Scalar I500 User's Guide - Quantum scalar i500 User Manual

Hide thumbs Also See for scalar i500:
Table of Contents

Advertisement

Scalar i500 User's Guide

particular library, that library attempts to automatically generate data
encryption keys on the SKM server. Both SKM servers must be running
and operational in order for automatic key generation to succeed.
If automatic key generation succeeds,
keys were generated and instructs you to back up both SKM server
keystores as soon as possible.
If automatic key generation fails,
new key is requested, until the keys are 90 percent depleted. At that
point, the library stops trying to auto-generate keys and issues a RAS
ticket stating that you must manually generate keys. See
Generating Data Encryption Keys
Generating Data Encryption Keys When 100% Depleted
server completely runs out of data encryption keys for a particular
library, that library generates a RAS ticket, which states that you have run
out of data encryption keys and that the library attempted to fail over to
the other SKM server. If this happens, it is imperative that you manually
generate a new set of data encryption keys on the depleted server
immediately and then back up both SKM servers. See
Generating Data Encryption Keys
Manually Generating Data Encryption Keys
data encryption keys, you need to temporarily disable library managed
encryption on a partition, and then enable it again. Enabling library
managed encryption on a partition triggers the library to check both SKM
servers to see if new data encryption keys are needed. If so, it creates the
keys.
The data encryption key generation process takes
Note:
approximately 15 minutes. You should not run any library or
host-initiated operations on SKM partitions during key
generation and backup.
Avoid manually generating keys on more than five libraries
simultaneously as the key generation process is resource-intensive on the
server. Generating keys manually on more than five libraries at once
could result in a failure to complete the key generation operation, or
interfere with key retrieval operations. If a failure does occur during key
generation, wait 10 minutes, then try to start it again. The key generation
process will resume from where the error was encountered.
Chapter 7 Encryption Key Management
Configuring Encryption Key Management on the Library
a RAS ticket informs you the
the library tries again every time a
on page 194.
on page 194.
Manually
If an SKM
Manually
To manually generate
7
7
194

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents