Cisco AJ732A - MDS 9134 Fabric Switch Configuration Manual page 269

Cisco mds 9000 family storage media encryption configuration guide - release 4.x (ol-18091-01, february 2009)
Hide thumbs Also See for AJ732A - Cisco MDS 9134 Fabric Switch:
Table of Contents

Advertisement

Appendix F
Planning For Cisco SME Installation
S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m
If you are using smart cards in the standard or advanced security mode, ensure that you do the following:
Security
Determine whether you will use SSL for switch-to-KMC communication. If you are using SSL, then do
the following tasks:
Note
Communication
Verify that you do the following tasks:
OL-18091-01, Cisco MDS NX-OS Release 4.x
For more information about key policies, refer to the
Note
Management White Paper
Use basic or standard or advanced key security mode.
To learn more about master key security modes, refer to
Management."
Install the GemPlus smart card reader drivers on the host used for Cisco SME provisioning. These
card reader drivers are included in the Cisco MDS 9000 Management Software and Documentation
CD-ROM.
Order the required number of smart cards and readers.
Identify a host in the customer environment for setting up the Fabric Manager server and KMC.
Refer to
Chapter 1, "Product Overview"
Identify whether a self-signed certificate is required or whether the customer will use their own
certificate as the root certificate.
List the names and IP addresses of the switches where the certificates will be installed.
Install OpenSSL. This application could be installed on the server used for Fabric Manager server
and KMC.
For the server running Windows operating system, download and install OpenSSL from the
following locations:
http://gnuwin32.sourceforge.net/packages/openssl.htm
http://www.slproweb.com/products/Win32OpenSSL.html
The SSL installed should be used to generate keys.
Use the OpenSSL application installed at the following location:
C:\Program Files\GnuWin32\bin\openssl.exe
For a server running on Linux, the OpenSSL application should already be available on the
server.
Identify the authentication modes used in the SAN, that is local database, TACACS+, or RADIUS.
Allow the following ports on the firewall server:
and
Chapter 6, "Cisco SME Key Management."
to learn about the server requirements.
Cisco MDS 9000 Family Storage Media Encryption Configuration Guide
Storage Media Encryption Key
Chapter 4, "Cisco SME Cluster
Security
F-3

Advertisement

Table of Contents
loading

Table of Contents