HP Cisco MDS 9020 Cisco MDS 9000 Family Storage Media Encryption Configuration - Page 138

Advanced Mode, Smartcards, Replace

Page 138 highlights

Key Management Operations Chapter 6 Cisco SME Key Management Send documentation comments to [email protected] Advanced Mode In Advanced security mode, the master key is stored on five smart cards. Depending on the quorum required to recover the master key, two or three of the five smart cards or two of the three smart cards will be required to unlock the master key. The master key is stored securely on a PIN-protected smart card. To replace a lost or damaged smart card, the quorum of Cisco SME Recovery Officers must be present with their smart cards to authorize the master key recovery. This ensures that the split-knowledge security policy of the master key is maintained throughout the lifetime of the Cisco SME cluster. This method guarantees that following the creation of the Cisco SME cluster in Advanced security mode, the master key can only be retrieved by the quorum of Cisco Recover Officers and both the replacement operation as well as the new smart card are authorized and authenticated by the quorum. The smart card replacement triggers a master key recreation (master key rekey) and a new version of the master key is generated for the cluster. The new set of master keyshares are stored in the smart cards. All the volume group keys are also synchronized with the new master key. In the unique key mode, a new tape volume group wrap key is generated for each volume group. The existing tape volume group wrap key is duplicated with the new master key and put in the archived state. In the shared key mode, a new tape volume group wrap key and tape volume group shared key are generated. The existing tape volume group wrap key is duplicated with the new master key and put in the archived state. The existing tape volume group shared key remains as it were. To replace a smart card (Advanced security mode), follow these steps: Step 1 Step 2 Select Smartcards to display the smart card information for the cluster. Select the smart card that you want to replace. Click Replace to launch the smart card replacement wizard. Step 3 Insert the new smart card. Click Next. 6-24 Cisco MDS 9000 Family Storage Media Encryption Configuration Guide OL-18091-01, Cisco MDS NX-OS Release 4.x

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280

Send documentation comments to [email protected]
6-24
Cisco MDS 9000 Family Storage Media Encryption Configuration Guide
OL-18091-01, Cisco MDS NX-OS Release 4.x
Chapter 6
Cisco SME Key Management
Key Management Operations
Advanced Mode
In Advanced security mode, the master key is stored on five smart cards. Depending on the quorum
required to recover the master key, two or three of the five smart cards or two of the three smart cards
will be required to unlock the master key. The master key is stored securely on a PIN-protected smart
card.
To replace a lost or damaged smart card, the quorum of Cisco SME Recovery Officers must be present
with their smart cards to authorize the master key recovery. This ensures that the split-knowledge
security policy of the master key is maintained throughout the lifetime of the Cisco SME cluster. This
method guarantees that following the creation of the Cisco SME cluster in Advanced security mode, the
master key can only be retrieved by the quorum of Cisco Recover Officers and both the replacement
operation as well as the new smart card are authorized and authenticated by the quorum.
The smart card replacement triggers a master key recreation (master key rekey) and a new version of the
master key is generated for the cluster. The new set of master keyshares are stored in the smart cards. All
the volume group keys are also synchronized with the new master key.
In the unique key mode, a new tape volume group wrap key is generated for each volume group. The
existing tape volume group wrap key is duplicated with the new master key and put in the archived state.
In the shared key mode, a new tape volume group wrap key and tape volume group shared key are
generated. The existing tape volume group wrap key is duplicated with the new master key and put in
the archived state. The existing tape volume group shared key remains as it were.
To replace a smart card (Advanced security mode), follow these steps:
Step 1
Select
Smartcards
to display the smart card information for the cluster.
Step 2
Select the smart card that you want to replace. Click
Replace
to launch the smart card replacement
wizard.
Step 3
Insert the new smart card. Click
Next
.