Your suggested change has been received. Thank you.

close

Suggest A Change

https://thales.na.market.dpondemand.io/docs/dpod/services/kmo….

back

DSM Resources

Managing DSM Domains

search

Please Note:

Managing DSM Domains

This section describes how to manage DSM domains on CCKM.

Before proceeding, make sure to fulfill prerequisites.

Adding DSM Domains

To add a DSM domain to CCKM:

  1. Log on to the CipherTrust Manager GUI as administrator.

  2. Open the Cloud Key Manager application.

  3. In the left pane, click Containers > DSM Domains. The DSM Domains page is displayed.

  4. Click Add Domain. The Add Existing Domain page is displayed.

  5. From the Connection drop-down list, select the desired connection to the DSM.

  6. From the Domain drop-down list, select the desired DSM domain. The drop-down list shows existing domains of the DSM linked to the selected connection.

    Select multiple DSM domains to add them at once.

  7. Click Add.

The DSM domain is added to CCKM.

A message Domain added successfully... is displayed on the screen.

Refreshing DSM Keys

Refreshing is the process of downloading keys created on the DSM domains to CCKM. Refresh can be achieved using any of the following ways:

Refreshing Specific Domains

To refresh a specific domain:

  1. Open the Cloud Key Manager application.

  2. In the left pane, click Containers > DSM Domains. The DSM Domains page is displayed. This page displays the list of DSM domains.

  3. Click the overflow icon (ellipsis) corresponding to the desired DSM domain and click Refresh Now.

A message Refresh started... is displayed on the screen. To cancel the refresh, click Cancel Refresh.

After successful refresh, the refreshed keys are listed on the Cloud Keys > DSM > DSM Keys page. Refer to Viewing DSM Keys for details.

Refreshing All Domains

To refresh all DSM domains:

  1. Open the Cloud Key Manager application.

  2. In the left pane, click Containers > DSM Domains. The DSM Domains page is displayed. This page displays the list of DSM domains.

  3. Click Refresh All. The "This may take a while..." message is displayed.

    Refreshing all DSM domains is a time intensive operation that could take several hours or days to complete. It will continue running in the background.

  4. Click Refresh All to continue.

A message Refresh started... is displayed on the screen. To cancel the refresh, click Cancel Refresh.

The refreshed keys are listed on the Cloud Keys > DSM > DSM Keys page. Refer to Viewing DSM Keys for details.

Viewing/Editing Details of DSM Domains

The DSM Domains page shows the list of existing DSM domains. Search for domains by Domain Name or Connection.

Viewing DSM Domains Details

To view the details of DSM domains:

  1. Open the Cloud Key Manager application.

  2. In the left pane, click Containers > DSM Domains. The DSM Domains page displays the following details.

    ColumnDescription
    Domain NameName of the DSM domain. Click the link to view more details about the domain.
    ConnectionName of the DSM connection.
    Admin TypeType of the DSM administrator linked with the domain. The type can be:
    • SYSTEM_ADMIN
    • DOMAIN_ADMIN
    • SECURITY_ADMIN
    • SECURITY_AND_DOMAIN_ADMIN
    • ALL_ADMIN
    Last RefreshedWhen the domain was last refreshed. Never is displayed for domains that are never refreshed.
    Created AtWhen the domain was created.

Click the Customize View (Custom View) icon, select the desired option, and click OK to display the column.

Modifying DSM Domain Details

To modify the details of a DSM domain:

  1. Open the Cloud Key Manager application.

  2. In the left pane, click Containers > DSM Domains. The DSM Domains page displays the list of added DSM domains.

  3. Click the overflow icon (ellipsis) corresponding to the desired DSM domain and click View/Edit Details.

    You can change the DSM connection and its description, and modify user/group permissions on the DSM domain. For details, refer to:

Changing the DSM Connection

To add permission for a user/group:

  1. Expand GENERAL INFO.

  2. From the Connection drop-down list, select the desired DSM connection.

  3. Click Update.

A message Updated connection for this domain is displayed on the screen.

Managing User Permissions on DSM Domains

To work with DSM, users/groups must have the minimum set of permissions that allow them to use the DSM resources such as DSM keys and domains. Initially, the user only has permission to view the keys. However, if required, the CCKM administrator can grant and revoke permissions.

Only the users who are member of the CCKM Users group will be granted permissions to perform operations on the DSM domain.

To add permission for a user/group:

  1. Expand ACCESS CONTROL.

  2. In the ACCESS CONTROL section, click Assign User/Group. The Assign User/Group screen is displayed.

  3. From the User/Group drop-down list, select the user or group to be assigned permissions.

  4. Click Save.

The newly added user/group is displayed under Name in the ACCESS CONTROL section.

CCKM allows the following operations on the DSM domains:

  • View Keys, Add Key, Edit Key, Delete Key

  • Refresh Domain

  • Remove

Granting Permission to Perform an Operation

To grant permissions to the user or group to perform any of the above mentioned operations:

  1. Select the check box under the desired operation corresponding to the desired users or groups.

  2. Click Update.

A message Updated access control for this domain is displayed on the screen.

Removing a Permission

To remove a permission assigned to a user or group:

  1. Clear the check box under the desired operation corresponding to the desired users or groups.

  2. Click Update.

A message Updated access control for this domain is displayed on the screen.

Removing Permission from a User/Group

To remove current permissions assigned to the user/group:

  1. Under Remove, click the X button corresponding to the desired user/group. The Remove User / Remove Group screen is displayed.

  2. Click Remove.

    Removing this user/group will remove all permissions currently assigned to the user/group. Are you sure you want to continue?

  3. Click Remove.

A message Updated access control for this key domain is displayed on the screen.

Deleting DSM Domains

To delete a DSM domain:

  1. Open the Cloud Key Manager application.

  2. In the left pane, click Containers > DSM Domains. The DSM Domains page displays the list of added DSM domains.

  3. Click the overflow icon (ellipsis) corresponding to the desired DSM domain and click Delete. The Delete DSM Domain screen is displayed.

    The deleted domain's keys will no longer be available on the DSM Keys page, but the keys will still exist on the DSM. If you later add this domain with the same ID, the keys will be available again.

  4. Select I wish to delete this domain.

  5. Click Delete Domain.

A message Domain deleted successfully is displayed on the screen.