Integrating HPE StoreOnce with ESKM

To integrate HPE StoreOnce with ESKM, perform the following steps:

  • Login to the HPE StoreOnce Management Console.

image-3356262550-1.jpg

StoreOnce Console - Log In

  • Navigate to StoreOnce>System Dashboard and check the availability of the encryption license.

image-3356262550-2.jpg

System Dashboard


To start with the integration, navigate to StoreOnce>Settings>Key Manager.

image-3356262550-3.jpg

Key Manager

  • Click on Generate CSR and click on “Provide External Key Manager Credentials”.

The “External Key Manager Credentials” are to be created on the ESKM.

Login to the ESKM and create a local user with username as “registration”, choose a password and confirm it, select the license type as storage, select the user administration permission and change password permission, do not select KMIP, and click create.

image-3356262550-4.jpg

Generate CSR

image-3356262550-5.jpg

Generate CSR

  • Provide the same username and password that was created on the ESKM and click OK.

image-3356262550-6.jpg

External key manager credentials

  • Click on Generate and the CSR will be displayed. Click on Select and Copy to copy the certificate and go to ESKM.

image-3356262550-7.jpg

Generate CSR

image-3356262550-8.jpg

Sign Request

  • Navigate to Security>Certificates & CAs>Local CAs and click on Sign Request. Select the certificate purpose as “Client” and paste the certificate in “Certificate Request” pane and click on Sign Request.

image-3356262550-9.jpg

Local Certificate Authority List

image-3356262550-10.jpg

Sign Request

image-3356262550-11.jpg

Certificate Information

  • Go to HPE StoreOnce Management Console, navigate StoreOnce>Settings>Key Manager>Actions and click on Enroll.

image-3356262550-12.jpg

Key Manager - Enroll

image-3356262550-13.jpg

Backup Configuration

  • To backup the local configuration, create a password and confirm it and click Backup.

The backup of local configuration is important if the local key management configuration mode has to be switched back or unenroll from the key manager.

image-3356262550-14.jpg

Backup

  • Download the backup file and save it onto the local machine.

  • To configure the external key manager server, click on Configure External Key Manger Server. A pop-up window will be displayed. Select the “ESKM” as option and enter the IP address, CA name, Port, EKM username, EKM password, and click OK. The ESKM is now registered.

image-3356262550-15.jpg

Configure External Key Manager Server

image-3356262550-16.jpg

Configure External Key Manager server