HP Cisco MDS 9120 Cisco MDS 9000 Family Storage Media Encryption Configuration - Page 168
Setting the SME Cluster Security Level
View all HP Cisco MDS 9120 manuals
Add to My Manuals
Save this manual to your list of manuals |
Page 168 highlights
Setting the SME Cluster Security Level Chapter 7 Using the Command Line Interface to Configure SME Send documentation comments to [email protected] • Volume tape groups • Tape compression To create an SME cluster, follow these steps: Step 1 Step 2 Command switch# config t switch(config)# sme cluster clustername1 switch(config-sme-cl)# Step 3 switch(config-sme-cl)# fabric f1 Purpose Enters configuration mode. Specifies the cluster name and enters SME cluster configuration submode. A cluster name can include a maximum of 32 characters. Adds fabric f1 to the cluster. Setting the SME Cluster Security Level There are 3 levels of security: Basic, Standard, and Advanced. Standard and Advanced security levels require smart cards. Table 7-1 Master Key Security Levels Security Level Basic Standard Advanced Definition The master key is stored in a file and encrypted with a password. To retrieve the master key, you need access to the file and the password. Standard security requires one smart card. When you create a cluster and the master key is generated, you are asked for the smart card. The Master key is then written to the smart card. To retrieve the master key, you need the smart card and the smart card pin. Advanced security requires five smart cards. When you create a cluster and select Advanced security mode, you designate the number of smart cards (two or three of five smart cards or two of three smart cards) that are required to recover the master key when data needs to be retrieved. For example, if you specify two of five smart cards, then you will need two of the five smart cards to recover the master key. Each smart card is owned by a Cisco SME Recovery Officer. Note The greater the number of required smart cards, the greater the security. However, if smart cards are lost or if they are damaged, this reduces the number of available smart cards that could be used to recover the master key. To set the SME cluster security level, follow these steps: Step 1 Command switch# config t Purpose Enters configuration mode. Cisco MDS 9000 Family Storage Media Encryption Configuration Guide 7-4 OL-18091-01, Cisco MDS NX-OS Release 4.x