Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

PowerScale OneFS 9.3.0.0 CLI Administration Guide

Enabling external key management

You can enable external key management for self-encrypting drives (SED).

Prerequisites:
  • A OneFS cluster of nodes made up of self-encrypting drives (SEDs)
  • A KMIP 1.2 compatible external key management server
    • Dell Technologies CloudLink Center 6.0
    • Gemalto KeySecure 8.7 k150v
    • KeySecure k170v
    • IBM Secure Key Lifecycle Manager (SKLM) v2.6.0.2; v2.7.0.0; v3.0.0
    • Thales e-Security keyAuthority 4.0
  • Certificates using X.509 PKI for TLS mutual authentication
  • Network connectivity between the OneFS cluster and the external key management server

For more information about external key management, see the OneFS Data-at-Rest Encryption whitepaper.

To enable external key management, follow these steps:
  1. Run the isi keymanager kmip servers create command to enable an external key management server. The following command enables an external key management server with ID of 1, with the hostname of key.management.onefs.com, with a server certificate at /ifs/certificates/onefs_kmip_ca.pem, and a client certificate at /ifs/certificates/onefs_client_bundle.pem.
    isi keymanager kmip servers create 1 key.management.onefs.com /ifs/certificates/onefs_kmip_ca.pem /ifs/certificates/onefs_client_bundle.pem 
  2. (Optional) To view configuration information about the external key management server, run the following command where <ID> is the id of the server you want to view.
    isi keymanager kmip servers view 1
OneFS confirms the connectivity between the OneFS server and the external key management server. Once confirmed, the external key management server is ready for SEDs to be migrated.

Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\