Unsolved

This post is more than 5 years old

18527

September 25th, 2010 15:00

A question on using Self Encrypting Drives

I have a Dell R710 with an H700 Perc with the 146GB Seagate drives and was testing out using the features of this drive and Perc.

So on my R710 I have a 300 GB non-encrypting drive which is running RedHat 5.5 (whatever the lastest release is).

I setup two 146GB sed's into a raid 1 mirror and then went into the PERC set the passphase to activate the SED

features. 

I used omsa 6.3 software after the system booted and saw they were secure.

Now I want to test the following:

I want to change the passphrase so now the data on the disk cannot be read.

I halted and powered off the system and rebooted it .  The Perc sees the two

virtual disks.  Disk 1 being the unencrypted disk (sdb) and the the second virtual disk

being the mirror set as drive sda.

First to my surprise the system did see the partition and allows it to be mounted.

Second I did a dd (copy from disk sectors) and checked to see if I could find my

original file of 10Gb of A's.  Again to my surprise I could see them.

My understanding is if you change the passphrase then the disk should not

be readable (as it is encrypting with new passphrase).  However it appears

not to me working.

What we want to do is setup an virtrual disks array that is encrypted and then

remove the disks and change the passphrase and allow a new set of disks

to run.  The original disks would be shelfed until they are needed at which

time we change the passphrase back and then place that original set in

the system and they could be read. 

I have read the h700 technical and user guides and also the OMSA

manuals and the storage manuals.

 

Questions:

1.  Why did changing the passphrase have no effect on reading the data that was encrypted with a different passphrase

2.  Does Dell have any better technical documentation on how to use these SED disks.

3.  How does the escrow file work on omconfig. This section just talks about it saving to a filepath but

does not discuss it much it detail.  Such as what is stored and in what format?  Can you retreive a key

from this file, etc.

4.  How is the security key identifier used?  Just to associate it with a passphrase?  Can a security id have several

passphrases or is it a one to one relationship?  When I changed my passphrase above I did not change the key id, should I have?

5.  It states you are allowed to have one security key per controller at a time.  Are the old ones stored anywhere or just replaced.

6.  Can you have many virtual disks use the one security key?

 

7 Posts

November 19th, 2010 23:00

I actually bought the Seagate Constellation 2TB 6Gb/s drives for my Dell T710 with Perc H700. I have the RAID set to secure and working fine. But here is the catch if someone steals the drives sure they cannot access the encrypted data. But if they steal the whole server or JUST the Perc H700 controller & your drives and put it in another server ie: T710 they can access all your data with no problem.


I have contacted Dell regarding this, but they have no clue or any answers. Technically it is not worth buying these SED drives with such a controller in place. This is just a bump on a road. You are still best to use Bitlocker/Truecrypt...But that has its perks if you are doing replication....

 

Kam

No Events found!

Top