Configuring Key Management Settings
Key management refers to configuring in-transit key wrapping, Windows auto protection, key rotation (rekey), and auto keys deletion. A ProtectV administrator can configure these features on the Settings page of the CipherTrust Manager console.
In-transit Key Wrapping
Enabling In-transit Key Wrapping
To enable in-transit key wrapping:
Log on to the CipherTrust Manager GUI.
Open the ProtectV application.
In the left pane, click Settings. The Settings page is displayed in the right pane.
This page contains the following tabs:
Tab Description Keys Provides options to configure key wrapping, Windows auto protection, key rotation, and automatic key deletion. This is the default tab. Keystore Provides options to configure a remote keystore. Autoscale Provides options to enable or disable global autoscaling. On the Keys tab, click the toggle switch next to Key Wrapping to turn it ON. This enables key wrapping. By default, key wrapping is OFF (disabled).
Disabling In-transit Key Wrapping
To disable in-transit key wrapping:
Log on to the CipherTrust Manager GUI.
Open the ProtectV application.
In the left pane, click Settings. The Settings page is displayed in the right pane. By default, the Keys tab is displayed.
Click the toggle switch next to Key Wrapping to turn it OFF. This disables key wrapping.
Windows Auto Protection
Note
Windows Auto Protection is applicable to Windows clients.
Disabling Windows Auto Protection
By default, Windows auto protection is enabled for all clients (turned ON). A ProtectV administrator can turn off this feature on the CipherTrust Manager console.
To disable Windows auto protection:
Log on to the CipherTrust Manager GUI.
Open the ProtectV application.
In the left pane, click Settings. The Settings page is displayed in the right pane. By default, the Keys tab is displayed.
Click the Windows Auto Protection toggle switch to turn it OFF.
This disables Windows automatic protection.
Enabling Windows Auto Protection
By default, Windows auto protection is ON (enabled). If the feature is disabled (turned OFF), a ProtectV administrator can enable it on the CipherTrust Manager console.
To enable Windows auto protection:
Log on to the CipherTrust Manager GUI.
Open the ProtectV application.
In the left pane, click Settings. The Settings page is displayed in the right pane. By default, the Keys tab is displayed.
Click the Windows Auto Protection toggle switch to turn it ON.
This enables Windows automatic protection.
Rekey (Key Rotation)
Configuring Rekey
To configure rekey:
Log on to the CipherTrust Manager GUI.
Open the ProtectV application.
In the left pane, click Settings. The Settings page is displayed in the right pane. By default, the Keys tab is displayed.
Click the Key Rotation toggle switch to turn it ON. This enables key rotation.
Specify the Rekey Interval after which the partition key should be changed automatically. By default, the partition key will be changed after
180
days.Click Save. A green mark indicates that key rotation is effective.
The partition key will be changed after the specified rekey interval (now onward).
Disabling Rekey
To disable key rotation:
Log on to the CipherTrust Manager GUI.
Open the ProtectV application.
In the left pane, click Settings. The Settings page is displayed in the right pane. By default, the Keys tab is displayed. It shows the current key rotation settings.
Click the Key Rotation toggle switch to turn it OFF.
This disables key rotation.
Automatic Key Deletion
ProtectV provides an option to configure automatic deletion of encryption keys on deletion of the associated ProtectV Client images.
By default, this option is disabled. In this case, the keys with which an image’s partitions are encrypted will not be deleted if the image is deleted. However, when the option is enabled, deletion of the encrypted image will automatically delete the linked encryption keys.
Enabling Automatic Key Deletion
To enable automatic key deletion:
Log on to the CipherTrust Manager GUI.
Open the ProtectV application.
In the left pane, click Settings. The Settings page is displayed in the right pane. By default, the Keys tab is displayed.
Click the Key Auto Delete toggle switch to turn it ON.
This enables automatic keys deletion with the deletion of associated ProtectV images. Subsequent deletion of encrypted images will automatically delete the linked encryption keys.
Disabling Auto Keys Deletion
To disable automatic keys deletion:
Log on to the CipherTrust Manager GUI.
Click the ProtectV tab. A shortcut menu appears in the left pane.
In the left pane, click Settings. The Settings page is displayed in the right pane. By default, the Keys tab is displayed. It shows that automatic keys deletion is enabled.
Click the Key Auto Delete toggle switch to turn it OFF.
This disables automatic keys deletion with the deletion of associated ProtectV images. Subsequent deletion of encrypted images will not delete the linked encryption keys.