HP Cisco MDS 9120 Cisco MDS 9000 Family Storage Media Encryption Configuration - Page 263

The default certificate store Windows is at C:\Program Files\Cisco Systems\MDS 9000\conf\cert\.

Page 263 highlights

Appendix D RSA Key Manager and Cisco SME Migrating From Cisco KMC to RKM Send documentation comments to [email protected] Step 5 Step 6 Step 7 Run the following database scripts from the database administrative console: • For the key catalog on PostgresSQL, run postgres-kmc-rkm-pre-migrate.sql. • For the key catalog on Oracle Express, run oracle-kmc-rkm-pre-migrate.sql. These scripts are packaged in Cisco Fabric Manager CD as of NX-OS Software Release 4.1(1). Install RKM on the system allocated for this purpose. RKM can be installed and configured separately. Ensure that RKM is ready prior to the start of the migration in order to decrease downtime. Configure the certificates for RKM and identify the following certificate files: • sme_rkm_client.jks • sme_rkm_trust.jks Copy the two certificate files on the Cisco Fabric Manager Server system. Copy the two files in the certificate store directory. Go to the SME tab on the Fabric Manager Web Client and choose Key Manager Settings to view the actual directory. Note The default certificate store (Windows) is at C:\Program Files\Cisco Systems\MDS 9000\conf\cert\. Step 8 Step 9 Step 10 Step 11 Step 12 Step 13 Step 14 Start Cisco Fabric Manager, which starts Cisco KMC. Go to the SME tab on the Fabric Manager Web Client and choose Key Manager Settings. Select RSA as the key manager and configure the IP address and port for RKM. Go to the Accounting Log and monitor the log messages until "Synchronization Complete for Cluster" is displayed. Create and import all the volume group keys from the password-protected files. Run the following post-migration scripts to delete the keys in the Cisco KMC key database: • For the key catalog previously on PostgresSQL, run postgres-kmc-rkm-post-migrate.sql • For the key catalog previously on Oracle Express, run oracle-kmc-rkm-post-migrate.sql These scripts are packaged in the Cisco Fabric Manager CD as of NX-OS Software Release 4.1(1) Restart any backup applications and jobs that were deactivated or suspended before the migration. Note In Cisco MDS 9000 SAN-OS Software Releases 3.2(3a) and 3.3(1a), the importing of the volume group leaves all the keys in a deactivated (archived) state, and after the migration, the tapes can be restored but cannot be used for active encryption. Note In Cisco MDS 9000 NX-OS Software Release 4.1(1c) and later, the keys are restored in the same state (active or deactivated) as before the migration. OL-18091-01, Cisco MDS NX-OS Release 4.x Cisco MDS 9000 Family Storage Media Encryption Configuration Guide D-9

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280

Send documentation comments to [email protected]
D-9
Cisco MDS 9000 Family Storage Media Encryption Configuration Guide
OL-18091-01, Cisco MDS NX-OS Release 4.x
Appendix D
RSA Key Manager and Cisco SME
Migrating From Cisco KMC to RKM
Step 5
Run the following database scripts from the database administrative console:
For the key catalog on PostgresSQL, run
postgres-kmc-rkm-pre-migrate.sql.
For the key catalog on Oracle Express, run
oracle-kmc-rkm-pre-migrate.sql.
These scripts are packaged in Cisco Fabric Manager CD as of NX-OS Software Release 4.1(1).
Step 6
Install RKM on the system allocated for this purpose.
RKM can be installed and configured separately. Ensure that RKM is ready prior to the start of the
migration in order to decrease downtime.
Configure the certificates for RKM and identify the following certificate files:
sme_rkm_client.jks
sme_rkm_trust.jks
Step 7
Copy the two certificate files on the Cisco Fabric Manager Server system.
Copy the two files in the certificate store directory. Go to the
SME
tab on the Fabric Manager Web Client
and choose
Key Manager Settings
to view the actual directory.
Note
The default certificate store (Windows) is at C:\Program Files\Cisco Systems\MDS 9000\conf\cert\.
Step 8
Start Cisco Fabric Manager, which starts Cisco KMC.
Step 9
Go to the
SME
tab on the Fabric Manager Web Client and choose
Key Manager Settings
.
Step 10
Select RSA as the key manager and configure the IP address and port for RKM.
Step 11
Go to the Accounting Log and monitor the log messages until “Synchronization Complete for Cluster”
is displayed.
Step 12
Create and import all the volume group keys from the password-protected files.
Step 13
Run the following post-migration scripts to delete the keys in the Cisco KMC key database:
For the key catalog previously on PostgresSQL, run
postgres-kmc-rkm-post-migrate.sql
For the key catalog previously on Oracle Express, run
oracle-kmc-rkm-post-migrate.sql
These scripts are packaged in the Cisco Fabric Manager CD as of NX-OS Software Release 4.1(1)
Step 14
Restart any backup applications and jobs that were deactivated or suspended before the migration.
Note
In Cisco MDS 9000 SAN-OS Software Releases 3.2(3a) and 3.3(1a), the importing of the volume group
leaves all the keys in a deactivated (archived) state, and after the migration, the tapes can be restored but
cannot be used for active encryption.
Note
In Cisco MDS 9000 NX-OS Software Release 4.1(1c) and later, the keys are restored in the same state
(active or deactivated) as before the migration.