Supported Encryption Key Manager Appliances - Brocade Communications Systems StoreFabric SN6500B User Manual

Brocade network advisor san user manual v12.0.0 (53-1002696-01, march 2013)
Hide thumbs Also See for StoreFabric SN6500B:
Table of Contents

Advertisement

20

Supported encryption key manager appliances

HA support should be set before you register the key vault. Three settings are supported; however,
certain settings are determined by the compliant key vault type that is being used:
Username authentication can be defined after TLS connectivity to a client device is requested.
Three modes are available:
The TLS certificates used between the Fabric OS encryption switch and the key vault are be either
Self -Signed or CA Signed.
Table 66
TABLE 66
IP
Key vault type
TKLM
TEKA
ESKM/SKM
DPM
1.
Supported encryption key manager appliances
As stated under
must be connected on the same LAN as the management port of the encryption switches, or of the
Backbone Chassis Control Processors (CPs) in the case of the encryption blade.
Secure communication between encryption nodes in an encryption group, and between encryption
nodes and key manager appliances requires an exchange of certificates that are used for mutual
authentication. Each supported key manager appliance has unique requirements for setting up a
secure connection and exchanging certificates.
542
Transparent: The client assumes the entire HA is implemented on the key vault. Key archival
and retrieval is performed without any additional hardening checks.
Opaque: The primary and secondary key vaults are both registered on the Fabric OS encryption
switch. The client archives the key to a single (primary) key vault. For disk operations, an
additional hardening check is done on the secondary key vault before the key is used for
encryption.
None: If no HA is selected, the primary and secondary key vaults are both registered on the
Fabric OS encryption switch. The client archives keys to both key vaults and ensures that the
archival succeeds before the key is used for encryption.
User Name: Only a user name is required to identify the client device.
User Name and Password: Both a user name and a password are required to identify the client
device.
None: No authentication is required.
identifies the supported KMIP key vault configurations and certificate formats.
KMIP key vault configurations and certificate formats
HA mode
No HA
No HA
HA Opaque
HA Transparent with IPLB
HA Opaque without IPLB
IPLB = IP Load Balancer.
"Network connections"
KAC certificate
Self signed
CA signed
CA signed
CA signed
1
CA signed
on page 539, a supported key management appliance
Brocade Network Advisor SAN User Manual
Username
Certificate
authentication
format
after TLS
No
DER
No
PEM
No
PEM
No
PEM
53-1002696-01

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Brocade network advisor 12.0.0

Table of Contents