Users Guide

Managing enterprise key manager mode
Enterprise key manager features are managed by iDRAC. For instructions on enabling enterprise key manager mode, see
www.dell.com/idracmanuals.
NOTE: If preserved cache is present, the controller will not allow OpenManage Secure Enterprise Key Manager mode to be
enabled.
NOTE: Transitioning a controller from LKM mode to enterprise key manager mode without disabling security or the reverse
is not supported.
NOTE: When enterprise key manager mode is enabled, the controller waits up to two minutes for iDRAC to send keys, after
which the PERC continues to boot.
NOTE: Rotation of keys is done by iDRAC. Any attempt to re-key the controller through a different management application
is not supported.
Disabling enterprise key manager mode
Enterprise key manager mode can be disabled from any supported Management applications for PERC cards. For more
information, see the management application's user's guide or see Disabling security key.
Managing virtual disks in enterprise key manager mode
Virtual disks are managed in the same way in enterprise key manager mode as in local key manager mode. SED capable virtual
disks can be secured during or after creation. See Creating secured virtual disk.
Migration of drives from local key management to enterprise key
management
Local key management drives can be migrated to an enterprise key management enabled system, but the controller cannot be
transitioned from local key management mode to enterprise key manager mode or the reverse without first disabling security on
the controller. Perform the following steps to migrate local key management drives to enterprise key management:
1. Save the current local key management security key.
2. Shut down both systems.
3. Remove the local key management drives and re-insert them to the enterprise key manager enabled system.
4. Power on the enterprise key manager system.
5. Navigate to HII foreign configuration.
6. Enter the local key management keys for those drives.
7. Import the configuration.
NOTE:
Once local key management drives are migrated to enterprise key manager, they cannot be migrated back to
local key management mode. The drives have to be cryptographically erased to disable security and then converted back
to local key management disks. For more information on performing this action, contact https://www.dell.com/
supportassist.
Security key and RAID management 73