HP B-series Fabric OS 7.0.2d Release Notes (5697-2822, August 2013--includes all 7.0.x versions)
• HP SKM/ESKM are supported with Multiple Nodes and Dual SKM/ESKM Key Vaults. Two-way
certificate exchange is supported. See the Encryption Admin Guide for configuration
information. If you are using dual SKM/ESKMs on HP StorageWorks Encryption SAN
Switch/HP StorageWorks DC Switch Encryption FC Blade Encryption Group, then these
SKM/ESKM appliances must be clustered. Failure to cluster results in key creation failure.
Otherwise, register only one SKM/ESKM on the HP StorageWorks Encryption SAN Switch/HP
StorageWorks DC Switch Encryption FC Blade Encryption Group.
• With Windows and Veritas Volume Manager/Veritas Dynamic Multipathing, when LUN sizes
less than 400 MB are presented to HP StorageWorks Encryption SAN Switch for encryption,
a host panic may occur and this configuration is not supported in the Fabric OS 6.3.1 or later
release.
• Hot Code Load from Fabric OS 6.4.1a to Fabric OS 7.0.0a or later is supported.
Cryptographic operations and I/O are disrupted, but other layer 2 FC traffic is not disrupted.
• When disk and tape CTCs are hosted on the same encryption engine, re-keying cannot be
done while tape backup or restore operations are running. Re-keying operations must be
scheduled at a time that does not conflict with normal tape I/O operations. The LUNs should
not be configured with auto rekey option when single EE has disk and tape CTCs.
• For new features added to encryption in Fabric OS 6.4.0, such as, disk device
decommissioning, combined disk-tape encryption support on the same encryption engine,
and redundant key ID metadata option for replication environments, all the nodes in the
encryption group must be running Fabric OS 6.4.0 or later versions of Fabric OS. Firmware
downgrade is prevented from Fabric OS 6.4.0 to an earlier version if one or more of these
features are in use.
• Special Notes for HP Data Protector backup/restore application:
For the Tape Pool encryption policy specification on Windows Systems, HP Data Protector
can be used with tape pool encryption specification only if the following pool label options
are used (for other options, behavior defaults to Tape LUN encryption policy):
◦
– Pick from Barcode
– User Supplied; no more than nine characters
◦ On HP-UX systems, HP Data Protector cannot be used with tape pool encryption
specification for any of the pool options. The behavior defaults to Tape LUN Encryption
Policy.
◦ For the Tape LUN encryption policy specification, no restrictions, tape LUN encryption
policy specification can be used with HP Data Protector on HP-UX and Windows systems.
• HP StorageWorks Encryption SAN Switch/HP StorageWorks DC Switch Encryption FC Blade
rejects the SCSI commands write same and extended copy, which are related to VAAI
(vStorage APIs for Array Integration) hardware acceleration in vSphere 4.1. This results in
non-VAAI methods of data transfer for the underlying arrays, and may affect the performance
of VM related operations.
FCIP (HP DC SAN Director Multiprotocol Extension Blade, HP 1606 SAN Extension Switch and
HP StorageWorks B-series Multi-protocol Router Blade)
• Any firmware activation disrupts I/O traffic on FCIP links.
• Latency measurements supported on FCIP Tunnels are for 1 GbE & 10 GbE a 200 ms round
trip time and 1% loss.
• After inserting a 4 Gbps SFP in GE ports of an HP DC SAN Director Multiprotocol Extension
Blade or HP 1606 SAN Extension Switch, sometimes sfpshow output might display Cannot
read serial data! . Removing and re-inserting the SFP should resolve this issue. HP
22