v
Recovery keys must be configured and must be securely maintained. As
a security or precautionary measure, ensure that you rekey your data
key labels for your encryption group periodically. Ensure that the data
keys for the primary key label and the secondary key label are unique.
The availability of a recovery key does not eliminate the requirement for
configuring isolated key servers or for properly configuring general key
servers. If a recovery key is needed to break an encryption deadlock, an
outage is already in progress.
v
Manually configure DS8000 devices on the Tivoli Key Lifecycle Manager
key server. The option to automatically configure them can be used, but
increases the risk that an unauthorized DS8000 might gain access to a
key server. In addition, automatic configuration associates the device
with the default key label. Manual configuration allows the device to be
associated with a specific key label so that this association can be
detected and can possibly help avoid accidental archival or deletion of
an active key label.
v
Each DS8000 storage facility image must be assigned a unique key label
on the Tivoli Key Lifecycle Manager to facilitate the independent
management of each storage facility image.
v
The DS8000 supports the attachment of up to four key servers. If
encryption is enabled, you must configure a minimum of two key
servers to theDS8000. At least one of the key servers that is configured
on the DS8000 must be an isolated key server. However, ensure that you
configure two isolated key servers on the DS8000. Any other key servers
that are configured on the DS8000 can be general key servers. Key
servers at the local site are preferable over key servers at a remote site to
improve reliability during a site failure.
v
The DS8000 verifies that at least two key servers are configured, enabled,
and accessible to the DS8000 when the DS8000 is configured to enable
encryption. This condition is checked when a encryption-enabled DS8000
is configuring a non-zero encryption group. Encryption group
configuration request is rejected if this condition is not met.
v
If encryption has not been activated on the DS8000, the DS8000 rejects
the configuration of ranks and extent pools with a nonzero encryption
group specified.
v
The DS8000 monitors all configured key servers. Notification is provided
for loss of access to key servers and other key server related errors
through DS8000 notification mechanism. For example, SNMP traps and
or email. Ensure that you set up monitoring for these indications and
take corrective action when a condition is detected which reflects a
degraded key server environment. The following conditions are
monitored and reported:
– If at power on, the DS8000 cannot obtain a required unwrapped data
key for a configured encryption group from a key server, it reports an
error condition to both you and IBM. In this case, the encrypted
logical volumes that are associated with the encryption group are not
accessible to attached hosts. If subsequent to reporting this error, the
DS8000 is able to obtain the required key services from a key server, it
reports the condition to both you and IBM and makes the associated
logical volume accessible.
– DS8000 access to each configured key server is verified at five minute
intervals. Loss of access is reported to you.
82
Introduction and Planning Guide
Summary of Contents for DS8700
Page 2: ......
Page 8: ...vi Introduction and Planning Guide...
Page 10: ...viii Introduction and Planning Guide...
Page 20: ...xviii Introduction and Planning Guide...
Page 22: ...xx Introduction and Planning Guide...
Page 44: ...22 Introduction and Planning Guide...
Page 142: ...120 Introduction and Planning Guide...
Page 160: ...138 Introduction and Planning Guide...
Page 212: ...190 Introduction and Planning Guide...
Page 218: ...196 Introduction and Planning Guide...
Page 224: ...202 Introduction and Planning Guide...
Page 242: ...220 Introduction and Planning Guide...
Page 254: ...232 Introduction and Planning Guide...
Page 255: ......
Page 256: ...Printed in USA GC27 2297 09...