HP Cisco MDS 9120 Cisco MDS 9000 Family Storage Media Encryption Configuration - Page 42

Cisco SME Role, Master Key, Security Mode, Required # of Users for This, What Operations is This Role

Page 42 highlights

Before You Begin Chapter 2 Getting Started Send documentation comments to [email protected] Table 2-1 shows a description of the Cisco SME roles and the number of users that should be considered for each role. Table 2-1 Cisco SME Roles and Responsibilities Cisco SME Role Cisco SME Administrator Master Key Security Mode Basic mode Standard mode Cisco SME KMC Basic mode Administrator Standard mode Cisco Storage Administrator Basic mode Standard mode Cisco SME Advanced mode Recovery Officer Required # of Users for This What Operations is This Role Role Responsible For? One user should hold the Cisco SME Administrator and the Cisco SME Recovery officer roles. One per VSAN is the minimum for day to day operations; must have access to all VSANs (if there are many VSANs and multiple VSAN administrators are assigned, then Cisco SME administrators, then there may be one Cisco SME Administrator per VSAN for key recovery operations. • Cisco SME management • Tape management • Export/Import tape volume groups The number of users is the same as for the Cisco SME Administrator role. • Key Management operations • Archive/purge volumes • Add/remove volume groups • Import/export volume groups • Rekey/replace smart cards The number of users is the same as for the Cisco SME Administrator role. • Cisco SME provisioning operations • Create/update/delete cluster • Create/update/delete tape backup groups • Add/remove tape devices • Create volume groups • View smart cards Five users (one for each smart card). Each smart card holder must be present during the cluster creation to provide the user login and password information and smart card pin. • Master key recovery • Replace smart card 2-10 Cisco MDS 9000 Family Storage Media Encryption Configuration Guide OL-18091-01, Cisco MDS NX-OS Release 4.x

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280

Send documentation comments to [email protected]
2-10
Cisco MDS 9000 Family Storage Media Encryption Configuration Guide
OL-18091-01, Cisco MDS NX-OS Release 4.x
Chapter 2
Getting Started
Before You Begin
Table 2-1
shows a description of the Cisco SME roles and the number of users that should be considered
for each role.
Table 2-1
Cisco SME Roles and Responsibilities
Cisco SME Role
Master Key
Security Mode
Required # of Users for This
Role
What Operations is This Role
Responsible For?
Cisco SME
Administrator
Basic mode
Standard mode
One user should hold the
Cisco SME Administrator
and the Cisco SME
Recovery officer roles.
One per VSAN is the
minimum for day to day
operations; must have
access to all VSANs (if
there are many VSANs and
multiple VSAN
administrators are
assigned, then Cisco SME
administrators, then there
may be one Cisco SME
Administrator per VSAN
for key recovery
operations.
Cisco SME management
Tape management
Export/Import tape volume
groups
Cisco SME KMC
Administrator
Basic mode
Standard mode
The number of users is the
same as for the Cisco SME
Administrator role.
Key Management operations
Archive/purge volumes
Add/remove volume groups
Import/export volume
groups
Rekey/replace smart cards
Cisco Storage
Administrator
Basic mode
Standard mode
The number of users is the
same as for the Cisco SME
Administrator role.
Cisco SME provisioning
operations
Create/update/delete cluster
Create/update/delete tape
backup groups
Add/remove tape devices
Create volume groups
View smart cards
Cisco SME
Recovery Officer
Advanced mode
Five users (one for each
smart card).
Each smart card holder
must be present during the
cluster creation to provide
the user login and
password information and
smart card pin.
Master key recovery
Replace smart card