Adding a device

You can add a device to the IBM Security Guardium Key Lifecycle Manager database.

About this task

If device.enableMachineAffinity is set to true, adding a device requires that you also add a relationship between a device and a machine. Otherwise, keys are not served to the added device. Using machine affinity, you can set key serving for specific device and machine combinations. Similarly, if device.enableVolserAffinity is set to true, adding a device requires that you also add a relationship between a device and its volume serial number.

You can use the Add Device dialog or the Device Add REST Service to add a device. Your role must have the permission to the create action and a permission to the appropriate device group.

Procedure

  1. Go to the appropriate page or directory.
    • Graphical user interface:
      1. Log on to the graphical user interface.
      2. In the Key and Device Management section on Welcome page, select DS5000.
      3. Click Go to > Manage keys and devices.
      4. Alternatively, right-click DS5000 and select Manage keys and devices.
      5. On the management page for DS5000, click Add.
      6. Click Device.
    • REST interface:
      • Open a REST client.
  2. Add a device.
    • Graphical user interface:

      On the Add Device dialog, type the required and optional information. Then, click Add Device.

    • REST interface:
      1. Obtain a unique user authentication identifier to access IBM Security Guardium Key Lifecycle Manager REST services. For more information about the authentication process, see Authentication process for REST services.
      2. To invoke the Device Add REST Service, send the HTTP POST request. Pass the user authentication identifier that you obtained in Step a along with the request message as shown in the following example:
        POST https://localhost:port/SKLM/rest/v1/devices
        Content-Type: application/json
        Accept : application/json
        Authorization : SKLMAuth userAuthId=37ea1939-1374-4db7-84cd-14e399be2d20
        Accept-Language : en
        {"type":"DS5000","serialNumber":"CDA39403AQJF","attributes":"worldwideName
        ABCdeF1234567890,description marketingDivisionDrive"}

What to do next

Next, you can associate the device with a machine.