Table 40. Magazine state (continued)
Magazine state LED state Description
Closed Slow Flash Magazine open is in process.
Closed Fast Flash Magazine is opened.
Closed OFF I/O station is not enabled.
Opened OFF Magazine is opened.
Conguring Library Managed Encryption
Library-Managed Encryption (LME) is a built-in feature that is enabled by using a purchased license.
The LME feature can be ordered from the factory, or you can order it as a eld upgrade. To order a feature,
contact your IBM Sales Representative or Business Partner. See Optional Features.
Two versions of Library-Managed Encryption are available for conguration.
• Key Management Interoperability Protocol (KMIP) Encryption (v1.2)
• Security Key Lifecycle Manager (SKLM) for z/OS
®
Encryption
Access the wizard from the Actions menu with the Manage Encryption option.
Notes: Before you run the Encryption wizard.
• Conrm that the Library-Managed Encryption license is activated on the Settings > Library > Licensed
Features page.
• Verify that the server is available on the network and is congured for use with this library. For
information on conguring servers for use with the library, see the server documentation.
Note: If you plan to use the IBM Security Key Lifecycle Manager (SKLM), go to “Related Publications” on
page xxxi for information on setup and conguration.
• If Library Encryption settings are cleared and recongured, you're required to accept the new certicate
on the server when the Library Self-Signed Certicate is used.
Key Management Interoperability Protocol (KMIP) Encryption
1. In the Actions menu, click Manage KMIP Encryption to start the wizard.
2. The Logical Library Selection screen displays the KMIP conguration options that can be set as the
default for all logical libraries, or on a per logical library basis. The second section provides the option
to copy the KMIP conguration settings to all logical libraries (default) or to specied logical libraries.
3. The Wizard Information screen displays information about the wizard. On this screen, it’s also
possible to Reset Encryption Settings. If the library conguration is complete and the KMIP server is
available on the network, click Next.
4. The Certicate Option screen displays the different certicate options that can be used to establish a
secure communication to the KMIP server. You can select from the following options:
• Library Self-Signed Certicate (default option) - A self-signed certicate that is generated by the
library is used.
• Uploaded Certicate - Upload a PCKS #12 le that includes a certicate and corresponding key.
• Generate Certicate Request (CSR) - A CSR is generated by the library that must be signed by a CA
server. This method requires a CA certicate that must be provided during the wizard steps.
a. Certication Conguration
– Library Self-Signed Certicate – skip to the next step.
– Uploaded Certicate
i) Upload the PKCS #12 le in the certicate area on the Certicate Option screen.
IBM Condential
88IBM TS4300 Tape Library Machine Type 3555: User's Guide