HP Cisco MDS 9120 Cisco MDS 9000 Family Storage Media Encryption Configuration - Page 118

Key Management Settings, Tape Recycling

Page 118 highlights

Key Management Settings Chapter 6 Cisco SME Key Management Send documentation comments to [email protected] Key Management Settings When creating a tape volume group, you will need to determine whether to enable or disable the key management settings. Table 6-2 provides a description of the key settings, considerations, and the type of keys that can be purged if a particular setting is chosen. All key settings are configured at the cluster level. Table 6-2 Key Management Settings Description Considerations Shared In shared key mode, only tape volume group keys are generated. All tape volumes that are part of a tape volume group share the same key. Cisco KMC key database-Is smaller storing only the tape volume group keys. Security-Medium. A compromise to one tape volume group key will compromise the data in all tapes that are part of that tape volume group. Purging-Available only at the volume group level Unique Key In unique key mode, each individual tape has it's own unique key. The default value is enabled. Cisco KMC key database-Is larger storing the tape volume group keys and every unique tape volume key. Security-High. A compromise to a tape volume key will not compromise the integrity of data on other tape volumes. Purging-Available at the volume group and volume level. Unique Key with Key-On-Tape In the key-on-tape mode, each unique tape volume key is stored on the individual tape. You can select key-on-tape (when you select unique key mode) to configure the most secure and scalable key management system. The default value is disabled. Note When key-on-tape mode is enabled, the keys stored on the tape media are encrypted by the tape volume group wrap key. Cisco KMC key database- Increases scalability to support a large number of tape volumes by reducing the size of the Cisco KMC key database. Only the tape volume group keys are stored on the Cisco KMC. Security-High. A compromise to a tape volume key will not compromise the integrity of data on other tape volumes. Purging-Available at the volume group level. Tape Recycling If Tape Recycling is enabled, old keys for the tape volume are purged from Cisco KMC when the tape is relabeled and new key is created and synchronized to the Cisco KMC. This setting should be selected when you do not need the old keys for previously backed-up data that will be rewritten. Cisco MDS 9000 Family Storage Media Encryption Configuration Guide 6-4 OL-18091-01, Cisco MDS NX-OS Release 4.x

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280

Send documentation comments to [email protected]
6-4
Cisco MDS 9000 Family Storage Media Encryption Configuration Guide
OL-18091-01, Cisco MDS NX-OS Release 4.x
Chapter 6
Cisco SME Key Management
Key Management Settings
Key Management Settings
When creating a tape volume group, you will need to determine whether to enable or disable the key
management settings.
Table 6-2
provides a description of the key settings, considerations, and the type of keys that can be
purged if a particular setting is chosen. All key settings are configured at the cluster level.
Tape Recycling
If Tape Recycling is enabled, old keys for the tape volume are purged from Cisco KMC when the tape
is relabeled and new key is created and synchronized to the Cisco KMC. This setting should be selected
when you do not need the old keys for previously backed-up data that will be rewritten.
Table 6-2
Key Management Settings
Description
Considerations
Shared
In shared key mode, only tape volume
group keys are generated. All tape
volumes that are part of a tape volume
group share the same key.
Cisco KMC key database
—Is smaller
storing only the tape volume group keys.
Security
—Medium. A compromise to one
tape volume group key will compromise
the data in all tapes that are part of that tape
volume group.
Purging
—Available only at the volume
group level
Unique Key
In unique key mode, each individual
tape has it’s own unique key.
The default value is enabled.
Cisco KMC key database
—Is larger
storing the tape volume group keys and
every unique tape volume key.
Security
—High. A compromise to a tape
volume key will not compromise the
integrity of data on other tape volumes.
Purging
—Available at the volume group
and volume level.
Unique Key with
Key-On-Tape
In the key-on-tape mode, each unique
tape volume key is stored on the
individual tape.
You can select key-on-tape (when you
select unique key mode) to configure
the most secure and scalable key
management system.
The default value is disabled.
Note
When key-on-tape mode is
enabled, the keys stored on
the tape media are encrypted
by the tape volume group
wrap key.
Cisco KMC key database
— Increases
scalability to support a large number of
tape volumes by reducing the size of the
Cisco KMC key database. Only the tape
volume group keys are stored on the Cisco
KMC.
Security
—High. A compromise to a tape
volume key will not compromise the
integrity of data on other tape volumes.
Purging
—Available at the volume group
level.