HP Cisco MDS 9120 Cisco MDS 9000 Family Storage Media Encryption Configuration - Page 168

Setting the SME Cluster Security Level

Page 168 highlights

Setting the SME Cluster Security Level Chapter 7 Using the Command Line Interface to Configure SME Send documentation comments to [email protected] • Volume tape groups • Tape compression To create an SME cluster, follow these steps: Step 1 Step 2 Command switch# config t switch(config)# sme cluster clustername1 switch(config-sme-cl)# Step 3 switch(config-sme-cl)# fabric f1 Purpose Enters configuration mode. Specifies the cluster name and enters SME cluster configuration submode. A cluster name can include a maximum of 32 characters. Adds fabric f1 to the cluster. Setting the SME Cluster Security Level There are 3 levels of security: Basic, Standard, and Advanced. Standard and Advanced security levels require smart cards. Table 7-1 Master Key Security Levels Security Level Basic Standard Advanced Definition The master key is stored in a file and encrypted with a password. To retrieve the master key, you need access to the file and the password. Standard security requires one smart card. When you create a cluster and the master key is generated, you are asked for the smart card. The Master key is then written to the smart card. To retrieve the master key, you need the smart card and the smart card pin. Advanced security requires five smart cards. When you create a cluster and select Advanced security mode, you designate the number of smart cards (two or three of five smart cards or two of three smart cards) that are required to recover the master key when data needs to be retrieved. For example, if you specify two of five smart cards, then you will need two of the five smart cards to recover the master key. Each smart card is owned by a Cisco SME Recovery Officer. Note The greater the number of required smart cards, the greater the security. However, if smart cards are lost or if they are damaged, this reduces the number of available smart cards that could be used to recover the master key. To set the SME cluster security level, follow these steps: Step 1 Command switch# config t Purpose Enters configuration mode. Cisco MDS 9000 Family Storage Media Encryption Configuration Guide 7-4 OL-18091-01, Cisco MDS NX-OS Release 4.x

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280

Send documentation comments to [email protected]
7-4
Cisco MDS 9000 Family Storage Media Encryption Configuration Guide
OL-18091-01, Cisco MDS NX-OS Release 4.x
Chapter 7
Using the Command Line Interface to Configure SME
Setting the SME Cluster Security Level
Volume tape groups
Tape compression
To create an SME cluster, follow these steps:
Setting the SME Cluster Security Level
There are 3 levels of security: Basic, Standard, and Advanced. Standard and Advanced security levels
require smart cards.
To set the SME cluster security level, follow these steps:
Command
Purpose
Step 1
switch#
config t
Enters configuration mode.
Step 2
switch(config)#
sme cluster
clustername1
switch(config-sme-cl)#
Specifies the cluster name and enters SME cluster
configuration submode. A cluster name can include a
maximum of 32 characters.
Step 3
switch(config-sme-cl)#
fabric f1
Adds fabric f1 to the cluster.
Table 7-1
Master Key Security Levels
Security Level
Definition
Basic
The master key is stored in a file and encrypted with a password. To retrieve the
master key, you need access to the file and the password.
Standard
Standard security requires one smart card. When you create a cluster and the
master key is generated, you are asked for the smart card. The Master key is then
written to the smart card. To retrieve the master key, you need the smart card and
the smart card pin.
Advanced
Advanced security requires five smart cards. When you create a cluster and select
Advanced security mode, you designate the number of smart cards (two or three
of five smart cards or two of three smart cards) that are required to recover the
master key when data needs to be retrieved. For example, if you specify two of
five smart cards, then you will need two of the five smart cards to recover the
master key. Each smart card is owned by a Cisco SME Recovery Officer.
Note
The greater the number of required smart cards, the greater the security.
However, if smart cards are lost or if they are damaged, this reduces the
number of available smart cards that could be used to recover the master
key.
Command
Purpose
Step 1
switch#
config t
Enters configuration mode.