Secure Mode - HP StoreEver MSL3040 User's And Service Manual

Tape libraries
Table of Contents

Advertisement

Procedure
All library partitions must be defined.
Encryption configuration must be complete and encryption enabled for the partition. The partition must
use library-managed encryption (such as KMIP or the MSL Encryption Kit).
All drives in the partition must be LTO-6 or later generation and running a firmware version that
supports Secure Mode.
1. Remove any LTO-5 or earlier generation tape drives from the partition.
2. For LTO-6 drives: All drive firmware that supports Secure Mode can be used with or without Secure
Mode enabled. If necessary, upgrade the drive firmware to a version that supports Secure Mode.
FC—253W or later
SAS—354W or later
3. For LTO-7 and later generation drives: LTO-7 and later generation tape drives have separate
firmware images that enable or disable Secure Mode when the firmware image is loaded onto the
drive. If necessary, download and install the Secure Mode firmware image.
For a current list of products that are FIPS 140-2 Validated, see the NIST FIPS 140-2 Crypto
Module Validation List. If FIPS 140-2 Validation is required, verify the validation status before
purchasing the product.

Secure Mode

Secure Mode is a setting in the tape drive that only permits encryption settings to be established by the
library that enabled Secure Mode using secure methods. Once a partition has been configured for FIPS
Support Mode, the library will enable Secure Mode for all LTO-6 drives in the partition each time the
library is powered on and disable Secure Mode for all the drives in the partition each time the library is
powered off via a soft power off. The library also disables Secure Mode for a drive when it is powered off
from the RMI.
Disabling Secure Mode for an LTO-6 tape drive
To disable Secure Mode for an LTO-6 tape drive, verify that the tape drive is installed in the library that
enabled Secure Mode and then either power off the drive, or power off or reboot the library.
IMPORTANT:
If Secure Mode is enabled for a drive and either the drive is removed from the library without
powering it off first or the library has a hard shutdown (for example it loses power or the front panel
power button is held for more than 10 seconds), the drive could still have Secure Mode enabled. To
disable Secure Mode, power on the drive in the library that enabled Secure Mode and then power
off the drive from the RMI or OCP.
Procedure
1. Power off the drive from the OCP or RMI Configuration > Drives > Settings screen.
2. Power off the library from the library OCP by holding the power button on the front panel for five
seconds.
Secure Mode
83

Advertisement

Table of Contents
loading

Table of Contents