---
title: "Fortanix DSM with Dell PowerFlex Using CloudLink"
slug: "fortanix-dsm-with-dell-powerflex-using-cloudlink"
updated: 2026-07-08T18:18:16Z
published: 2026-07-08T18:18:16Z
canonical: "support.fortanix.com/fortanix-dsm-with-dell-powerflex-using-cloudlink"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://support.fortanix.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Fortanix DSM with Dell PowerFlex Using CloudLink

## 1.0 Introduction

This article describes how to integrate **Fortanix-Data-Security-Manager (DSM)** with **Dell PowerFlex** using **CloudLink** through Key Management Interoperability Protocol (KMIP) server configuration.

Dell PowerFlex, combined with CloudLink, offers a comprehensive data security solution by integrating data encryption and centralized key management into a high-performance, software-defined storage platform. PowerFlex ensures outstanding scalability, flexibility, and performance to meet the demands of modern workloads. CloudLink enhances data security by encrypting data at rest and providing key management capabilities such as key generation, rotation, and revocation.

This integration ensures compliance with industry regulations, simplifies key management, and protects critical data both at rest and in motion, without compromising the agility and performance of the PowerFlex platform in modern data centers.

## 2.0 Prerequisites

To successfully integrate Fortanix DSM with PowerFlex using CloudLink, ensure you have the following:

- Dell CloudLink and PowerFlex are set up and running, with root, administrator, and security administrator access.
- Secure connectivity is established between Fortanix DSM, Dell PowerFlex, and CloudLink.
- Administrator access to the Fortanix DSM. *For more information, refer to* [*Section 5.1: Signing Up*](/v1/docs/using-fortanix-data-security-manager-with-dell-powerflex-using-cloudlink#51-signing-up) *and* [*Section 5.2: Creating an Account*](/v1/docs/using-fortanix-data-security-manager-with-dell-powerflex-using-cloudlink#52-creating-an-account)*.*

## 3.0 Product Tested Version

This integration has been tested on the following versions:

- Fortanix DSM version 4.27, 4.31, and 4.34
- PowerFlex version 4.5.1.0
- CloudLink version 8.0.2. *For more information about the compatible PowerFlex versions, refer to* [*Dell CloudLink Support Matrix*](https://www.dell.com/support/manuals/en-in/cloudlink-securevm/cl_8_1_x_support_matrix/powerflex-software-versions-supported-for-cloudlink?guid=guid-fee2e5f9-e571-4c76-ba1d-bb3156647caa&amp;lang=en-us)*.*

## 4.0 Architecture Diagram

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/PowerFlex_Arch.png)

**Figure 1: Architecture diagram**

This architecture diagram illustrates the workflow between Dell PowerFlex, Dell CloudLink, and Fortanix DSM to secure data.

Dell PowerFlex is a software-defined storage infrastructure that contains important information and connects to different storage devices, such as USB drives and servers. To protect this data, Dell CloudLink acts as a security tool that encrypts it so that only authorized users can access the information. Fortanix DSM generates and securely stores the encryption keys.

When data is stored in PowerFlex, CloudLink encrypts it using a key provided by DSM. If access is required, CloudLink requests the appropriate key from DSM, allowing authorized systems or users to retrieve it.

This integration keeps the data protected. Even if an unauthorized user tries to access or steal the stored information, they cannot decrypt it without the proper encryption key from DSM. This setup strengthens data security and prevents unauthorized access.

## 5.0 Configure Fortanix DSM

A Fortanix DSM service must be configured, and the URL must be accessible. To create a Fortanix DSM account and group, refer to the following sections:

### 5.1 Signing Up

To get started with the Fortanix DSM cloud service, you must register an account at <Your_DSM_Service_URL>. For example, [https://amer.smartkey.io.](https://amer.smartkey.io.) On-premises customers use the KMS URL, and the SaaS customers can use the URLs as listed [*here*](https://support.fortanix.com/hc/en-us/articles/4406135346068-Fortanix-DSM-SaaS-Global-Availability-Map) based on the application region.

