Dell PowerVault TL2000 Dell PowerVault ML6000 Encryption Key Manager User's - Page 48

Using CLI Commands to Define Key Groups, Submit Changes, createkeygroup, createkeygroup -password

Page 48 highlights

a14m0245 Figure 3-10. Delete Drive 3. Select the tape drive from the Drive List. 4. Verify the drive name at the bottom of the window and click Submit Changes. Using CLI Commands to Define Key Groups The Encryption Key Manager has a key group feature that allows you to group sets of keys. Once the Encryption Key Manager application is installed and configured (keystore and keys generated) and the Encryption Key Manager server is started, log in to into the server using the client and follow these steps: 1. Run the createkeygroup command. This command creates the initial key group object in the KeyGroups.xml file. Run this only once. Syntax: createkeygroup -password password -password The password that is used to encrypt the keystore's password in the KeyGroups.xml file for later retrieval. The keystore encrypts the key group's key, which in turn encrypts each individual key group alias password. Therefore no key in the KeyGroups.xml file is in the clear. Example: createkeygroup -password a75xynrd 2. Run the addkeygroup command. This command creates an instance of a key group with a unique Group ID in the KeyGroups.xml. 3-18 Dell Encryption Key Mgr User's Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122

3.
Select the tape drive from the Drive List.
4.
Verify the drive name at the bottom of the window and click
Submit Changes
.
Using CLI Commands to Define Key Groups
The Encryption Key Manager has a key group feature that allows you to group
sets of keys.
Once the Encryption Key Manager application is installed and configured (keystore
and keys generated) and the Encryption Key Manager server is started, log in to
into the server using the client and follow these steps:
1.
Run the
createkeygroup
command.
This command creates the initial key group object in the KeyGroups.xml file.
Run this only once.
Syntax:
createkeygroup -password
password
-password
The
password
that is used to encrypt the keystore’s password in the
KeyGroups.xml file for later retrieval. The keystore encrypts the key
group’s key, which in turn encrypts each individual key group alias
password. Therefore no key in the KeyGroups.xml file is in the clear.
Example:
createkeygroup -password a75xynrd
2.
Run the
addkeygroup
command.
This command creates an instance of a key group with a unique Group ID in
the KeyGroups.xml.
a14m0245
Figure 3-10. Delete Drive
3-18
Dell Encryption Key Mgr User's Guide