Lenovo ThinkServer RD330 MegaRAID SAS Software User Guide - Page 180

Destroy the Security Key, Create a Security Key, Drive Security Key

Page 180 highlights

Chapter 5: MegaRAID Command Tool | SafeStore Security Options MegaRAID SAS Software User Guide 5.7.3 Destroy the Security Key 5.7.4 Create a Security Key 5.7.5 Drive Security Key Page 180 Use the command in the following table to destroy the security key. Table 30: Destroy the Security Key Convention Description MegaCli -DestroySecurityKey | [-Force] -aN Destroys the security key. The controller uses the security key to lock and unlock access to the secure user data. This key is encrypted into the security key blob and stored on the controller. Re-provisioning disables the security system of a device. For a controller, it involves destroying the security key. For SED drives, when the drive lock key is deleted, the drive is unlocked and any user data on the drive is securely deleted. Use the command in the following table to create a security key. Table 31: Create a Security Key Convention Description MegaCli -CreateSecurityKey -SecurityKey sssssssssss | [-Passphrase sssssssssss] |[-KeyID kkkkkkkkkkk] -aN Creates a security key based on a user-provided string. The controller uses the security key to lock and unlock access to the secure user data. This key is encrypted into the security key blob and stored on the controller. If the security key is unavailable, user data is irretrievably lost. You must take all precautions to never lose the security key. -CreateSecurityKey: Creates the security key. -SecurityKey sssssssssss: Enters the new security key. The security key is case-sensitive. It must be between eight and thirty-two characters and contain at least one number, one lowercase letter, one uppercase letter, and one non-alphanumeric character (e.g. < > @ +). The space character is not permitted. [-Passphrase sssssssssss]: Enters the new passphrase.The pass phrase is case-sensitive. It must be between eight and thirty-two characters and contain at least one number, one lowercase letter, one uppercase letter, and one non-alphanumeric character (e.g. < > @ +). The space character is not permitted. If you want to use the security key using EKMS, the EKMS must provide the security key. You can create a security key using EKMS, or switch from EKM to LKM, or from LKM to EKM. Table 32: Drive Security Key Convention Description Convention Description Convention Description Convention Description MegaCli -CreateSecurityKey useEKMS -aN Creates security key using EKMS. MegaCli -ChangeSecurityKey -SecurityKey sssssssssss [-Passphrase sssssssssss] | [-KeyID kkkkkkkkkkk] -aN To change the security from EKMS to LKM. MegaCli -ChangeSecurityKey useEKMS -OldSecurityKey sssssssssss -aN To change security from LKM to EKM. MegaCli -ChangeSecurityKey -useEKMS -aNrekeying in EKMS

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401

Page 180
MegaRAID SAS Software User Guide
Chapter 5: MegaRAID Command Tool
|
SafeStore Security Options
5.7.3
Destroy the Security Key
Use the command in the following table to destroy the security key.
5.7.4
Create a Security Key
Use the command in the following table to create a security key.
5.7.5
Drive Security Key
If you want to use the security key using EKMS, the EKMS must provide the security key.
You can create a security key using EKMS, or switch from EKM to LKM, or from LKM to
EKM.
Table 30:
Destroy the Security Key
Convention
MegaCli -DestroySecurityKey | [-Force] -aN
Description
Destroys the security key. The controller uses the security key to lock and
unlock access to the secure user data. This key is encrypted into the security
key blob and stored on the controller.
Re-provisioning disables the security system of a device. For a controller, it
involves destroying the security key. For SED drives, when the drive lock key
is deleted, the drive is unlocked and any user data on the drive is securely
deleted.
Table 31:
Create a Security Key
Convention
MegaCli -CreateSecurityKey -SecurityKey sssssssssss |
[-Passphrase sssssssssss] |[-KeyID kkkkkkkkkkk] -aN
Description
Creates a security key based on a user-provided string. The controller uses
the security key to lock and unlock access to the secure user data. This key is
encrypted into the security key blob and stored on the controller. If the
security key is unavailable, user data is irretrievably lost. You must take all
precautions to never lose the security key.
-CreateSecurityKey
: Creates the security key.
-SecurityKey sssssssssss
: Enters the new security key. The security
key is case-sensitive. It must be between eight and thirty-two characters and
contain at least one number, one lowercase letter, one uppercase letter, and
one non-alphanumeric character (e.g. < > @ +). The space character is not
permitted.
[-Passphrase sssssssssss]
: Enters the new passphrase.The pass
phrase is case-sensitive. It must be between eight and thirty-two characters
and contain at least one number, one lowercase letter, one uppercase letter,
and one non-alphanumeric character (e.g. < > @ +). The space character is
not permitted.
Table 32:
Drive Security Key
Convention
MegaCli -CreateSecurityKey useEKMS –aN
Description
Creates security key using EKMS.
Convention
MegaCli -ChangeSecurityKey -SecurityKey sssssssssss [-Passphrase
sssssssssss] | [-KeyID kkkkkkkkkkk] –aN
Description
To change the security from EKMS to LKM.
Convention
MegaCli -ChangeSecurityKey useEKMS -OldSecurityKey sssssssssss –aN
Description
To change security from LKM to EKM.
Convention
MegaCli -ChangeSecurityKey -useEKMS –aN-
Description
rekeying in EKMS