Hp Secure Encryption Manuel d'utilisateur

Naviguer en ligne ou télécharger Manuel d'utilisateur pour Logiciel Hp Secure Encryption. HP Secure Encryption User Manual Manuel d'utilisatio

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 76
  • Table des matières
  • DEPANNAGE
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 0
HP Secure Encryption
Installation and User Guide
Abstract
This document includes feature, installation, and configuration information about HP Smart Encryption and is for the person w
ho installs, administers,
and troubleshoots servers and storage systems. HP assumes you are qualified in the servicing of computer equipment and trained in recognizing
hazards in products with hazardous energy levels.
Part Number: 759078-001
January 2014
Edition: 1
Vue de la page 0
1 2 3 4 5 6 ... 75 76

Résumé du contenu

Page 1 - Installation and User Guide

HP Secure Encryption Installation and User Guide Abstract This document includes feature, installation, and configuration information about HP Smar

Page 2

Overview 10 • For the BL460c: P230i • For connection to JBODs: P431 or P731m For more information about HP Smart Array Px3x controllers, see the a

Page 3 - Contents

Overview 11 The HP ESKM 3.1 keys and users can be organized into different groups depending on the policies set by an administrator. These groups de

Page 4 - Contents 4

Planning 12 Planning Encryption setup guidelines When setting up HP Secure Encryption, consider the information described in the following table. C

Page 5 - Overview

Planning 13 unencrypted when accessed from the host system and placed on tape. Software or hardware utilizing an independent encryption feature is n

Page 6 - Encryption features

Configuration 14 Configuration Local key management mode Local Key Management Mode, or Local Mode, is a solution designed for small to medium-size d

Page 7 - Feature Description Notes

Configuration 15 2. Click Perform Initial Setup. The following screen appears. 3. Complete the following: o Under Create Crypto Officer Password

Page 8 - Solution components

Configuration 16 o Under Key Management Mode, select Local Key Management Mode. 4. Click OK. 5. If you have read and agree to the terms of the E

Page 9 - HP Smart Array Controller

Configuration 17 b. Create a user account to host Master Encryption Keys. 3. Create a group ("Adding a group" on page 19). 4. Assign th

Page 10 - HP SmartCache

Configuration 18 3. Click Local Users & Groups. 4. Under Local Users, click Add. The following fields appear. 5. Complete the following f

Page 11 - Licensing

Configuration 19 d. If this is a standard user account, leave the User Administration Permission and Change Password Permission check boxes empty.

Page 12 - Planning

© Copyright 2014 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. The only warrantie

Page 13 - Deployment scenarios

Configuration 20 4. Under Local Groups, click Add. 5. Enter the group name in the Group entry field. 6. Click Save. Assigning a user to a grou

Page 14 - Configuration

Configuration 21 3. Click Local Users & Groups. 4. Under Local Groups, select the group name and click Properties.

Page 15

Configuration 22 A new window appears, listing the group properties. 5. Click Add. 6. Enter the Username in the field provided. 7. Click Sav

Page 16 - Remote Key Management Mode

Configuration 23 Creating a Master Key The steps below outline how to create a key in the HP ESKM 3.1. The HP ESKM 3.1 does not differentiate betwee

Page 17 - Adding a user

Configuration 24 4. Under the section Create Key, complete the following: o Key Name: Enter the preferred key name. The name must consist only o

Page 18

Configuration 25 3. From the left side panel, expand the Keys menu and click Query Keys.

Page 19 - Adding a group

Configuration 26 The following screen appears. 4. Under Create Query, complete the following: a. Query Name: Enter a query name here. Your query

Page 20 - Assigning a user to a group

Configuration 27 3. Select the key, and then click Properties. 4. A new Key and Policy Configuration screen appears. Click the Permissions tab.

Page 21 - Configuration 21

Configuration 28 • The HP ESKM 3.1 must be configured with a deployment user. For more information, see "Configuring the HP ESKM 3.1 (on page

Page 22 - 7. Click Save

Configuration 29 3. The Enterprise Secure Key Manager configuration page appears. 4. Under Key Manager Servers, complete the following: a. Prima

Page 23 - Creating a Master Key

Contents 3 Contents Overview ...