*For more information on how to set up the Fortanix DSM, refer to the* [*Sign Up for Fortanix Data Security Manager SaaS*](https://support.fortanix.com/docs/users-guide-sign-up-for-fortanix-data-security-manager-saas)*.*

### 5.2 Creating an Account

Access <Your_DSM_Service_URL> in a web browser and enter your credentials to log in to Fortanix DSM.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/DSM_SaaS_Login_page(15).png)

**Figure 2: Logging in**

*For more information on how to set up an account in Fortanix DSM, refer to the* [*Getting Started with Fortanix Data Security Manager - UI*](https://support.fortanix.com/docs/users-guide-getting-started-with-fortanix-data-security-manager-ui)*.*

### 5.3 Creating a Group

Perform the following steps to create a group in the Fortanix DSM:

1. In the DSM left navigation panel, click the **Groups** menu item, and then click **ADD GROUP** to create a new group.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/Add-Group(16).png)

**Figure 3: Add groups**
2. On the **Adding new group** page:
  1. **Title**: Enter a name for your group.
  2. **Description** (optional): Enter a short description of the group.
3. Click **SAVE** to create the new group.

*For more information about groups, refer to* [*Definitions*](/v1/docs/dsm-definitions#40-groups)*.*

> [!NOTE]
> TIP
> 
> It is recommended to configure a **Key undo policy** for groups for the cryptographic keys used by the application before creating or using the keys. Without a configured **Key undo policy**, key deletion is permanent and the deleted key cannot be recovered. Deleting an encryption key may result in permanent loss of access to the protected data and service disruption for applications that depend on the deleted key. *For detailed steps, refer to* [*Key Undo Policy*](/v1/docs/fortanix-dsm-key-undo-policy)*.*

### 5.4 Creating an Application

Perform the following steps to create an application (app) in the Fortanix DSM:

1. In the DSM left navigation panel, click the **Apps** menu item, and then click **ADD APP** to create a new app.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/Add-App(15).png)

**Figure 4: Add application**
2. On the **Adding new app** page:
  1. **App name**: Enter the name for your application.
  2. **ADD DESCRIPTION** (optional): Enter a short description of the application.
  3. **Authentication method**: Select the default **API Key** as the authentication method from the drop down menu. *For more information on these authentication methods, refer to the* [*User's Guide: Authentication*](https://support.fortanix.com/docs/users-guide-authentication)*.*
  4. **Assigning the new app to groups**: Select the group created in [*Section 5.3: Creating a Group*](/v1/docs/using-fortanix-data-security-manager-with-dell-powerflex-using-cloudlink#53-creating-a-group) [](/v1/docs/using-data-security-manager-with-idcentral-key-management#43-creating-a-group)from the list.
3. Click **SAVE** to add the new application.

*For more information about applications, refer to* [*Definitions*](https://support.fortanix.com/docs/dsm-definitions#50-applications)*.*

### 5.5 Copying the App UUID

Perform the following steps to copy the app UUID from the Fortanix DSM:

1. In the DSM left navigation panel, click the **Apps** menu item, and then click the app created in [*Section 5.4: Creating an Application*](/v1/docs/using-fortanix-data-security-manager-with-dell-powerflex-using-cloudlink#54-creating-an-application) [](/v1/docs/using-data-security-manager-with-idcentral-key-management#44-creating-an-application)to go to the detailed view of the app.
2. On the **INFO** tab, click **VIEW API KEY DETAILS**.
3. Click **USERNAME/PASSWORD**.
4. From the **Credentials Details** dialog box, copy the **Username (app UUID)** and **Password** as it will be used in [*Section 5.6: Generating the Client Certificate and Private Key*](/v1/docs/using-fortanix-data-security-manager-with-dell-powerflex-using-cloudlink#56-generating-the-client-certificate-and-private-key) as the value of Common Name (CN).

