beautypg.com

B. encryption group configuration – Dell POWEREDGE M1000E User Manual

Page 217

background image

Fabric OS Command Reference

185

53-1001764-02

cryptoCfg

2

Remote EE Reachability :

Node WWN/Slot EE IP Addr EE State IO Link State

10:00:00:05:1e:54:22:36/0 10.32.72.62 EE_STATE_ONLINE Reachable

10:00:00:05:1e:47:30:00/1 10.32.72.104 EE_STATE_ONLINE Reachable

10:00:00:05:1e:47:30:00/3 10.32.72.105 EE_STATE_ONLINE Reachable

10:00:00:05:1e:47:30:00/10 10.32.72.106 EE_STATE_ONLINE Reachable

10:00:00:05:1e:47:30:00/12 10.32.72.107 EE_STATE_ONLINE Reachable

(output truncated)

To rebalance load between tape and disk LUNS for optimal performance on slot 1:

switch:admin>

cryptocfg --rebalance 1

Rebalancing the EE may cause disruption to disk I/Os.Backup applications to

tapes may need to be restarted after rebalance.

ARE YOU SURE (yes, y, no, n): [no] yes

Operation succeeded

switch:admin>

B. Encryption group configuration
To create an encryption group “brocade”:

SecurityAdmin:switch>

cryptocfg --create -encgroup brocade

Encryption group create status: Operation Succeeded.

To delete the encryption group “brocade”:

SecurityAdmin:switch>

cryptocfg --delete -encgroup brocade

Encryption group create status: Operation Succeeded.

To register a NetApp LKM appliance as the primary key vault "LKM1":

SecurityAdmin:switch>

cryptocfg --reg -regkeyvault LKM1 lkmcert.pem 10.33.54.231 primary

decru-lkm-1

Register key vault status: Operation Succeeded.

To set the key vault type to LKM:

SecurityAdmin:switch>

cryptocfg --set -keyvault LKM

Set key vault status: Operation Succeeded.

To add a member node to the encryption group:

SecurityAdmin:switch>

cryptocfg --add -membernode 10:00:00:05:1e:39:14:00

Add node status: Operation Succeeded.

To eject a member node from the encryption group:

SecurityAdmin:switch>

cryptocfg --eject -membernode 10:00:00:05:1e:53:b8:45

Eject node status: Operation Succeeded.

To leave the encryption group:

SecurityAdmin:switch>

cryptocfg --leave_encryption_group

Leave node status: Operation Succeeded.

To generate the master key (RKM) on the group leader:

SecurityAdmin:switch>

cryptocfg --genmasterkey