Configuration on Utimaco ESKM

We must create “temporary credentials” on the ESKM for the iLO to authenticate and execute the enrollment steps.

  1. Log in to the ESKM Management Console using the admin username and the password.

  2. Go to Security > Users & Groups > Local Users.

  3. Click on ADD.

  4. Create a local user with the username “ilo_reg_user”

    1. Enable “User Administration Permission” to allow this user to create other client users.

    2. Enable “Change Password Permission” to allow this user to change client user passwords.

    3. Uncheck “Enable KMIP” and leave this field blank.

Do not assign this user to any User group. It must remain stand-alone.

image-20250909-063656.png

Create Local User

  1. Go to Security > Users & Groups > Local Groups.

  2. Click on ADD.

  3. Create a user group that lists all servers under the “Group” that serves the same applications or function.

    1. Group: “FinanceGroup”, for the servers used by Finance applications, for example

    2. Group Type: ESKM.

Utimaco recommends grouping ProLiant Servers based on organizational unit/department.

image-20250909-063927.png

Local Groups

  1. Click on Save.

  2. Go to Security > Keys & KMIP Objects > Create Keys.

  3. Create a Key that will be used as a “master key” to encrypt “drive keys”.

    1. Key Name: “FinanceMasterKey”, for example, or some preferred name.

    2. Owner Username: ilo_reg_user.

    3. Key Type: ESKM.

    4. Algorithm: AES-256.

    5. Exportable: Enable.

Owner Username is the master user created earlier.

  1. Click on Create.

image-20250909-064403.png

Create Key

  1. Assign the master key to the group that was previously created.

  2. Run a Key Query in the ESKM.

  3. Find the key that you created in step 10.

  4. Click on the key to view its properties.

  5. Under “Group Permissions”, add the group to which this key is going to be a part of.

    1. Export: select “Always”

    2. Full: select “Always”

image-20250909-064513.png


Group Permissions

  1. Click on Save.