Brocade Communications Systems Brocade 8/12c Administrator's Manual page 227

Supporting hp secure key manager (skm) environments and hp enterprise secure key manager (eskm) environments
Hide thumbs Also See for Brocade 8/12c:
Table of Contents

Advertisement

3. Determine the state of the node. Log in to the member node and enter the cryptocfg
4. Reclaim the WWN of the member node.
5. On the group leader, enter the cryptocfg
6. Log in to the member node and execute the cryptocfg
Fabric OS Encryption Administrator's Guide
53-1002159-03
-groupmember command followed by the node WWN. Provide a slot number if the encryption
engine is a blade.
SecurityAdmin:switch>cryptocfg --show -groupmember \
10:00:00:05:1e:41:99:bc
Node Name:
State:
Role:
IP Address:
Certificate:
Current Master Key State:
Current Master KeyID:
b8:2a:a2:4f:c8:fd:12:e2:a9:25:d9:5b:58:2c:96:7e
Alternate Master Key State: Not configured
Alternate Master KeyID:
00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00
EE Slot:
SP state:
Current Master KeyID:
b8:2a:a2:4f:c8:fd:12:e2:a9:25:d9:5b:58:2c:96:7e
Alternate Master KeyID:
00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00
No HA cluster membership
a. If the node is in the DISCOVERED state and the security processor (SP) state is online (as
shown above), you can remove the node from the encryption group. Complete step 4 and
step 5, which completes the procedure.
b. If the node is not in the DISCOVERED state, and you wish to remove the node from the
encryption group, you must first deregister the node. To do this, log in to the group leader
and enter the cryptocfg
SecurityAdmin:switch>cryptocfg --dereg -membernode 10:00:00:05:1e:41:99:bc
Operation succeeded.
a. Enter the cryptocfg
--
leader to reclaim the VI/VT WWN base for node to be removed.
When prompted, enter yes.
b. Enter the cryptocfg
--
all nodes in the encryption group:
WWN.
SecurityAdmin:switch> cryptocfg --eject -membernode 10:00:00
:05:1e:55:3a:f0
WARNING: Before ejecting the membernode, ensure that the VI/VT WWN's
are reclaimed.
Refer to "cryptocfg --reclaimWWN" commands.
ARE YOU SURE
(yes, y, no, n): [no] Node eject granted by protocol clients
[10:00:00:05:1e:55:3a:f0]
Eject node status: Operation Succeeded.
Encryption group and HA cluster maintenance
10:00:00:05:1e:41:99:bc
DEF_NODE_STATE_DISCOVERED
MemberNode
10.32.33.145
10.32.33.145_my_cp_cert.pem
Saved
0
Online
dereg -membernode command followed by the node WWN.
--
reclaimWWN -membernode <node-WWN> command on the group
commit command on the group leader to propagate the change to
eject -membernode command followed by the node
--
(current node)
reclaimWWN -cleanup command.
--
6
show
--
207

Advertisement

Table of Contents
loading

This manual is also suitable for:

Fabric os encryption

Table of Contents