Use the KMIPCLI configure-hsm-kek command to configure encrypting KMIP objects using a KEK stored in a system HSM.

Syntax

kmipcli configure-hsm-kek [options]

Option

Description

-h or --help

Displays usage text.

-s, --hsm_type string

The HSM type that is configured on the system. This can be NCIPHER or LUNA. NCIPHER is the default.

-t, --kek_cache_timeout int

For KMIP Key wrapping, this is the cache timeout for the KEK. Because connecting frequently to the System HSM to fetch the KEK and encrypt the object can affect performance, you can select how long you would like to keep the KEK cached in the Cryptographic Security Platform Vault for KMIP. When the timeout period ends, the KEK is deleted from the cache. The default value is 1800 seconds. Set to 0 to disable KEK cache timeout.

-R, --revision int

Enter the current revision number of the HSM KEK. If you do not know the revision number, run the get-kek-setting command.

-l, --rootkey_label string

The identifier to identify the root key on the HSM that is used to wrap and unwrap keys. If the root key label already exists, it will be used. If it does not exist, the Cryptographic Security Platform Vault for KMIP creates a new one. The root key label must meet the following requirements:

  • At least 8 characters

  • No more than 31 characters

  • Can include uppercase, lowercase, numbers, and special characters

  • No space or tab character

At this point, all existing KMIP objects and all new Key creation requests will be encrypted using the key.