Encryption user privileges – Brocade Network Advisor SAN User Manual v12.3.0 User Manual

Page 747

Advertising
background image

Brocade Network Advisor SAN User Manual

695

53-1003154-01

Encryption user privileges

20

“Blade processor links”

on page 707 describes the steps for interconnecting encryption

switches or blades in an encryption group through a dedicated LAN. This must be done before
the encryption engines are enabled. Security parameters and certificates cannot be
exchanged if these links are not configured and active.

“Encryption node initialization and certificate generation”

on page 708 lists the security

parameters and certificates that are generated when an encryption node is initialized.

“Supported encryption key manager appliances”

on page 712 lists the supported key manager

appliances, and lists topics that provide additional detail.

Encryption user privileges

In the Management application, resource groups are assigned privileges, roles, and fabrics.
Privileges are not directly assigned to users; users get privileges because they belong to a role in a
resource group. A user can only belong to one resource group at a time.

The Management application provides three pre-configured roles:

Storage encryption configuration

Storage encryption key operations

Storage encryption security

Table 66

lists the associated roles and their read/write access to specific operations. The functions

are enabled from the Encryption Center dialog box:

TABLE 66

Encryption privileges

Privilege

Read/Write

Storage Encryption
Configuration

Launch the Encryption center dialog box.

View switch, group, or engine properties.

View the Encryption Group Properties Security tab.

View encryption targets, hosts, and LUNs.

View LUN centric view

View all rekey sessions

Add/remove paths and edit LUN configuration on LUN centric view

Rebalance encryption engines.

Clear tape LUN statistics

Create a new encryption group or add a switch to an existing encryption group.

Edit group engine properties (except for the Security tab)

Add targets.

Select encryption targets and LUNs to be encrypted or edit LUN encryption settings.

Edit encryption target hosts configuration.

Show tape LUN statistics.

Storage Encryption Key
Operations

Launch the Encryption center dialog box.

View switch, group, or engine properties,

View the Encryption Group Properties Security tab.

View encryption targets, hosts, and LUNs.

View LUN centric view.

View all rekey sessions.

Initiate manual rekeying of all disk LUNs.

Initiate refresh DEK.

Enable and disable an encryption engine.

Decommission LUNs.

Zeroize an encryption engine.

Restore a master key.

Edit key vault credentials.

Show tape LUN statistics.

Advertising