HP Brocade 8/12c Fabric OS Encryption Administrator's Guide v6.4.0 (53-1001864 - Page 37

Enabling or disabling the system card requirement, Registering system cards from a card reader

Page 37 highlights

Smart card usage 2 Enabling or disabling the system card requirement If you want to use a system card to control activation of an encryption engine on a switch, you must enable the system card requirement. You can use the following procedure to enable or disable the system card requirement. 1. From the Encryption Center select an encryption group, and select the Security menu. The Select Security Settings dialog is displayed. 2. Set System Cards to Required to require the use a system card to control activation of an encryption engine. If System Cards is set to Not Required, the encryption engine activates without the need to read a system card first. 3. Click OK. Registering system cards from a card reader System cards are smart cards that can be used to control activation of encryption engines. Encryption switches and blades have a card reader that enables the use of a system card. System cards discourage theft of encryption switches or blades by requiring the use of a system card at the switch or blade to enable the encryption engine. When the switch or blade is powered off, the encryption engine will not work without first inserting a system card into its card reader. If someone removes a switch or blade with the intent of accessing the encryption engine, it will function as an ordinary FC switch or blade when it is powered up, but use of the encryption engine is denied. To register a system card from a card reader, a smart card must physically available. System cards can be registered during encryption group creation or member configuration when running the configuration wizard, or they can be registered using the following procedure. 1. Select Configure > Encryption from the menu bar. The Encryption Center dialog box displays. 2. Select the switch from the Encryption Devices table, and select Switch > System Cards from the menu task bar, or right-click the switch or and select System Card. The Register System Card dialog box is displayed. 3. Insert a smart card into the card reader. Be sure to wait for the card serial number to appear, and then enter card assignment information, as directed. 4. Click OK. 5. Wait for the confirmation dialog box indicating initialization is done, and click OK. The card is added to the Registered System Cards table on the System Cards dialog box. 6. Store the card in a secure location, not in the proximity of the switch or blade. Fabric OS Encryption Administrator's Guide 19 53-1001864-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248

Fabric OS Encryption Administrator’s Guide
19
53-1001864-01
Smart card usage
2
Enabling or disabling the system card requirement
If you want to use a system card to control activation of an encryption engine on a switch, you must
enable the system card requirement. You can use the following procedure to enable or disable the
system card requirement.
1.
From the
Encryption Center
select an encryption group, and select the
Security
menu.
The
Select Security Settings
dialog is displayed.
2.
Set
System Cards
to
Required
to require the use a system card to control activation of an
encryption engine. If
System Cards
is set to
Not Required
, the encryption engine activates
without the need to read a system card first.
3.
Click
OK
.
Registering system cards from a card reader
System cards are smart cards that can be used to control activation of encryption engines.
Encryption switches and blades have a card reader that enables the use of a system card. System
cards discourage theft of encryption switches or blades by requiring the use of a system card at the
switch or blade to enable the encryption engine. When the switch or blade is powered off, the
encryption engine will not work without first inserting a system card into its card reader. If someone
removes a switch or blade with the intent of accessing the encryption engine, it will function as an
ordinary FC switch or blade when it is powered up, but use of the encryption engine is denied.
To register a system card from a card reader, a smart card must physically available. System cards
can be registered during encryption group creation or member configuration when running the
configuration wizard, or they can be registered using the following procedure.
1.
Select
Configure > Encryption
from the menu bar.
The
Encryption Center
dialog box displays.
2.
Select the switch from the
Encryption Devices
table, and select
Switch > System Cards
from
the menu task bar, or right-click the switch or and select
System Card
.
The
Register System Card
dialog box is displayed.
3.
Insert a smart card into the card reader. Be sure to wait for the card serial number to appear,
and then enter card assignment information, as directed.
4.
Click
OK
.
5.
Wait for the confirmation dialog box indicating initialization is done, and click
OK
.
The card is added to the
Registered System Cards
table on the
System Cards
dialog box.
6.
Store the card in a secure location, not in the proximity of the switch or blade.