Master Keys; Active Master Key; Alternate Master Key - Brocade Communications Systems Brocade 8/12c User Manual

Brocade network advisor san user manual v11.1x (53-1002167-01, may 2011)
Hide thumbs Also See for Brocade 8/12c:
Table of Contents

Advertisement

18

Master keys

Master keys
When an opaque key vault is used, a master key is used to encrypt the data encryption keys. The
master key status indicates whether a master key is used and whether it has been backed up.
Encryption is not allowed until the master key has been backed up.
Only the active master key can be backed up, and multiple backups are recommended. You can
back up or restore the master key to the key vault, to a file, or to a recovery card set. A recovery
card set is set of smart cards. Each recovery card holds a portion of the master key. The cards must
be gathered and read together from a card reader attached to a PC running the Management
application to restore the master key.
Master keys belong to the group and are managed from Group Properties.
NOTE
It is important to back up the master key because if the master key is lost, none of the data
encryption keys can be restored and none of the encrypted data can be decrypted.
For more information, see the following topics:

Active master key

The active master key is used to encrypt newly created data encryption keys (DEKs) prior to sending
them to a key vault to be stored. You can restore the active master key under the following
conditions:

Alternate master key

The alternate master key is used to decrypt data encryption keys that were not encrypted with the
active master key. Restore the alternate master key for the following reasons:
540
"Active master key"
on page 540
"Alternate master key"
on page 540
"Master key actions"
on page 541
"Reasons master keys can be disabled"
The active master key has been lost, which happens if all encryption engines in the group have
been zeroized or replaced with new hardware at the same time.
You want multiple encryption groups to share the same active master key. Groups should share
the same master key if the groups share the same key vault and if tapes (or disks) are going to
be exchanged regularly between the groups.
To read an old tape that was created when the group used a different active master key.
To read a tape (or disk) from a different encryption group that uses a different active master
key.
on page 541
Brocade Network Advisor SAN User Manual
53-1002167-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

Network advisor 11.1.xBrocade bladesystem 4/24

Table of Contents