Lenovo ThinkServer RD330 MegaRAID SAS Software User Guide - Page 355

Enabling Drive Security using EKM

Page 355 highlights

MegaRAID SAS Software User Guide Chapter 11: Using MegaRAID® Advanced Software | SafeStore Encryption Services 11.5.1 Enabling Drive Security using EKM 11.5.2 Supporting EKM mode  Enabling Drive Security using EKM  Enabling Drive Security using LKM EKM is used for key management when large number of systems are deployed. You can automate and manage the life cycle of keys and unlock configurations using EKM. Yet another important feature of EKM is that you can use it without human intervention to perform operations like drive migration and controller replacement. MegaRAID accomplishes the task of obtaining keys by interacting with the EKM agent. The EKM agent talks to the EKM server (EKMS) through a network and gets the security key for the controller. Keys are retrieved or created to perform the following tasks:  Create secure VDs.  Insert drives to replace failed drives in a secure configuration.  Re-key the system based on EKMS policies or user request.  Gain access to a secured configuration during boot.  Unlock and import secured drives during migration. Perform the following configurations to enable the drive security to create secure VD using the EKM mode with the support of EKM servers.  EKM mode is supported by MSM, and EKMS is present.  EKM mode is supported by MSM, and EKMS is not present.  Change the current security settings, or switch between the modes.  Change the security settings when the user is in EKM, and wants to switch to LKM.  Import Foreign Drives. When you choose EKM for drive security, and decide to configure, EKM mode is supported, and EKMS is present, the application responds to different behaviors depending on the scenarios at that particular time. The first scenario occurs when EKM is enabled, and the second scenario occurs when EKM is enabled and EKMS is present. The details of this scenario are described further in this section. Perform the following steps to configure, EKM mode is supported, and EKMS is present. 1. Select the Physical View tab in the left panel of the MegaRAID Storage Manager window, and click a controller icon. 2. Choose any one of the following options to arrive at the Drive Security Choose Mode wizard.  Select Go To >Controller>Enable Drive Security in the main navigation bar in the top portion of the MSM screen.  Right-click the controller icon, and click Enable Drive Security menu. The Drive Security Choose Mode wizard appears as shown in the following figure. Page 355

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401

Page 355
MegaRAID SAS Software User Guide
Chapter 11: Using MegaRAID® Advanced Software
|
SafeStore Encryption Services
Enabling Drive Security using EKM
Enabling Drive Security using LKM
11.5.1
Enabling Drive Security using
EKM
EKM is used for key management when large number of systems are deployed. You can
automate and manage the life cycle of keys and unlock configurations using EKM.
Yet another important feature of EKM is that you can use it without human intervention
to perform operations like drive migration and controller replacement.
MegaRAID accomplishes the task of obtaining keys by interacting with the EKM agent.
The EKM agent talks to the EKM server (EKMS) through a network and gets the security
key for the controller.
Keys are retrieved or created to perform the following tasks:
Create secure VDs.
Insert drives to replace failed drives in a secure configuration.
Re-key the system based on EKMS policies or user request.
Gain access to a secured configuration during boot.
Unlock and import secured drives during migration.
Perform the following configurations to enable the drive security to create secure VD
using the EKM mode with the support of EKM servers.
EKM mode is supported by MSM, and EKMS is present.
EKM mode is supported by MSM, and EKMS is not present.
Change the current security settings, or switch between the modes.
Change the security settings when the user is in EKM, and wants to switch to LKM.
Import Foreign Drives.
11.5.2
Supporting EKM mode
When you choose EKM for drive security, and decide to configure,
EKM mode is
supported, and EKMS is present
, the application responds to different behaviors
depending on the scenarios at that particular time.
The first scenario occurs when EKM is enabled, and the second scenario occurs when
EKM is enabled and EKMS is present. The details of this scenario are described further in
this section.
Perform the following steps to configure, EKM mode is supported, and EKMS is present.
1.
Select the Physical View tab in the left panel of the MegaRAID Storage Manager
window, and click a controller icon.
2.
Choose any one of the following options to arrive at the Drive Security Choose
Mode wizard.
Select Go To >Controller>Enable Drive Security in the main navigation bar in the
top portion of the MSM screen.
Right-click the controller icon, and click Enable Drive Security menu. The Drive
Security Choose Mode wizard appears as shown in the following figure.