DCFM Enterprise User Manual (53-1001775-01, June 2010)

DCFM Enterprise User Manual 507
53-1001775-01
RKM key vault high availability deployment
20
i. Repeat a. through h. for each key class.
j. Click Finish.
9. For each encryption node, create an identity as follows.
a. Select the Identities tab.
b. Click Create.
c. Enter a label for the node in the Name field. This is a user-defined identifier.
d. Select the Hardware Retail Group in the Identity Groups field.
e. Select the Operational User role in the Authorization field.
f. Click Browse and select the imported certificate as the Identity certificate.
g. Click Save.
RKM key vault high availability deployment
When dual RKM appliances are used for high availability, the RKM appliances must be clustered,
and must operate in maximum availability mode, as described in the RKM appliance user
documentation.
When dual RKM appliances are clustered, they are accessed using an IP load balancer. For a
complete high availability deployment, the multiple IP load balancers are clustered, and the IP load
balancer cluster exposes a virtual IP address called a floating IP address. The floating IP address
must be registered on the Brocade encryption group leader.
The secondary RKM appliance must not be registered, and also individual RKM appliance IP
addresses must not be registered.
Steps for connecting to an LKM appliance
The NetApp Lifetime Key Manager (LKM) resides on an FIPS 140-2 Level 3-compliant network
appliance. The encryption engine and LKM appliance communicate over a trusted link. A trusted
link is a secure connection established between the Encryption switch or blade and the NetApp
LKM appliance, using a shared secret called a link key.
The following configuration steps are performed from the NetApp DataFort Management Console
and from the Management application:
Install and launch the NetApp DataFort Management Console.
Establish the trusted link.
Obtain and import the LKM certificate.
Export and register encryption node certificates on LKM.
If required, create an LKM cluster for high availability.
These steps are described in more detail in the following sections.