Aborting A Pending Database Transaction; Key Vault Diagnostics - Brocade Communications Systems StoreFabric SN6500B Administrator's Manual

Brocade fabric os encryption administrator's guide v7.1.0 (53-1002721-01, march 2013)
Hide thumbs Also See for StoreFabric SN6500B:
Table of Contents

Advertisement

6

Key vault diagnostics

Aborting a pending database transaction

You can abort a pending database transaction for any device configurations invoked earlier through
the CLI or BNA interfaces by completing the following steps.
1. Use the
2. Use the

Key vault diagnostics

With the introduction of Fabric OS 7.0.0, you can run key vault diagnostics tests to identify any key
vault connectivity or key operation errors. You configure the key vault diagnostic test using the
cryptocfg
If an encryption switch is part of an EG, the diagnostic testing is performed on that switch only and
not the entire group. If multiple nodes in an encryption group have different Fabric OS versions,
only those nodes running Fabric OS 7.0.0 and later can be configured for periodic key vault
diagnostic testing.
You can set the diagnostic tests to run at regular intervals. When incidents occur, the findings are
collected in log reports. The first instance of a failure and subsequent restoration of operation is
reported as a Remote Access Server (RAS) log. Subsequent findings for the same incident are not
logged to avoid redundant messages.
Key vault connectivity
Key vault connectivity is adiagnostics feature that allows you to periodically collect information
about the state of key vault connectivity from the Brocade Encryption Switch and possible version,
configuration, or cluster information of the key vault (KV).
This feature reports the following types of configuration information:
322
transshow command to determine the currently pending transaction ID.
--
The
transshow command displays the pending database transaction for any device
--
configurations invoked earlier through the CLI or BNA interfaces. The command displays the
transaction status (completed or pending), the transaction ID, and the transaction owner (CLI
or BNA).
transabort <transaction_ID> command to abort the transaction, where
--
<transaction_ID> specifies the ID of the transaction to be aborted.
kvdiag command.
--
Key Vault/Cluster scope:
CA Certificate and its validity (for example, valid header and expiry date)
Key Vault IP/Port
KV firmware version
Time of day on the KV
Key class and format on the KV configured for the user group
Client session timeout
Encryption node scope
Node KAC certificate and its validity (for example, valid header and expiry date)
Username/password
User group
Fabric OS Encryption Administrator's Guide (SKM/ESKM)
53-1002721-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

Fabric os 7.1.0

Table of Contents