HP Cisco MDS 9120 Cisco MDS 9000 Family Storage Media Encryption Configuration - Page 162

Migrating a KMC Server

Page 162 highlights

Migrating a KMC Server Chapter 6 Cisco SME Key Management Send documentation comments to [email protected] Operation: ABORT_REKEY_MASTER_KEY Logged as: "Abort master key rekey" Description: A re-key operation has been aborted. If the operation cannot be aborted, the failure is logged. Details: SUCCESS: "" FAILURE: "error: " Operation: GET_MASTER_KEY_SHARE Logged as: "Master key share retrieved" Description: When storing master key shares on smartcards, the share is verified as being written correctly by reading the share and comparing. This logs the result of that GET operation. Details: SUCCESS: "share index: smartcard label: smartcard serial number: GUID: " FAILURE: "share index: smartcard label: smartcard serial number: GUID: error: " Operation: REKEY_CLONE_WRAP_KEYS Logged as: "Clone tape volume- group wrap keys" Description: Part of Master Key re-key involves cloning wrap keys and re-wrapping them with the new master key. This logs the result of that cloning and re-wrap operation. Details: SUCCESS: " keys of cloned successfully" FAILURE: " keys of cloned successfully" Migrating a KMC Server To migrate a KMC server, follow these steps: Step 1 Step 2 Migrate all keys to the new KMC server. Refer to the backup and restore procedures outlined in Appendix E, "Database Backup and Restore." After restoring the database, install Fabric Manager in the new KMC server and point the Fabric Manager to the database. This ensures that all the keys are maintained across the KMC migration. 6-48 Cisco MDS 9000 Family Storage Media Encryption Configuration Guide OL-18091-01, Cisco MDS NX-OS Release 4.x

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280

Send documentation comments to [email protected]
6-48
Cisco MDS 9000 Family Storage Media Encryption Configuration Guide
OL-18091-01, Cisco MDS NX-OS Release 4.x
Chapter 6
Cisco SME Key Management
Migrating a KMC Server
Operation: ABORT_REKEY_MASTER_KEY
Logged as: "Abort master key
rekey"
Description: A re-key operation has been aborted.
If the operation
cannot be aborted, the failure is logged.
Details:
SUCCESS:
""
FAILURE:
"error: <description>"
-------------------------------------
Operation: GET_MASTER_KEY_SHARE
Logged as: "Master key share
retrieved"
Description: When storing master key shares on smartcards, the share
is verified as being written correctly by reading the share and
comparing.
This logs the result of that GET operation.
Details:
SUCCESS:
"share index: <share index> smartcard label: <smartcard
label> smartcard serial number: <serial number> GUID: <guid>"
FAILURE:
"share index: <share index> smartcard label: <smartcard
label> smartcard serial number: <serial number> GUID: <guid> error:
<description>"
-------------------------------------
Operation: REKEY_CLONE_WRAP_KEYS
Logged as: "Clone tape volume-
group wrap keys"
Description: Part of Master Key re-key involves cloning wrap keys and
re-wrapping them with the new master key.
This logs the result of
that cloning and re-wrap operation.
Details:
SUCCESS:
"<count> keys of <total count> cloned successfully"
FAILURE:
"<count> keys of <total count> cloned successfully"
Migrating a KMC Server
To migrate a KMC server, follow these steps:
Step 1
Migrate all keys to the new KMC server. Refer to the backup and restore procedures outlined in
Appendix E, “Database Backup and Restore.”
Step 2
After restoring the database, install Fabric Manager in the new KMC server and point the Fabric
Manager to the database. This ensures that all the keys are maintained across the KMC migration.