Hp Secure Encryption Manuale Utente

Navigare online o scaricare Manuale Utente per Software Hp Secure Encryption. HP Secure Encryption User Manual Manuale Utente

  • Scaricare
  • Aggiungi ai miei manuali
  • Stampa
Vedere la pagina 0
HP Secure Encryption
Installation and User Guide
Abstract
This document includes feature, installation, and configuration information about HP Smart Encryption and is for the person w
ho installs, administers,
and troubleshoots servers and storage systems. HP assumes you are qualified in the servicing of computer equipment and trained in recognizing
hazards in products with hazardous energy levels.
Part Number: 759078-001
January 2014
Edition: 1
Vedere la pagina 0
1 2 3 4 5 6 ... 75 76

Sommario

Pagina 1 - Installation and User Guide

HP Secure Encryption Installation and User Guide Abstract This document includes feature, installation, and configuration information about HP Smar

Pagina 2

Overview 10 • For the BL460c: P230i • For connection to JBODs: P431 or P731m For more information about HP Smart Array Px3x controllers, see the a

Pagina 3 - Contents

Overview 11 The HP ESKM 3.1 keys and users can be organized into different groups depending on the policies set by an administrator. These groups de

Pagina 4 - Contents 4

Planning 12 Planning Encryption setup guidelines When setting up HP Secure Encryption, consider the information described in the following table. C

Pagina 5 - Overview

Planning 13 unencrypted when accessed from the host system and placed on tape. Software or hardware utilizing an independent encryption feature is n

Pagina 6 - Encryption features

Configuration 14 Configuration Local key management mode Local Key Management Mode, or Local Mode, is a solution designed for small to medium-size d

Pagina 7 - Feature Description Notes

Configuration 15 2. Click Perform Initial Setup. The following screen appears. 3. Complete the following: o Under Create Crypto Officer Password

Pagina 8 - Solution components

Configuration 16 o Under Key Management Mode, select Local Key Management Mode. 4. Click OK. 5. If you have read and agree to the terms of the E

Pagina 9 - HP Smart Array Controller

Configuration 17 b. Create a user account to host Master Encryption Keys. 3. Create a group ("Adding a group" on page 19). 4. Assign th

Pagina 10 - HP SmartCache

Configuration 18 3. Click Local Users & Groups. 4. Under Local Users, click Add. The following fields appear. 5. Complete the following f

Pagina 11 - Licensing

Configuration 19 d. If this is a standard user account, leave the User Administration Permission and Change Password Permission check boxes empty.

Pagina 12 - Planning

© Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. The only warrantie

Pagina 13 - Deployment scenarios

Configuration 20 4. Under Local Groups, click Add. 5. Enter the group name in the Group entry field. 6. Click Save. Assigning a user to a grou

Pagina 14 - Configuration

Configuration 21 3. Click Local Users & Groups. 4. Under Local Groups, select the group name and click Properties.

Pagina 15

Configuration 22 A new window appears, listing the group properties. 5. Click Add. 6. Enter the Username in the field provided. 7. Click Sav

Pagina 16 - Remote Key Management Mode

Configuration 23 Creating a Master Key The steps below outline how to create a key in the HP ESKM 3.1. The HP ESKM 3.1 does not differentiate betwee

Pagina 17 - Adding a user

Configuration 24 4. Under the section Create Key, complete the following: o Key Name: Enter the preferred key name. The name must consist only o

Pagina 18

Configuration 25 3. From the left side panel, expand the Keys menu and click Query Keys.

Pagina 19 - Adding a group

Configuration 26 The following screen appears. 4. Under Create Query, complete the following: a. Query Name: Enter a query name here. Your query

Pagina 20 - Assigning a user to a group

Configuration 27 3. Select the key, and then click Properties. 4. A new Key and Policy Configuration screen appears. Click the Permissions tab.

Pagina 21 - Configuration 21

Configuration 28 • The HP ESKM 3.1 must be configured with a deployment user. For more information, see "Configuring the HP ESKM 3.1 (on page

Pagina 22 - 7. Click Save

Configuration 29 3. The Enterprise Secure Key Manager configuration page appears. 4. Under Key Manager Servers, complete the following: a. Prima

Pagina 23 - Creating a Master Key

Contents 3 Contents Overview ...

