background image

www.quantum.com

Scalar Key Manager 2.5

Scalar Key Manager 2.5

 

Quick Start Guide

This quick start guide provides basic installation and configuration 

instructions for the Scalar® Key Manager (SKM). SKM can be deployed in 

one of two ways:

• a pair of physical appliances (servers) purchased from Quantum, or 
• a pair of virtual machines (VMs) installed in a VMware® or KVM 

environment. 

Definition of terms: 

This guide uses the following terms to differentiate 

between the two types of deployment:

SKM appliance server

 — Physical key server purchased from 

Quantum.

SKM VM server

 — Virtual machine key server purchased from 

Quantum and installed in a VMware or KVM environment.

SKM server

 — Generic term applying to either an SKM appliance server 

or an SKM VM server.

These instructions guide you through installing and configuring both 

options. For more information, see the 

Scalar Key Manager User’s Guide

 

located at 

http://www.quantum.com/ServiceandSupport/

SoftwareandDocumentationDownloads/SKM/Index.aspx

. (Scroll down and 

click the 

Documentation

 tab, and then locate the 

Product Use Guides

 

heading.)
Perform all of the steps, in order, before you begin encrypting tapes.
This instruction uses the following conventions:

Note:

Notes emphasize important information related to the main topic.

Caution:

Cautions indicate potential hazards to equipment and are 

included to prevent damage to equipment.

Contents

Installing and Configuring the SKM 

Appliance Servers

   ................................. 2

Items Required for Setup   ................. 2
Installing the SKM Appliance Servers

   3

Configuring the SKM Appliance 
Servers   .............................................. 5

Installing and Configuring the SKM 
VMware Servers  .................................... 9

Equipment and Software Needed for 
VMware   ............................................ 9
Deploying the .ova Image on 
VMware   .......................................11
Configuring the SKM VM Servers on 
VMware   .......................................... 11

Installing and Configuring the SKM KVM 
Servers   ................................................ 17

Equipment and Software Needed for 
KVM   ................................................ 17
Deploying the .raw Image on KVM   18
Configuring the SKM VM Servers on 
KVM   ................................................ 21

Installing TLS Certificates on the SKM 
Server for Pre-SKM 2.4 (240Q)   ........... 25

Installation Process  ......................... 25
Requirements for Installing User-
provided TLS Certificates  ................ 27

Installing TLS Certificates on the SKM 
Server for SKM 2.4 (240Q) or Later   .... 28

Begin the Installation  ..................... 28
Executing the Script Using the -d 
Option

   ............................................ 28

Executing the Script Without Using the 
-d Option

   ........................................ 31

Generating Quantum Bundles for 
Certificates

   ..................................... 36

Configuring Your Library For SKM   ..... 38

Configuring the Scalar i40/i80 and 
Scalar i500 Tape Libraries   ............... 38
Configuring the Scalar i2000/i6000 
Tape Library   .................................... 40
Configuring the Scalar i3/i6 Tape 
Library

   ............................................ 41

Backing Up the Servers  ....................... 43
Configuring Multiple Libraries   ........... 42

Summary of Contents for Scalar i40

Page 1: ...llowing conventions Note Notes emphasize important information related to the main topic Caution Cautions indicate potential hazards to equipment and are included to prevent damage to equipment Conten...

Page 2: ...s each comes with two hard disk drives installed Power cord supplied Rackmount kit supplied CAT5e or higher Ethernet cable crossover for initial configuration not supplied CAT5e or higher Ethernet cab...

Page 3: ...er it unusable 1 Determine the location for the servers It is recommended that the two servers be in different geographical locations for disaster recovery purposes Ensure the air temperature is below...

Page 4: ...wer button is active If the power on LED is not blinking there could be a problem with the power supply or the LED Check the power connection If this LED still does not blink contact Quantum Support P...

Page 5: ...rvers Follow the instructions below for both SKM appliance servers Note Both SKM appliance servers must be configured operational and connected to the network before any libraries can be set up to use...

Page 6: ...is a static IP address that cannot be changed 4 At the login prompt type the following this is the user login ID which will never change akmadmin 5 At the Password prompt type the default password pas...

Page 7: ...ord a At the current UNIX password prompt type the default password password and press Enter b Type a new password and press Enter c Type the new password again and press Enter d Press Enter 11 Contin...

Page 8: ...f SKM Admin commands displays see Figure 4 If you made any mistakes during the setup wizard you can go back and change them by entering the number corresponding to the item Figure 4 SKM Admin Commands...

Page 9: ...r s Guide Installing and Configuring the SKM VMware Servers Note Quantum provides support for SKM however Quantum does not support the virtual environment hardware or software VMware or KVM Follow the...

Page 10: ...one of the following VMware ESX 4 x 64 bit and higher VMware ESXi 4s x 64 bit and higher Video memory must be set to 3 MB Library firmware must be at the following minimum versions to run SKM To acce...

Page 11: ...pending on network speed and location of the ova image in relation to the VM host Wait until the file deploys before continuing Configuring the SKM VM Servers on VMware Follow the instructions below f...

Page 12: ...gure the MAC address as follows see Figure 5 a Under the Hardware tab select Network adapter 1 b Under MAC Address select Manual c In the MAC Address field type the MAC ID from the label attached to t...

Page 13: ...ll lose the ability to use your mouse cursor To regain the use of the mouse cursor press Ctrl Alt Note If you receive the following error message when trying to use the console follow the workaround s...

Page 14: ...ontinue or n to decline and stop the installation process 15 When prompted press Enter to set up the server 16 The first setup wizard task prompts you to change the akmadmin password see Figure 7 Ther...

Page 15: ...neration Quantum recommends setting both the Primary and Secondary SKM servers to the same date time and time zone even if they are in different time zones On both servers use the date time and time z...

