Users Guide

Table Of Contents
NOTE: If Auto-Configure for non-RAID disk is enabled, the disk becomes a non-RAID disk. Else, it is unconfigured.
Dell EMC OpenManage Secure Enterprise Key
Manager
This feature allows the PERC to receive a security key from a remote server instead of saving the key on a local controller. This
protects data on secured disks under the PERC if the disks or entire system is stolen. Refer to the www.dell.com/idracmanuals
for more information on configuring OpenManage Secure Enterprise Key Manager, as well as Secure Sockets Layer (SSL) or
Transport Layer Security (TLS) related configuration.
NOTE: Downgrade of PERC firmware to a firmware that does not support enterprise key management while enterprise key
manager mode is enabled, is blocked.
NOTE: When replacing a controller enabled with enterprise key management, lifecycle controller part replacement will
re-configure the new controller to match the existing controller's configuration.
NOTE: If key exchange fails during boot, view and correct any connection issues with the key server identified in the iDRAC
lifecycle log. Then the system can be cold booted.
Supported controllers for OpenManage Secure Enterprise Key
Manager
Enterprise key manager mode is supported on the PERC H740P adapter, PERC H740P mini adapter, H745 front card, H745
adapter and on split backplane mode. For more information on supported platforms, see www.dell.com/idracmanuals.
Enterprise key manager mode is not supported on the PERC H345, PERC H840 external adapter, PERC H745P (NGM), or on
the H740P and H745 with eHBA mode enabled.
Managing enterprise key manager mode
Enterprise key manager features are managed by iDRAC. For instructions on enabling enterprise key manager mode, see
www.dell.com/idracmanuals.
NOTE:
If preserved cache is present, the controller will not allow OpenManage Secure Enterprise Key Manager mode to be
enabled.
NOTE: Transitioning a controller from LKM mode to enterprise key manager mode without disabling security or the reverse
is not supported.
NOTE: When enterprise key manager mode is enabled, the controller waits up to two minutes for iDRAC to send keys, after
which the PERC continues to boot.
NOTE: Rotation of keys is done by iDRAC. Any attempt to re-key the controller through a different management application
is not supported.
Disabling enterprise key manager mode
nterprise key manager mode can be disabled from any supported Management applications for PERC cards. Enterprise key
manager mode can be disabled from any supported Management applications for PERC cards.
Managing virtual disks in enterprise key manager mode
Virtual disks are managed in the same way in enterprise key manager mode as in local key manager mode. SED capable virtual
disks can be secured during or after creation. See Creating secured virtual disk.
Security key and RAID management
75