Sun Microsystems, Inc.  Sun System Handbook - ISO 3.4 June 2011 Internal/Partner Edition
   Home | Current Systems | Former STK Products | EOL Systems | Components | General Info | Search | Feedback

Asset ID: 1-71-1021080.1
Update Date:2011-03-01
Keywords:

Solution Type  Technical Instruction Sure

Solution  1021080.1 :   KMS - 2.x Passwords, Passphrase and Quorums  


Related Items
  • Sun StorageTek Crypto Key Management System
  •  
  • Oracle Key Manager
  •  
Related Categories
  • GCS>Sun Microsystems>Storage - Tape>Encryption KMS
  •  

PreviouslyPublishedAs
270470


Applies to:

Sun StorageTek Crypto Key Management System - Version: Not Applicable and later   [Release: N/A and later ]
Oracle Key Manager - Version: 2.0.0 and later    [Release: 2.0 and later]
All Platforms
Checked for relevance on 1-Mar-2011.

Goal

It is the customers responsibility to record and safeguard KMS user Logins, Quorums and Pass-phrases.
If customer looses this information, Tier-3 Support and Engineering are unable to reset any of the passwords.

Solution

Steps to Follow
Options:
If a customers KMS Manager login is locked out, then customer can still login to the KMS console via ELOM and reset the passphrase. The user is only locked out from the KMS Manager.
The customer does still need to remember the passphrase to login to KMS console, but their is no limit on attempts.

If customer forgets all security login passphrases, then customer will need to replace all KMA's in the cluster.
If customer has a backup of keys and core security then customer can restore cluster from these files, but customer will need to know his quorum users and passphrases to restore the key database.
If customer does not know this information they need to be aware that they are then looking at a complete loss of customer key data.

Please consult the KMS 2.0 Disaster Recovery Reference Manual




Attachments
This solution has no attachment
  Copyright © 2011 Sun Microsystems, Inc.  All rights reserved.
 Feedback