HP Cisco MDS 9216 Cisco MDS 9000 Family Storage Media Encryption Configuration - Page 272

Assigning Cisco SME Roles and Users, Creating Cisco SME Fabrics, Installing SSL Certificates

Page 272 highlights

Preconfiguration Tasks Appendix F Planning For Cisco SME Installation Send documentation comments to [email protected] • Set the FC Redirect version to 2 (if you are using SAN-OS Release 3.1(1a) or later, or NX-OS 4.x). To learn more about enabling the version2 mode, refer to the "fc-redirect version2 enable" section on page A-12. Note To learn about enabling these services, refer to Chapter 2, "Getting Started." Assigning Cisco SME Roles and Users The Cisco SME feature provides two primary roles: Cisco SME Administrator (sme-admin) and the Cisco SME Recovery Officer (sme-recovery). The Cisco SME Administrator role also includes the Cisco SME Storage Administrator (sme-stg-admin) and Cisco SME KMC Administrator (sme-kmc-admin) roles. To set up the roles and users, note the following guidelines: • Create the appropriate Cisco SME roles, that is, sme-admin and/or sme-stg-admin and sme-kmc-admin, and sme-recovery in the Advanced Master Key Security mode. • Choose separate users for the sme-kmc-admin role and the sme-stg-admin role to split the responsiblities of key management and SME provisioning. To combine these responsibilities into one role, choose the stg-admin role. • Use the Fabric Manager to create users for sme-admin, sme-stg-admin, and sme-kmc-admin roles as appropriate. • In the Advanced mode for the master key, create three or five users under the sme-recovery role. • Create users on the switches for all of these roles. To know more about the roles and their responsibilities refer to the "Creating and Assigning Cisco SME Roles and Cisco SME Users" section on page 2-9. For detailed information on creating and assigning roles, refer to the Cisco MDS 9000 Family Fabric Manager Configuration Guide and the Cisco MDS 9000 Family CLI Configuration Guide. Creating Cisco SME Fabrics When creating Cisco SME fabrics, note the following guidelines: • Add the Cisco SME fabrics using the Fabric Manager Web client. Modify the names to exclude switch names from the fabric name. • The fabric name must remain constant. You cannot change the fabric name after you have configured Cisco SME. For more information, refer to the "Adding a Fabric and Changing the Fabric Name" section on page 2-13. Installing SSL Certificates To create SSL certificates, do the following tasks: • Follow the procedure specified in Appendix C, "Provisioning Self-Sign Certificates," to install SSL certificates on the switches and the KMC. • Use the same password at every step of the installation procedure to simplify the process. Cisco MDS 9000 Family Storage Media Encryption Configuration Guide F-6 OL-18091-01, Cisco MDS NX-OS Release 4.x

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280

Send documentation comments to [email protected]
F-6
Cisco MDS 9000 Family Storage Media Encryption Configuration Guide
OL-18091-01, Cisco MDS NX-OS Release 4.x
Appendix F
Planning For Cisco SME Installation
Preconfiguration Tasks
Set the FC Redirect version to 2 (if you are using SAN-OS Release 3.1(1a) or later, or NX-OS 4.x).
To learn more about enabling the version2 mode, refer to the
“fc-redirect version2 enable” section
on page A-12
.
Note
To learn about enabling these services, refer to
Chapter 2, “Getting Started.”
Assigning Cisco SME Roles and Users
The Cisco SME feature provides two primary roles: Cisco SME Administrator (sme-admin) and the
Cisco SME Recovery Officer (sme-recovery). The Cisco SME Administrator role also includes the Cisco
SME Storage Administrator (sme-stg-admin) and Cisco SME KMC Administrator (sme-kmc-admin)
roles.
To set up the roles and users, note the following guidelines:
Create the appropriate Cisco SME roles, that is, sme-admin and/or sme-stg-admin and
sme-kmc-admin, and sme-recovery in the Advanced Master Key Security mode.
Choose separate users for the sme-kmc-admin role and the sme-stg-admin role to split the
responsiblities of key management and SME provisioning. To combine these responsibilities into
one role, choose the stg-admin role.
Use the Fabric Manager to create users for sme-admin, sme-stg-admin, and sme-kmc-admin roles
as appropriate.
In the Advanced mode for the master key, create three or five users under the sme-recovery role.
Create users on the switches for all of these roles.
To know more about the roles and their responsibilities refer to the
“Creating and Assigning Cisco SME
Roles and Cisco SME Users” section on page 2-9
. For detailed information on creating and assigning
roles, refer to the
Cisco MDS 9000 Family Fabric Manager Configuration Guide
and the
Cisco MDS
9000 Family CLI Configuration Guide.
Creating Cisco SME Fabrics
When creating Cisco SME fabrics, note the following guidelines:
Add the Cisco SME fabrics using the Fabric Manager Web client. Modify the names to exclude
switch names from the fabric name.
The fabric name must remain constant. You cannot change the fabric name after you have configured
Cisco SME.
For more information, refer to the
“Adding a Fabric and Changing the Fabric Name” section on
page 2-13
.
Installing SSL Certificates
To create SSL certificates, do the following tasks:
Follow the procedure specified in
Appendix C, “Provisioning Self-Sign Certificates,”
to install SSL
certificates on the switches and the KMC.
Use the same password at every step of the installation procedure to simplify the process.