The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Export disk encryption key(s) for a system

Prev Next

The purpose of encrypting the client's data is to control access to the data by controlling access to the encryption keys. These keys are referred to as Machine Keys. Each system has its own unique Machine Key. The Machine Key is stored in ePO - On-prem database to be used for client recovery when required. Use the eeadmin.exportMachineKey command to remotely export disk encryption key(s) for a system.

eeadmin.exportMachineKey command

Command

Syntax

Description

eeadmin.exportMachineKey

eeadmin.exportMachineKey[machineIdOrName=<>] [keyCheck=<>] [oldKeys=<>]

A system may be activated and deactivated multiple times. Each activation produces a new disk encryption key.

Specify the following:

  • the ePO - On-prem System ID or ePO - On-prem System Name to export disk encryption key(s) for a specific system, or

  • a disk Key-Check value to look up the encryption key related to the disk

    Note

    This lookup might take some time and the Key-Check value can be obtained for a disk from DETech.

The encryption key of a disk might not be the same as the encryption key of a system. This is applicable when the disk is removed from the (encrypted) system prior to a deactivation/reactivation.

Specify oldKeys=’True’ to export all disk encryption keys related to the system.