B. encryption group configuration – Dell POWEREDGE M1000E User Manual
Page 217
Fabric OS Command Reference
185
53-1001764-02
cryptoCfg
2
Remote EE Reachability :
Node WWN/Slot EE IP Addr EE State IO Link State
10:00:00:05:1e:54:22:36/0 10.32.72.62 EE_STATE_ONLINE Reachable
10:00:00:05:1e:47:30:00/1 10.32.72.104 EE_STATE_ONLINE Reachable
10:00:00:05:1e:47:30:00/3 10.32.72.105 EE_STATE_ONLINE Reachable
10:00:00:05:1e:47:30:00/10 10.32.72.106 EE_STATE_ONLINE Reachable
10:00:00:05:1e:47:30:00/12 10.32.72.107 EE_STATE_ONLINE Reachable
(output truncated)
To rebalance load between tape and disk LUNS for optimal performance on slot 1:
switch:admin>
cryptocfg --rebalance 1
Rebalancing the EE may cause disruption to disk I/Os.Backup applications to
tapes may need to be restarted after rebalance.
ARE YOU SURE (yes, y, no, n): [no] yes
Operation succeeded
switch:admin>
B. Encryption group configuration
To create an encryption group “brocade”:
SecurityAdmin:switch>
cryptocfg --create -encgroup brocade
Encryption group create status: Operation Succeeded.
To delete the encryption group “brocade”:
SecurityAdmin:switch>
cryptocfg --delete -encgroup brocade
Encryption group create status: Operation Succeeded.
To register a NetApp LKM appliance as the primary key vault "LKM1":
SecurityAdmin:switch>
cryptocfg --reg -regkeyvault LKM1 lkmcert.pem 10.33.54.231 primary
decru-lkm-1
Register key vault status: Operation Succeeded.
To set the key vault type to LKM:
SecurityAdmin:switch>
cryptocfg --set -keyvault LKM
Set key vault status: Operation Succeeded.
To add a member node to the encryption group:
SecurityAdmin:switch>
cryptocfg --add -membernode 10:00:00:05:1e:39:14:00
Add node status: Operation Succeeded.
To eject a member node from the encryption group:
SecurityAdmin:switch>
cryptocfg --eject -membernode 10:00:00:05:1e:53:b8:45
Eject node status: Operation Succeeded.
To leave the encryption group:
SecurityAdmin:switch>
cryptocfg --leave_encryption_group
Leave node status: Operation Succeeded.
To generate the master key (RKM) on the group leader:
SecurityAdmin:switch>
cryptocfg --genmasterkey