40 Configuring Your Library For SKM
Quantum Scalar Key Manager 2.5 Quick Start Guide
Configuring the 
Scalar
 i2000/i6000 Tape 
Library
Perform these steps, in order, on the Scalar i2000/i6000 library only.
See the library user’s guide or online help for detailed instructions on how to 
complete each of these steps.
1 Install the Encryption Key Management (EKM) license on your library.
2 Prepare partitions for library-managed encryption:
a Install HP LTO-4, HP LTO-5, and/or HP LTO-6, or IBM LTO-5, IBM LTO-6, and/or 
IBM LTO-7 tape drives in the library, if not already installed. Unload all tape 
cartridges from these tape drives.
b On the tape drives, install the latest version of firmware that is qualified for the 
library firmware installed on your library. Refer to the library release notes for 
the correct version of tape drive firmware.
3 TLS certificates must be installed on the library as well as on the SKM server. Verify 
the appropriate TLS communication certificates are installed on the library. If you 
installed your own TLS certificates on the SKM servers, you must install your own TLS 
certificates on the library. If you used Quantum-supplied TLS certificates on the SKM 
servers, you must use Quantum-supplied certificates on the library. 
4 Configure the SKM server IP addresses and generate data encryption keys. 
a On the library’s remote Web client, navigate to the EKM server configuration 
screen.
b Enter the SKM primary and secondary server IP addresses or hostnames in the 
fields provided. 
c Click OK. 
Data encryption keys are generated. As soon as you apply the SKM server IP 
addresses, the library automatically triggers each SKM server to generate a set 
of unique data encryption keys. The key generation process should take 30 
minutes or less to complete, depending on network performance. The library 
generates a RAS ticket when the process is complete. Wait until you receive this 
ticket before going to the next step.
Note: If the key generation fails, the library generates a RAS ticket. Follow the 
instructions in the ticket to resolve any errors, then initiate manual key 
generation by changing the encryption method on an SKM partition to 
Enable Library Managed (as described in 
Step 5 below). If key 
generation continues to fail, run EKM Path Diagnostics to help 
determine where the problem lies.
5 Configure partitions for library-managed encryption.
a On the library’s remote client, navigate to the EKM partition configuration 
screen.
b For each partition in which you will use SKM, in the Encryption Method drop-
down list, select Enable Library Managed.
c Click OK.