### 5.6 Generating the Client Certificate and Private Key

There are two types of client certificates that can be used based on your security policy:

- **Self-Signed Certificates**: These certificates are generated and signed by the user. They are suitable if your security policy permits self-signing.
- **Externally Signed Certificates**: These certificates are generated using a Certificate Signing Request (CSR) and signed by a trusted Certificate Authority (CA).

Perform the following steps to generate a private key and create a CSR for obtaining a signed certificate from a trusted CA:

1. Log in to a system with OpenSSL installed.
2. Run the following OpenSSL command to generate the private key and client certificate:

```bash
openssl req -newkey rsa:2048 -nodes -keyout <privatekey>.key -x509 -days 365 -out <clientcertificate>.crt
```

For example:

```bash
openssl req -newkey rsa:2048 -nodes -keyout test.key -x509 -days 365 -out test.crt
```

When prompted, enter the following details:
  - **Country Name**: Enter the two-letter code representing your country.
  - **State or Province Name**: Enter the full name of your state or province.
  - **Locality Name**: Enter the full name of your city.
  - **Organization Name**: Enter the full name of your organization.
  - **Organizational Unit Name**: Enter the full name of your department within the organization.
  - **Common Name**: Use the app UUID as noted in [*Section 5.5: Copying the App UUID*](/v1/docs/using-fortanix-data-security-manager-with-dell-powerflex-using-cloudlink#55-copying-the-app-uuid).
  - **Email Address**: Enter the email ID of the user.

This command will generate a client certificate and a private key. Ensure that both files are securely stored on your system.

### 5.7 Updating the Authentication Method

> [!NOTE]
> NOTE
> 
> Based on the selected authentication method, the **Credentials Type** required for creating a keystore in CloudLink will vary.
> 
> - **Username and Password-based authentication**: The DSM app **Username** and **Password** are required.
> - **Certificate-based authentication**: The DSM app **Username** and **Password** are not required in this case.

Perform the following steps to change the authentication method:

1. Go to the detailed view of the app created in [*Section 5.4: Creating an Application*](/v1/docs/using-fortanix-data-security-manager-with-dell-powerflex-using-cloudlink#54-creating-an-application), and click **Change authentication method** and selectthe **Certificate** to change the authentication method to Certificate.
2. Click **SAVE**.
3. On the **Add certificate** dialog box, click **UPLOAD NEW CERTIFICATE** to upload the certificate file or paste the content of the client certificate generated in [*Section 5.6: Generating the Client Certificate and Private Key*](/v1/docs/using-fortanix-data-security-manager-with-dell-powerflex-using-cloudlink#56-generating-the-client-certificate-and-private-key).
4. Select both the check boxes to confirm your understanding about the action.
5. Click **UPDATE** to save the changes.

### 5.8 Extracting Fortanix DSM Internal CA Certificate

Perform the following steps to extract the Fortanix DSM internal CA certificate:

1. Log in to a system with OpenSSL installed.
2. Run the following OpenSSL command to display the certificates of Fortanix DSM. The first certificate is the server certificate and the second is the root certificate:

```bash
$ openssl s_client -connect <Your_DSM_Service_URL>:5696 - showcerts
```

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/CloudLink_View_Certificates(1).png)

**Figure 5: View certificates**

## 6.0 Configure CloudLink

This section describes the steps for configuring a keystore in CloudLink to integrate with Fortanix DSM, adding a machine group, and ensuring proper communication between CloudLink and DSM.

CloudLink supports both local database keystore and external KMIP server keystore, offering flexibility for users. They can choose between faster access with the local database, protected by an external keystore, or enhanced security and compliance with the external KMIP server.

- **Local Database keystore**: It stores the encryption keys securely within the local database protected by external KMIP server of the CloudLink appliance, offering minimal latency and simplified management.
- **External KMIP Server keystore**: It integrates with KMIP-compliant external key management servers to enable the centralized key storage and lifecycle management across applications, such as Fortanix DSM.