Page 16: ...to continue the installation process 21 Complete steps 1 20 on the secondary SKM node before proceeding 22 When you are finished do one of the following For pre SKM 2 4 240Q systems proceed to Install...

Page 17: ...ment and Software Needed for KVM You need the following to set up and configure the SKM VM servers Two 2 Scalar Key Manager VM Installation CD packages You must use a different CD package for each SKM...

Page 18: ...low the instructions below for both SKM VM servers The raw installation process is performed via QEMU KVM 1 Insert the Scalar Key Manager VM Installation CD into the your computer s CD ROM drive 2 Dec...

Page 19: ...Manager 2 5 6 In the Name field type the name of the new virtual machine 7 Select Import existing disk image and click Forward 8 Click Browse and navigate to the raw file 9 For OS type select Linux an...

Page 20: ...SKM KVM Servers Quantum Scalar Key Manager 2 5 Quick Start Guide 10 For Memory RAM select 1024 and for CPUs select 2 Click Forward 11 For Advanced Options select the host device which corresponds wit...

Page 21: ...track of which CD you use for which SKM server It is recommended that you keep each CD in its respective CD case and write on the case which server it applies to The TLS certificates and serial numbe...

Page 22: ...d prompt type the default password password 6 At the akmadmin skmserver prompt type skmcmds 7 At the Password prompt type the default password password 8 When prompted for the license type the 29 digi...

Page 23: ...ter using SKM Admin Commands If you wish to change the password a At the current UNIX password prompt type the default password password and press Enter b Type the new password and press Enter c Type...

Page 24: ...command prompt Figure 10 SKM Admin Commands 16 At the Command prompt type q and press Enter to quit save your changes and restart the SKM key server This process takes a few seconds Note You MUST quit...

Page 25: ...ver If you install your own TLS certificates you must make sure that your certificates meet all of the requirements in Requirements for Installing User provided TLS Certificates on page 27 Note Any ti...

Page 26: ...located on the Scalar Key Manager VM Installation CD and has the file name QKMCertXXXXXXX tgz XXXXXXX is a unique combination of letters and numbers 11 Once you have transferred the files press Enter...

Page 27: ...ies require certificate installation See your library user s guide for instructions on how to verify whether TLS certificates are installed on the library and how to install them You need to provide t...

Page 28: ...provided by Quantum By executing the script without using the d option If the d option is not used information used to generate the certificates must be provided Begin the Installation 1 SSH in to the...

Page 29: ...default values in brackets used 2 When prompted enter and re enter a password that will be used during the pk12 file generation TLS certificate generation is completed using the default values A mess...

Page 30: ...he Scalar i3 refer to the topic Load Certificate Encryption in the Scalar i3 Documentation Center http qsupport quantum com kb flare content Scalar_i3 docCenter Encryption_Load_Certificate htm For the...

Page 31: ...alues If desired you can press Enter to accept the default value displayed in brackets for any item 1 Once logged into an SKM server running version 2 4 240Q or greater execute genSKMcerts to begin en...

Page 32: ...antum Scalar Key Manager 2 5 Quick Start Guide 4 At this time the only valid certificate digest is SHA1 so press Enter to accept the default value and continue 5 Enter your two character country ident...

Page 33: ...8 Enter your company or organization name 9 Enter your organizational unit or section name 10 The next three entries are common names for the Tape libraries SKM primary server and SKM secondary server...

Page 34: ...n 12 When prompted confirm that the displayed information is correct Enter y to confirm and begin the certificate generation process Enter n if you want to change any of the values you entered Note th...

Page 35: ...ser s guide for the applicable libraries For the Scalar i40 i80 refer to Importing Encryption Certificates in the Scalar i40 and Scalar i80 User s Guide For the Scalar i2000 i6000 refer to Step 3 Inst...

Page 36: ...s onto the SKM servers and tape libraries return to this guide and proceed with the steps in Configuring Your Library For SKM on page 38 15 If desired you can verify the certificate details by running...

Page 37: ...e saved at home akmadmin generatedcerts qbundles After bundle generation is complete load the bundles listed on the screen onto the library and SKM servers using the user interface The TapeLibraryQKMC...

Page 38: ...ur library 2 Prepare partitions for library managed encryption a Install HP LTO 4 HP LTO 5 and or HP LTO 6 or IBM LTO 5 IBM LTO 6 and or IBM LTO 7 i500 only tape drives in the library if not already i...

Page 39: ...h Diagnostics again Figure 12 EKM Path Diagnostics PASSED Window 6 Configure SKM partitions and generate data encryption keys a On the library s Web client navigate to the encryption partition configu...

Page 40: ...ou must use Quantum supplied certificates on the library 4 Configure the SKM server IP addresses and generate data encryption keys a On the library s remote Web client navigate to the EKM server confi...

Page 41: ...HH SAS LTO6 IBM HH SAS LTO7 IBM HH FC LTO6 IBM HH FC LTO7 For the Scalar i6 IBM FH FC LTO6 IBM FH FC LTO7 b On the tape drives install the latest version of firmware that is qualified for the library...

Page 42: ...ntinues to fail run EKM Path Diagnostics to help determine where the problem lies 5 Configure partitions for library managed encryption a From the Navigation panel select Partitions b In the North Pan...

Page 43: ...Note For multiple libraries accessing the same SKM server pair If you are configuring more than one library to use the same SKM servers be aware that each library triggers the SKM servers to create a...

Page 44: ...ver will be stopped 6 Type y and press Enter to agree to stop the SKM key server The list of SKM Admin commands displays 7 At the command prompt enter 7 to Back up SKM server 8 Press Enter Backup file...

Reviews: