Hp Secure Encryption Manual do Utilizador Página 1

Consulte online ou descarregue Manual do Utilizador para Software Hp Secure Encryption. HP Secure Encryption User Manual Manual do Utilizador

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir
Vista de página 0
HP Secure Encryption
Installation and User Guide
Abstract
This document includes feature, installation, and configuration information about HP Smart Encryption and is for the person w
ho installs, administers,
and troubleshoots servers and storage systems. HP assumes you are qualified in the servicing of computer equipment and trained in recognizing
hazards in products with hazardous energy levels.
Part Number: 759078-001
January 2014
Edition: 1
Vista de página 0
1 2 3 4 5 6 ... 75 76

Resumo do Conteúdo

Página 1 - Installation and User Guide

HP Secure Encryption Installation and User Guide Abstract This document includes feature, installation, and configuration information about HP Smar

Página 2

Overview 10 • For the BL460c: P230i • For connection to JBODs: P431 or P731m For more information about HP Smart Array Px3x controllers, see the a

Página 3 - Contents

Overview 11 The HP ESKM 3.1 keys and users can be organized into different groups depending on the policies set by an administrator. These groups de

Página 4 - Contents 4

Planning 12 Planning Encryption setup guidelines When setting up HP Secure Encryption, consider the information described in the following table. C

Página 5 - Overview

Planning 13 unencrypted when accessed from the host system and placed on tape. Software or hardware utilizing an independent encryption feature is n

Página 6 - Encryption features

Configuration 14 Configuration Local key management mode Local Key Management Mode, or Local Mode, is a solution designed for small to medium-size d

Página 7 - Feature Description Notes

Configuration 15 2. Click Perform Initial Setup. The following screen appears. 3. Complete the following: o Under Create Crypto Officer Password

Página 8 - Solution components

Configuration 16 o Under Key Management Mode, select Local Key Management Mode. 4. Click OK. 5. If you have read and agree to the terms of the E

Página 9 - HP Smart Array Controller

Configuration 17 b. Create a user account to host Master Encryption Keys. 3. Create a group ("Adding a group" on page 19). 4. Assign th

Página 10 - HP SmartCache

Configuration 18 3. Click Local Users & Groups. 4. Under Local Users, click Add. The following fields appear. 5. Complete the following f

Página 11 - Licensing

Configuration 19 d. If this is a standard user account, leave the User Administration Permission and Change Password Permission check boxes empty.

Página 12 - Planning

© Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. The only warrantie

Página 13 - Deployment scenarios

Configuration 20 4. Under Local Groups, click Add. 5. Enter the group name in the Group entry field. 6. Click Save. Assigning a user to a grou

Página 14 - Configuration

Configuration 21 3. Click Local Users & Groups. 4. Under Local Groups, select the group name and click Properties.

Página 15

Configuration 22 A new window appears, listing the group properties. 5. Click Add. 6. Enter the Username in the field provided. 7. Click Sav

Página 16 - Remote Key Management Mode

Configuration 23 Creating a Master Key The steps below outline how to create a key in the HP ESKM 3.1. The HP ESKM 3.1 does not differentiate betwee

Página 17 - Adding a user

Configuration 24 4. Under the section Create Key, complete the following: o Key Name: Enter the preferred key name. The name must consist only o

Página 18

Configuration 25 3. From the left side panel, expand the Keys menu and click Query Keys.

Página 19 - Adding a group

Configuration 26 The following screen appears. 4. Under Create Query, complete the following: a. Query Name: Enter a query name here. Your query

Página 20 - Assigning a user to a group

Configuration 27 3. Select the key, and then click Properties. 4. A new Key and Policy Configuration screen appears. Click the Permissions tab.

Página 21 - Configuration 21

Configuration 28 • The HP ESKM 3.1 must be configured with a deployment user. For more information, see "Configuring the HP ESKM 3.1 (on page

Página 22 - 7. Click Save

Configuration 29 3. The Enterprise Secure Key Manager configuration page appears. 4. Under Key Manager Servers, complete the following: a. Prima

Página 23 - Creating a Master Key

Contents 3 Contents Overview ...