### 6.1 Verifying the Connectivity

Perform the following steps to verify connectivity between Fortanix DSM and CloudLink:

1. Log in to the CloudLink application using valid credentials.
2. Click the **SERVER** → **DNS** menu item in the left navigation panel.
3. On the **DNS Configuration** page, click the **Ping** tab to verify connectivity between Fortanix DSM and CloudLink.

> [!NOTE]
> NOTE
> 
> This step verifies basic connectivity. It is critical to ensure that CloudLink establishes a connection to Fortanix DSM on Transmission Control Protocol (TCP) port 5696.
4. Enter the required load balancer IP address or Fortanix DSM URL in the provided field.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/CloudLink_Ping.png)

**Figure 6: Ping page**
5. Click **Ping** and check the response displayed on the screen to confirm successful connectivity. A positive response indicates that Fortanix DSM and CloudLink are connected successfully.

### 6.2 Creating a Local Keystore

Perform the following steps to configure the local keystore with external KMIP protector in CloudLink and integrate it with Fortanix DSM:

1. Click the **SYSTEM** → **Keystores** menu item in the left navigation panel.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/CloudLink_Keystore(2).png)

**Figure 7: Keystore page**
2. On the **Keystores** page, click **Add** to create a new keystore.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/CloudLink_Keystores(2).png)

**Figure 8: Add keystore**
3. In the **ADD NEW KEYSTORE** dialog box:
  1. Enter a **Name** and **Description** for the keystore. Click **Next**.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/CloudLink_Name_Description(1).png)

**Figure 9: Name and description**
  2. Select **Local Database** from the drop down menu for **Key Location Type** field to store encrypted keys locally within CloudLink. Click **Next**.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/CloudLink_Location_Type(1).png)

**Figure 10: Key location type field**
  3. Select **KMIP** from the drop down menu for **Protector Type** and enter the following required details:

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/CloudLink_Key_Protector(1).png)

**Figure 11: Protector type**

Where,

    1. **KMIP Server Address**: Enter the Fortanix DSM Load Balancer IP (Internet Protocol) or Fully Qualified Domain Name (FQDN).
    2. **Port**: **5696**. This is the default KMIP port.
    3. **Credential Type**: Based on the selected DSM app authentication method in [*Section 5.4: Creating an Application*](/v1/docs/using-fortanix-data-security-manager-with-dell-powerflex-using-cloudlink#54-creating-an-application), select the required option from the drop down menu.
      1. If the app uses **API Key** as the authentication method, select **Username and Password** as the keystore credential type and enter the following details:
        1. **Username/Serial Number**: Enter the **Username (app UUID)** as copied in [*Section 5.5: Copying the App UUID*](/v1/docs/using-fortanix-data-security-manager-with-dell-powerflex-using-cloudlink#55-copying-the-app-uuid).
        2. **Password**: Enter the **Password** as copied in [*Section 5.5: Copying the App UUID*](/v1/docs/using-fortanix-data-security-manager-with-dell-powerflex-using-cloudlink#55-copying-the-app-uuid).
      2. If the app uses **Certificate** as the authentication method, select **No Credentials**.
    4. **Key**: Browse and upload the private key generated in [*Section 5.6: Generating the Client Certificate and Private Key*](/v1/docs/using-fortanix-data-security-manager-with-dell-powerflex-using-cloudlink#56-generating-the-client-certificate-and-private-key).
    5. **Certificate**: Browse and upload the certificate generated in [*Section 5.6: Generating the Client Certificate and Private Key*](/v1/docs/using-fortanix-data-security-manager-with-dell-powerflex-using-cloudlink#56-generating-the-client-certificate-and-private-key).
    6. **Trusted Certificate**: Browse the full chain of Fortanix DSM certificates in **Base64-encoded ASCII** format as a **certificate chain**. Ensure the **Trusted Certificate** includes the entire chain.
  4. Click **Test** to verify connectivity between CloudLink and Fortanix DSM.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/CloudLink_KMIP_Details(1).png)