Pagina 24 - Placing a key in a group

Configuration 30 6. Under Key Manager Configuration, enter the group name created previously in the HP ESKM 3.1 in the Group field. 7. Under ESKM

Pagina 25 - Configuration 25

Configuration 31 3. Complete the following: o Under Create Crypto Officer Password, enter and re-enter the password in the fields provided. o Und

Pagina 26 - Assigning a key to a group

Operations 32 Operations Accessing Encryption Manager Opening Encryption Manager 1. Start HP SSA. For more information, see the HP Smart Storage Ad

Pagina 27 - Configuring HP iLO

Operations 33 2. Click Encryption Login. 3. A new window appears. Select an account to log in with and enter the password in the field provided.

Pagina 28 - Configuration 28

Operations 34 4. A new window appears. Enter in the new password in the New Password fields. 5. Click OK. Set or change the password recovery q

Pagina 29

Operations 35 IMPORTANT: If this is the first time setting the User password, you must be logged in as the Crypto Officer. The User account is

Pagina 30

Operations 36 3. Under Settings, locate Controller Password. Click Set/Change Controller Password. 4. A new window appears. Enter and re-enter the

Pagina 31

Operations 37 3. Under Settings, locate Controller Password. Click Suspend Controller Password. 4. A new window appears, asking if you want to sus

Pagina 32 - Operations

Operations 38 Working with keys Changing the Master Encryption Key IMPORTANT: HP recommends that you keep a record of the Master Encryption Keys

Pagina 33 - Managing passwords

Operations 39 3. Under Settings, locate Encrypted Physical Drive Count. Click Drive Key Rekey. 4. A prompt appears, indicating new Drive Encryptio

Pagina 34

Contents 4 Replacing a server while retaining the controller ... 49 Pre

Pagina 35

Operations 40 2. Under Controller Devices, click on Unassigned Drives. 3. Select drives.

Pagina 36

Operations 41 4. Click Create Array. A new window appears. 5. Complete the following fields: a. Create Plaintext Volume: Select Yes. b. My A

Pagina 37

Operations 42 8. Array Details, Logical Drives, Physical Drives and Device Path specifications appear. Click Finish to complete. Converting plaint

Pagina 38 - Working with keys

Operations 43 5. Under Actions, click Convert Plaintext Data to Encrypted Data. A new window appears. 6. Select one of the following: a. To pre

Pagina 39 - Creating a plaintext volume

Operations 44 3. Under Settings, locate Key Management Mode. Click Change. 4. A new window appears with the key management mode selected. Enter t

Pagina 40 - Select drives

Operations 45 3. Under Settings, locate Allow New Plaintext Volumes. 4. Do one of the following: a. If encryption is disabled, click Allow Plain

Pagina 41

Operations 46 5. A prompt appears, asking you to confirm the change. Click Yes to proceed. Enabling/disabling local key cache 1. Open HP Encrypti

Pagina 42

Operations 47 b. Retry Interval in Minutes 6. Click OK. Importing drive sets in Local Key Management Mode When the Master Encryption Key on an i

Pagina 43

Operations 48 10. A new screen appears. Enter the new Master Encryption Key name assigned to the drives being imported in the Master Key field. 11.

Pagina 44

Maintenance 49 Maintenance Controllers Clearing the controller To clear all logical drives and arrays on controllers: 1. Start HP SSA. For more inf

Pagina 45

Overview 5 Overview About HP Secure Encryption HP Secure Encryption is a controller-based, enterprise-class data encryption solution that protects d

Pagina 46

Maintenance 50 Flashing firmware If the firmware lock function is enabled, the firmware lock on the controller must be unlocked before attempting to

Pagina 47

Maintenance 51 Groups Locating groups associated with a drive Use one of the following methods to locate the group name associated with a drive. •

Pagina 48 - 11. Click OK

Maintenance 52 The Key Policy and Configuration screen appears. 4. If you want to save this query, enter a name in the Query Name field. 5. Und

Pagina 49 - Maintenance

Maintenance 53 Query by previous server name 1. Log in to the HP ESKM 3.1 ("Logging in to the HP ESKM 3.1" on page 17). 2. Click the Se

Pagina 50 - Replacing a physical drive

Maintenance 54 The Key Policy and Configuration screen appears. 4. If you want to save this query, enter a name in the Query Name field. 5. Und

Pagina 51 - Query by drive serial number

Maintenance 55 8. Click the Permissions tab to view the group name. Displaying log information The event log displays events for all controllers

Pagina 52

Maintenance 56 2. From the left side panel, expand the Administration menu. 3. Click Key Manager. The Enterprise Secure Key Manager Events appears

Pagina 53 - Click the Security tab

Maintenance 57 3. From the left side panel, expand the Keys menu and click Query Keys.

