Use the KMIPCLI configure-hsm-kek command to configure encrypting KMIP objects using a KEK stored in a system HSM.
Syntax
kmipcli configure-hsm-kek [options]
Option | Description |
-h or --help | Displays usage text. |
-s, --hsm_type string | The HSM type that is configured on the system. This can be NCIPHER or LUNA. NCIPHER is the default. |
-t, --kek_cache_timeout int | For KMIP Key wrapping, this is the cache timeout for the KEK. Because connecting frequently to the System HSM to fetch the KEK and encrypt the object can affect performance, you can select how long you would like to keep the KEK cached in the Cryptographic Security Platform Vault for KMIP. When the timeout period ends, the KEK is deleted from the cache. The default value is 1800 seconds. Set to 0 to disable KEK cache timeout. |
-R, --revision int | Enter the current revision number of the HSM KEK. If you do not know the revision number, run the |
-l, --rootkey_label string | The identifier to identify the root key on the HSM that is used to wrap and unwrap keys. If the root key label already exists, it will be used. If it does not exist, the Cryptographic Security Platform Vault for KMIP creates a new one. The root key label must meet the following requirements:
At this point, all existing KMIP objects and all new Key creation requests will be encrypted using the key. |