**Figure 12: KMIP keystore**
4. After the connectivity test is successful, click **Add** to add the local keystore to complete the setup.
5. Review and verify the keystore details to ensure proper configuration.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/CloudLink_Review_Verify(2).png)

**Figure 13: Review and verify**
6. After the keystore is successfully configured in CloudLink, it generates a security object (AES 256 bits key) in Fortanix DSM for the local keystore. The security object contains information about the key, its intended use (for example: encryption, decryption, signing, and so on), its lifecycle management (for example: creation, modification, or deletion), and how it is linked to the CloudLink keystore.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/DellPowerflex-1.png)

**Figure 14: View security object**
7. Validate the activity logs in the detailed view of the security object in Fortanix DSM to ensure that the application details are correctly logged and verified.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/DellPowerflex-2(1).png)

**Figure 15: Logs of security object**

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/DellPowerflex-3(1).png)

**Figure 16: Attributes and tags of the key**
8. Run the following command to verify the encryption status from the Storage Data Server (SDS) host:

```bash
svm status
```

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/CloudLink_SDS_Status(1).png)

**Figure 17: SDS status**

### 6.3 Creating an External Keystore

Perform the following steps to configure the external keystore in CloudLink and integrate it with Fortanix DSM:

1. Click the **SYSTEM** → **Keystores** menu item in the left navigation panel.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/CloudLink_Keystore(3).png)

**Figure 18: Keystore page**
2. On the **Keystores** page, click **Add** to create a new keystore.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/CloudLink_Keystores(3).png)

**Figure 19: Add keystore**
3. In the **ADD NEW KEYSTORE** dialog box,
  1. Enter a **Name** and **Description** for the keystore. Click **Next**.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/CloudLink_Name_Description_External(1).png)

**Figure 20: Name and description**
  2. Select **External KMIP Server** from the drop down menu for **Key Location Type** field to store encrypted keys externally on KMIP server. Click **Next**.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/CloudLink_Key_Location_External(1).png)

**Figure 21: Key location type field**
  3. Select **KMIP Proxy** from the drop down menu for **Protector Type** and enter the following required details:

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/CloudLink_Protector_Type_External(1).png)

**Figure 22: KMIP proxy**
    - **KMIP Server Address**: Enter the Fortanix DSM Load Balancer IP (Internet Protocol) or Fully Qualified Domain Name (FQDN).
    - **Port**: **5696**. This is the default KMIP port.
    - **Credential Type**: Based on the selected DSM app authentication method in [*Section 5.4: Creating an Application*](/v1/docs/using-fortanix-data-security-manager-with-dell-powerflex-using-cloudlink#54-creating-an-application), select the required option from the drop down menu.
      - If the app uses **API Key** as the authentication method, select **Username** and **Password** as the keystore credential type and enter the following details:
        - **Username/Serial Number**: Enter the **Username (app UUID)** as copied in [*Section 5.5: Copying the App UUID*](/v1/docs/using-fortanix-data-security-manager-with-dell-powerflex-using-cloudlink#55-copying-the-app-uuid).
        - **Password**: Enter the **Password** as copied in [*Section 5.5: Copying the App UUID*](/v1/docs/using-fortanix-data-security-manager-with-dell-powerflex-using-cloudlink#55-copying-the-app-uuid).
      - If the app uses **Certificate** as the authentication method, select **No Credentials**.
    - **Key**: Browse and upload the private key generated in [*Section 5.6: Generating the Client Certificate and Private Key*](/v1/docs/using-fortanix-data-security-manager-with-dell-powerflex-using-cloudlink#56-generating-the-client-certificate-and-private-key).
    - **Certificate**: Browse and upload the certificate generated in [*Section 5.6: Generating the Client Certificate and Private Key*](/v1/docs/using-fortanix-data-security-manager-with-dell-powerflex-using-cloudlink#56-generating-the-client-certificate-and-private-key).
    - **Trusted Certificate**: Browse the full chain of the Fortanix DSM certificates.
  4. Click **Test** to verify connectivity between CloudLink and Fortanix DSM.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/CloudLink_KMIP_Proxy(3).png)

