Setup Guide

Thales Data Security Manager (DSM)
20 Enable OpenManage Secure Enterprise Key Manager (SEKM) on Dell EMC PowerEdge Servers
3 Thales Data Security Manager (DSM)
3.1 Prerequisites for Thales Data Security Manager (DSM)
Before you start setting up iDRAC SEKM support, you must first ensure that the following prerequisites are
fulfilled. If these prerequisites are not fulfilled, you will not be able to successfully set up SEKM.
PowerEdge Server Prerequisites
iDRAC SEKM license installed
iDRAC Data Center or Enterprise license
iDRAC updated to the firmware version which supports SEKM
PERC updated to the firmware version which supports SEKM
Thales Vormetric DSM Prerequisites
Set up a valid external certificate authority to sign the iDRAC CSR.
Create a host that represents the iDRAC on the KMS.
Ensure a KMIPenabled license is applied to the DSM. If applying a new KMIP enabled license to an
existing DSM for the first time, restart the DSM after applying the license.
3.2 Set up SEKM on Thales DSM
This section describes the Thales Vormetric Data Security Manager features that are supported by iDRAC.
For information about all other Thales features, see the Thales Appliance Administration Guide.
When you install and configure the appliance, include the IP address of the DSM as the hostname. Also
include the IP address as the host name when generating a certificate authority on the DSM.
3.2.1 Add a new host in Thales Vormetric Data Security Manager
1. Log in to Thales as an administrator.
2. Switch to the domain where the keys will be managed. Click Domains Switch Domains Select
desired Domain Switch to Domain.
Switch to Domain where keys will be managed