Arctera

New secure configuration file format for storing SecureFS configuration data

When you configure SecureFS in InfoScale releases prior to 9.0, the SecureFS configuration data is stored in a job configuration file that is visible and accessible in the user namespace. If the file is compromised or deleted, it can break the SecureFS functionality altogether.

For enhanced security and resiliency, this release introduces a new structural file type that stores the SecureFS configuration data in a secure and non-user-accessible location. You cannot access or write anything directly to this file. The new secure file format is the default format for storing all SecureFS configurations that are created in InfoScale version 9.0 and later.

When you upgrade InfoScale from an earlier version to 9.0, you have to manually convert the SecureFS configuration file format to the new secure format. It is not done automatically after an InfoScale upgrade. You must first perform a disk layout version (DLV) upgrade to version 18 and then update the configuration file format using the vxschadm command.

Refer to the Storage Foundation 9.0 Administrator’s Guide - Linux or the Storage Foundation Cluster File System High Availability 9.0 Administrator’s Guide - Linux for more details about SecureFS and the secure structural file type.

New secure configuration file format for storing SecureFS configuration data

In this article