
Licensing
The KMIP feature requires that the StoreEver MSL2024/4048/8096 KMIP license has been installed before
the feature can be enabled and configured.
Application-managed encryption
Hardware encryption is off by default and is switched on by settings in your backup application. The backup
application also generates and supplies the encryption key. Your backup application must support hardware
encryption for this feature to work. For a current list of suitable backup software, see the compatibility matrix
at:
http://www.hpe.com/storage/DAPRcompatibility
NOTE:
The library can only obtain encryption keys from one source. Using the encryption kit will prevent application-
managed encryption.
Encryption is primarily designed to protect the media once it is offline and to prevent it being accessed from
another machine. The tape drive can read and append the encrypted media without being prompted for a key
while the machine and application that first encrypted the tape are accessing the tape.
There are two main instances when you will need to know the key:
• If you try to import the media to another machine or another instance of the backup application.
• If you are recovering your system after a disaster.
NOTE:
Encryption with keys that are generated directly from passwords or passphrases might be less secure than
encryption using truly random keys. Your application will explain the available options and methods. Refer to
the application user documentation for more information.
If you are unable to supply the key when requested to do so, no one will be able to access the encrypted
data, including support engineers.
This feature guarantees the security of your data, but also means that you must carefully manage the
encryption key used to generate the tape.
CAUTION:
Keep a record or backup of your encryption keys and store it in a secure place separate from the
computer running the backup software.
For detailed instructions about enabling encryption, see the documentation supplied with your backup
application or with the encryption kit. The documentation will also highlight any default states, for example
when copying tapes, that might need to be changed when using encrypted tapes.
Logical libraries
You can configure a tape library with multiple tape drives into logical libraries. Each logical library must
contain at least one tape drive. Each logical library is configured independently, allowing use by different
backup applications and with different backup policies. For example, one logical library could perform a
backup operation for one department while the second logical library restores data for another department.
Data cartridges in one logical library cannot be shared with other logical libraries.
If the mailslot is enabled, all logical libraries have access to the mailslot. The tape library prohibits a cartridge
that was placed in the mailslot by one logical library from being moved into another logical library. The library
allows a cartridge that was placed in the mailslot by the operator to be moved into any logical library. If
Application-managed encryption
21