Página 24 - Placing a key in a group

Configuration 30 6. Under Key Manager Configuration, enter the group name created previously in the HP ESKM 3.1 in the Group field. 7. Under ESKM

Página 25 - Configuration 25

Configuration 31 3. Complete the following: o Under Create Crypto Officer Password, enter and re-enter the password in the fields provided. o Und

Página 26 - Assigning a key to a group

Operations 32 Operations Accessing Encryption Manager Opening Encryption Manager 1. Start HP SSA. For more information, see the HP Smart Storage Ad

Página 27 - Configuring HP iLO

Operations 33 2. Click Encryption Login. 3. A new window appears. Select an account to log in with and enter the password in the field provided.

Página 28 - Configuration 28

Operations 34 4. A new window appears. Enter in the new password in the New Password fields. 5. Click OK. Set or change the password recovery q

Página 29

Operations 35 IMPORTANT: If this is the first time setting the User password, you must be logged in as the Crypto Officer. The User account is

Página 30

Operations 36 3. Under Settings, locate Controller Password. Click Set/Change Controller Password. 4. A new window appears. Enter and re-enter the

Página 31

Operations 37 3. Under Settings, locate Controller Password. Click Suspend Controller Password. 4. A new window appears, asking if you want to sus

Página 32 - Operations

Operations 38 Working with keys Changing the Master Encryption Key IMPORTANT: HP recommends that you keep a record of the Master Encryption Keys

Página 33 - Managing passwords

Operations 39 3. Under Settings, locate Encrypted Physical Drive Count. Click Drive Key Rekey. 4. A prompt appears, indicating new Drive Encryptio

Página 34

Contents 4 Replacing a server while retaining the controller ... 49 Pre

Página 35

Operations 40 2. Under Controller Devices, click on Unassigned Drives. 3. Select drives.

Página 36

Operations 41 4. Click Create Array. A new window appears. 5. Complete the following fields: a. Create Plaintext Volume: Select Yes. b. My A

Página 37

Operations 42 8. Array Details, Logical Drives, Physical Drives and Device Path specifications appear. Click Finish to complete. Converting plaint

Página 38 - Working with keys

Operations 43 5. Under Actions, click Convert Plaintext Data to Encrypted Data. A new window appears. 6. Select one of the following: a. To pre

Página 39 - Creating a plaintext volume

Operations 44 3. Under Settings, locate Key Management Mode. Click Change. 4. A new window appears with the key management mode selected. Enter t

Página 40 - Select drives

Operations 45 3. Under Settings, locate Allow New Plaintext Volumes. 4. Do one of the following: a. If encryption is disabled, click Allow Plain

Página 41

Operations 46 5. A prompt appears, asking you to confirm the change. Click Yes to proceed. Enabling/disabling local key cache 1. Open HP Encrypti

Página 42

Operations 47 b. Retry Interval in Minutes 6. Click OK. Importing drive sets in Local Key Management Mode When the Master Encryption Key on an i

Página 43

Operations 48 10. A new screen appears. Enter the new Master Encryption Key name assigned to the drives being imported in the Master Key field. 11.

Página 44

Maintenance 49 Maintenance Controllers Clearing the controller To clear all logical drives and arrays on controllers: 1. Start HP SSA. For more inf

Página 45

Overview 5 Overview About HP Secure Encryption HP Secure Encryption is a controller-based, enterprise-class data encryption solution that protects d

Página 46

Maintenance 50 Flashing firmware If the firmware lock function is enabled, the firmware lock on the controller must be unlocked before attempting to

Página 47

Maintenance 51 Groups Locating groups associated with a drive Use one of the following methods to locate the group name associated with a drive. •

Página 48 - 11. Click OK

Maintenance 52 The Key Policy and Configuration screen appears. 4. If you want to save this query, enter a name in the Query Name field. 5. Und

Página 49 - Maintenance

Maintenance 53 Query by previous server name 1. Log in to the HP ESKM 3.1 ("Logging in to the HP ESKM 3.1" on page 17). 2. Click the Se

Página 50 - Replacing a physical drive

Maintenance 54 The Key Policy and Configuration screen appears. 4. If you want to save this query, enter a name in the Query Name field. 5. Und

Página 51 - Query by drive serial number

Maintenance 55 8. Click the Permissions tab to view the group name. Displaying log information The event log displays events for all controllers

Página 52

Maintenance 56 2. From the left side panel, expand the Administration menu. 3. Click Key Manager. The Enterprise Secure Key Manager Events appears

Página 53 - Click the Security tab

Maintenance 57 3. From the left side panel, expand the Keys menu and click Query Keys.

