HP Brocade 8/12c Fabric OS Encryption Administrator's Guide - Page 258

BES removal and replacement, Multi Node EG Case

Page 258 highlights

6 BES removal and replacement 7. Zeroize the new encryption engine. cryptocfg --zeroizeEE 4 The new encryption engine will power off and power on again automatically. 8. If a system card authentication is needed to enable the encryption engine, re-register the system card through the Management application client for the new encryption engine. 9. Initialize the new encryption engine. cryptocfg --initEE 4 10. Register the new encryption engine. cryptocfg --regEE 4 11. Enable the new encryption engine. cryptocfg --enableEE 4 12. Verify that this blade encryption engine has the same Master Key as rest of Encryption Engines in the Encryption Group using the cryptocfg --show -groupmember -all command. 13. Check the encryption engine state using the cryptocfg --show -localEE command to ensure that the encryption engine is online. 14. Check the encryption group state using the cryptocfg --show -groupcfg command to ensure that entire encryption group is in the converged and In Sync states. NOTE Because the FS8-18 blade was inserted to the same slot as the previous one, no change of HAC container ownership is required. The HAC configuration is retained as is. If manual failback was set on the HAC, then user intervention is required to manually failback the LUNs owned by the newly replaced encryption engine. There is no change in crypto-target container ownership. The container ownerships are retained as is. BES removal and replacement Multi Node EG Case The following procedure uses Brocade Encryption Switch (BES) 3 as the BES to be removed from an encryption group with the group leader designated as BES1. Two scenarios are considered: • When the Brocade Encryption Switch has failed • When the Brocade Encryption Switch has not failed When BES3 has failed, complete the following steps: 1. Deregister BES3 from the encryption group. cryptocfg --dereg -membernode 238 Fabric OS Encryption Administrator's Guide 53-1002159-03

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282

238
Fabric OS Encryption Administrator’s Guide
53-1002159-03
BES removal and replacement
6
7.
Zeroize the new encryption engine.
cryptocfg --zeroizeEE 4
The new encryption engine will power off and power on again automatically.
8.
If a system card authentication is needed to enable the encryption engine, re-register the
system card through the Management application client for the new encryption engine.
9.
Initialize the new encryption engine.
cryptocfg --initEE 4
10.
Register the new encryption engine.
cryptocfg --regEE 4
11.
Enable the new encryption engine.
cryptocfg --enableEE 4
12.
Verify that this blade encryption engine has the same Master Key as rest of Encryption Engines
in the Encryption Group using the
cryptocfg
--
show -groupmember -all
command.
13.
Check the encryption engine state using the
cryptocfg
--
show -localEE
command to ensure
that the encryption engine is online.
14.
Check the encryption group state using the
cryptocfg
--
show -groupcfg
command to ensure
that entire encryption group is in the
converged
and
In Sync
states.
NOTE
Because the FS8-18 blade was inserted to the same slot as the previous one, no change of
HAC container ownership is required. The HAC configuration is retained as is. If
manual
failback
was set on the HAC, then user intervention is required to manually failback the LUNs
owned by the newly replaced encryption engine. There is no change in crypto-target container
ownership. The container ownerships are retained as is.
BES removal and replacement
Multi Node EG Case
The following procedure uses Brocade Encryption Switch (BES) 3 as the BES to be removed from an
encryption group with the group leader designated as BES1. Two scenarios are considered:
When the Brocade Encryption Switch has failed
When the Brocade Encryption Switch has not failed
When BES3 has failed, complete the following steps:
1.
Deregister BES3 from the encryption group.
cryptocfg –-dereg –membernode <switchWWN>