A KMS can be set up in Grid Manager before or after the appliance is installed in StorageGRID. See the
information about KMS and appliance configuration in the instructions for administering StorageGRID for
additional details.
• If a KMS is set up before installing the appliance, KMS-controlled encryption begins when you enable node
encryption on the appliance and add it to a StorageGRID site where KMS is configured.
• If a KMS is not set up before you install the appliance, KMS-controlled encryption is performed on each
appliance that has node encryption enabled as soon as a KMS is configured and available for the site that
contains the appliance node.
Data that exists prior to connecting to the KMS on an appliance that has node encryption
enabled is encrypted with a temporary key that is not secure. The appliance is not protected
from removal or theft until the key is set to a value provided by the KMS.
Without the KMS key needed to decrypt the disk, data on the appliance cannot be retrieved and is effectively
lost. This is the case whenever the decryption key cannot be retrieved from the KMS. The key becomes
inaccessible if a customer clears the KMS configuration, a KMS key expires, connection to the KMS is lost, or
the appliance is removed from the StorageGRID system where its KMS keys are installed.
Steps
1. Open a browser, and enter one of the IP addresses for the appliance’s compute controller.
https://
Controller_IP
:8443
Controller_IP
is the IP address of the compute controller (not the storage controller) on any of the
three StorageGRID networks.
The StorageGRID Appliance Installer Home page appears.
After the appliance has been encrypted with a KMS key, the appliance disks cannot be
decrypted without using the same KMS key.
2. Select
Configure Hardware
>
Node Encryption
.
3. Select
Enable node encryption
.
Prior to appliance installation you can unselect
Enable node encryption
without risk of data loss. When
81
Содержание StorageGRID Webscale SG6000 Series
Страница 128: ...Callout Description 1 SG6000 CN 126...