Deleting A Cryptotarget Container - Brocade Communications Systems Brocade 8/12c Administrator's Manual

Supporting hp secure key manager (skm) environments and hp enterprise secure key manager (eskm) environments
Hide thumbs Also See for Brocade 8/12c:
Table of Contents

Advertisement

3
CryptoTarget container configuration
switch and another path has direct access to the device from a host outside the protected realm
of the encryption platform. Refer to the section
page 166 for more information.

Deleting a CryptoTarget container

You may delete a CryptoTarget container to remove the target port from a given encryption switch
or blade. Deleting a CryptoTarget container removes the virtual target and all associated LUNs from
the fabric.
Before deleting a container, be aware of the following:
1. Log in to the group leader as Admin or FabricAdmin.
2. Enter the cryptocfg
3. Commit the transaction.
CAUTION
When configuring a multi-path LUN, you must remove all necessary CryptoTarget containers in
sequence before committing the transaction. Failure to do so may result in a potentially
catastrophic situation where one path ends up being exposed through the encryption switch and
another path has direct access to the device from a host outside the protected realm of the
encryption platform. Refer to the section
more information.
152
Stop all traffic to the target port for which the CryptoTarget container is being deleted. Failure
to do so will cause data corruption (a mix of encrypted data and cleartext data will be written to
the LUN).
Deleting a CryptoTarget container while a re-key or first-time encryption session causes all
data to be lost on the LUNs that are being re-keyed. Ensure that no re-key or first time
encryption sessions are in progress before deleting a container. Use the cryptocfg --show
-rekey -all command to determine the runtime status of the session. If for some reason, you
need to delete a container while re-keying, when you create a new container, be sure the LUNs
added to the container are set to cleartext. You can then start a new re-key session on clear
text LUNs.
delete -container command followed by the CryptoTarget container
--
name. The following example removes the CryptoTarget container "my_disk_tgt".
FabricAdmin:switch>cryptocfg --delete -container my_disk_tgt
Operation Succeeded
FabricAdmin:switch>cryptocfg --commit
Operation Succeeded
"Configuring a multi-path Crypto LUN"
"Configuring a multi-path Crypto LUN"
Fabric OS Encryption Administrator's Guide
on
on page 166 for
53-1002159-03

Advertisement

Table of Contents
loading

This manual is also suitable for:

Fabric os encryption

Table of Contents