Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Integrated Dell Remote Access Controller 9 User's Guide

PDF

iLKM Functionalities

iDRAC offers iDRAC Local Key Management (iLKM) feature for users who currently do not have SEKM, and needs to secure the storage devices using iDRAC. You may later migrate to SEKM also. When using iLKM, iDRAC acts as key manager and generates authentication keys that are used to secure storage devices. To use iLKM as key management system, navigate to iDRAC Settings > Services > iDRAC Key Management > Key Management Settings and select iLKM from the drop down menu.

You need to provide passphrase and a key ID to enable iLKM. Both passphrase and Key ID lengths should be maximum 255 characters.

NOTE:
  • iLKM is available through iDRAC GUI, RACADM, and Redfish interfaces.
  • You need SEKM licence to use iLKM feature.
  • iLKM is not supported for PERC/HBA/BOSS controllers.
  • You can enable/disable security on supported NVMe SED when iDRAC is in iLKM security mode.
  • You can not enable, disable, or rekey iLKM in system lockdown mode.
  • iLKM provides rekey option, where you need to provide the passphrase and key ID for authentication.

Auto Secure drives

  • Option to request iDRAC to auto secure non-PERC attached NVMe SED and SAS SED behind a security enabled SAS HBA. Drives are auto secured on a host reboot or on a drive hot plug.
  • Option does not auto enable security on controllers such as PERC and SAS HBA.
  • Option is enabled by default - can be disabled by the user using racadm command.
  • Disable Auto secure option before re-purposing a drive by using the cryptographic erase option (or PSID revert option) if the drive is no longer required to be secured by iDRAC.

iLKM to SEKM Transition

You must provide iLKM passphrase to authenticate the transition along with the SEKM configuration details. If the authentication is successful, SEKM is enabled on iDRAC and the previous iLKM key ID is deleted. You need to perform the following steps for iLKM to SEKM transition:

  1. Certificate Setup
  2. Configure SEKM settings
  3. Execute the iLKM to SEKM transition.

Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\