Using Remote Keystore
Last updated
Last updated
The encryption keystore provides centralized management of volume encryption passwords. This feature allows you to store and manage encryption passwords securely, simplifying the process of unlocking encrypted volumes.
See also. To learn how to configure your remote keystore, see Encryption Keystore.
You can add encryption passwords to the Encryption Keystore in two ways:
During volume creation, switch on the Save key in Encryption Store toggle.
In the key management interface for existing volumes, if the Enable encryption toggle was on during volume creation and the volume key has not been saved in the keystore.
To add a password for an existing volume:
Navigate to System > System Settings tab > Encryption Keystore pane.
Click Manage keys. The Manage Keys dialog will open.
Tip. If the Manage keys button is disabled, configure your Encryption Keystore first. See Encryption Keystore.
Click Add key next to the volume for which you want to add the encryption key. The Add Encryption Key dialog will open.
Type the encryption key specified when creating the volume.
Click Save.
To remove a stored password:
Navigate to System Settings > Security and Network.
Click Manage keys in the Encryption Keystore pane.
Hover over the desired volume.
To unlock a volume whose encryption key is stored in the Encryption Keystore:
Select the volume from the volumes list.
Select Unlock. The Volume Unlock dialog will open.
Instead of specifying the volume’s encryption key, select Unlock using stored key.
If you prefer not to use the stored password, you can still unlock volumes by entering the encryption password manually.
The Encryption Keystore must be properly configured before storing or using encryption passwords.
Removing a password from the keystore does not affect the volume’s encryption settings.
All passwords stored in the Encryption Keystore are encrypted.
Attention! Always maintain secure backups of your encryption passwords, even when using the Encryption Keystore.
Click the button next to the volume name.