The purpose of encrypting the client's data is to control access to the data by controlling access to the encryption keys. These keys are referred to as Machine Keys. Each system has its own unique Machine Key. The Machine Key is stored in ePO - On-prem database to be used for client recovery when required. Use the eeadmin.exportMachineKey command to remotely export disk encryption key(s) for a system.
Command | Syntax | Description |
|---|---|---|
eeadmin.exportMachineKey |
| A system may be activated and deactivated multiple times. Each activation produces a new disk encryption key. Specify the following:
The encryption key of a disk might not be the same as the encryption key of a system. This is applicable when the disk is removed from the (encrypted) system prior to a deactivation/reactivation. Specify |