I would like to make sure at-rest encryption is done in one place and correctly. If there's shared storage, that seems like the right place rather than DAS.
Mainly I'd like to cover the case of drives being recovered without keys and the keys be required when the SAN boots (should be a rare event to not be a pain but also cover the case of someone stealing the whole kit and caboodle).
To attach to the SAN you need iSCSI (with credentials) or be on the FC switch.
This seems like it would cover database and NAS cases.
What's right or wrong with this?