Administrator Guide

Table Of Contents
The Full Disk Encryption panel opens with the FDE General Configuration tab selected.
2. Type a passphrase in the Passphrase field of the Set/Create Passphrase section. A passphrase is case-sensitive and can
include 832 printable UTF-8 characters except for the following: , < > \
3. Retype the passphrase in the Re-enter Passphrase field.
4. Perform one of the following:
To secure the system now, click Secure, and then click Set. A dialog box confirms that the passphrase was changed
successfully.
To save the passphrase without securing the system, click Set. A dialog box confirms that the passphrase was changed
successfully. To secure the system later, see Securing the system.
Clearing lock keys
Lock keys are generated from the passphrase and manage locking and unlocking the FDE-capable disks in the system. Clearing
the lock keys and power cycling the system denies access to data on the disks. Use this procedure when the system is not
under your physical control.
If the lock keys are cleared while the system is secured, the system enters the FDE lock-ready state, in preparation for the
system being powered down and transported.
After the system has been transported and powered up, the system and disks enter the Secured, Locked state, and volumes
become inaccessible. To restore access to data, re-type the original passphrase using the CLI command set fde-lock-key.
NOTE: The FDE tabs are dynamic, and the Clear All FDE Keys option is not available on a secured system until the current
passphrase is entered in the Current Passphrase field. (If you do not have a passphrase, the Clear All FDE Keys option
is not displayed. If you have a passphrase but have not entered it, you can view but not access this option.) If there is no
passphrase, set one using the procedure in Setting the passphrase.
Clear lock keys
Performing the steps to clear the lock keys:
1. In the System topic, select Action > Full Disk Encryption.
The Full Disk Encryption panel opens with the FDE General Configuration tab selected.
2. Enter the passphrase in the Current Passphrase field.
3. In the Secure System section, click the Secure button.
4. Click Clear.
A dialog box appears.
5. Perform one of the following:
To clear the lock keys for the system, click OK.
To cancel the request, click Cancel.
Securing the system
An FDE-capable system must be secured to enable FDE protection.
The FDE tabs are dynamic, and the Secure option is not available until the current passphrase is entered in the Current
Passphrase field. (If you do not have a passphrase, the Secure option is not displayed. If you have a passphrase but have not
entered it, you can view but not access this option.) If there is no passphrase, set one using the procedure in Setting the
passphrase.
Perform the following steps to secure the system:
1. In the System topic, select Action > Full Disk Encryption.
The Full Disk Encryption panel opens with the FDE General Configuration tab selected.
2. Type the passphrase in the Current Passphrase field.
3. Click Secure.
A message displays confirming that the system is in a secure state.
Working in the System topic
67