Configure Library: Encryption Activation - IBM TS3100 Setup, Operator, And Service Manual

Tape library
Table of Contents

Advertisement

Figure 47. Configure Library: Encryption Activation screen
4. Select Enable SSL for EKM to enable Secure Sockets Layer for the IBM SKLM application.
5. Select an Encryption method for each logical library.
v Without an encryption license key, select None or Application Managed Encryption.
v With an encryption license key, select Library Managed Encryption or System Managed
Encryption.
6. Select an Encryption policy for each logical library.
v Encrypt All: This is the default policy. It encrypts all cartridges with the default data keys that are
specified in the key manager. This setting applies to all drives in a 3573 logical library.
v Internal Label - Selective Encryption: This policy is based on the internal volume label
information. Currently, the only application that supports this option is Symantec NetBackup. It
encrypts only cartridges with pool identifiers 1500 - 9999 (inclusive), with keys specific to each
pool. Labels for these keys are generated by the tape drive that is based on the pool identifier; for
instance, key label IL_NBU_1505 is generated for a cartridge in pool 1505.
v Internal Label - Encrypt All: This policy is based on the internal volume label information.
Currently, the only application that supports this option is Symantec NetBackup. It encrypts all
cartridges. Cartridges with pool identifiers 2000 - 65535 (inclusive) are encrypted with keys
specific to each pool. Labels for these keys are generated by the tape drive that is based on the
pool identifier; for instance, key label IL_NBU_2505 is generated for a cartridge in pool 2505.
7. A primary and secondary key management server is set for each logical library. Each partition has its
own Encryption and key management settings. Maintaining primary and secondary key
management servers is wanted for maximum availability of encrypted backup and recovery. These
settings are required for Library Managed Encryption only. Enter the EKM Server Setting
information.
v Primary IP address (IPv4 or IPv6): Enter the IP address of the primary key management server.
v Primary TCP port: After the Primary IP address is entered, the library automatically sets the value
of the Primary TCP port.
Installation and configuration
65

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Ts3200

Table of Contents