Setting encryption node initialization, Steps for connecting to a dpm appliance – Brocade Fabric OS Encryption Administrator’s Guide Supporting RSA Data Protection Manager (DPM) Environments (Supporting Fabric OS v7.2.0) User Manual

Page 49

Advertising
background image

Fabric OS Encryption Administrator’s Guide (DPM)

29

53-1002922-01

Steps for connecting to a DPM appliance

2

Setting encryption node initialization

Encryption nodes are initialized by the Configure Switch Encryption wizard when you confirm a
configuration. Encryption nodes may also be initialized from the Encryption Center dialog box.

1. Select a switch from the Encryption Center Devices table, then select Switch > Init Node from

the menu task bar.

2. Select Yes after reading the warning message to initialize the node.

Steps for connecting to a DPM appliance

All switches that you plan to include in an encryption group must have a secure connection to the
RSA Data Protection Manager (DPM). The following is a suggested order of steps needed to create
a secure connection to the DPM.

NOTE

The Brocade Encryption Switch uses the manual enrollment of identities with client registration to
connect with DPM 3.x servers. Client registration is done automatically when you upgrade to
Fabric 7.1.0 from an earlier Fabric OS version; no user interaction is required.

Once completed, client registration occurs after key vault registration, when the Brocade
Encryption Switch attempts to connect to the DPM server for the first time.

1. Export the KAC CSR to a location accessible to a CA for signing. Refer to

“Exporting the KAC

certificate signing request (CSR)”

on page 30.

2. Submit the KAC CSR for signing by a CA. Refer to

“Submitting the CSR to a certificate authority”

on page 30.

3. Set the KAC certificate registration expiry. Refer to

“KAC certificate registration expiry”

on

page 31.

4. Import the signed certificate into the Fabric OS encryption node. Refer to

“Importing the signed

KAC certificate”

on page 31.

5. Upload the signed KAC and CA certificates onto the DPM appliance and select the appropriate

key classes. Refer to the following:

“Uploading the CA certificate onto the DPM appliance (and first-time configurations)”

on

page 32

“Uploading the KAC certificate onto the DPM appliance (manual identity enrollment)”

on

page 33

6. If dual DPM appliances are used for high availability, the DPM appliances must be clustered,

and must operate in maximum availability mode, as described in the DPM appliance user
documentation. Refer to

“DPM key vault high availability deployment”

on page 33.

Advertising