IBM TS2340 User Guide - Page 38

Data Encryption, IPv4 EKM, server IPv4-only, server, dual-stack host

Page 38 highlights

Data Encryption # IBM Encryption Key Manager Configuration File # # (C) COPYRIGHT International Business Machines Corp. 2006 # All Rights Reserved # Licensed Materials - Property of IBM # # US Government Users Restricted Rights - Use, duplication or # disclosure restricted by GSA ADP Schedule Contract with IBM Corp. # # This file contains the TCP/IP address(s) and port(s) for the Encryption Key # Server with a configuration entry in the following formats. The IPv4 address # entered as x.x.x.x:port. The IPv6 address entered as x:x:x:x:x:x:x:x port. # The server is for information only and is not used. The timeout value is # specified in seconds. # # The format for IPv4 address: # server timeout address:port # for example, # ekmtest 10 9.12.123.1234:8050 # # The format for IPv6 address: # server timeout address port # for example, # ekmtest 10 fe80::207:30ee:edcb:d05d 8050 # # The Encryption Key Server address and port can be a local loop back # address 127.0.0.1:port in IPv4 format or ::1 port in IPv6 format if the server # is on the same host or a network address and port if external to the host. # Up to 16 server address and port entries are supported if there are multiple # TCP/IP connections to the same server and/or multiple servers. # # Interoperability between IPv4 and IPv6 versions running on dual-stack hosts: # IPv4 Client IPv4/IPv6 Server using IPv4 address for EKM server # IPv6 Client IPv4 Server using IPv4 address for EKM server # IPv6 Client IPv6 Server using IPv6 address for EKM server # # Sample entry for a local server with a 10 second timeout using port 8050 # in IPv4 format # ekmtest 10 127.0.0.1:8050 # # in IPv6 format # ekmtest 10 ::1 8050 Figure 6. Sample Encryption Configuration File The following shows the different entry formats for IPv4 and IPv6 addresses in the ibmekm.conf configuration file: v IPv4 format: "EKMserver timeout IPv4_address Port_number" v IPv6 format: "EKMserver timeout IPv6_address Port_number" To set up an IP address for an EKM server, use Table 4 to choose an appropriate IP address type and then add the IP address in the entry of the encryption configuration file. Table 4. Interoperability between IPv4 and IPv6 Clients and Servers IPv4 EKM IPv6 EKM IPv4 EKM server IPv4-only server IPv6-only server host host dual-stack host IPv4 IPv4 (no) Client/IPv4-only host IPv4 IPv6 EKM server Dual-stack host IPv4 20 IBM Tape Device Drivers Installation and User's Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457

The following shows the different entry formats for IPv4 and IPv6 addresses in the
ibmekm.conf
configuration file:
v
IPv4 format: “EKMserver timeout IPv4_address Port_number”
v
IPv6 format: “EKMserver timeout IPv6_address Port_number”
To set up an IP address for an EKM server, use Table4 to choose an appropriate IP
address type and then add the IP address in the entry of the encryption
configuration file.
Table 4. Interoperability between IPv4 and IPv6 Clients and Servers
IPv4 EKM
server IPv4-only
host
IPv6 EKM
server IPv6-only
host
IPv4 EKM
server
dual-stack host
IPv6 EKM
server
Dual-stack host
IPv4
Client/IPv4-only
host
IPv4
(no)
IPv4
IPv4
#
IBM Encryption Key Manager Configuration File
#
#
(C) COPYRIGHT International Business Machines Corp. 2006
#
All Rights Reserved
#
Licensed Materials - Property of IBM
#
#
US Government Users Restricted Rights - Use, duplication or
#
disclosure restricted by GSA ADP Schedule Contract with IBM Corp.
#
#
This file contains the TCP/IP address(s) and port(s) for the Encryption Key
#
Server with a configuration entry in the following formats. The IPv4 address
#
entered as x.x.x.x:port. The IPv6 address entered as x:x:x:x:x:x:x:x port.
#
The server is for information only and is not used. The timeout value is
#
specified in seconds.
#
#
The format for IPv4 address:
#
server timeout address:port
#
for example,
#
ekmtest
10
9.12.123.1234:8050
#
#
The format for IPv6 address:
#
server timeout address port
#
for example,
#
ekmtest
10
fe80::207:30ee:edcb:d05d
8050
#
#
The Encryption Key Server address and port can be a local loop back
#
address 127.0.0.1:port in IPv4 format or ::1 port in IPv6 format if the server
#
is on the same host or a network address and port if external to the host.
#
Up to 16 server address and port entries are supported if there are multiple
#
TCP/IP connections to the same server and/or multiple servers.
#
# Interoperability between IPv4 and IPv6 versions running on dual-stack hosts:
#
IPv4 Client <--> IPv4/IPv6 Server
using IPv4 address for EKM server
#
IPv6 Client <--> IPv4 Server
using IPv4 address for EKM server
#
IPv6 Client <--> IPv6 Server
using IPv6 address for EKM server
#
#
Sample entry for a local server with a 10 second timeout using port 8050
#
in IPv4 format
#
ekmtest
10
127.0.0.1:8050
#
#
in IPv6 format
#
ekmtest
10
::1
8050
Figure 6. Sample Encryption Configuration File
Data Encryption
20
IBM Tape Device Drivers Installation and User’s Guide