Enabling the encryption engine, Checking encryption engine status – Brocade Fabric OS Encryption Administrator’s Guide Supporting RSA Data Protection Manager (DPM) Environments (Supporting Fabric OS v7.2.0) User Manual

Page 176

Advertising
background image

156

Fabric OS Encryption Administrator’s Guide (DPM)

53-1002922-01

Enabling the encryption engine

3

Enabling the encryption engine

Enable the encryption engine by entering the cryptocfg

--

enableEE command. Provide a slot

number if the encryption engine is a blade.

NOTE

Every time a Brocade Encryption Switch or DCX Backbone chassis containing one or more FS8-18
blades goes through a power cycle event, or after issuing slotpoweroff <slot number> followed by
slotpoweron <slot number> for an FS8-18 blade in the DCX Backbone chassis, the encryption
engine must be enabled manually by the Security Administrator. Hosts cannot access the storage
LUNs through the storage paths exposed on this Brocade Encryption Switch or FS8-18 blade until
the encryption engine is enabled. The encryption engine state can viewed using the cryptocfg

--

show

-

localEE command, or by displaying switch or blade properties from DFCM. An encryption

engine that is not enabled indicates Waiting for Enable EE.

SecurityAdmin:switch> cryptocfg --enableEE

Operation succeeded.

Checking encryption engine status

You can verify the encryption engine status at any point in the setup process and get information
about the next required configuration steps or to troubleshoot an encryption engine that behaves in
unexpected ways. Use the cryptocfg

--

show

-

localEE command to check the encryption engine

status.

SecurityAdmin:switch> cryptocfg --show -localEE

EE Slot: 0

SP state: Waiting for initEE

EE key status not available: SP TLS connection is not up.

No HA cluster membership

EE Slot: 1

SP state: Online

Current Master KeyID:

a3:d7:57:c7:54:66:65:05:61:7a:35:2c:59:af:a5:dc

Alternate Master KeyID:

e9:e4:3a:f8:bc:4e:75:44:81:35:b8:90:d0:1f:6f:4d

HA Cluster Membership: hacDcx2

EE Attributes:

Media Type : DISK

EE Slot: 3

SP state: Online

Current Master KeyID:

a3:d7:57:c7:54:66:65:05:61:7a:35:2c:59:af:a5:dc

Alternate Master KeyID:

e9:e4:3a:f8:bc:4e:75:44:81:35:b8:90:d0:1f:6f:4d

No HA cluster membership

EE Attributes:

Media Type : DISK

EE Slot: 10

SP state: Online

Current Master KeyID:

a3:d7:57:c7:54:66:65:05:61:7a:35:2c:59:af:a5:dc

Alternate Master KeyID:

e9:e4:3a:f8:bc:4e:75:44:81:35:b8:90:d0:1f:6f:4d

Advertising