About encryption at rest
Access Appliance provides advanced security for data at rest by the encryption of data volumes. Encryption is a technology that converts data or information into code that can be decrypted only by authorized users.
You can encrypt Access Appliance data volumes to:
Protect sensitive data from unauthorized access.
Retire disks from use or ship them for replacement without the overhead of secure wiping of content.
Encryption is implemented using the Advanced Encryption Standard (AES) cryptographic algorithm with 256-bit key size validated by the Federal Information Processing Standard (FIPS) Publication 140-2, (FIPS PUB 140-2) security standard.
When you create file systems in Access Appliance on encrypted volumes using this feature, Access Appliance generates a volume encryption key at the time of file system creation. This encryption key is encrypted (wrapped) using a different key that is retrieved from a Key Management Server (KMS). The wrapped key is stored with the volume record. The volume encryption key is not stored on disk.
Access Appliance supports the use of a KMS that conforms to the OASIS Key Management Interoperability Protocol (KMIP) version 1.1 specification.
During creation of encrypted volumes:
Access Appliance sends a key generation request to the configured KMS using the Key Management Interoperability Protocol (KMIP) protocol.
The KMS responds with a unique identifier. Access Appliance sends the identifier to the KMS to obtain the key that is generated by the KMS.
The KMS responds with the key. Access Appliance generates the random volume encryption key, and encrypts it using the key that is provided by the KMS.
Access Appliance stores the encrypted key and the KMS identifier in the volume record.
During startup of encrypted volumes:
Access Appliance retrieves the encrypted key and the KMS identifier from the volume record.
Access Appliance sends the identifier to the KMS to obtain the key.
The KMS responds with the key. Access Appliance decrypts the encrypted key (stored in the volume record) with the key provided by the KMS.
Note:
Veritas recommends that you use CPUs designed to support Advanced Encryption Standard Instruction Set (or the Intel Advanced Encryption Standard New Instructions (AES-NI) to improve performance.
Veritas recommends that you use IBM Secure Key Lifecycle Manager (SKLM), which supports KMIP protocol version 1.1, as a KMS server for this feature.
To register a Access Appliance cluster with the IBM SKLM KMS server
- Install the IBM SKLM server on any system in your environment. You can visit this URL to find the supported IBM SKLM servers with Access Appliance. Obtain the KMS server's public certificate in base64 format using its admin GUI console or the CLI.
- In the Access Appliance GUI management console, go to Settings > Services Management to register the Access Appliance cluster with the KMS server.
- Ensure that the time on the Access Appliance server and IBM SKLM server are in sync.
- Select Provide Key & Certificates to generate self-sign certificates for the Access Appliance cluster. Provide the KMS server's public SSL certificate in the same window.
- Configure KMS Server gets activated now. Select this tab to enter the KMS server-related details.
- Use the IBM SKLM server's GUI-based management to accept the client request from the Access Appliance cluster and to accept its SSL keys.
You can use the Storage> fs create command to create the file system with the encrypt=on option.
storage> fs create mirrored fs2 1g 2 pool1 protection=disk blksize=8192 pdir_enable=no encrypt=on
You can use the storage encryption feature in the GUI by activating the secure data storage policy. You can add new NFS and CIFS shares using the activated policy.
Note:
Use the encrypt=on option for all the file systems.