A Secure Deployment Checklist
This checklist includes guidelines that help secure your key management system:
- Install each KMA in a physically secure environment.
- Secure the OpenBoot PROM on each KMA.
- Secure the Lights Out Manager on each KMA.
- Define the key split configuration for this Oracle Key Manager Cluster.
- Set the autonomous unlock setting for each KMA as appropriate.
- Define Oracle Key Manager users and their associated roles.
- Practice the principle of least privilege.
- Grant each Oracle Key Manager user only those roles as needed.
- Monitor activity on the Oracle Key Manager Cluster.
- Investigate any errors, especially Security Violations, that are logged in the Oracle Key Manager audit log.
- Back up the core security when the key split configuration is initially defined and whenever the key split configuration is modified.
- Perform Oracle Key Manager backups on a regular basis.
- Store core security backup files and Oracle Key Manager backup files in a secure location.
- Set the Export Format attribute of key transfer partners to
v2.1 (FIPS)
when key sharing is used.