Chapter 10—Encryption and Key Management Spectra SKLM Key Management
August 2017 User Guide—Spectra T50e Library
288
SPECTRA SKLM KEY MANAGEMENT
SpectraTivoliKeyLifecycleManager(SpectraSKLM)isacentralizedkey
managementsystemthatallowsyoutomanagethelifecycleofthe
encryptionkeysandsecuritycertificatesforyourlibrary.SpectraSKLM
providesrole‐basedaccesscontrol,basedonuserprivileges,fortasksthat
rangefromcreatingandassigningencryptionkeystothebackupand
restorationofdata.
SpectraSKLMisinstalledonanexternalserver,whichisconnectedtothe
librarybyEthernet.Alladministrativeactivitiesareperformedonthe
server,includingconfiguration;administrationofgroups,users,androles;
andmanagementofkeys,keygroups,anddevices.Encryptionis
performedatthedriveleve l,throughencryption‐enabledLTO‐5andlater
generationtapedrives.
AfterSpectraSKLMkeymanagementisenabled,thedrivesinan
encryption‐enabledpartitionrequestakeyfromtheSpectraSKLMserver.
Theserversendstheencryptionkeytothedrive,andthedriveusesthekey
toautomaticallyencryptdataasitisbackedup.
BeforeyouconfigureyourlibrarytoimplementSpectraSKLMkey
management,therearethreerequiredcomponents:
SpectraSKLMEncryption‐capableDrivesSpectraSKLMkey
managementisonlycompatiblewithLTO‐5andlatergenerationtape
drives.
SpectraSKLMOptionKeyPurchaseandinstalltheSpectraSKLM
optionkeytoactivateSpectraSKLMkeymanagement.Formore
informationonhowtoinstalltheoptionkeyonyourlibrary,seeEnter
ActivationKeysonpage113.
SpectraSKLMServerInstallandconfigureSpectraSKLMonyourserv er.
SpectraSKLMisavailableforeitherLinuxorWindows.Foradditional
informationthatcanassistyouduringtheinstallationandconfigurationof
yourserv er,seethefollowingwebsites:
IBMTivoliKeyLifecycleManagerInformationCenter
TivoliKeyLifecycleManagerInstallationandConfigurationGuide
SpectraSKLMkeymanagementisnotcompatiblewithBlu eScale
Encryptionkeymanagement,becausetheycannotshareencryptionkeys.
DataencryptedusingSpectraSKLMkeymanagementcannotbe
decryptedusingBlueScaleEncryptionkeymanagement,andviceversa.