IBM TS2340 User Guide - Page 202

System-Managed Encryption, Device Driver Configuration, Configuration File

Page 202 highlights

Windows System-Managed Encryption System-Managed Encryption Device Driver Configuration System-managed encryption parameters on Windows are placed in the registry under the key for the device driver. The parameters are populated in user-created subkey containing the serial number of the device. The registry keys (sys_encryption_proxy and sys_encryption_write) are used to determine SME enablement and invocation of the EKM proxy on write, respectively. Note: Leading zeros in the serial number should be excluded. For example, if the serial number of the encryption-capable tape drive were 0123456789, the user would create the following registry key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ibmtp2k3\123456789 Under this key, the user would create DWORD values called sys_encryption_proxy and/or sys_encryption_write, and assign them values corresponding with the desired behavior. The device driver SME settings can be set for all drives at once by placing the ″sys_encryption_proxy″ and ″sys_encryption_write″ registry options under the device driver key, found at: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ibmtp2k3 When this option is chosen, the settings established for all drives are overridden by the serial-number specific settings described the previous paragraph. If no options are specified in the registry, the driver uses the default values for the parameters. v The default value for sys_encryption_proxy is 1. This value causes the device driver to handle encryption key requests, if the drive is set up for system-managed encryption. This value should not need to be changed. A value of 0 causes the device driver to ignore encryption key requests for system-managed encryption drives, and is not desirable. v The default value for sys_encryption_write is 2. This value causes the device driver to leave the encryption write-from-BOP settings alone. It does not turn on or turn off encryption writing, but instead uses the settings that are already in the drive. If encryption has not been set up previously, then the drive writes unencrypted data. A value of 0 causes the device driver to write unencrypted data. A value of 1 causes the device driver to write encrypted data. Changes to the registry require a reboot before the settings are able to be viewed; however, during new installations of the driver, if the old driver is not uninstalled, the old settings remain in place and no reboot is required. Configuration File The file %system_root%:\IBMEKM.conf is used to store the IP address of the EKM server and other network-related parameters. The phrase %system_root% refers to the drive letter where the Windows installation is located, typically C (for example C:\IBMEKM.conf). The format for the EKM server parameters is: 184 IBM Tape Device Drivers Installation and User's Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457

System-Managed Encryption
Device Driver Configuration
System-managed encryption parameters on Windows are placed in the registry
under the key for the device driver. The parameters are populated in user-created
subkey containing the serial number of the device. The registry keys
(
sys_encryption_proxy
and
sys_encryption_write
) are used to determine SME
enablement and invocation of the EKM proxy on write, respectively.
Note:
Leading zeros in the serial number should be excluded. For example, if the
serial number of the encryption-capable tape drive were 0123456789, the
user would create the following registry key:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ibmtp2k3\123456789
Under this key, the user would create DWORD values called
sys_encryption_proxy
and/or
sys_encryption_write
, and assign them values corresponding with the
desired behavior.
The device driver SME settings can be set for all drives at once by placing the
sys_encryption_proxy
and
sys_encryption_write
registry options under the
device driver key, found at:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ibmtp2k3
When this option is chosen, the settings established for all drives are overridden by
the serial-number specific settings described the previous paragraph.
If no options are specified in the registry, the driver uses the default values for the
parameters.
v
The default value for
sys_encryption_proxy
is 1.
This value causes the device driver to handle encryption key requests, if the
drive is set up for system-managed encryption. This value should not need to be
changed. A value of 0 causes the device driver to ignore encryption key requests
for system-managed encryption drives, and is not desirable.
v
The default value for
sys_encryption_write
is 2.
This value causes the device driver to leave the encryption write-from-BOP
settings alone. It does not turn on or turn off encryption writing, but instead
uses the settings that are already in the drive. If encryption has not been set up
previously, then the drive writes unencrypted data. A value of 0 causes the
device driver to write unencrypted data. A value of 1 causes the device driver to
write encrypted data.
Changes to the registry require a reboot before the settings are able to be viewed;
however, during new installations of the driver, if the old driver is not uninstalled,
the old settings remain in place and no reboot is required.
Configuration File
The file
%system_root%:\IBMEKM.conf
is used to store the IP address of the EKM
server and other network-related parameters. The phrase
%system_root%
refers to
the drive letter where the Windows installation is located, typically C (for example
C:\IBMEKM.conf).
The format for the EKM server parameters is:
Windows System-Managed Encryption
184
IBM Tape Device Drivers Installation and User’s Guide