Chapter 10—Encryption and Key Management BlueScale Key Management
August 2017 User Guide—Spectra T50e Library
299
ThefollowingpasswordsarerequiredwithbotheditionsofBlueScale
Encryption:
SuperuserPassword—Onlyauserloggedintothelibrarywith
superuserprivilegescanaccesstheEncryptionUserLoginscreen.
EncryptionPassword—Letsyouaccessencryptionfeatures.This
passwordmustbeenteredafterthesuperuserlogin.
Password(s) for Key Import and Export Passwordsarealsousedtoencrypt
keysforexportandwhenimportingpreviouslyexportedkeys.Yoursite
mayconsiderwhethertocreatedifferentrulesforthesepasswords,suchas
requiringthatthesepasswordsarelongerthantheencryptionaccess
password(s),andthereforemoresecure.Optionally,inProfessional
Edition,youcanrequiretwodifferentpasswordsinordertoimportand
exportkeys.
Monikers Amonikerisanalphanumericidentifierthatistiedtothenever‐
revealedtruekeyvalue,whichisa256‐bitencryptionkey.Thelibraryuses
monikerstogenerateuniqueencryptionkeys.Thelibrarydisplaysthe
moniker,nottheencryptionkeyitself,wheneveritreferencesthe
encryptionkey.Theactualvalueofanencryptionkeyisneverdisplayed.
Themonikerhelpstoprotectdataencryptedusingthekeybyeliminating
theneedtodisplayortypetheactualkeyvalue.
Yoursitemaywanttocreaterulesgoverningnamingconventionsforkey
monikerstoensurethateachkeyisunique.
RecommendedMakeahabitofusingasinglecase(allupperoralllower)
formonikers.Aftertheencryptionkeyiscreatedandexported,thelibrary
ignoresthecaseusedinthemoniker.
Forexample,thelibraryinterpretsSpectra1,spectra1,andSPECTRA1as
thesamemonikerwhenimportingakey.However,thekeygeneratedby
eachvariationisunique.
Password and Moniker Standards Createstandardstogovernpasswords
andmonikernamesbasedonyoursite’ssecurityrequirements.For
example,ifyoursiterequiresahighlevelofsecurityforaccessto
encryptionpartitions,yourpasswordsandmonikersmayneedto
incorporatesomecombinationofthefollowingrequirements:
Useaminimumnumberofcharacters.
Usebothalphabeticcharactersandnumericcharacters.
Usebothuppercaseandlowercaselettersforpasswords.
Donotusewordsfoundinadictionary.
Changethepasswordsatregularlyscheduledintervals.
If you create two monikers that are identical except for case, you may not be able to
retrieve your data after importing a key that was created using a different variation
of the moniker.