Unsolved
This post is more than 5 years old
4 Posts
0
18527
September 25th, 2010 15:00
A question on using Self Encrypting Drives
I have a Dell R710 with an H700 Perc with the 146GB Seagate drives and was testing out using the features of this drive and Perc.
So on my R710 I have a 300 GB non-encrypting drive which is running RedHat 5.5 (whatever the lastest release is).
I setup two 146GB sed's into a raid 1 mirror and then went into the PERC set the passphase to activate the SED
features.
I used omsa 6.3 software after the system booted and saw they were secure.
Now I want to test the following:
I want to change the passphrase so now the data on the disk cannot be read.
I halted and powered off the system and rebooted it . The Perc sees the two
virtual disks. Disk 1 being the unencrypted disk (sdb) and the the second virtual disk
being the mirror set as drive sda.
First to my surprise the system did see the partition and allows it to be mounted.
Second I did a dd (copy from disk sectors) and checked to see if I could find my
original file of 10Gb of A's. Again to my surprise I could see them.
My understanding is if you change the passphrase then the disk should not
be readable (as it is encrypting with new passphrase). However it appears
not to me working.
What we want to do is setup an virtrual disks array that is encrypted and then
remove the disks and change the passphrase and allow a new set of disks
to run. The original disks would be shelfed until they are needed at which
time we change the passphrase back and then place that original set in
the system and they could be read.
I have read the h700 technical and user guides and also the OMSA
manuals and the storage manuals.
Questions:
1. Why did changing the passphrase have no effect on reading the data that was encrypted with a different passphrase
2. Does Dell have any better technical documentation on how to use these SED disks.
3. How does the escrow file work on omconfig. This section just talks about it saving to a filepath but
does not discuss it much it detail. Such as what is stored and in what format? Can you retreive a key
from this file, etc.
4. How is the security key identifier used? Just to associate it with a passphrase? Can a security id have several
passphrases or is it a one to one relationship? When I changed my passphrase above I did not change the key id, should I have?
5. It states you are allowed to have one security key per controller at a time. Are the old ones stored anywhere or just replaced.
6. Can you have many virtual disks use the one security key?


kyaride
7 Posts
0
November 19th, 2010 23:00
I actually bought the Seagate Constellation 2TB 6Gb/s drives for my Dell T710 with Perc H700. I have the RAID set to secure and working fine. But here is the catch if someone steals the drives sure they cannot access the encrypted data. But if they steal the whole server or JUST the Perc H700 controller & your drives and put it in another server ie: T710 they can access all your data with no problem.
I have contacted Dell regarding this, but they have no clue or any answers. Technically it is not worth buying these SED drives with such a controller in place. This is just a bump on a road. You are still best to use Bitlocker/Truecrypt...But that has its perks if you are doing replication....
Kam