Using MegaRAID Advanced Software : Avago MegaRAID SafeStore Encryption Services : Enabling Drive Security

Enabling Drive Security

This section describes how to enable, change, and disable the drive security, and how to import a foreign configuration using the SafeStore Encryption Services advanced software.

To enable security on the drives, you need to perform the following actions to set drive security:

*

Enter a security key identifier.

A security key identifier appears whenever you have to enter a security key. If you have more than one security key, the identifier helps you determine which security key to enter.

*

Enter a security key.

After you create a security key, you have the option to create secure virtual drives using the key. You have to use the security key to perform certain operations.

You can improve security by entering a password. To provide additional security, you can require the password whenever anyone boots the server.

Perform the following steps to enable drive security.

1.

Select the Physical tab in the left panel of the MegaRAID Storage Manager window, and select a controller icon.

2.

Select Go To > Controller > Enable Drive Security.

The Enable Drive Security dialog appears, as shown in the following figure.

Figure 132. Enable Drive Security – Security Key Identifier

3.

Either use the default security key identifier, or enter a new security key identifier.

NOTE  If you create more than one security key, make sure that you change the security key identifier. Otherwise, you cannot differentiate between the security keys.

4.

Either click Suggest Security Key to have the system create a security key, or you can enter a new security key.

5.

Enter the new security key again to confirm.

CAUTION  If you are prompted for the security key and you forgot it or don't have access to it, you will lose access to your data. Make sure to record your security key information. You might need to enter the security key to perform certain operations.

The security key is case-sensitive. It must be between 8 and 32 characters and contain at least one number, one lowercase letter, one uppercase letter, and one non-alphanumeric character (e.g., < > @ +). The space character is not permitted.

NOTE  Non-U.S. keyboard users must be careful not to enter double-byte character set (DBCS) characters in the security key field. The firmware works with the ASCII character set only.

The following figure shows the security key entered and confirmed on this dialog.

Figure 133. Enable Drive Security - Security Key

6.

(Optional) Select the Pause for password at boot time check box.

If you choose this option, you must enter the password whenever you boot the server.

7.

(Optional) Select the Enforce strong password security check box.

If you choose this option, make sure the password is between 8 and 32 characters and contain at least one number, one lowercase letter, one uppercase letter, and one non-alphanumeric character (e.g. < > @ +). The space character is not permitted. The password is case-sensitive.

8.

(Optional) Enter a password in the Password field and then enter the same password in the Confirm field.

Warning messages appear if a mismatch exists between the characters entered in the Password field and the Confirm field, or if there is an invalid character entered.

NOTE  Be sure to record the password. If you lose the password, you could lose access to your data.

The following figure shows the password entered and confirmed on this dialog.

Figure 134. Enable Drive Security - Password

ATTENTION  If you forget the security key, you will lose access to your data. Be sure to record your security key. You might need to enter the security key to perform certain operations.

9.

Select the I recorded the security settings for future reference check box, and click Yes to confirm that you want to enable drive security on this controller and have recorded the security settings for future reference.

The MegaRAID Storage Manager software enables drive security and returns you to the main menu.