Migrating a GuardPoint Out of CTE-LDT
Migrating a GuardPoint from CTE-LDT removes the security encryption. It also provides an Administrator with the flexibility to relax the compliance requirement, when strict compliance for frequent key rotation on specific data is no longer mandatory. The following sections describe how to migrate a GuardPoint from CTE-LDT to a non-CTE-LDT policy, or to remove encryption protection from it.
Converting a GuardPoint from an LDT Policy to a Standard Policy
If you want to do more than just change the policy on a GuardPoint from an CTE-LDT policy to a non-CTE-LDT policy, see Deleting CTE-LDT Metadata (Linux) or Deleting CTE-LDT Metadata (Windows).
Note
Converting LDT CIFS/NFS GuardPoints from Live Data Transformation policies to Standard CTE policies is not supported. Similarly, LDT CIFS/NFS-protected GuardPoints cannot be migrated to clear_key.
-
Clone the versioned key associated with the CTE-LDT GuardPoint to a non-versioned key.
The clone function creates a new key with the same cryptographic encryption material as the current version of the cloned versioned key.
This allows CTE-LDT to use the cloned key in a non-CTE-LDT policy to convert the GuardPoint from an CTE-LDT to a non-CTE-LDT managed policy.
-
In the CipherTrust Manager Applications Page, open the Keys & Access Management application.
-
Click the name of the versioned key that you want to clone.
-
In the Key Details area, click the (...) button at the end of the row showing the current version of the key and select Clone to clone the current version.
-
Enter a new name for the key in the Key Name field. Do not select the CTE Versioned option for the clone.
-
Click Clone.
-
-
Open the CTE application and click Clients in the left-hand menu bar.
-
Click on the name of the client whose GuardPoint you want to migrate.
-
Find the GuardPoint you want to migrate in the GuardPoints table, then click the (...) button at the end of the row and select Disable.
-
After CTE-LDT disables the GuardPoint, click the (...) button at the end of the row and select Remove.
-
(Linux only) Ensure that the GuardPoint is removed on the managed host:
secfsd -status guard No ${gp}s configured
-
CTE-LDT creates extended attributes for every file under the GuardPoint as well as the GuardPoint directory. Now that the CTE-LDT policy does not manage the GuardPoint, you must remove the extended attributes for every file in the GuardPoint, type:
voradmin ldt attr delete /<${gp}>
-
The command may take some time depending on the number of files in the GuardPoint.
Note
For all of the file system mount points that contain an CTE-LDT protected GuardPoint, you must clean up the metadata first. See Deleting CTE-LDT Metadata (Linux).
-
Create a non-CTE-LDT policy using the cloned key you created earlier in this procedure.
-
In the CTE application, click Policies in the left-hand menu bar and then click Create Policy.
-
Enter a name for the policy in the Name field.
-
In Policy Type, choose Standard.
-
Click Next.
-
On the Security Rules page, click Next to skip adding a security rule.
-
On the Key Selection Rules, click Create Key Rule.
-
In the Key Name field, select the cloned key you created earlier.
-
Click Add.
-
Click Next
-
Confirm that the key rule is correct and click Save.
-
-
Apply the non-CTE-LDT policy to the GuardPoint.
Caution
Make sure that you have removed all of the CTE-LDT metadata from the GuardPoint before applying the non-CTE-LDT policy.
-
Open the CTE application and click Clients in the left-hand menu bar.
-
Click on the name of the client whose GuardPoint you want to migrate.
-
Click Create GuardPoint.
-
In the Create GuardPoint dialog box, select the Policy that you just created in the Policy field.
-
Select the Type: Auto Directory or Manual Directory.
-
In the Path field, and enter or browse to the directory to protect.
-
When you are done, click Create.
-
Remove Protection from a GuardPoint
When compliance may no longer require protecting data in a GuardPoint, you may choose to unprotect/decrypt it. Before removing protection from your GuardPoint, you must decrypt the data in your GuardPoint by setting it to clear. You have two options to decrypt your data:
-
While a GuardPoint is protected and enabled under an CTE-LDT policy, you can use copy or backup/restore commands to save files in your GuardPoint to a location outside of your GuardPoint.
