PowerFlex: Unable to Deploy SO RG, with external Keystore Protector for CloudLink
Summary: PS is unable to deploy SO Resource Group. An issue with the deployment logic does not allow to change the "Keystore Protector."
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Symptoms
PS is following the same steps as PowerFlex Manager 3.8 however, it is changed in PowerFlex Manager 4.5 SO service template that is picking up the External Keystore protector type is wrong (CloudLink Vault) instead of the "KMIP" which is causing the issue.
PS using default keystore (initial) is selecting to deploy SO services and continuing the deployment.
Cause
PFxM 4.5 SO template picking up wrong attributes when selecting keystore with an external key protector
Resolution
Since PS used the default keystore (initial) to deploy SO services all the keys were created in it.
We must move the keys from the initial keystore to the Ciphertrust1 keystore to use the Ciphertrust1 keystore with protector type as KMIP.
Follow the steps:
- Log in to the CloudLink node as secadmin
- Ensure that the Keystores status is accessible.

- Go to Agents --> Machine group --> Select 'Default' group -->Actions --> Modify --> Change keystore to Ciphertrust1 (which is already created).
- Next, go to System -->Keystores --> Select 'initial' keystore -->Actions --> Move Keys --> select Ciphertrust1 --> ok to move keys from initial to Ciphertrust1.
- Moving keys may take a couple of minutes to complete the task.
- Once it is done, you may test by rebooting one of the SO nodes and see if it is getting the key and ensure all the are mounted.
Affected Products
PowerFlex rack RCM SoftwareArticle Properties
Article Number: 000221742
Article Type: Solution
Last Modified: 25 Jun 2025
Version: 4
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.