Encryption Commands And Permissions - Brocade Communications Systems Brocade 8/12c Command Reference Manual

Brocade fabric os command reference manual supporting fabric os v7.0.0 (april 2011)
Hide thumbs Also See for Brocade 8/12c:
Table of Contents

Advertisement

A

Encryption commands and permissions

4. Virtual Fabric availability: If Virtual Fabrics are enabled, commands are checked for context
5. Command-specific: checks whether the command is supported on the platform for which it is
Encryption commands and permissions
There are two system RBAC roles that are permitted to perform Encryption operations.
1.
2.
Refer to
1082
AD0Only = Allowed to execute only in AD0 when ADs are not configured.
and switch type as follows:
Virtual Fabric context (VF) = Command applies to the current logical switch only, or to a
specified logical switch.
Virtual Fabric commands are further constrained by one of the following switch types:
All Switches (All) = Command can be run in any switch context.
Base Switch (BS) = Command can be run only on the base switch
Default Switch ((DS) = Command can be run only in default switch
N/A = Switch Type is not applicable to the command.
Chassis context (CH)= Command applies to the chassis on which it is executed.
Switch and Chassis context (VF/CH) = Command applies to the switch and the chassis.
Disallowed = Command can not be executed when Virtual Fabrics are enabled.
targeted.
Admin and SecurityAdmin
Users authenticated with the Admin and SecurityAdmin RBAC roles may perform cryptographic
functions assigned to the FIPS Crypto Officer including the following:
-
Perform encryption node initialization.
-
Enable cryptographic operations.
-
Manage critical security parameters (CSP) input/output functions.
-
Zeroize encryption CSPs.
-
Register and configure a key vault.
-
Configure a recovery share policy.
-
Create and register recovery share.
-
Encryption group- and clustering-related operations.
-
Manage keys, including creation, recovery, and archiving functions.
Admin and FabricAdmin
Users authenticated with the Admin and FabricAdmin RBAC roles may perform routine encryption
switch management functions including the following:
-
Configure virtual devices & crypto LUN.
-
Configure LUN/tape associations.
-
Perform re-keying operations.
-
Perform firmware download.
-
Perform regular Fabric OS management functions.
Table 7
for the RBAC permissions of the encryption configuration commands.
Fabric OS Command Reference
53-1002147-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

Fabric os v7.0.0

Table of Contents