EasyManuals Logo
Home>IBM>Storage>TS4300 3555

IBM TS4300 3555 User Manual

IBM TS4300 3555
262 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #104 background imageLoading...
Page #104 background image
Two versions of Library-Managed Encryption are available for conguration.
Key Management Interoperability Protocol (KMIP) Encryption
Security Key Lifecycle Manager (SKLM) for z/OS
®
Encryption
Access the wizard from the Actions menu with the Manage Encryption option.
Notes: Before you run the Encryption wizard.
Conrm that the Library-Managed Encryption license is activated on the Settings > Library > Licensed
Features page.
Verify that the server is available on the network and is congured for use with this library. For
information on conguring servers for use with the library, see the server documentation.
Note: If you plan to use the IBM Security Key Lifecycle Manager (SKLM), go to “Related Publications” on
page xxx for information on setup and conguration.
If Library Encryption settings are cleared and recongured, you're required to accept the new certicate
on the server when the Library Self-Signed Certicate is used.
Key Management Interoperability Protocol (KMIP) Encryption
1. In the Actions menu, click Manage KMIP Encryption to start the wizard.
2. The Logical Library Selection screen displays the KMIP conguration options that can be set as the
default for all logical libraries, or on a per logical library basis. The second section provides the option
to copy the KMIP conguration settings to all logical libraries (default) or to specied logical libraries.
3. The Wizard Information screen displays information about the wizard. On this screen, it’s also
possible to Reset Encryption Settings. If the library conguration is complete and the KMIP server is
available on the network, click Next.
4. The Certicate Option screen displays the different certicate options that can be used to establish a
secure communication to the KMIP server. You can select from the following options:
Library Self-Signed Certicate (default option) - A self-signed certicate that is generated by the
library is used.
Uploaded Certicate - Upload a PCKS #12 le that includes a certicate and corresponding key.
Generate Certicate Request (CSR) - A CSR is generated by the library that must be signed by a CA
server. This method requires a CA certicate that must be provided during the wizard steps.
a. Certication Conguration
Library Self-Signed Certicate – skip to the next step.
Uploaded Certicate
1) Upload the PKCS #12 le in the certicate area on the Certicate Option screen.
2) If this le requires a password, it must be provided in the Certicate Password input eld.
If no password, the eld can be left empty.
3) After successfully upload of the certicate, click Next.
Generate Certicate Request (CSR)
1) The Certicate Authority Information screen displays prerequisites for using the KMIP
certicate. When the prerequisites are met, click Next.
2) The Certicate Authority Certicate Entry screen displays instructions for obtaining the
CA certicate for the KMIP server. Follow the instructions to copy the CA certicate from
the Management Console. Paste the CA certicate into the wizard and then click Next.
3) The Library Certicate Information screen displays information about the next wizard
steps. Click Next.
b. The KMIP Client Conguration screen provides options for two types of server authentication.
74
IBM TS4300 Tape Library Machine Type 3555: User's Guide

Table of Contents

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the IBM TS4300 3555 and is the answer not in the manual?

IBM TS4300 3555 Specifications

General IconGeneral
BrandIBM
ModelTS4300 3555
CategoryStorage
LanguageEnglish

Related product manuals