • Deleting a CryptoTarget container while a re-key or first-time encryption session causes all data to be lost on the LUNs that are being re-keyed. Ensure that no re-key or first time encryption sessions are in progress before deleting a container. Use the cryptocfg --show -rekey -all command to determine the runtime status of the session. If for some reason, you need to delete a container while re-keying, when you create a new container, be sure the LUNs added to the container are set to cleartext. You can then start a new re-key session on clear text LUNs. Fabric OS Encryption Administrator's Guide 125 53-1001864-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248

Fabric OS Encryption Administrator’s Guide
125
53-1001864-01
CryptoTarget container configuration
3
Removing an initiator from a CryptoTarget container
You may remove one or more initiators from a given CryptoTarget container. This operation removes
the initiators’ access to the target port.
If the initiator has access to multiple targets and you wish to remove access to all targets, follow the
procedure described to remove the initiator from every CryptoTarget container that is configured
with this initiator.
NOTE
Stop all traffic between the initiator you intend to remove and its respective target ports. Failure to
do so results in I/O failure between the initiator and the target port.
1.
Log into the group leader as Admin or FabricAdmin.
2.
Enter the
cryptocfg
--
remove -initiator
command. Specify the CryptoTarget container name
followed by one or more initiator port WWNs. The following example removes one initiator from
the CryptoTarget container “my_disk_tgt”.
FabricAdmin:switch>
cryptocfg --rem -initiator my_disk_tgt
10:00:00:00:c9:2b:c9:3a
Operation Succeeded
3.
Commit the transaction.
FabricAdmin:switch>
cryptocfg --commit
Operation Succeeded
CAUTION
When configuring a multi-path LUN, you must remove all initiators from all CryptoTarget
containers in sequence before committing the transaction. Failure to do so may result in a
potentially catastrophic situation where one path ends up being exposed through the encryption
switch and another path has direct access to the device from a host outside the protected realm
of the encryption platform. Refer to the section
“Configuring a multi-path Crypto LUN”
on
page 141 for more information.
Deleting a CryptoTarget container
You may delete a CryptoTarget container to remove the target port from a given encryption switch
or blade. Deleting a CryptoTarget container removes the virtual target and all associated LUNs from
the fabric.
Before deleting a container, be aware of the following:
Stop all traffic to the target port for which the CryptoTarget container is being deleted. Failure
to do so will cause data corruption (a mix of encrypted data and cleartext data will be written to
the LUN).
Deleting a CryptoTarget container while a re-key or first-time encryption session causes all data
to be lost on the LUNs that are being re-keyed. Ensure that no re-key or first time encryption
sessions are in progress before deleting a container. Use the
cryptocfg
--
show -rekey -all
command to determine the runtime status of the session. If for some reason, you need to
delete a container while re-keying, when you create a new container, be sure the LUNs added
to the container are set to
cleartext
. You can then start a new re-key session on clear text LUNs.