**Figure 23: KMIP proxy keystore**
4. After the connectivity test is successful, click **Add** to add the external keystore to complete the setup.
5. Review and verify the keystore details to ensure proper configuration.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/CloudLink_Review_Verify_External(2).png)

**Figure 24: Review and verify**

### 6.4 Adding Approved Network

Perform the following steps to add approved networks in the CloudLink application:

1. Click the **SYSTEM** → **Approved Networks** menu item in the left navigation panel.
2. On the **Approved Networks** page, click **Add** to create a new approved network.
3. In the **ADD APPROVED NETWORK** dialog box,
  1. **Network Name**: Enter a descriptive name for the network.
  2. **Network IP Address Range**: Specify the IP address range of the network you want to approve. For example, **192.168.1.0/24**.
  3. **Description** (Optional): Enter a description for the network to help identify it later.
4. Click **Save** to add the approved network to the list.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/CloudLink_Approved_Networks(1).png)

**Figure 25: Approved network added**

The newly added network will appear in the **Approved Networks** list. Verify that the IP range and description are correct.

### 6.5 Creating Machine Group

Perform the following steps to create a machine group in the CloudLink application:

1. Click the **AGENTS** → **Machine Groups** menu item in the left navigation panel.
2. On the **Machine Groups** page, click **Add** to create a new machine group.
3. In the **ADD NEW GROUP** dialog box,

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/CloudLink_Machine_Group_Dialog_box(1).png)

**Figure 26: Adding machine group**
  1. Enter a **Name** and **Description** for the machine group.
  2. **Encryption Policy**: Select the required option from the drop down menu. Selecting **All Data** will display a new field named, **Managed SED Drives**.
    1. Select **Enabled** from the drop down menu for **Managed SED Drives** field.
  3. **Keystore**: Select the required keystore from the drop down menu.
  4. **Managed By**: Select the appropriate management option from the drop down menu.
  5. **Approved Networks**: Select the network from the approved list using the IP addresses as created in [*Section 6.4: Adding Approved Network*](/v1/docs/using-fortanix-data-security-manager-with-dell-powerflex-using-cloudlink#64-adding-approved-network).
  6. **Key Lifetime**: Select the key lifetime from the drop down menu.
  7. **Machine Agent Upgrade**: Select the upgrade as **Manual** or **Auto** as required from the drop down menu.
4. Click **Add** to add machine group to complete the setup.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/CloudLink_Machine_Group_Added(1).png)

**Figure 27: Add machine group**

### 6.5 Downloading the Agent

Perform the following steps to download the agent from the CloudLink application:

1. Navigate to the **AGENTS** → **Agent Download** menu item in the left navigation panel.
2. On the **Agent Download** page, select the required agent from the list and click **Download Selected**. *Refer to* [*Dell CloudLink Deployment*](https://dl.dell.com/content/manual38157879-dell-cloudlink-8-0-1-deployment-guide.pdf?language=en-us) *for the latest CloudLink version.*

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/CloudLink_Agents_Download(1).png)

**Figure 28: List of agents**
3. Select the appropriate agent version based on your operating system or environment from the drop down menu.
4. Click **Download** to start the download process.

### 6.6 Installing and Configuring CloudLink Agent

Perform the following steps to install and configure the CloudLink agent on your system:

1. Run the following command to create the CloudLink directory and navigate to it:

```plaintext
mkdir -p /root/CL
cd /root/CL
```
2. Run the following command to download the CloudLink agent installation script:

```plaintext
wget --no-check-certificate https://<server-ip>/cloudlink/agent -O clagent.sh
```

Where, `&lt;server-ip&gt;` is the IP address of the CloudLink server.
3. Run the following command to retrieve the certificate from the CloudLink server and save it as `cloudlink-&lt;hostname&gt;.pem` :

```plaintext
openssl s_client -servername <server-ip> -connect <server-ip>:443 < /dev/null | sed -ne '/-BEGIN CERTIFICATE-/,/-END CERTIFICATE-/p' > cloudlink-<hostname>.pem
```

