Encryption user privileges – Brocade Network Advisor SAN + IP User Manual v12.3.0 User Manual
Page 1049
Brocade Network Advisor SAN + IP User Manual
977
53-1003155-01
Encryption user privileges
25
•
on page 989 describes the steps for interconnecting encryption
switches or blades in an encryption group through a dedicated LAN. This must be done before
the encryption engines are enabled. Security parameters and certificates cannot be
exchanged if these links are not configured and active.
•
“Encryption node initialization and certificate generation”
on page 990 lists the security
parameters and certificates that are generated when an encryption node is initialized.
•
“Supported encryption key manager appliances”
on page 994 lists the supported key manager
appliances, and lists topics that provide additional detail.
Encryption user privileges
In the Management application, resource groups are assigned privileges, roles, and fabrics.
Privileges are not directly assigned to users; users get privileges because they belong to a role in a
resource group. A user can only belong to one resource group at a time.
The Management application provides three pre-configured roles:
•
Storage encryption configuration
•
Storage encryption key operations
•
Storage encryption security
lists the associated roles and their read/write access to specific operations. The
functions are enabled from the Encryption Center dialog box:
TABLE 110
Encryption privileges
Privilege
Read/Write
Storage Encryption
Configuration
•
Launch the Encryption center dialog box.
•
View switch, group, or engine properties.
•
View the Encryption Group Properties Security tab.
•
View encryption targets, hosts, and LUNs.
•
View LUN centric view
•
View all rekey sessions
•
Add/remove paths and edit LUN configuration on LUN centric view
•
Rebalance encryption engines.
•
Clear tape LUN statistics
•
Create a new encryption group or add a switch to an existing encryption group.
•
Edit group engine properties (except for the Security tab)
•
Add targets.
•
Select encryption targets and LUNs to be encrypted or edit LUN encryption settings.
•
Edit encryption target hosts configuration.
•
Show tape LUN statistics.
Storage Encryption Key
Operations
•
Launch the Encryption center dialog box.
•
View switch, group, or engine properties,
•
View the Encryption Group Properties Security tab.
•
View encryption targets, hosts, and LUNs.
•
View LUN centric view.
•
View all rekey sessions.
•
Initiate manual rekeying of all disk LUNs.
•
Initiate refresh DEK.
•
Enable and disable an encryption engine.
•
Decommission LUNs.
•
Zeroize an encryption engine.
•
Restore a master key.
•
Edit key vault credentials.
•
Show tape LUN statistics.