-149-
6.5
FAQ about Encryption Key Management function
1. Encryption key management
Q1-1 What happens if I forget the master key or individual encryption keys?
A You will no longer be able to restore encryption information if the device fails.
Be sure to back up data when changing the master key or other encryption information.
Q1-2 Who does have authority to back up encryption information (the master key and KEY database)?
A The device administrator does. (The maintenance staff is not authorized to back up encryption
information.)
Q1-3 What is the relationship between the master key and individual tape medium keys specified for
each tape medium?
A Although you can set the encryption key for each tape medium by automatically generating it
from the master key or individually setting it, there is no special relationship between the master
key and individually specified keys.
However, you need to set up the master key to both automatically generate keys and to protect the
KEY database in the Library, even if you individually set keys to all the tape media.
Q1-4 How to use tape media that created under the previous master key after changing the master key?
A If you change the master key, the information about the previous master key is not left in the
Library.
You must export an encryption key for each tape media before changing the master key, and then
individually import the exported encryption keys after changing the master key.
It is therefore not recommended that you change the master key once operation starts.
Q1-5 How to clear encryption information?
A Use Remote Manager to execute “Clear Encryption Setting” (in [Encryption Detail]), or execute
“Set Default” from the operation panel.
Note that “Set Default” clears encryption information and other settings.
Because it is not possible to restore encryption information after clearing it, back up this
information in advance if necessary.
2. Remote Manager
Q2-1 Is it needed to keep on connecting WEB browser terminal at all times?
A A constant connection is not required.
It is enough to connect the WEB browser terminal as needed, such as when changing encryption
information settings.
3. Operation
Q3-1 Does encryption give any bad impact to performance?
A Performance is not degraded because data is encrypted using the hardware.
Q3-2 Can I specify encryption keys for each backup job?
A No. Specify encryption keys for each tape media.
Q3-3 Can I add encrypted data to tape medium that contains plain text data?
A Yes.
A tape drive can determine whether data is encrypted during operation. However, note that you
cannot use tape medium that have multiple encryption keys for this Library.
Q3-4 What happens if I store an LTO3 or earlier tape in a slot for which encryption is enabled?
A The MOVE MEDIUM command, which moves a tape media from its slot to the drive, ends with
an error, and the tape returns to the source slot.
Disable encryption for the slot when using an LT
O
3 or earlier tape medium.