IBM TS2340 User Guide - Page 36

Planning for Application-Managed Tape Encryption, System-Managed Tape Encryption

Page 36 highlights

Data Encryption encryption. For details on setting up application-managed tape encryption refer to the Tivoli Storage Manager documentation or for more information, visit the following site: http://publib.boulder.ibm.com/infocenter/tivihelp/v1r1/index.jsp System-Managed Tape Encryption In this method, key generation and management is performed by the EKM, a Java™ application running on the host. Policy controls and keys pass through the data path between the system layer (device drivers) and the encryption-capable tape drives. Encryption is transparent to the applications. It is required to use the latest device drivers available on the ftp down load site: ftp://ftp.software.ibm.com/storage/devdrvr/ Refer to "Planning for System-Managed Tape Encryption" on page 19 for details on the hardware and software requirements for system-managed encryption. For details on setting up system-managed encryption in different operating system environment, refer to the applicable chapter for each operating system. Library-Managed Tape Encryption This method is best for encryption-capable tape drives in an open attached IBM tape libraries. Scratch encryption policies specifying when to use encryption are set up through the IBM System Storage Tape Library Specialist Web interface. Policies are based on cartridge volume serial numbers. Key generation and management is performed by the EKM, a Java application running on a host. Policy control and keys pass through the library-to-drive interface, therefore encryption is transparent to the applications. Library-managed encryption is supported on AIX, Windows Server 2003, Windows Server 2008, Linux, Solaris, and HP-UX. Please refer to "Planning for Library-Managed Tape Encryption" on page 21 for details on the hardware and software requirements for library-managed encryption. For details on setting up library-managed encryption on encryption-capable tape drives, please refer to the IBM System Storage Tape Library Operator's Guide for your library. Planning for Application-Managed Tape Encryption Note: Please contact your IBM Representative for additional information about encryption on the IBM encryption-capable tape drive. In order to perform encryption on the encryption-capable tape drive, the following is required: v Encryption-capable tape drive(s) v Encryption configuration features: - Library code updates and Transparent LTO Encryption feature code for libraries with Ultrium LTO4 drives - Tape drive code updates Application-Managed Tape Encryption Setup Tasks Any task not identified as an IBM service task is the responsibility of the customer. 1. Install, cable, and configure the encryption-capable tape drive (refer your IBM System Storage Tape Drive or Library Operator's Guide ) 2. Install appropriate IBM tape device driver level (Atape, for example). 3. Set up encryption policies. Refer to the appropriate TSM documentation. 18 IBM Tape Device Drivers Installation and User's Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457

encryption. For details on setting up application-managed tape encryption refer to
the Tivoli Storage Manager documentation or for more information, visit the
following site:
System-Managed Tape Encryption
In this method, key generation and management is performed by the EKM, a
Java
application running on the host. Policy controls and keys pass through the
data path between the system layer (device drivers) and the encryption-capable
tape drives. Encryption is transparent to the applications.
It is required to use the latest device drivers available on the
ftp
down load site:
Refer to “Planning for System-Managed Tape Encryption” on page 19 for details on
the hardware and software requirements for system-managed encryption. For
details on setting up system-managed encryption in different operating system
environment, refer to the applicable chapter for each operating system.
Library-Managed Tape Encryption
This method is best for encryption-capable tape drives in an open attached IBM
tape libraries. Scratch encryption policies specifying when to use encryption are set
up through the IBM System Storage Tape Library Specialist Web interface. Policies
are based on cartridge volume serial numbers. Key generation and management is
performed by the EKM, a Java application running on a host. Policy control and
keys pass through the library-to-drive interface, therefore encryption is transparent
to the applications.
Library-managed encryption is supported on AIX, Windows Server 2003, Windows
Server 2008, Linux, Solaris, and HP-UX. Please refer to “Planning for
Library-Managed Tape Encryption” on page 21 for details on the hardware and
software requirements for library-managed encryption. For details on setting up
library-managed encryption on encryption-capable tape drives, please refer to the
IBM System Storage Tape Library Operator’s Guide for your library.
Planning for Application-Managed Tape Encryption
Note:
Please contact your IBM Representative for additional information about
encryption on the IBM encryption-capable tape drive.
In order to perform encryption on the encryption-capable tape drive, the following
is required:
v
Encryption-capable tape drive(s)
v
Encryption configuration features:
Library code updates and Transparent LTO Encryption feature code for
libraries with Ultrium LTO4 drives
Tape drive code updates
Application-Managed Tape Encryption Setup Tasks
Any task not identified as an IBM service task is the responsibility of the customer.
1.
Install, cable, and configure the encryption-capable tape drive (refer your IBM
System Storage Tape Drive or Library Operator’s Guide )
2.
Install appropriate IBM tape device driver level (Atape, for example).
3.
Set up encryption policies. Refer to the appropriate TSM documentation.
Data Encryption
18
IBM Tape Device Drivers Installation and User’s Guide