data:image/s3,"s3://crabby-images/6792c/6792c192b11145eac018c8ff0b878a6fdb67b151" alt="Nvidia DGX Station A100 User Manual Download Page 36"
Managing Self-Encrypting Drives on DGX Station A100
DGX Station A100
DU-10189-001 _v5.0.2 | 30
5.2.
Installing the
nv-disk-encrypt
Package
Use the package manager to install the
nv-disk-encrypt
package.
You can also optionally install the TPM2 tools package and reboot the system. The TPM tools
package is required if you plan use the TPM2 to store security keys.
1. Update the packages.
$
sudo apt update
2. Install the
nv-disk-encrypt
package.
$
sudo apt install -y nv-disk-encrypt
3.
Optional:
Install
tpm2-tools
.
$
sudo apt install -y tpm2-tools
4. Reboot the system.
$
sudo reboot
If you plan to use TPM2, ensure that you enable it. See
5.3.
Initializing the System for Drive
Encryption
Here is some information about how you can initialize your DGX system for drive encryption.
Note:
Before you initialize drive encryption, see
and, if
necessary, complete the configuration instructions.
Initialize the system for drive encryption using the nv-disk-encrypt command.
$
sudo nv-disk-encrypt init [-k <your-vault-password>] [-f <path/to/ json-file>] [-g] [-
r]
Here are the options:
‣
k
lets you create the vault password within the command. Otherwise, the software will
prompt you to create a password before proceeding.
‣
-f
lets you specify a JSON file that contains a mapping of passwords to drives.
Example 1: Passing in the JSON File
‣
-g
generates random salt values (stored in /etc/nv-disk-encrypt/
.dgxenc.salt) for each drive password. NVIDIA strongly recommends using this option
for best security, otherwise the software will use a default salt value instead of a
randomly generated one.
‣
-r
generates random passwords for each drive.