Página 54

Maintenance 58 A new screen appears. 4. Under Create Query, complete the following: a. If you want to save the query for future use, fill in the

Página 55 - Displaying log information

Maintenance 59 — Exportable — Deletable — Algorithm — Creation Date — Versioned Key — Custom attributes d. When you have finished structuring

Página 56 - Running queries

Overview 6 Benefits Broad encryption coverage • Encrypts data on both the attached bulk storage and the cache memory of HP Smart Array Px3x control

Página 57 - Maintenance 57

Troubleshooting 60 Troubleshooting Common issues Lost or forgotten Crypto Officer password 1. Open Encryption Manager ("Opening Encryption Man

Página 58

Troubleshooting 61 If the OS logical drive is encrypted, offline HP SSA will be required to perform the steps below. For more information, see the H

Página 59 - Maintenance 59

Troubleshooting 62 2. Click the Security tab. 3. From the left side panel, expand the Keys menu and click Keys. 4. The Key and Policy Configura

Página 60 - Troubleshooting

Troubleshooting 63 2. From the left side panel, expand the Administration menu. 3. Click Key Manager. The Enterprise Secure Key Manager Events app

Página 61 - Lost or forgotten Master Key

Troubleshooting 64 2. Run a key query with the following search parameters ("Running queries" on page 56): a. Choose Keys Where drop down

Página 62 - Locating the key using iLO

Troubleshooting 65 Testing the connection between HP iLO and the HP ESKM 3.1 HP iLO connects and manages key exchanges between the controller and HP

Página 63 - Troubleshooting 63

Troubleshooting 66 The following screen appears. 3. Under Key Manager Configuration, click Test ESKM Connections: o If HP iLO is connected to th

Página 64 - Master key not exporting

Troubleshooting 67 Error Description Action Remote key manager communication failure Slot X Encryption Failure – Communication issue prevents dri

Página 65 - ESKM 3.1

Troubleshooting 68 Error Description Action NVRAM failure Non-volatile storage corrupted. Critical Security Parameters erased per policy. Encrypte

Página 66 - Potential errors encountered

Support and other resources 69 Support and other resources Before you contact HP Be sure to have the following information available before you call

Página 67 - Error Description Action

Overview 7 Feature Description Notes Dynamic Encryption Enables smooth transitions between local and remote modes, the conversion of plaintext dat

Página 68

Appendix 70 Appendix Encryption algorithms In keeping with the encryption standards outlined in FIPS 140-2 (http://csrc.nist.gov/groups/STM/cmvp/doc

Página 69 - Support and other resources

Glossary 71 Glossary ACU Array Configuration Utility Controller key A key created by the controller and permanently saved to the Remote Key Manager

Página 70 - Appendix

Glossary 72 ESKM Enterprise Secure Key Manager FIPS Federal Information Processing Standard HIPAA Health Insurance Portability and Accountability

Página 71 - Glossary

Glossary 73 Remote Key Manager A server used to store, backup and retrieve keys for a group of controllers in a data center. Volume encryption key

Página 72 - Glossary 72

Documentation feedback 74 Documentation feedback HP is committed to providing documentation that meets your needs. To help us improve the documentat

Página 73 - Volume encryption key

Index 75 A access 32 algorithms, supported 70 Array Configuration Utility (ACU) 9 B backing up data 12 before you contact HP 69 benefits

Página 74 - Documentation feedback

Index 76 license, iLO 11 Local Key Management Mode 14, 43, 61 log information, displaying 55 logging in 17, 32 logical drive 64 logical dr

Página 75 - Index 75

Overview 8 Feature Description Notes Key rotation support Supports the rekeying of all keys utilized by the controller to enable a robust key rota

Página 76 - Index 76

Overview 9 Component Model ML • ML350e V2 • ML350p Rack • DL360e/p • DL380e/p • DL385p • DL560 • DL580 SL • SL270s • SL210 For more infor

Comentários a estes Manuais

Sem comentários