HP Cisco MDS 9120 Cisco MDS 9000 Family Storage Media Encryption Configuration - Page 262

Migrating From Cisco KMC to RKM

Page 262 highlights

Migrating From Cisco KMC to RKM Appendix D RSA Key Manager and Cisco SME Send documentation comments to [email protected] The confirmation window displays the RKM server IP address and the RKM port number. Migrating From Cisco KMC to RKM You can use RKM at the time of Cisco SME installation, or you can choose to deploy Cisco SME with the integrated Cisco KMC later. If RKM is deployed after Cisco KMC has been used alone, you need to perform an explicit key migration procedure before using RKM with Cisco SME. This section describes the procedure for migrating encryption keys, wrap keys, and encryption policy information from Cisco KMC to RKM. Note The migration procedure will differ when Cisco KMC uses the PostgresSQL database or the Oracle Express database for the key catalog. These differences are documented wherever applicable. To migrate keys from the Cisco KMC to RKM, follow these steps: Step 1 Step 2 Step 3 Step 4 Suspend all backup applications and jobs. The migration procedure temporarily suspends access to keys, so the execution of backup operations must be suspended until the migration is completed. Back up the key database. We recommend that you back up the key database before performing the migration. The backup procedure should have been previously tested to help ensure the correct restoration of the keys in case any problems arise during migration. Export all volume group keys in the cluster. Each volume group export will generate a separate password-protected file. The password-protected files contain the keys to be imported in RKM. Shut down the Cisco Fabric Manager, which shuts down the Cisco KMC. This step prevents any key operation from being performed during migration. Cisco MDS 9000 Family Storage Media Encryption Configuration Guide D-8 OL-18091-01, Cisco MDS NX-OS Release 4.x

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280

Send documentation comments to [email protected]
D-8
Cisco MDS 9000 Family Storage Media Encryption Configuration Guide
OL-18091-01, Cisco MDS NX-OS Release 4.x
Appendix D
RSA Key Manager and Cisco SME
Migrating From Cisco KMC to RKM
The confirmation window displays the RKM server IP address and the RKM port number.
Migrating From Cisco KMC to RKM
You can use RKM at the time of Cisco SME installation, or you can choose to deploy Cisco SME with
the integrated Cisco KMC later. If RKM is deployed after Cisco KMC has been used alone, you need to
perform an explicit key migration procedure before using RKM with Cisco SME.
This section describes the procedure for migrating encryption keys, wrap keys, and encryption policy
information from Cisco KMC to RKM.
Note
The migration procedure will differ when Cisco KMC uses the PostgresSQL database or the Oracle
Express database for the key catalog. These differences are documented wherever applicable.
To migrate keys from the Cisco KMC to RKM, follow these steps:
Step 1
Suspend all backup applications and jobs.
The migration procedure temporarily suspends access to keys, so the execution of backup operations
must be suspended until the migration is completed.
Step 2
Back up the key database.
We recommend that you back up the key database before performing the migration. The backup
procedure should have been previously tested to help ensure the correct restoration of the keys in case
any problems arise during migration.
Step 3
Export all volume group keys in the cluster.
Each volume group export will generate a separate password-protected file. The password-protected
files contain the keys to be imported in RKM.
Step 4
Shut down the Cisco Fabric Manager, which shuts down the Cisco KMC.
This step prevents any key operation from being performed during migration.