Backing Up Keys of an HP-UX EVFS Volume

This section describes how to back up the keys of an HP-UX EVFS volume by using HP OpenView Storage Data Protector.

EVFS uses symmetric volume encryption keys to encrypt the volume data. EVFS also uses public and private keys to encrypt the volume encryption keys, and it uses passphrases to encrypt private keys. Hence, it is critical to back up the keys along with the data. The keys that are backed up include the public keys, private keys, and passphrase files in the default key storage directory

(/etc/evfs/pkey).

Note:

You must back up the keys of an HP-UX EVFS volume when you back up the data on HP-UX EVFS volumes. However, for security reasons, HP recommends that you back up the keys of an HP-UX EVFS volume to a backup medium, which is different from the backup medium on which the data is backed up.

Table 5 lists the source and the target for the backup of keys of an HP-UX EVFS volume.

Table 5 Source and Target for the Backup of Keys of an HP-UX EVFS Volume

Source/Target

Description

 

 

Source

Key directory structure on the client

 

system (where HP-UX EVFS is

 

configured)

 

 

Target

Tape device or a file library device

 

 

To back up the keys of an HP-UX EVFS volume by using HP OpenView Storage Data Protector, complete the following steps:

Note:

You must back up the keys whenever the keys are modified.

Step 1 To create a sample HP-UX EVFS volume, complete the following tasks:

(This step is not necessary if the source HP-UX EVFS volume already exists with the keys.)

1.Create a source LVM volume for the HP-UX EVFS volume.

2.Create HP-UX EVFS volume device files by mapping the LVM volume to EVFS.

3.Generate user keys for the EVFS volume.

Step 2 Back up the keys of the HP-UX EVFS volume to the tape, or a file library device by using HP OpenView Storage Data Protector. For more information on using HP OpenView Storage Data Protector, see the HP Data Protector Software website at:

http://www.hp.com/go/dataprotector

For more information on using HP OpenView Storage Data Protector to back up keys of an HP-UX EVFS volume, see Test Scenario 3A.

8