Lenovo ThinkServer RD330 MegaRAID SAS Software User Guide - Page 179

SafeStore Security, Options

Page 179 highlights

MegaRAID SAS Software User Guide Chapter 5: MegaRAID Command Tool | SafeStore Security Options 5.7 SafeStore Security Options 5.7.1 Use Instant Secure Erase on a Physical Drive Use the commands in this section to manage the SafeStore Security feature. This feature offers the ability to encrypt data on disks and use disk-based key management to provide data security. With this feature, data is encrypted by the drives. You can designate which data to encrypt at the individual virtual drive (VD) level. This solution provides data protection in the event of theft or loss of physical drives. With self-encrypting disks, if you remove a drive from its storage system or the server it is housed in, the data on that drive is encrypted and useless to anyone who attempts to access without the appropriate security authorization. Any encryption solution requires management of the encryption keys. This feature provides a way to manage these keys. You can change the encryption key for all ServeRAID controllers that are connected to SED drives. All SED drives, whether locked or unlocked, always have an encryption key. This key is set by the drive and is always active. When the drive is unlocked, the data to host from the drive (on reads) and from the host to the drive cache (on writes) is always provided. However, when resting on the drive platters, the data is always encrypted by the drive. In the following options, [E0:S0, E1:S1] specifies the enclosure ID and slot ID for the drive. See Chapter 3, SafeStore Disk Encryption for more information about the SED feature. Use the command in the following table to perform an Instant Secure Erase of data on a physical drive. The Instant Secure Erase feature lets you erase data on SED drives. Table 28: Use Instant Secure Erase on a Physical Drive Convention Description MegaCli -PDInstantSecureErase -PhysDrv[E0:S0,E1:S1,...] | [-Force] -aN|-a0,1,2|-aALL Erases the data on a specified drive or drives. -PDInstantSecureErase: Use the Instant Secure Erase feature to erase data on a drive or drives. -PhysDrv[E0:S0,...]: Specifies the drive(s) that you want to perform the Instant Secure Erase on. -Force: Specifies that the MegaCLI utility does not ask you for confirmation before it performs this command (you might lose data using this option with some commands). NOTE: NOTE: Previously -szXXX expressed capacity in MB but now you can enter the capacity in your choice of units. For example, to create a virtual drive of 10 GB, enter the size as sz10GB. If you do not enter a unit, by default it is considered as MB. 5.7.2 Secure Data on a Virtual Drive Use the command in the following table to secure data on a virtual drive. Table 29: Secure Data on a Virtual Drive Convention Description MegaCli -LDMakeSecure -Lx|-L0,1,2,...|-Lall -aN|-a0,1,2|-aALL Secures data on a specified virtual drive or drives. Page 179

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401

Page 179
MegaRAID SAS Software User Guide
Chapter 5: MegaRAID Command Tool
|
SafeStore Security Options
5.7
SafeStore Security
Options
Use the commands in this section to manage the SafeStore Security feature. This
feature offers the ability to encrypt data on disks and use disk-based key management
to provide data security. With this feature, data is encrypted by the drives. You can
designate which data to encrypt at the individual virtual drive (VD) level.
This solution provides data protection in the event of theft or loss of physical drives.
With self-encrypting disks, if you remove a drive from its storage system or the server it
is housed in, the data on that drive is encrypted and useless to anyone who attempts to
access without the appropriate security authorization.
Any encryption solution requires management of the encryption keys. This feature
provides a way to manage these keys. You can change the encryption key for all
ServeRAID controllers that are connected to SED drives. All SED drives, whether locked
or unlocked, always have an encryption key. This key is set by the drive and is always
active. When the drive is unlocked, the data to host from the drive (on reads) and from
the host to the drive cache (on writes) is always provided. However, when resting on
the drive platters, the data is always encrypted by the drive.
In the following options, [E0:S0, E1:S1] specifies the enclosure ID and slot ID for the
drive.
See
Chapter 3, SafeStore Disk Encryption
for more information about the SED feature.
5.7.1
Use Instant Secure Erase on a
Physical Drive
Use the command in the following table to perform an Instant Secure Erase of data on a
physical drive. The Instant Secure Erase feature lets you erase data on SED drives.
5.7.2
Secure Data on a Virtual Drive
Use the command in the following table to secure data on a virtual drive.
Table 28:
Use Instant Secure Erase on a Physical Drive
Convention
MegaCli -PDInstantSecureErase
-PhysDrv[E0:S0,E1:S1,...] | [-Force]
-aN|-a0,1,2|-aALL
Description
Erases the data on a specified drive or drives.
-PDInstantSecureErase
: Use the Instant Secure Erase feature to
erase data on a drive or drives.
-PhysDrv[E0:S0,...]
: Specifies the drive(s) that you want to
perform the Instant Secure Erase on.
-Force
: Specifies that the MegaCLI utility does not ask you for
confirmation before it performs this command (you might lose data
using this option with some commands).
NOTE:
NOTE: Previously
-szXXX
expressed capacity in MB but now you can
enter the capacity in your choice of units. For example, to create a virtual
drive of 10 GB, enter the size as
sz10GB
. If you do not enter a unit, by default
it is considered as MB.
Table 29:
Secure Data on a Virtual Drive
Convention
MegaCli -LDMakeSecure -Lx|-L0,1,2,...|-Lall
-aN|-a0,1,2|-aALL
Description
Secures data on a specified virtual drive or drives.