Chapter 2: DSM V6100 Hardware Appliance
Full Disk Encryption
DSM Installation and Configuration Guide
Copyright 2009 - 2020 Thales Group. All rights reserved.
41
2. You will be prompted for an RSA public key with a minimum length of 2048 bits. Copy and paste the contents of
your public key file at the prompt, then press Enter again to end with an empty line.
An RSA public key with minimum length of 2048 bits is required for boot passphrase
recovery. Please enter one now, ending with an empty line:
-----BEGIN PUBLIC KEY-----
MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwYIf0Z04nzne9j78BY7Q9kMTgh8YErtklECnVVhxExob/Uv
AWOvSBcGDVgixpeMCywWVh8OgTIbj751PVfaTI8/C+gP4Rd6cdtO7fGzsYsAZxN9OCssRQlCJfCe6y6fNep3dDOh1no
TFyFNTq3WW0gAlJ9ILPwn6uxVRgtXPgLnFfP9zNieyWmHTLw6He8BZAAYkWbESMgnA5BoJmcxdpv/i/8ZODTMMo/6Ji
4oYpQPa8i9Ex7qTZinl5hxjIjC8eIcUOMNdAhvslNzT6FZJ2BEYBU6TAQpxDPLwPAQIEw1x/NzcYUUfgaP1pZIAdhWF
JUZkx4FqmEA5odMwIDAQAB
-----END PUBLIC KEY-----
3. You are prompted to enter a passphrase, which must conform to the configured password policy. After you enter
the passphrase, a message is displayed, warning you that you will need access to the console, either directly or
via IPMI, so that you can enter the boot passphrase when prompted. If the console is available, type ‘
yes
’ to
continue.
Enter new boot passphrase:
Enter new boot passphrase again:
WARNING: After setting the new boot passphrase, the system will be rebooted automatically
and the new passphrase must be entered on the console. If you do not have direct or IPMI
access to the console, then choose 'no' to cancel. DSM will not boot up until a correct
boot passphrase is entered.
Continue? (yes|no)[no]: yes
CAUTION
Save this encrypted passphrase as it is required each time the DSM reboots. In the
event that you forget the passphrase and lose the encrypted passphrase and/or the RSA
private key, your DSM will be unrecoverable.
4. You will be reminded to set a boot passphrase on each of the designated DSM HA nodes as well. A message
confirming that a boot passphrase has been set is displayed and the system will reboot.
NOTE: run this command on every server node in the cluster to keep them at a uniform
security level.
SUCCESS: custom boot passphrase has been set.
DSM server is rebooting...
5. Open the IPMI Java console (or if using a virtual machine, the console from the virtualization application). During
the reboot you will be prompted to enter the boot passphrase. The system will continue to reprint the prompt until
the correct value is entered.
Please enter passphrase for disk <disk_name> (DSM_ROOT)!
6. Enter the passphrase, the system startup messages will continue to scroll until the system is ready and the log in
prompt is displayed. Now you can log into your system as before.
Welcome to the Vormetric Data Security Manager on <dsm_server_name>.com
<dsm_server_name> login: cliadmin
Password: