To modify EKM settings:
From the left navigation menu, select Settings, Cluster and then KMIP. The encryption configuration is displayed, including the configured EKM type.
The following EKM parameters can be modified without breaking communication with the EKM. Make changes as needed.
To add an EKM server, enter the Server Address and Port, then click + Add Server Address.
To remove an EKM server, locate the server IP address in the Server List and click the X next to the address.
To upload new a new EKM certificate, under EKM Certificate, click + Add Certificate.
To upload new a new EKM private key, under EKM Private Key, click + Add Key.
To upload a new EKM CA certificate, under EKM CA Certificate, click + Add Certificate.
If the encryption type is CIPHER_TRUST_KMIP, the auth domain can be added or updated in the Auth Domain field.
EKM Server Address
The IP addresses or DNS names and port numbers for up to four EKM servers.
EKM proxy address
The proxy address used to connect to the Thales CipherTrust Manager in the format https://proxy-address:port. For example: --ekm-proxy-address https://squid:squid@10.27.103.73:3128
Certificate
The SSL certificate for the connection to the EKM servers. The certificate content is encapsulated in quotation marks (""), including the "-----BEGIN CERTIFICATE-----" and "-----END CERTIFICATE-----" lines from the certificate file content.
Private key
The private key of the SSL certificate for connection to the EKM servers. The private key content is encapsulated in quotation marks (""), including the "-----BEGIN EC PRIVATE KEY-----" and "-----END EC PRIVATE KEY-----" lines from the private key file content.
CA certificate
The CA certificate file content for connection to the EKM servers. The CA certificate file content is encapsulated in quotation marks (""), including the ""-----BEGIN CA CERTIFICATE-----" and "-----END CA CERTIFICATE-----" lines from the CA certificate file content.
Click Save.