Creating an Encryption Key and Enabling LKM
About this task
Steps
- Select the Enable Local Key Management (LKM) option.
-
Type
Encryption Key Identifier.
An Encryption Key Identifier can contain numerals, alphabets both lower and upper case are allowed, nonalphanumeric characters, or a combination of any of these.NOTE: For the Encryption Key Identifier and Passphrase guidelines, click the
icon on the page.
-
Type a
Passphrase.
A Passphrase must contain at least one numeral, alphabets both lower and upper case , and one nonalphanumeric character (except space).NOTE: PERC 12 controllers allow the space character in addition to the above passphrase acceptance rule.NOTE: Server Administrator Storage Management provides a suggested passphrase below the Passphrase text box.
-
If you want to save the Encryption Key credentials in a file on the managed node, select the
Escrow
check box.
The file is saved in the location C:\Windows for Microsoft Windows operating system and /var/log for Linux and ESXi operating system which contains a filename as dell_<ControllerModel>_<SASAddress>.xml. The saved file contains the information: SAS address, Encryption Key Identifier, Passphrase, and modified date. You can use this file for future reference.CAUTION: To understand that if you lose the Passphrase, you cannot recover it. If you move the physical disks that are associated with the lost Passphrase to another controller or if the controller fails or is replaced, you cannot access data from that disk.NOTE: If Encryption Key Identifier or Passphrase contain special characters such as & , " , <, and >, in the file, they are written as & , ", < and > respectively.NOTE: If the system crashes while the file is created, the backup file is saved in the specified location.
-
Select the check-box indicating that you understand the implications of using a passphrase and click
Apply Changes.
In the controller Information/Configuration page, the Encryption Key Present is set to Yes and the Encryption mode is set to LKM.