Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
syno:dsm7kmip [2026/09/01 13:24] – [DSM as Client] Bernard Condrausyno:dsm7kmip [2026/09/01 13:58] (current) – [DSM as Client] Bernard Condrau
Line 40: Line 40:
   - Upload the certificate authority file ''ca.pem'' and click **Next**. Wait until you see the connection is successful.   - Upload the certificate authority file ''ca.pem'' and click **Next**. Wait until you see the connection is successful.
   - Now you need to go to **Storage Manager --> Storage** and click //Global Settings//. Scroll down to **Encryption Key Vault** and click //Reset// (important!) to make the switch to the KMIP Server permanent and move the encryption keys.   - Now you need to go to **Storage Manager --> Storage** and click //Global Settings//. Scroll down to **Encryption Key Vault** and click //Reset// (important!) to make the switch to the KMIP Server permanent and move the encryption keys.
-  - Go to **Control Panel --> Security --> KMIP**, check //Set as remote key client//, and make sure your KMIP Server is running+  - Go to **Control Panel --> Security --> KMIP**, check //Set as remote key client//, and make sure your KMIP Server with uploaded Synology certificates is running (either Synology DSM, or PyKMIP on Debian, or a commercial KMIP Server) 
 +  - Enter the following credentials. Note that every time you edit the connection you need to upload the //Certificate Authority// file (<color red>**ca.pem**</color>).{{ :syno:kmip-credentials.jpg?600 |KMIP Credentials}}
  
 ===== How to gain access to encrypted volumes when the KMIP Server was unavailable during DSM boot ===== ===== How to gain access to encrypted volumes when the KMIP Server was unavailable during DSM boot =====