Use pkcs11_kms with ZFS

Configure ZFS to use the PKCS#11 provider (pkcs11_kms) to retrieve encryption keys from an OKM cluster.

This requires a configured OKM cluster and a Solaris 11 system with established connectivity to KMAs in this OKM cluster. Once a Solaris 11 administrator installs and configures pkcs11_kms, the administrator can request that pkcs11_kms create a key, and then direct ZFS to use it.

See the following sections for more information about pkcs11_kms: