kmip.update =========== Update KMIP Server Configuration. The system authenticates to the remote KMIP server with a TLS handshake and synchronizes ZFS/SED keys between the local database and the server according to the configuration. This method is a job. .. raw:: html
KMIP configuration update arguments.
No Additional PropertiesWhether to enable KMIP functionality. Cannot be set to disabled while there are keys pending sync, unless force_clear is also set.
Whether to use KMIP for managing SED (Self-Encrypting Drive) keys. When enabled, SED keys are synced from the local database to the remote KMIP server. When disabled, any SED keys still held on the KMIP server are synced back to the local database.
Whether to use KMIP for managing ZFS encryption keys. When enabled, ZFS keys are synced from the local database to the remote KMIP server. When disabled, any ZFS keys still held on the KMIP server are synced back to the local database.
ID of the client certificate used to initiate the TLS handshake with the KMIP server, or null.
ID of the certificate authority used to verify the KMIP server during the TLS handshake, or null.
TCP port number for the KMIP server connection.
Value must be greater or equal to 1 and lesser or equal to 65535
Hostname or IP address of the KMIP server or null if not configured.
Must be at least 1 characters long
SSL/TLS protocol version to use for KMIP connections. Specify this to match the SSL configuration used by the KMIP server.
When enabled, removes all keys pending sync from the database. Use with extreme caution: ZFS dataset or SED disk keys may be lost, leaving them locked forever. Disabled by default.
Allows migrating data between two KMIP servers. The system first migrates keys from the old server to the local database, then from the database to the new server. If it cannot retrieve all keys from the old server the operation fails, which can be bypassed with force_clear.
When enabled (the default), the system tests the connection to server to make sure it is reachable before saving.
The updated KMIP configuration.
No Additional PropertiesUnique identifier for the KMIP configuration.
Whether KMIP (Key Management Interoperability Protocol) is enabled.
Whether to use KMIP for managing SED (Self-Encrypting Drive) keys. When enabled, SED keys are synced from the local database to the remote KMIP server. When disabled, any SED keys still held on the KMIP server are synced back to the local database.
Whether to use KMIP for managing ZFS encryption keys. When enabled, ZFS keys are synced from the local database to the remote KMIP server. When disabled, any ZFS keys still held on the KMIP server are synced back to the local database.
ID of the client certificate used to initiate the TLS handshake with the KMIP server, or null.
ID of the certificate authority used to verify the KMIP server during the TLS handshake, or null.
TCP port number for the KMIP server connection.
Value must be greater or equal to 1 and lesser or equal to 65535
Hostname or IP address of the KMIP server or null if not configured.
Must be at least 1 characters long
SSL/TLS protocol version to use for KMIP connections. Specify this to match the SSL configuration used by the KMIP server.