Brocade Communications Systems Encryption Switch Service Manual Page 282

  • Download
  • Add to my manuals
  • Print
  • Page
    / 326
  • Table of contents
  • TROUBLESHOOTING
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 281
264 Fabric OS Encryption Administrator’s Guide (DPM)
53-1002720-02
Key vault diagnostics
6
Aborting a pending database transaction
You can abort a pending database transaction for any device configurations invoked earlier through
the CLI or BNA interfaces by completing the following steps.
1. Use the
--transshow command to determine the currently pending transaction ID.
The
--transshow command displays the pending database transaction for any device
configurations invoked earlier through the CLI or BNA interfaces. The command displays the
transaction status (completed or pending), the transaction ID, and the transaction owner (CLI
or BNA).
2. Use the
--transabort <transaction_ID> command to abort the transaction, where
<transaction_ID> specifies the ID of the transaction to be aborted.
Key vault diagnostics
With the introduction of Fabric OS 7.0.0, you can run key vault diagnostics tests to identify any key
vault connectivity or key operation errors. You configure the key vault diagnostic test using the
cryptocfg
--kvdiag command.
If an encryption switch is part of an EG, the diagnostic testing is performed on that switch only and
not the entire group. If multiple nodes in an encryption group have different Fabric OS versions,
only those nodes running Fabric OS 7.0.0 and later can be configured for periodic key vault
diagnostic testing.
You can set the diagnostic tests to run at regular intervals. When incidents occur, the findings are
collected in log reports. The first instance of a failure and subsequent restoration of operation is
reported as a Remote Access Server (RAS) log. Subsequent findings for the same incident are not
logged to avoid redundant messages.
Key vault connectivity
Key vault connectivity is adiagnostics feature that allows you to periodically collect information
about the state of key vault connectivity from the Brocade Encryption Switch and possible version,
configuration, or cluster information of the key vault (KV).
This feature reports the following types of configuration information:
Key Vault/Cluster scope:
CA Certificate and its validity (for example, valid header and expiry date)
Key Vault IP/Port
KV firmware version
Time of day on the KV
Key class and format on the KV configured for the user group
Client session timeout
Encryption node scope
Node KAC certificate and its validity (for example, valid header and expiry date)
Username/password
User group
Page view 281
1 2 ... 277 278 279 280 281 282 283 284 285 286 287 ... 325 326

Comments to this Manuals

No comments