Users Guide

Table Of Contents
1. Local Key Management (LKM) System - LKM is used to generate the key ID and the password or key required to secure
the virtual disk. If you are using LKM, you must create the encryption key by providing the Security Key Identifier and the
Passphrase.
2. Secure Enterprise Key Manager (SEKM) - This feature is used to generate the key using the Key Management Server
(KMS). If you are using SEKM, you must configure iDRAC with KMS information as well as SSL related configuration.
NOTE:
This task is not supported on PERC hardware controllers running in eHBA mode.
If you create the security key in 'Add to Pending Operation' mode and a job is not created, and then if you delete the
security key, the create security key pending operation is cleared.
NOTE:
For enabling SEKM, ensure that the supported PERC firmware is installed.
You cannot downgrade the PERC firmware to the previous version if SEKM is enabled. Downgrading of other PERC
controller firmware in the same system which is not in SEKM mode may also fail. To downgrade the firmware for the
PERC controllers that are not in SEKM mode, you can use OS DUP update method, or disable SEKM on the controllers
and then retry the downgrade from iDRAC.
NOTE: When importing a hot plugged locked volume from one server to another, you will see CTL entries for Controller
attributes being applied in the LC Log.
Configuring controller properties using web interface
1. In the iDRAC web interface, go to Storage > Overview > Controllers.
The Setup Controllers page is displayed.
2. In the Controller section, select the controller that you want to configure.
3. Specify the required information for the various properties.
The Current Value column displays the existing values for each property. You can modify this value by selecting the option
from the Action drop-down menu for each property.
For information about the fields, see the iDRAC Online Help.
4. From the Apply Operation Mode, select when you want to apply the settings.
5. Click Apply.
Based on the selected operation mode, the settings are applied.
Configuring controller properties using RACADM
To set Patrol Read Mode:
racadm set storage.controller.<index>.PatrolReadMode {Automatic | Manual | Disabled}
If Patrol read mode is set to manual, use the following commands to start and stop Patrol read Mode:
racadm storage patrolread:<Controller FQDD> -state {start|stop}
NOTE:
Patrol read mode operations such as Start and Stop are not supported if there are no virtual disks available in
the controller. Though you can invoke the operations successfully using the iDRAC interfaces, the operations will fail
when the associated job is started.
To specify the Check Consistency Mode, use Storage.Controller.CheckConsistencyMode object.
To enable or disable the Copyback Mode, use Storage.Controller.CopybackMode object.
To enable or disable the Load Balance Mode, use Storage.Controller.PossibleloadBalancedMode object.
To specify the percentage of the system's resources dedicated to perform a check consistency on a redundant virtual disk,
use Storage.Controller.CheckConsistencyRate object.
To specify the percentage of the controller's resources dedicated to rebuild a failed disk, use
Storage.Controller.RebuildRate object
252
Managing storage devices