Brocade Communications Systems StoreFabric SN6500B User Manual page 644

Brocade network advisor san user manual v12.0.0 (53-1002696-01, march 2013)
Hide thumbs Also See for StoreFabric SN6500B:
Table of Contents

Advertisement

20
Creating a new encryption group
596
Using this dialog box, you can select a key vault for the encryption group that contains the
selected switch. Prior to selecting your Key Vault Type, the selection is shown as None. The
dialog box contains the following information:
Key Vault Type:
If an encryption group contains mixed firmware nodes, the Encryption Group Properties
Key Vault Type name is based on the firmware version of the group leader.
Options are:
NetApp Lifetime Key Manager (LKM): The NetApp KeySecure Key Vault Type name is
shown as NetApp Lifetime Key Manager (LKM) for both NetApp Lifetime Key Manager
(LKM) and SafeNet KeySecure for Key Management (SSKM) Key Vault Types.
RSA Data Protection Manager (DPM): If an encryption group contains mixed firmware
nodes, the Encryption Group Properties Key Vault Type name is based on the firmware
version of the group leader. For example, If a switch is running Fabric OS 7.1.0 or later,
the Key Vault Type is displayed as "RSA Data Protection Manager (DPM)."If a switch is
running a Fabric OS version prior to v7.1.0, Key Vault Type is displayed as "RSA Key
Manager (RKM)".
HP Secure Key Manager (SKM): The HP Key Vault Type name is shown as HP Secure
Key Manager (SKM) for both SKM and Enterprise Secure Key Management (ESKM)
Key Vault Types.
Thales e-Security keyAuthority (TEKA): If an encryption group contains mixed firmware
nodes, the Encryption Group Properties Key Vault Type name is based on the firmware
version of the group leader. For example, If a switch is running Fabric OS 7.1.0 or later,
the Key Vault Type is displayed as "Thales e-Security keyAuthority (TEKA)."If a switch is
running a Fabric OS version prior to v7.1.0, Key Vault Type is displayed as "Thales Key
Manager (TEMS)".
Tivoli Key Lifecycle Manager (TKLM)
Key Management Interoperability Protocol (KMIP): Any KMIP-compliant server can be
registered as a key vault on the Fabric OS encryption switch after setting the key vault
type to KMIP.
Currently, only KMIP with SafeNet KeySecure for key management (SSKM) native
hosting LKM is supported.
Before selecting KMIP as the key vault type, all nodes in an encryption group must be
running Fabric OS 7.1.0 or later.
Primary Key Vault: The primary key vault name, either an IPv4 address or Host name.
Primary Certificate File: The name of a file containing the key vault's public key certificate.
This file can be generated from the key vault's administrative console.
User Name: The key vault user name. This field is active for ESKM/SKM and TEKA key
vaults. For ESKM/SKM, it is needed only for the primary key vault. For TEKA, it is needed
only for the secondary key vault.
Password: The key vault password. This field is active for ESKM/SKM and TEKA key vaults.
For ESKM/SKM, it is needed only for the primary key vault. For TEKA, it is needed for both
the primary and secondary key vaults.
Re-type Password: Re-enter the password for verification.
Backup Key Vault: Optional. The secondary key vault, either an IPv4 address or Host name.
The backup address can be left blank.
Brocade Network Advisor SAN User Manual
53-1002696-01

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Brocade network advisor 12.0.0

Table of Contents