ONTAP Hardware

NSE drives and key management server

MPERIYAK
3,533 Views

Need help with a key management server. I did buy the FAS 8040 with NSE drives. No budget for a kms server.

Was of the opinion that I can get the encryption going without a KMS. Is this true ? I know the risk of maintaining my keys etc..But it is ok.

If I need a KMS are there any cheap alternatives apart from Gemalto/Safenet

1 ACCEPTED SOLUTION

zacharyt
3,315 Views

Update:  ONTAP 9 now has OKM ( Onbox Key Management ) meaning you no longer have to purchase an external KMIP key server.  OKM is included with the purchase price at no additional cost.

View solution in original post

2 REPLIES 2

NigelM
3,500 Views

Hi There

 

I am afraid it is not true, for NSE you need a KMS.  IBM Tivoli Lifetime Key Manager (TKLMv2) should do the trick - see attached doc or as you mention, SafeNet Keysucure

 

N

zacharyt
3,316 Views

Update:  ONTAP 9 now has OKM ( Onbox Key Management ) meaning you no longer have to purchase an external KMIP key server.  OKM is included with the purchase price at no additional cost.

Public