Adding key manager configuration details
Prerequisites
• Configure iLO Settings privilege
• An iLO license that supports this feature is installed.
Procedure
1.
Click
Administration
in the navigation tree, and then click the
Key Manager
tab.
The listed
iLO Account on ESKM
account name is
ilo-<iLO MAC address>
. The account name is
read-only and is used when iLO communicates with the ESKM.
2.
Enter the following information in the
iLO Account on ESKM
section:
•
Group
•
ESKM Local CA Certificate Name
(optional)
3.
Enter the following information in the
ESKM Administrator Account
section:
•
Login Name
•
Password
4.
Click
Update ESKM
.
iLO verifies that an account named
ilo-<iLO MAC address>
exists on the ESKM.
If the account exists, iLO verifies that the account password is correct. iLO generates this password
automatically. If the password is incorrect, iLO updates the password. The password might be
incorrect if iLO was restored to the factory default settings. If the account does not exist, iLO creates it.
If iLO is not a member of an ESKM Local Group, it will try to create a group with the requested name.
If iLO is already a member of an ESKM Local Group, it ignores the group entered in step 2, and uses
the existing group assignment that is present on the ESKM. Attempted group changes in iLO do not
affect current key group permissions that are set on the ESKM. If a new group assignment is needed,
update the ESKM before updating the iLO settings.
If you entered the
ESKM Local CA Certificate Name
in step 2, certificate information is listed in the
Imported Certificate Details
section of the ESKM page.
Testing the ESKM configuration
Use the Test ESKM Connections feature to verify the configuration settings. The tests confirm that iLO
and the ESKM servers are set up to provide key management services for HPE Secure Encryption.
During the test, iLO attempts the following tasks:
• Connects to the primary ESKM server (and secondary ESKM server, if configured) by using TLS.
• Tries to authenticate to the ESKM by using the configured credentials and account.
• Confirms that the version of the ESKM software is compatible with iLO.
216
Adding key manager configuration details