Pagina 54

Maintenance 58 A new screen appears. 4. Under Create Query, complete the following: a. If you want to save the query for future use, fill in the

Pagina 55 - Displaying log information

Maintenance 59 — Exportable — Deletable — Algorithm — Creation Date — Versioned Key — Custom attributes d. When you have finished structuring

Pagina 56 - Running queries

Overview 6 Benefits Broad encryption coverage • Encrypts data on both the attached bulk storage and the cache memory of HP Smart Array Px3x control

Pagina 57 - Maintenance 57

Troubleshooting 60 Troubleshooting Common issues Lost or forgotten Crypto Officer password 1. Open Encryption Manager ("Opening Encryption Man

Pagina 58

Troubleshooting 61 If the OS logical drive is encrypted, offline HP SSA will be required to perform the steps below. For more information, see the H

Pagina 59 - Maintenance 59

Troubleshooting 62 2. Click the Security tab. 3. From the left side panel, expand the Keys menu and click Keys. 4. The Key and Policy Configura

Pagina 60 - Troubleshooting

Troubleshooting 63 2. From the left side panel, expand the Administration menu. 3. Click Key Manager. The Enterprise Secure Key Manager Events app

Pagina 61 - Lost or forgotten Master Key

Troubleshooting 64 2. Run a key query with the following search parameters ("Running queries" on page 56): a. Choose Keys Where drop down

Pagina 62 - Locating the key using iLO

Troubleshooting 65 Testing the connection between HP iLO and the HP ESKM 3.1 HP iLO connects and manages key exchanges between the controller and HP

Pagina 63 - Troubleshooting 63

Troubleshooting 66 The following screen appears. 3. Under Key Manager Configuration, click Test ESKM Connections: o If HP iLO is connected to th

Pagina 64 - Master key not exporting

Troubleshooting 67 Error Description Action Remote key manager communication failure Slot X Encryption Failure – Communication issue prevents dri

Pagina 65 - ESKM 3.1

Troubleshooting 68 Error Description Action NVRAM failure Non-volatile storage corrupted. Critical Security Parameters erased per policy. Encrypte

Pagina 66 - Potential errors encountered

Support and other resources 69 Support and other resources Before you contact HP Be sure to have the following information available before you call

Pagina 67 - Error Description Action

Overview 7 Feature Description Notes Dynamic Encryption Enables smooth transitions between local and remote modes, the conversion of plaintext dat

Pagina 68

Appendix 70 Appendix Encryption algorithms In keeping with the encryption standards outlined in FIPS 140-2 (http://csrc.nist.gov/groups/STM/cmvp/doc

Pagina 69 - Support and other resources

Glossary 71 Glossary ACU Array Configuration Utility Controller key A key created by the controller and permanently saved to the Remote Key Manager

Pagina 70 - Appendix

Glossary 72 ESKM Enterprise Secure Key Manager FIPS Federal Information Processing Standard HIPAA Health Insurance Portability and Accountability

Pagina 71 - Glossary

Glossary 73 Remote Key Manager A server used to store, backup and retrieve keys for a group of controllers in a data center. Volume encryption key

Pagina 72 - Glossary 72

Documentation feedback 74 Documentation feedback HP is committed to providing documentation that meets your needs. To help us improve the documentat

Pagina 73 - Volume encryption key

Index 75 A access 32 algorithms, supported 70 Array Configuration Utility (ACU) 9 B backing up data 12 before you contact HP 69 benefits

Pagina 74 - Documentation feedback

Index 76 license, iLO 11 Local Key Management Mode 14, 43, 61 log information, displaying 55 logging in 17, 32 logical drive 64 logical dr

Pagina 75 - Index 75

Overview 8 Feature Description Notes Key rotation support Supports the rekeying of all keys utilized by the controller to enable a robust key rota

Pagina 76 - Index 76

Overview 9 Component Model ML • ML350e V2 • ML350p Rack • DL360e/p • DL380e/p • DL385p • DL560 • DL580 SL • SL270s • SL210 For more infor

Commenti su questo manuale

Nessun commento