HP Brocade 8/12c Fabric OS Encryption Administrator's Guide - Page 40

Using authentication cards, Enabling or disabling the system card requirement

Page 40 highlights

2 Smart card usage Using authentication cards When a quorum of authentication cards is registered for use, an Authenticate dialog box is displayed to grant access to the following: • The Encryption Group Properties dialog box Link Keys tab (for NetApp LKM only). • The Encryption Group Properties dialog box Security tab, which provides access to the following: - Master Key Actions, which includes Backup Master Key, Restore Master Key, and Create Master Key. - System Cards radio buttons used to specify whether a system card is Required or Not Required. - Authentication Card Quorum Size selector. - Register from Card Reader, Register From Archive, and Deregister buttons. • The Master Key Backup dialog box. • The Master Key Restore dialog box. To authenticate using a quorum of authentication cards, complete the following steps: 1. When the Authenticate dialog box is displayed, gather the number of cards needed, per instructions in the dialog box. The currently registered cards and the assigned owners are listed in the table near the bottom of the dialog box. 2. Insert a card, then wait for the ID to appear in the Card ID field. 3. Enter the assigned password. 4. Click Authenticate. 5. Wait for the confirmation dialog box, then click OK. 6. Repeat step 2 through step 5 for each card until at least the quorum plus one is reached. 7. Click OK. Enabling or disabling the system card requirement To use a system card to control activation of an encryption engine on a switch, you must enable the system card requirement. You can use the following procedure to enable or disable the system card requirement. 1. Select an encryption group from the Encryption Center Devices table, then select Group > Security from the menu task bar, or right-click a group and select Security. The Encryption Group Properties dialog box displays, with the Security tab selected. 2. Do one of the following: • Set System Cards to Required to require the use of a system card for controlling activation of the encryption engine. Click OK after reading the message in the encryption message dialog box. • Set System Cards to Not Required to permit activation of the encryption engine without the need to read a system card first. 20 Fabric OS Encryption Administrator's Guide 53-1002159-03

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282

20
Fabric OS Encryption Administrator’s Guide
53-1002159-03
Smart card usage
2
Using authentication cards
When a quorum of authentication cards is registered for use, an
Authenticate
dialog box is
displayed to grant access to the following:
The
Encryption Group Properties
dialog box
Link Keys
tab (for NetApp LKM only).
The
Encryption Group Properties
dialog box
Security
tab, which provides access to the
following:
-
Master Key Actions
, which includes
Backup Master Key
,
Restore Master Key
, and
Create
Master Key
.
-
System Cards
radio buttons used to specify whether a system card is
Required
or
Not Required
.
-
Authentication Card Quorum Size
selector.
-
Register from Card Reader
,
Register From Archive
, and
Deregister
buttons.
The
Master Key Backup
dialog box.
The
Master Key Restore
dialog box.
To authenticate using a quorum of authentication cards, complete the following steps:
1.
When the
Authenticate
dialog box is displayed, gather the number of cards needed, per
instructions in the dialog box. The currently registered cards and the assigned owners are
listed in the table near the bottom of the dialog box.
2.
Insert a card, then wait for the ID to appear in the
Card ID
field.
3.
Enter the assigned password.
4.
Click
Authenticate
.
5.
Wait for the confirmation dialog box, then click
OK
.
6.
Repeat step 2 through step 5 for each card until at least the quorum plus one is reached.
7.
Click
OK
.
Enabling or disabling the system card requirement
To use a system card to control activation of an encryption engine on a switch, you must enable the
system card requirement. You can use the following procedure to enable or disable the system card
requirement.
1.
Select an encryption group from the
Encryption Center Devices
table, then select
Group >
Security
from the menu task bar, or right-click a group and select
Security
.
The
Encryption Group Properties
dialog box displays, with the
Security
tab selected.
2.
Do one of the following:
Set
System Cards
to
Required
to require the use of a system card for controlling activation
of the encryption engine. Click
OK
after reading the message in the encryption message
dialog box.
Set
System Cards
to
Not Required
to permit activation of the encryption engine without the
need to read a system card first.