Page 24 - Placing a key in a group

Configuration 30 6. Under Key Manager Configuration, enter the group name created previously in the HP ESKM 3.1 in the Group field. 7. Under ESKM

Page 25 - Configuration 25

Configuration 31 3. Complete the following: o Under Create Crypto Officer Password, enter and re-enter the password in the fields provided. o Und

Page 26 - Assigning a key to a group

Operations 32 Operations Accessing Encryption Manager Opening Encryption Manager 1. Start HP SSA. For more information, see the HP Smart Storage Ad

Page 27 - Configuring HP iLO

Operations 33 2. Click Encryption Login. 3. A new window appears. Select an account to log in with and enter the password in the field provided.

Page 28 - Configuration 28

Operations 34 4. A new window appears. Enter in the new password in the New Password fields. 5. Click OK. Set or change the password recovery q

Page 29

Operations 35 IMPORTANT: If this is the first time setting the User password, you must be logged in as the Crypto Officer. The User account is

Page 30

Operations 36 3. Under Settings, locate Controller Password. Click Set/Change Controller Password. 4. A new window appears. Enter and re-enter the

Page 31

Operations 37 3. Under Settings, locate Controller Password. Click Suspend Controller Password. 4. A new window appears, asking if you want to sus

Page 32 - Operations

Operations 38 Working with keys Changing the Master Encryption Key IMPORTANT: HP recommends that you keep a record of the Master Encryption Keys

Page 33 - Managing passwords

Operations 39 3. Under Settings, locate Encrypted Physical Drive Count. Click Drive Key Rekey. 4. A prompt appears, indicating new Drive Encryptio

Page 34

Contents 4 Replacing a server while retaining the controller ... 49 Pre

Page 35

Operations 40 2. Under Controller Devices, click on Unassigned Drives. 3. Select drives.

Page 36

Operations 41 4. Click Create Array. A new window appears. 5. Complete the following fields: a. Create Plaintext Volume: Select Yes. b. My A

Page 37

Operations 42 8. Array Details, Logical Drives, Physical Drives and Device Path specifications appear. Click Finish to complete. Converting plaint

Page 38 - Working with keys

Operations 43 5. Under Actions, click Convert Plaintext Data to Encrypted Data. A new window appears. 6. Select one of the following: a. To pre

Page 39 - Creating a plaintext volume

Operations 44 3. Under Settings, locate Key Management Mode. Click Change. 4. A new window appears with the key management mode selected. Enter t

Page 40 - Select drives

Operations 45 3. Under Settings, locate Allow New Plaintext Volumes. 4. Do one of the following: a. If encryption is disabled, click Allow Plain

Page 41

Operations 46 5. A prompt appears, asking you to confirm the change. Click Yes to proceed. Enabling/disabling local key cache 1. Open HP Encrypti

Page 42

Operations 47 b. Retry Interval in Minutes 6. Click OK. Importing drive sets in Local Key Management Mode When the Master Encryption Key on an i

Page 43

Operations 48 10. A new screen appears. Enter the new Master Encryption Key name assigned to the drives being imported in the Master Key field. 11.

Page 44

Maintenance 49 Maintenance Controllers Clearing the controller To clear all logical drives and arrays on controllers: 1. Start HP SSA. For more inf

Page 45

Overview 5 Overview About HP Secure Encryption HP Secure Encryption is a controller-based, enterprise-class data encryption solution that protects d

Page 46

Maintenance 50 Flashing firmware If the firmware lock function is enabled, the firmware lock on the controller must be unlocked before attempting to

Page 47

Maintenance 51 Groups Locating groups associated with a drive Use one of the following methods to locate the group name associated with a drive. •

Page 48 - 11. Click OK

Maintenance 52 The Key Policy and Configuration screen appears. 4. If you want to save this query, enter a name in the Query Name field. 5. Und

Page 49 - Maintenance

Maintenance 53 Query by previous server name 1. Log in to the HP ESKM 3.1 ("Logging in to the HP ESKM 3.1" on page 17). 2. Click the Se

Page 50 - Replacing a physical drive

Maintenance 54 The Key Policy and Configuration screen appears. 4. If you want to save this query, enter a name in the Query Name field. 5. Und

Page 51 - Query by drive serial number

Maintenance 55 8. Click the Permissions tab to view the group name. Displaying log information The event log displays events for all controllers

Page 52

Maintenance 56 2. From the left side panel, expand the Administration menu. 3. Click Key Manager. The Enterprise Secure Key Manager Events appears

Page 53 - Click the Security tab

Maintenance 57 3. From the left side panel, expand the Keys menu and click Query Keys.

