Brocade Fabric OS Encryption Administrator's Guide v7.1.0 (53-1002721-01, March 2013)

Table Of Contents
Fabric OS Encryption Administrator’s Guide (SKM/ESKM) 49
53-1002721-01
Creating a new encryption group
2
After configuration of the encryption group is completed, BNA sends API commands to verify
the switch configuration. See “Understanding configuration status results” on page 49 for
more information.
13. Review important messages, then click Next.
The Next Steps dialog box displays (Figure 24). Instructions for installing public key certificates
for the encryption switch are displayed.
FIGURE 24 Next Steps dialog box
14. Review post-configuration instructions, which you can copy to a clipboard or print for later.
15. Click Finish to exit the Configure Switch Encryption wizard.
Refer to “Understanding configuration status results” on page 49.
Understanding configuration status results
After configuration of the encryption group is completed, BNA sends API commands to verify the
switch configuration. The CLI commands are detailed in the encryption administrator’s guide for
your key vault management system.
1. Initialize the switch. If the switch is not already in the initiated state, BNA performs the
cryptocfg
--initnode command.
2. Create an encryption group on the switch. BNA creates a new group using the cryptocfg
--create -encgroup command, and sets the key vault type using the cryptocfg --set -keyvault
command.
3. Register the key vault. BNA registers the key vault using the cryptocfg
--reg keyvault
command.
4. Enable the encryption engines. BNA initializes an encryption switch using the cryptocfg
--
initEE [<slotnumber>] and cryptocfg --regEE [<slotnumber>] commands.