Changing an SED key
Appliances with self-encrypting drive (SED) capability use encryption keys to protect the drives. Each node in a multi-node appliance has its own key. The storage shelves share another key. You can see the last time that the key was changed from the System topology page.
Use the following procedure to change the SED encryption key on an appliance node or the storage shelves.
Note:
This procedure requires a user with the SED key administrator role. If you have not assigned the SED key administrator role yet, see the topic "Managing Flex Appliance Console users and tenants" in the Flex Appliance Getting Started and Administration Guide.
To change an SED key
- Sign in to the Flex Appliance Console as an SED key administrator and navigate to the System topology page.
- Locate the widget for the nodes or the storage and click Rekey next to the device that you want to change the key for.
- Follow the prompts to change the key. You can optionally switch from the internal key management service (KMS) to an external KMS if you have added one, or back to the internal KMS.
See Adding an external key management service (KMS).
If you have never changed the key before, use the following default keys for the current key:
For a node: The node serial number
For the storage: Encrypt!0nK3y
- Click Rekey.
- Follow the prompts in the confirmation window that appears and click Rekey or Switch and rekey.
Warning:
If you use the internal KMS and forget the encryption key, all data becomes lost and unrecoverable. Make sure that you save the new key in a safe location.