-
Use the dataxform command to transform your GuardPoint to clear in an offline transformation process.
For GuardPoints over NFS, you must backup the entire GuardPoint before you unguard the GuardPoint. Then you can restore the files from backup over the GuardPoint directory after you remove the protection on the GuardPoint.
Copying Files to Decrypt Them
If you choose to copy your files, you must create a directory outside of the GuardPoint and then copy the files into the GuardPoint directory. After finishing copying, complete the following steps:
-
Open the CTE application and click Clients in the left-hand menu bar.
-
Click on the name of the client whose GuardPoint you want to remove.
-
Find the GuardPoint you want to remove in the GuardPoints table, then click the (...) button at the end of the row and select Disable.
-
After CTE-LDT disables the GuardPoint, click the (...) button at the end of the row and select Remove.
-
(Linux only) Ensure that the GuardPoint is removed on the managed host:
secfsd -status guard No ${gp}s configured
This completes removal of the GuardPoint under an CTE-LDT policy. You can now remove the original files and data within the GuardPoint namespace.
Using Dataxform Command to Transform the Files
If you choose to use the dataxform command to transform data in your GuardPoint to clear, use the voradmin
command to verify that earlier versions of the versioned key are not in use on your GuardPoint. Complete the following steps to clear all metadata in your GuardPoint. Then, transform your GuardPoint to clear.
-
Clone the versioned key associated with the CTE-LDT GuardPoint to a non-versioned key.
-
In the CipherTrust Manager Applications Page, open the Keys & Access Management application.
-
Click the name of the versioned key that you want to clone.
-
In the Key Details area, click the (...) button at the end of the row showing the current version of the key and select Clone to clone the current version.
-
Enter a new name for the key in the Key Name field. Do not select the CTE Versioned option for the clone.
-
Click Clone.
-
-
Create a Standard policy using the cloned key you just created.
-
In the CTE application, click Policies in the left-hand menu bar and then click Create Policy.
-
Enter a name for the policy in the Name field.
-
In Policy Type, choose Standard.
-
Enable the Data Transformation option.
-
Click Next.
-
On the Security Rules page, click Next to skip adding a security rule.
-
On the Key Selection Rules, click Create Key Rule.
-
In the Key Name field, select the cloned key you created earlier.
-
Click Add, then click Next.
-
On the Data Transformation page, click Create Data Transformation Rule.
-
In the Transformation Key Name field, select
clear_key
. -
Click Add, then click Next.
-
Confirm that the key rule and data transformation rule are correct and click Save.
-
-
Click Clients in the left-hand menu bar.
-
In the Clients table, click on the name of the client whose GuardPoint you want to remove.
-
Find the GuardPoint you want to remove in the GuardPoints table, then click the (...) button at the end of the row and select Disable.
-
After CTE-LDT disables the GuardPoint, click the (...) button at the end of the row and select Remove.
Before you apply the offline data transformation policy to your GuardPoint, you must clean up the CTE-LDT metadata from your GuardPoint. CTE-LDT creates extended attributes for every file under the GuardPoint, as well as the GuardPoint directory. Now that the CTE-LDT policy does not manage the GuardPoint, you can remove the extended attributes for every file in the GuardPoint.
-
Remove the extended attributes of files in a GuardPoint, type:
voradmin ldt attr delete <${gp}>
The command may take some time depending on the number of files in the GuardPoint. After metadata deletion is complete, you can apply the offline transformation policy on the GuardPoint.
-
CipherTrust Manager, guard and enable the GuardPoint with the Standard policy you created earlier.
-
After enabling your GuardPoint, run the dataxform command on the managed host to transform the GuardPoint to a
clear_key
, type:dataxform --rekey --gp /<${gp}>/ --preserve_modified_time --preserve_access_time --cleanup_on_success
-
After completion of dataxform, unguard the GuardPoint.
-
Remove the GuardPoint from the dataxform policy in CipherTrust Manager.