Where,
  - `&lt;server-ip&gt;`: Refers to the IP address of the CloudLink server.
  - `&lt;hostname&gt;`: Refers to the name of the host. For example, **pfmpcl-sds1**.
4. Run the following commands to copy the certificate to the required directories:

```plaintext
cp cloudlink-<hostname>.pem /usr/share/pki/ca-trust-source/anchors/
cp cloudlink-<hostname>.pem /etc/pki/ca-trust/source/anchors/
```
5. Run the following command to start the CloudLink agent on the PowerFlex storage device server CLI:

```plaintext
./clagent.sh -S <server-ip> -G <group-id> &
```

Where,
  - `&lt;server-ip&gt;`: Refers to the IP address of the PowerFlex SDS server.
  - `&lt;group-id&gt;`: Refers to the specific group identifier for the CloudLink agent.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/CloudLink_Commands(2).png)

**Figure 29: Commands**

### 6.7 Encrypting SDS

Perform the following steps to encrypt the SDS from PowerFlex and CloudLink:

1. Navigate to the **AGENTS** → **Machines** menu item in the left navigation panel.
2. Click the **Actions** drop down menu and select **Encrypt** after verifying the **RAW** status.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/CloudLink_Machine_Detailed_View(1).png)

**Figure 30: Detailed view of machine**

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/CloudLink_Machine_Details(1).png)

**Figure 31: Actions menu**

## 7.0 Configure PowerFlex Manager

This section outlines the steps to encrypt PowerFlex Manager using CloudLink and then re-integrate it back into PowerFlex SDS.

### 7.1 Removing the Storage Device

Perform the following steps to remove the storage device from the SDS host:

1. Log in to the PowerFlex Manager application using valid credentials.
2. Click the **Block** menu from the ribbon navigation panel and select **SDSs**.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/PowerFlex_Block_Menu(1).png)

**Figure 32: Block menu**
3. From the displayed list, select the specific SDS.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/PowerFlex_SDS_List(1).png)

**Figure 33: List of SDSs**
4. Identify and select the storage devices (for example, hard drives, SSDs) associated with or hosted by the selected SDS.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/PowerFlex_Devices(1).png)

**Figure 34: Topology section**
5. Clicking the **Devices** box will display the following screen:

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/PowerFlex_Devices_List(1).png)

**Figure 35: List of attached devices**
6. Click **More Actions** and select **Remove** from the drop down menu to remove the device from the host.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/PowerFlex_More_Actions(1).png)

**Figure 36: More actions menu**
7. Refresh the **PowerFlex SDS** page to confirm that the device has been successfully removed.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/PowerFlex_Devices_List_Final(1).png)

**Figure 37: List of final devices**

### 7.2 Encrypting a Storage Device Using CloudLink

Perform the following steps to encrypt a storage device using CloudLink:

1. After removing the device from the PowerFlex SDS host, go to CloudLink application and click the **Machines** menu in the left navigation panel.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/CloudLink_Detailed_View_Machine(1).png)

**Figure 38: Detailed view of machine**
2. Verify the status and type of the device to confirm that it is listed as **RAW** before proceeding with encryption.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/PowerFlex_Status(1).png)

**Figure 39: Check status**
3. After the device is ready for encryption, select **Encrypt** from the **Actions** drop down menu.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/CloudLink_Machine_Encrypt(1).png)

**Figure 40: Actions menu**
4. From the list of available devices, select the one that needs to be encrypted from the drop down menu.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/CloudLink_Encrypt_Button(1).png)

**Figure 41: Devices field**
5. The device status will update once the encryption process begins.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/CloudLink_Status_Banner(1).png)

**Figure 42: Status**
6. Monitor the encryption progress in the user **Actions** page.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/CloudLink_Summary(1).png)

