Lenovo ThinkServer RD330 MegaRAID SAS Software User Guide - Page 50

Instant Secure Erase

Page 50 highlights

Chapter 3: SafeStore Disk Encryption | Instant Secure Erase MegaRAID SAS Software User Guide 3.4.3.1 Simple Configuration 3.4.3.2 Advanced Configuration 3.4.4 Import a Foreign Configuration If you select simple configuration, select the redundancy type and drive security method to use for the drive group. See Section 8.1.4, Creating a Virtual Drive Using Simple Configuration for the procedures used to select the redundancy type and drive security method for a configuration. If you select advanced configuration, select the drive security method, and add the drives to the drive group. See Section 8.1.5, Creating a Virtual Drive Using Advanced Configuration for the procedures used to import a foreign configuration. After the drive group is secured, you cannot remove the security without deleting the virtual drives. After you create a security key, you can run a scan for a foreign configuration and import a locked configuration. (You can import unsecured or unlocked configurations when security is disabled.) A foreign configuration is a RAID configuration that already exists on a replacement set of drives that you install in a computer system. WebBIOS Configuration Utility and MSM allows you to import the existing configuration to the RAID controller or clear the configuration so you can create a new one. See Section 4.8, Viewing and Changing Device Properties for the procedure used to import a foreign configuration in WebBIOS or Section 11.5.12, Importing or Clearing a Foreign Configuration for the procedure in MegaRAID Storage Manager. To import a foreign configuration, you must first enable security to allow importation of locked foreign drives. If the drives are locked and the controller security is disabled, you cannot import the foreign drives. Only unlocked drives can be imported when security is disabled. After you enable the security, you can import the locked drives. To import the locked drives, you must provide the security key used to secure them. Verify whether any drives are left to import as the locked drives can use different security keys. If there are any drives left, repeat the import process for the remaining drives. After all of the drives are imported, there is no configuration to import. 3.5 Instant Secure Erase Instant Secure Erase is a feature used to erase data from encrypted drives. After the initial investment for an encrypted disk, there is no additional cost in dollars or time to erase data using the Instant Secure Erase feature. You can change the encryption key for all MegaRAID RAID controllers that are connected to encrypted drives. All encrypted drives, whether locked or unlocked, always have an encryption key. This key is set by the drive and is always active. When the drive is unlocked, the data to host from the drive (on reads) and from the host to the drive cache (on writes) is always provided. However, when resting on the drive platters, the data is always encrypted by the drive. You might not want to lock your drives because you have to manage a password if they are locked. Even if you do not lock the drives, there is still a benefit to using encrypted disks. If you are concerned about data theft or other security issues, you might already invest in drive disposal costs, and there are benefits to using SafeStore encryption over other technologies that exists today, both in terms of the security provided and time saved. Page 50

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401

Page 50
MegaRAID SAS Software User Guide
Chapter 3: SafeStore Disk Encryption
|
Instant Secure Erase
3.4.3.1
Simple Configuration
If you select simple configuration, select the redundancy type and drive security
method to use for the drive group.
See
Section 8.1.4,
Creating a Virtual Drive Using Simple Configuration
for the procedures
used to select the redundancy type and drive security method for a configuration.
3.4.3.2
Advanced Configuration
If you select advanced configuration, select the drive security method, and add the
drives to the drive group.
See
Section 8.1.5,
Creating a Virtual Drive Using Advanced Configuration
for the
procedures used to import a foreign configuration.
After the drive group is secured, you cannot remove the security without deleting the
virtual drives.
3.4.4
Import a Foreign Configuration
After you create a security key, you can run a scan for a foreign configuration and
import a locked configuration. (You can import unsecured or unlocked configurations
when security is disabled.) A foreign configuration is a RAID configuration that already
exists on a replacement set of drives that you install in a computer system. WebBIOS
Configuration Utility and MSM allows you to import the existing configuration to the
RAID controller or clear the configuration so you can create a new one.
See
Section 4.8,
Viewing and Changing Device Properties
for the procedure used to
import a foreign configuration in WebBIOS or
Section 11.5.12,
Importing or Clearing a
Foreign Configuration
for the procedure in MegaRAID Storage Manager.
To import a foreign configuration, you must first enable security to allow importation of
locked foreign drives. If the drives are locked and the controller security is disabled, you
cannot import the foreign drives. Only unlocked drives can be imported when security
is disabled.
After you enable the security, you can import the locked drives. To import the locked
drives, you must provide the security key used to secure them. Verify whether any
drives are left to import as the locked drives can use different security keys. If there are
any drives left, repeat the import process for the remaining drives. After all of the drives
are imported, there is no configuration to import.
3.5
Instant Secure Erase
Instant Secure Erase is a feature used to erase data from encrypted drives. After the
initial investment for an encrypted disk, there is no additional cost in dollars or time to
erase data using the Instant Secure Erase feature.
You can change the encryption key for all MegaRAID RAID controllers that are
connected to encrypted drives. All encrypted drives, whether locked or unlocked,
always have an encryption key. This key is set by the drive and is always active. When
the drive is unlocked, the data to host from the drive (on reads) and from the host to
the drive cache (on writes) is always provided. However, when resting on the drive
platters, the data is always encrypted by the drive.
You might not want to lock your drives because you have to manage a password if they
are locked. Even if you do not lock the drives, there is still a benefit to using encrypted
disks.
If you are concerned about data theft or other security issues, you might already invest
in drive disposal costs, and there are benefits to using SafeStore encryption over other
technologies that exists today, both in terms of the security provided and time saved.