Page 54

Maintenance 58 A new screen appears. 4. Under Create Query, complete the following: a. If you want to save the query for future use, fill in the

Page 55 - Displaying log information

Maintenance 59 — Exportable — Deletable — Algorithm — Creation Date — Versioned Key — Custom attributes d. When you have finished structuring

Page 56 - Running queries

Overview 6 Benefits Broad encryption coverage • Encrypts data on both the attached bulk storage and the cache memory of HP Smart Array Px3x control

Page 57 - Maintenance 57

Troubleshooting 60 Troubleshooting Common issues Lost or forgotten Crypto Officer password 1. Open Encryption Manager ("Opening Encryption Man

Page 58

Troubleshooting 61 If the OS logical drive is encrypted, offline HP SSA will be required to perform the steps below. For more information, see the H

Page 59 - Maintenance 59

Troubleshooting 62 2. Click the Security tab. 3. From the left side panel, expand the Keys menu and click Keys. 4. The Key and Policy Configura

Page 60 - Troubleshooting

Troubleshooting 63 2. From the left side panel, expand the Administration menu. 3. Click Key Manager. The Enterprise Secure Key Manager Events app

Page 61 - Lost or forgotten Master Key

Troubleshooting 64 2. Run a key query with the following search parameters ("Running queries" on page 56): a. Choose Keys Where drop down

Page 62 - Locating the key using iLO

Troubleshooting 65 Testing the connection between HP iLO and the HP ESKM 3.1 HP iLO connects and manages key exchanges between the controller and HP

Page 63 - Troubleshooting 63

Troubleshooting 66 The following screen appears. 3. Under Key Manager Configuration, click Test ESKM Connections: o If HP iLO is connected to th

Page 64 - Master key not exporting

Troubleshooting 67 Error Description Action Remote key manager communication failure Slot X Encryption Failure – Communication issue prevents dri

Page 65 - ESKM 3.1

Troubleshooting 68 Error Description Action NVRAM failure Non-volatile storage corrupted. Critical Security Parameters erased per policy. Encrypte

Page 66 - Potential errors encountered

Support and other resources 69 Support and other resources Before you contact HP Be sure to have the following information available before you call

Page 67 - Error Description Action

Overview 7 Feature Description Notes Dynamic Encryption Enables smooth transitions between local and remote modes, the conversion of plaintext dat

Page 68

Appendix 70 Appendix Encryption algorithms In keeping with the encryption standards outlined in FIPS 140-2 (http://csrc.nist.gov/groups/STM/cmvp/doc

Page 69 - Support and other resources

Glossary 71 Glossary ACU Array Configuration Utility Controller key A key created by the controller and permanently saved to the Remote Key Manager

Page 70 - Appendix

Glossary 72 ESKM Enterprise Secure Key Manager FIPS Federal Information Processing Standard HIPAA Health Insurance Portability and Accountability

Page 71 - Glossary

Glossary 73 Remote Key Manager A server used to store, backup and retrieve keys for a group of controllers in a data center. Volume encryption key

Page 72 - Glossary 72

Documentation feedback 74 Documentation feedback HP is committed to providing documentation that meets your needs. To help us improve the documentat

Page 73 - Volume encryption key

Index 75 A access 32 algorithms, supported 70 Array Configuration Utility (ACU) 9 B backing up data 12 before you contact HP 69 benefits

Page 74 - Documentation feedback

Index 76 license, iLO 11 Local Key Management Mode 14, 43, 61 log information, displaying 55 logging in 17, 32 logical drive 64 logical dr

Page 75 - Index 75

Overview 8 Feature Description Notes Key rotation support Supports the rekeying of all keys utilized by the controller to enable a robust key rota

Page 76 - Index 76

Overview 9 Component Model ML • ML350e V2 • ML350p Rack • DL360e/p • DL380e/p • DL385p • DL560 • DL580 SL • SL270s • SL210 For more infor

Commentaires sur ces manuels

Pas de commentaire