**Figure 43: Summary view**
7. After encryption is complete, check the device status. It must now be listed as **Encrypted** and **RAW**.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/CloudLink_Status_Check(1).png)

**Figure 44: Status check**
8. Navigate to the **Audit Log** page in Fortanix DSM to confirm that the encryption process was successfully completed.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/DellPowerflex-4(1).png)

**Figure 45: Audit log**

### 7.3 Adding Device Back to SDS

Perform the following steps to re-integrate a removed storage device into PowerFlex SDS:

1. In the PowerFlex Manager application, click the **Block** menu from the ribbon navigation panel and select **SDSs**.
2. From the list, select the **SDS** for which the device was removed earlier. Then, click **Add Device** drop down menu and select **Storage Device**.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/PowerFlex_Storage_Device(1).png)

**Figure 46: Add device menu**
3. Enter the required details for the storage device in the prompted fields, then click **Add Devices** to finalize the addition.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/PowerFlex_Add_Device(2).png)

**Figure 47: Add a device form**

The following dialog box will be displayed to confirm that the device is added successfully.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/CloudLink_Success_Notification(1).png)

**Figure 48: Success notification**
4. Refresh the **Storage Devices** list to reflect the added device in the list.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/CloudLink_SDSs_List(1).png)

**Figure 49: List of SDSs**
5. Verify the encryption status of the device in the **Machines** tab.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/CloudLink_Machine_Status(2).png)

**Figure 50: Status of machine**

### 7.4 Encrypting Devices Using External Keystore

Perform the following steps to encrypt devices using an external keystore:

1. Navigate to the **Machine Group** menu item and select the appropriate external keystore from the list.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/CloudLink_Machine_Details(2).png)

**Figure 51: Detailed view of machine**
2. Perform the steps to remove the storage device from the SDS in **PowerFlex Manager** application as outlined in [*Section 7.1: Removing the Devices*](/v1/docs/using-fortanix-data-security-manager-with-dell-powerflex-using-cloudlink#71-removing-the-device), before encryption.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/DellPowerflex-4.png)

**Figure 52: Encrypting the machine status**
3. Perform the encryption steps in CloudLink as outlined in [*Section 7.2: Encrypting a Storage Device Using CloudLink*](/v1/docs/using-fortanix-data-security-manager-with-dell-powerflex-using-cloudlink#72-encrypting-a-storage-device-using-cloudlink).
4. After the storage device is encrypted using the external keystore, a new security object will be created for each device.
5. Verify the newly created security object.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/DellPowerflex-5.png)

**Figure 53: Review the security object**
6. Review the logs in Fortanix DSM to ensure the encryption was completed successfully.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/DellPowerflex-6(1).png)

**Figure 54: Audit logs**

## 8.0 Backup and Restore

CloudLink keystore can be backed up and restored within CloudLink for both local and external keystores. *For more information, refer to* [*Dell CloudLink Deployment*](https://www.dell.com/support/product-details/en-in/product/cloudlink-securevm/docs)*.*

## 9.0 Key Rotation

CloudLink supports key rotation, allowing the key to be rotated internally. *For more information, refer to* [*Dell CloudLink Deployment*](https://www.dell.com/support/product-details/en-in/product/cloudlink-securevm/docs)*.* Additionally, external keys can also be rotated using the Fortanix DSM user interface (UI).

## 10.0 Rollback/Reverse Migration

A restore can only be performed if a keystore backup exists prior to encryption. You can move the keys for this operation. *For more information, refer to* [*Dell CloudLink Deployment*](https://www.dell.com/support/product-details/en-in/product/cloudlink-securevm/docs)*.*

Fortanix Data Security Manager (DSM) is the world’s first cloud service secured with Intel® SGX. With Fortanix DSM, you can securely generate, store, and use cryptographic keys and certificates, as well as other secrets such as passwords, API keys, tokens, or any blob of data. Your business-critical applications and containers can integrate with Fortanix DSM using legacy cryptographic interfaces (PKCS#11, CNG, and JCE) or using the native Fortanix DSM RESTful interface.
