
Security key and RAID management
Security key implementation
The Dell PowerEdge RAID Controller (PERC) 10 series of cards support Self-Encrypting Disks (SED) for protection of data against loss or
theft of SEDs. Protection is achieved by the use of encryption technology on the drives. There is one security key per controller. You can
manage the security key under Local Key Management (LKM). The key can be escrowed in to a file using Dell OpenManage storage
management application. The security key is used by the controller to lock and unlock access to encryption-capable physical disks. In order
to take advantage of this feature, you must:
1
Have SEDs in your system.
2
Create a security key.
Security key management in the HII configuration
utility
The Dell OpenManage storage management application and the
HII Configuration Utility
of the controller allow security keys to be created
and managed as well as create secured virtual disks. The following section describes the menu options specific to security key management
and provide detailed instructions to perform the configuration tasks. The contents in the following section apply to the
HII Configuration
Utility
. For more information on the management applications, see
Management applications for PERC cards
•
The
Controller Management
screen displays controller information and action menus. You can perform the following security-related
actions through the controller management menu:
–
Security Key Management
—Creates, changes, or deletes the security settings on a controller.
•
The
Virtual Disk Management
screen displays physical disk information and action menus. You can perform the following security
related actions through the virtual disk management menu:
–
Secure Disk Group
—Secures all virtual disks in disk group.
–
Create secure virtual disk
—Creates a new virtual disk that is secured with the security key on the controller.
•
The
Physical Disk Management
screen displays physical disk information and action menus. You can perform the following security-
related actions through the physical disk management menu:
–
Cryptographic Erase
—Permanently erases all data on the physical disk and resets the security attributes.
For more information on the Physical Disk Management screen and the Virtual Disk Management screen, see
Local Key Management
You can use Local Key Management (LKM) to generate the key ID and the passphrase required to secure the virtual disk. You can secure
virtual disks, change security keys, and manage secured foreign configurations using this security mode.
NOTE:
Under LKM, you are prompted for a passphrase when you create the key.
8
Security key and RAID management
61