Brocade Communications Systems Brocade 8/12c Administrator's Manual page 263

Supporting hp secure key manager (skm) environments and hp enterprise secure key manager (eskm) environments
Hide thumbs Also See for Brocade 8/12c:
Table of Contents

Advertisement

14. Check the encryption engine state using following command to ensure encryption engine is
15. Export the KAC CSR from the new node and sign the CSR from the HP SKM/ESKM Local CA.
16. Import the signed CSR/Certificate onto the new node.
17. Register back the signed KAC CSR/Certificate onto the new node.
18. Register the new node KAC Certificate with the HP SKM/ESKM appliances and create a
19. Create the username and password on the new node same as created on the HP SKM/ESKM
20. In the case where the new node is single node encryption group, register the HP SKM/ESKM
21. If a master key is not present, restore the master key from a backed up copy. Procedures will
22. Set the defzone as allaccess on the new Brocade Encryption Switch, so the configuration from
23. Run the following command on the new Brocade Encryption Switch:
24. Connect the FC Cables to the new Brocade Encryption Switch.
25. Run the cfgsave command on any switch in that fabric. The fabric configuration from the
26. If the previous uploaded configuration is available, run the following command on the new
27. Issue commit.
Fabric OS Encryption Administrator's Guide
53-1002159-03
online:
cryptocfg --show -localEE
cryptocfg --reg -KACcert
username and password for this node on the HP SKM/ESKM appliances under the group
"Brocade."
appliances using the following command:
cryptocfg --reg -KACLogin
appliances IP and CA Certificate onto this node.
differ depending on the backup media used (from recovery smart cards, from the key vault,
from a file on the network or a file on a USB-attached device).
Fabric is pushed to new Brocade Encryption Switch.
cfgsave
existing fabric is merged into the new Brocade Encryption Switch. Verify that defzone is now set
as no access.
Brocade Encryption Switch to transfer the ownership of containers to the new Brocade
Encryption Switch:
cryptocfg --replace <old node WWN> <new node WWN>
If the uploaded configuration is not available, you must re-create the container.
cryptocfg --commit
BES removal and replacement
6
243

Advertisement

Table of Contents
loading

This manual is also suitable for:

Fabric os encryption

Table of Contents