HP Brocade 8/12c Fabric OS Encryption Administrator's Guide - Page 111

Redirection zones, Re-keying all disk LUNs manually

Page 111 highlights

Re-keying all disk LUNs manually 2 The Encryption Targets dialog box enables you to launch a variety of wizards and other related dialog boxes. Redirection zones It is recommended that you configure the host and target in the same zone before you configure them for encryption. Doing so creates a redirection zone to redirect the host/target traffic through the encryption engine; however, a redirection zone can only be created if the host and target are in the same zone. If the host and target are not already configured in the same zone, you can configure them for encryption, but you will still need to configure them in the same zone, which will then enable you to create the redirection zone as a separate step. NOTE If the encryption group is busy when you click Commit, you are given the option to either force the commit, or abort the changes. Click Commit to re-create the redirection zone. Re-keying all disk LUNs manually The encryption management application allows you to perform a manual rekey operation on all encrypted primary disk LUNs and all non-replicated disk LUNs hosted on the encryption node that are in the read-write state. Manual rekey of all LUNs might take an extended period of time. The management application allows manual rekey of no more than 10 LUNs concurrently. If the node has more than 10 LUNs, additional LUN rekey operations will remain in the pending state until others have finished. The following conditions must be satisfied for the manual re-key operation to run successfully: • The node on which you perform the manual rekey operation must be a member of an encryption group, and that encryption group must have a key vault configured. • The node must be running Fabric OS 7.0.0 or later. • The encryption group must be in the converged state. • The target container that hosts the LUN must be online. In addition to providing the ability to launch manual re-key operations, the management application also enables you to monitor their progress. To re-key all disk LUNs on an encryption node, complete the following steps: 1. Select Configure > Encryption from the menu task bar. The Encryption Center dialog box displays. 2. Select the switch on which to perform a manual re-key from the Encryption Center Devices table, then select Switch > Re-Key All from the menu task bar, or right-click the switch and select Re-Key All. Fabric OS Encryption Administrator's Guide 91 53-1002159-03

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282

Fabric OS Encryption Administrator’s Guide
91
53-1002159-03
Re-keying all disk LUNs manually
2
The
Encryption Targets
dialog box enables you to launch a variety of wizards and other related
dialog boxes.
Redirection zones
It is recommended that you configure the host and target in the same zone
before
you configure
them for encryption. Doing so creates a redirection zone to redirect the host/target traffic through
the encryption engine; however, a redirection zone can only be created if the host and target are in
the same zone. If the host and target are not already configured in the same zone, you can
configure them for encryption, but you will still need to configure them in the same zone, which will
then enable you to create the redirection zone as a separate step.
NOTE
If the encryption group is busy when you click
Commit
, you are given the option to either force the
commit, or abort the changes. Click
Commit
to re-create the redirection zone.
Re-keying all disk LUNs manually
The encryption management application allows you to perform a manual rekey operation on all
encrypted primary disk LUNs and all non-replicated disk LUNs hosted on the encryption node that
are in the read-write state.
Manual rekey of all LUNs might take an extended period of time. The management application
allows manual rekey of no more than 10 LUNs concurrently. If the node has more than 10 LUNs,
additional LUN rekey operations will remain in the pending state until others have finished.
The following conditions must be satisfied for the manual re-key operation to run successfully:
The node on which you perform the manual rekey operation must be a member of an
encryption group, and that encryption group must have a key vault configured.
The node must be running Fabric OS 7.0.0 or later.
The encryption group must be in the converged state.
The target container that hosts the LUN must be online.
In addition to providing the ability to launch manual re-key operations, the management application
also enables you to monitor their progress.
To re-key all disk LUNs on an encryption node, complete the following steps:
1.
Select
Configure > Encryption
from the menu task bar.
The
Encryption Center
dialog box displays.
2.
Select the switch on which to perform a manual re-key from the
Encryption Center Devices
table, then select
Switch > Re-Key All
from the menu task bar, or right-click the switch and
select
Re-Key All
.