HP Cisco MDS 9020 Cisco MDS 9000 Family Storage Media Encryption Configuration - Page 67

Selecting Master Key Security Levels, Security Level, Definition

Page 67 highlights

Chapter 4 Cisco SME Cluster Management Creating a Cisco SME Cluster Using the Cisco SME Wizard Send documentation comments to [email protected] Selecting Master Key Security Levels There are three master key security levels: Basic, Standard, and Advanced. Standard and Advanced security levels require smart cards. Table 4-1 describes the master key security levels. Caution You cannot modify the cluster security level after a cluster is created. Before confirming the cluster creation, you will be prompted to review the cluster details. At that time, you can return to modify the security level. Note For information on cluster security, see the "Cisco Storage Media Encryption Security Overview" section on page 1-13 and the "Master Key Security Modes" section on page 6-3. Table 4-1 Master Key Security Levels Security Level Basic Standard Advanced Definition The master key is stored in a file and encrypted with a password. To retrieve the master key, you need access to the file and the password. Standard security requires one smart card. When you create a cluster and the master key is generated, you are prompted to insert the smart card into the smart card reader. The master key is then written to the smart card. To retrieve the master key, you need the smart card and the smart card pin. Advanced security requires 5 smart cards. When you create a cluster and select Advanced security mode, you designate the number of smart cards (2 or 3 of 5 smart cards or 2 of 3 smart cards) that are required to recover the master key when data needs to be retrieved. For example, if you specify 2 of 5 smart cards, then you will need 2 of the 5 smart cards to recover the master key. Each smart card is owned by a Cisco SME Recovery Officer. Note The greater the number of required smart cards to recover the master key, the greater the security. However, if smart cards are lost or if they are damaged, this reduces the number of available smart cards that could be used to recover the master key. Note For Basic and Standard security modes, one user should hold the Cisco SME Administrator and the Cisco SME Recovery Officer roles. In the Master Key Security screen, select the cluster security type you wish to use. You can choose any of the following security levels: • Selecting Basic Security, page 4-6 • Selecting Standard Security, page 4-6 • Selecting Advanced Security, page 4-7 OL-18091-01, Cisco MDS NX-OS Release 4.x Cisco MDS 9000 Family Storage Media Encryption Configuration Guide 4-5

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280

Send documentation comments to [email protected]
4-5
Cisco MDS 9000 Family Storage Media Encryption Configuration Guide
OL-18091-01, Cisco MDS NX-OS Release 4.x
Chapter 4
Cisco SME Cluster Management
Creating a Cisco SME Cluster Using the Cisco SME Wizard
Selecting Master Key Security Levels
There are three master key security levels: Basic, Standard, and Advanced. Standard and Advanced
security levels require smart cards.
Table 4-1
describes the master key security levels.
Caution
You cannot modify the cluster security level after a cluster is created. Before confirming the cluster
creation, you will be prompted to review the cluster details. At that time, you can return to modify the
security level.
Note
For information on cluster security, see the
“Cisco Storage Media Encryption Security Overview”
section on page 1-13
and the
“Master Key Security Modes” section on page 6-3
.
Note
For Basic and Standard security modes, one user should hold the Cisco SME Administrator and the
Cisco SME Recovery Officer roles.
In the Master Key Security screen, select the cluster security type you wish to use. You can choose any
of the following security levels:
Selecting Basic Security, page 4-6
Selecting Standard Security, page 4-6
Selecting Advanced Security, page 4-7
Table 4-1
Master Key Security Levels
Security Level
Definition
Basic
The master key is stored in a file and encrypted with a password. To retrieve the
master key, you need access to the file and the password.
Standard
Standard security requires one smart card. When you create a cluster and the
master key is generated, you are prompted to insert the smart card into the smart
card reader. The master key is then written to the smart card. To retrieve the
master key, you need the smart card and the smart card pin.
Advanced
Advanced security requires 5 smart cards. When you create a cluster and select
Advanced security mode, you designate the number of smart cards (2 or 3 of 5
smart cards or 2 of 3 smart cards) that are required to recover the master key when
data needs to be retrieved. For example, if you specify 2 of 5 smart cards, then
you will need 2 of the 5 smart cards to recover the master key. Each smart card is
owned by a Cisco SME Recovery Officer.
Note
The greater the number of required smart cards to recover the master key,
the greater the security. However, if smart cards are lost or if they are
damaged, this reduces the number of available smart cards that could be
used to recover the master key.