Bes Removal And Replacement; Multi Node Eg Case - Brocade Communications Systems Brocade 8/12c Administrator's Manual

Supporting hp secure key manager (skm) environments and hp enterprise secure key manager (eskm) environments
Hide thumbs Also See for Brocade 8/12c:
Table of Contents

Advertisement

6

BES removal and replacement

7.
8. If a system card authentication is needed to enable the encryption engine, re-register the
9. Initialize the new encryption engine.
10. Register the new encryption engine.
11. Enable the new encryption engine.
12. Verify that this blade encryption engine has the same Master Key as rest of Encryption Engines
13. Check the encryption engine state using the cryptocfg
14. Check the encryption group state using the cryptocfg

BES removal and replacement

Multi Node EG Case

The following procedure uses Brocade Encryption Switch (BES) 3 as the BES to be removed from an
encryption group with the group leader designated as BES1. Two scenarios are considered:
When BES3 has failed, complete the following steps:
1. Deregister BES3 from the encryption group.
238
Zeroize the new encryption engine.
cryptocfg --zeroizeEE 4
The new encryption engine will power off and power on again automatically.
system card through the Management application client for the new encryption engine.
cryptocfg --initEE 4
cryptocfg --regEE 4
cryptocfg --enableEE 4
in the Encryption Group using the cryptocfg
that the encryption engine is online.
that entire encryption group is in the converged and In Sync states.
NOTE
Because the FS8-18 blade was inserted to the same slot as the previous one, no change of
HAC container ownership is required. The HAC configuration is retained as is. If manual
failback was set on the HAC, then user intervention is required to manually failback the LUNs
owned by the newly replaced encryption engine. There is no change in crypto-target container
ownership. The container ownerships are retained as is.
When the Brocade Encryption Switch has failed
When the Brocade Encryption Switch has not failed
cryptocfg –-dereg –membernode <switchWWN>
show -groupmember -all command.
--
show -localEE command to ensure
--
show -groupcfg command to ensure
--
Fabric OS Encryption Administrator's Guide
53-1002159-03

Advertisement

Table of Contents
loading

This manual is also suitable for:

Fabric os encryption

Table of Contents