Brocade Communications Systems Brocade 8/12c Administrator's Manual page 238

Supporting hp secure key manager (skm) environments and hp enterprise secure key manager (eskm) environments
Hide thumbs Also See for Brocade 8/12c:
Table of Contents

Advertisement

6
Encryption group merge and split use cases
Given that you may have up to four nodes per encryption group, an EG split may leave you with any
of the following possible EG split combinations:
EG split manual recovery steps
Regardless of which particular EG Split combination occurs, the recovery procedure is the same.
The following recovery procedures make the following assumptions:
To re-converge the EG, you will need to perform a series of steps. The following is a listing of the
basic steps involved - this listing is followed by an example with the details of each step:
1. Confirm that your EG is not in a CONVERGED state.
2. Determine which GL Node will remain the GL Node once the EG is re-converged.
3. Use the selected EG island's GL Node to deregister every node that is not in a DISCOVERED
4. Go to every other EG island and delete the associated EG.
5. Re-register all Nodes from that were a part of the other EG islands.
6. Verify your EG is re-converged.
218
Two node EG split - resulting in two single node encryption groups. Each node is a group leader
node.
Three node EG split - resulting in one of two outcomes:
-
A two node encryption group with a single group leader node, and one single node
encryption group where the node is a group leader.
-
Three single Node EGs, each of which is a group leader.
Four node EG split - resulting in one of three outcomes:
-
One three node encryption group with a single group leader, and one single node
encryption group where the node is a group leader.
-
A pair of two node encryption groups, with each encryption group having its own group
leader.
-
Four single node encryption groups. Each node is a group leader.
The networking issues that caused the EG split have been resolved.
The output of the cryptocfg
status as being DEGRADED.
NOTE
If one or more EG status displays as CONVERGED contact technical support as the following
procedure will not work.
It is recommended to pick the GL from the largest EG island that exists (i.e. if you EG islands do
not all have the same number of members). For example, if you have an EG island with 3
Nodes and another EG island with just 1 Node, pick the GL from the 3 Node EG island.
state.
NOTE
One additional step is needed here when a four node encryption group splits into a pair of two
node encryption groups, with each encryption group having its own group leader. This single
special case is addressed in the
show -groupcfg command on every EG island shows the EG
--
"Two node EG split manual recovery
example".
Fabric OS Encryption Administrator's Guide
53-1002159-03

Advertisement

Table of Contents
loading

This manual is also suitable for:

Fabric os encryption

Table of Contents