Skip to content

Latest commit

 

History

History
101 lines (59 loc) · 4.53 KB

File metadata and controls

101 lines (59 loc) · 4.53 KB
title excerpt updated
KMS configuration with Nutanix on OVHcloud
Learn how to configure OVHcloud Key Management System (KMS) with Nutanix to secure your data at rest
2025-02-14

Objective

This guide explains how to configure the OVHcloud Key Management System (KMS) with Nutanix on OVHcloud.

Nutanix provides two options for securing data at rest:

  • Self-Encrypted Drives (SEDs)
  • Software-only encryption which offers key-based access management through either the cluster's native key manager or an external key management system (KMS).

By following this guide, you will learn how to leverage Nutanix's data-at-rest encryption capabilities using the OVHcloud KMS.

Requirements

Instructions

Step 1 - Access Prism Central and Prism Element

1. Log in to Prism Central.

2. Navigate to Prism Element{.action}.

Prism element{.thumbnail}

3. Go to Settings{.action}.

Prism element settings{.thumbnail}

Step 2 - Configure Data-at-Rest Encryption

1. Scroll to Data-at-Rest Encryption{.action} in the settings menu.

2. Click on Edit Configuration{.action}.

Data at rest encryption{.thumbnail}

3. Select the Encryption Type{.action} and KMS Type{.action}.

Encryption type {.thumbnail}

KMS type{.thumbnail}

4. Enter your configuration details to generate the Certificate Signing Request (CSR).

configuration details{.thumbnail}

Step 3 - Add and manage Certificates

1. Add your Key Management Server (KMS).

KMS{.thumbnail}

2. Click on Manage Certificates{.action}.

KMS{.thumbnail}

3. Upload your Certificate Authority (CA).

4. Once the CA is uploaded, go back to Key Management Server{.action} and click Manage Certificates{.action}.

KMS{.thumbnail}

Step 4 - Test and Enable Encryption

1. Test all nodes in the cluster.

nodes{.thumbnail}

2. If the test is successful, you can now enable encryption for your Nutanix cluster.

testing successful{.thumbnail}

3. You can enable both software encryption and Self-Encrypting Drives (SEDs).

SED{.thumbnail}

Go Further

If you need training or technical assistance to implement our solutions, contact your sales representative or click on this link to get a quote and ask our Professional Services experts for assisting you on your specific use case of your project.

Join our community of users.