This chapter describes hicli, which can be used for managing operations between the Cryptographic Security Platform Vault cluster and a Entrust Policy Agent present in Linux and Windows virtual machines. hicli uses a combination of the Cryptographic Security Platform Vault REST APIs to communicate with Cryptographic Security Platform Vault, and SSH to invoke hcl commands on Windows and Linux VMs.

The Policy Agent provides for encryption of devices within Linux and Windows virtual machines. The management of keys and the administration of the Policy Agent is through a Cryptographic Security Platform Vault cluster. Administration can take place through the webGUI, through the RESTful APIs, or through using the hicli command.

hicli can only be accessed through the Cryptographic Security Platform Vault for Databases webGUI and the Cryptographic Security Platform Vault for VM Encryption webGUI.

The following figure shows the servers that are involved:

We will be operating with one or more clustered Cryptographic Security Platform Vault nodes, a number of Linux or Windows VMs and the API Server, a server from which hicli will be invoked. This can be almost any UNIX-like server including Linux, BSD variants, OS/X and so on.