Prerequisites
- Infisical KMIP server deployed and running (see KMIP Integration)
- Dell PowerEdge server with iDRAC Enterprise license
- SEKM license installed on iDRAC
- Network connectivity between iDRAC and KMIP server on port 5696
Integration Steps
Create a KMIP Client in Infisical
In your KMS project, navigate to KMIP and create a KMIP client for the iDRAC.
Configure SEKM on iDRAC
- Log into the iDRAC web interface
- Navigate to iDRAC Settings > Services
- Expand iDRAC Key Management and select SEKM
- Enter the KMIP server address and port (default: 5696)
- Click Next
Generate Certificate Request on iDRAC
When iDRAC prompts you to generate a certificate request, you’ll need to enter subject values. You can find the required values in Infisical by clicking Generate Certificate on your KMIP client and selecting the CSR request method - the modal will display the exact Client ID and Project ID to use.
- Click Generate CSR on iDRAC
- Enter the certificate information:
- Common Name (CN): Enter the Client ID shown in Infisical
- Organizational Unit (OU): Enter the Project ID shown in Infisical
- Fill in other fields as needed (Organization, Country, etc.)
- Click Generate and download the certificate request file
Sign the Certificate in Infisical
- In the Infisical modal, paste the certificate request content from iDRAC
- Set the certificate validity period (e.g., “1y” for one year)
- Click Sign Certificate
- Download the signed certificate and certificate chain
Upload Certificate to iDRAC
- In iDRAC, upload the signed client certificate
- Upload the certificate chain as the KMS CA certificate
- Click Test Network Connection to verify connectivity
- Complete the SEKM configuration
Troubleshooting
- Certificate validation fails: Make sure you used the correct Client ID and Project ID when generating the certificate request on iDRAC.
- Connection timeout: Verify network connectivity and that firewall rules allow traffic on port 5696.
- Authentication errors: Ensure you uploaded both the signed certificate and the certificate chain to iDRAC.