Chapter 4: Installing and Configuring a DSM
Full Disk Encryption
DSM Installation and Configuration Guide
Copyright 2009 - 2020 Thales Group. All rights reserved.
86
1. Click
System
2. Select
License
3. Click
Upload the license file
.
After uploading your license file, all the other functions for which you have a license will be visible.
Full Disk Encryption
The DSM root filesystem is automatically encrypted for enhanced security. This feature is only available on: a fresh
installation of the DSM software on the V6x00 appliances and a fresh DSM build on a virtual appliance. See
for details and procedures for this feature.
This feature also requires use of the IPMI, see
for details and procedures for this
feature.
nShield Connect Integration
DSM appliances that do not have a built in hardware security module (HSM)—DSM V6000 hardware appliance and the
virtual appliance—can now utilize an nShield Connect HSM or a Luna HSM appliance to create and protect the DSM
master key. The DSM can be configured with any of the following nShield appliance types: nShield Connect, nShield
Connect Plus, or nShield Connect XC. See
"nShield Connect Integration" on page 63
for details about this feature. For
more information about the Luna HSM, see,
DSM Installation on bare metal using IBM Cloud
To install the DSM virtual appliance on a bare metal system using IBM Cloud, you need to have an IBM Cloud account
and your bare metal system in place before you begin.
Upload the DSM ISO image to the IBM Cloud NAS storage
This process assumes that you have an IBM Cloud account with Cloud NAS storage, and have set up your bare metal
system.
1. Enable IBM Cloud VPN access using SSL.
Open a local secure shell session (SSH) and connect to your bare metal system using the public IP address and
root password. The public IP address is available under the Configuration tab for your device. The root user
password is available under the Password tab. Use the secure copy (scp) command to copy the DSM ISO image
to your bare metal system.
2. Open an SSH, log into your bare metal system as root and follow the instructions to mount NAS in IBM Cloud.
3. Copy the DSM ISO image to the mounted NAS directory.
4. Log into the IBM Cloud portal and enable VPN access and set your VPN password.
5. Next, file a ticket with IBM Cloud requesting the following:
a. Permission to "mount" virtual media in KVM.
b. Support to change the BIOS boot order.
n
If you are using dual-processors with multi-core, e.g., E5 CPU, then request to boot the hard disk first and
CDROM second. IBM Cloud locks BIOS access with a password, which is why you need to request a
change in the boot order.