HP Brocade 8/12c Fabric OS Encryption Administrator's Guide - Page 102

Saving a master key to a smart card set

Page 102 highlights

2 Master keys Saving a master key to a smart card set A card reader must be attached to the SAN Management application PC to complete this procedure. Recovery cards can only be written once to back up a single master key. Each master key backup operation requires a new set of previously unused smart cards. NOTE Windows operating systems do not require smart card drivers to be installed separately; the driver is bundled with the operating system. However, you must install a smart card driver for Unix operating systems. For instructions, refer to the Installation Guide. The key is divided among the cards in the card set, up to 10. The quorum of cards required to restore the master key must be less than the total number of cards in the set, and no greater than five. For example, when the master key is backed up to a set of three cards, a quorum of any two cards can be used together to restore the master key. When the master key is backed up to a set of 10 cards, a quorum size of up to 5 cards can be configured for restoring the master key.. Backing up the master key to multiple recovery cards is the recommended and most secure option. NOTE When you write the key to the card set, be sure you write the full set without canceling. If you cancel, all previously written cards become unusable, and you will need to discard them and create a new set. 1. Select Configure > Encryption from the menu task bar. The Encryption Center dialog box displays. 2. Select a group from the Encryption Center Devices table, then select Group > Security from the menu task bar, or right-click a group and select Security. The Encryption Group Properties dialog box displays with the Security tab selected. 3. Select Backup Master Key as the Master Key Action. The Backup Master Key for Encryption Group dialog box displays. 82 Fabric OS Encryption Administrator's Guide 53-1002159-03

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282

82
Fabric OS Encryption Administrator’s Guide
53-1002159-03
Master keys
2
Saving a master key to a smart card set
A card reader must be attached to the SAN Management application PC to complete this
procedure. Recovery cards can only be written once to back up a single master key. Each master
key backup operation requires a new set of previously unused smart cards.
NOTE
Windows operating systems do not require smart card drivers to be installed separately; the driver
is bundled with the operating system. However, you must install a smart card driver for Unix
operating systems. For instructions, refer to the
Installation Guide
.
The key is divided among the cards in the card set, up to 10. The quorum of cards required to
restore the master key must be less than the total number of cards in the set, and no greater than
five. For example, when the master key is backed up to a set of three cards, a quorum of any two
cards can be used together to restore the master key. When the master key is backed up to a set of
10 cards, a quorum size of up to 5 cards can be configured for restoring the master key.. Backing
up the master key to multiple recovery cards is the recommended and most secure option.
NOTE
When you write the key to the card set, be sure you write the full set without canceling. If you cancel,
all previously written cards become unusable, and you will need to discard them and create a new
set.
1.
Select
Configure > Encryption
from the menu task bar.
The
Encryption Center
dialog box displays.
2.
Select a group from the
Encryption Center Devices
table, then select
Group > Security
from the
menu task bar, or right-click a group and select
Security
.
The
Encryption Group Properties
dialog box displays with the
Security
tab selected.
3.
Select
Backup Master Key
as the
Master Key Action
.
The
Backup Master Key for Encryption Group
dialog box displays.