Brocade Fabric OS Encryption Administrator's Guide v7.1.0 (53-1002721-01, March 2013)

Table Of Contents
88 Fabric OS Encryption Administrator’s Guide (SKM/ESKM)
53-1002721-01
Master keys
2
Master key actions
NOTE
Master keys belong to the group and are managed from Group Properties.
Master key actions are as follows:
Backup master key: Enabled any time a master key exists. Selecting this option launches the
Backup Master Key for Encryption Group dialog box.
You can back up the master key to a file, to a key vault, or to a smart card. You can back up the
master key multiple times to any of these media in case you forget the passphrase you
originally used to back up the master key, or if multiple administrators each needs a
passphrase for recovery. Refer to the following procedures for more information:
- “Saving the master key to a file” on page 88
- “Saving a master key to a key vault” on page 89
- “Saving a master key to a smart card set” on page 90
You must back up the master key when the status is Created but not backed up.
Restore master key: Enabled when no master key exists or the previous master key has been
backed up. This option is also enabled when using a DPM key vault.
When this option is selected, the Restore Master Key for Encryption Group dialog box displays,
from which you can restore a master key from a file, key vault, or smart card set. Refer to the
following procedures for more information:
- “Restoring a master key from a file” on page 92
- “Restoring a master key from a key vault” on page 93
- “Restoring a master key from a smart card set” on page 94
Create new master key: Enabled when no master key exists, or the previous master key has
been backed up. Refer to “Creating a new master key” on page 95.
You must create a new master key when the status is Required but not created.
NOTE
If a master key was not created, Not Used is displayed as the status and the Master Key
Actions list is grayed out. In this case, you must create a new master key. Additional master key
statuses are: Backed up but not propagated and Created and backed up.
Saving the master key to a file
Use the following procedure to save the master key to a file.
1. Select Configure > Encryption from the menu task bar to display the Encryption Center
dialog box (Refer to Figure 1 on page 14).
2. Select a group from the Encryption Center Devices table, then select Group > Security from the
menu task bar.
The Encryption Group Properties dialog box displays with the Security tab selected.