Administrator Guide

Technical support and resources
ID 483
3.4.3 Secure Enterprise Key Manager (SEKM)
OpenManage SEKM delivers a central key management solution to manage data-at-rest across the
organization. SEKM uses an external Key Management Server (KMS) to manage keys that iDRAC uses to
lock and unlock storage devices.
The advantages of using SEKM over Local key Management (LKM) are:
o SEKM protects theft of a server” since the keys are not stored on the server and are stored
externally. Only authenticated iDRACs can retrieve the key from the external server.
o Centralized and scalable key management for encrypted devices with high availability.
o Supports industry standard KMIP protocol, which enables the use of other KMIP compatible devices.
o Protects data at rest when drives or entire server are compromised.
o On-drive encryption performance scales with drive count.