Restrictions; Using Self-Encrypting Disks; Taking Ownership - HP 3PAR StoreServ 7200 2-node Administrator's Manual

Hp 3par command line interface administrator's manual: hp 3par os 3.1.2 (qr482-96525, september 2013)
Hide thumbs Also See for 3PAR StoreServ 7200 2-node:
Table of Contents

Advertisement

To view the license using the HP 3PAR CLI, issue the showlicense command:
cli%showlicense
License key was generated on Thu May 23 16:29:37 2013
License features currently enabled:
...
Data Encryption
...
To view the license using the HP 3PAR MC, navigate to the Software tab.

Restrictions

These restrictions apply to the first release of data encryption (HP 3PAR OS 3.1.2 MU2):
Data encryption is available only with the purchase of a new HP 3PAR StoreServ system.
Data encryption cannot be enabled on an HP StoreServ storage system earlier than HP 3PAR
OS 3.1.2 MU2.
Data encryption is not supported on any HP 3PAR encrypted storage array with mixed
configurations of SEDs and non-SEDs; the array must contain only SEDs.
A single authentication key is used to unlock all the drives in the array for reading and writing
to media.
Authentication keys are managed using a local key manager (LKM) in the storage system.
The controlencryption commands (or GUI call) are recorded in the HP 3PAR OS eventlog,
but the filename and password contents are not. For example:
Time
Severity : Informational
Type
Message
enable_start <password > <secret>} {}
Message
status_details} {}
Message
rekey_finish} {}
A user with Super authority is responsible for physical security of a backup copy of the
authentication keys and for remembering the password.
Encryption should be enabled before writing data to the array. The system will function, and
the same data can be accessed before and after encryption is enabled, but it will not be
secure (no DAR) until encryption is enabled.

Using Self-encrypting Disks

Taking Ownership

Ownership means changing the authentication key and locking state of an SED from its default
settings, so that the data on the drive is secure.
To enable the SED, issue the admitpd [option] [<WWN>...] command. Options are:
-nold: Do not use the physical disk (as identifed by the WWN specifier) for LD allocation.
Specify the nold option when adding a physical disk to replace a failed disk whose chunklets
: 2013-05-28 13:52:20 PDT
: CLI command executed
: {3parsvc super all {{0 8}} -1 127.0.0.1 9534} {controlencryption
: {3paradm super all {{0 8}} -1 16.94.229.83 9706} {controlencryption
: {3paradm super all {{0 8}} -1 16.94.229.83 30353} {controlencryption
Restrictions
1 13

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents