
5. Using Professional Edition in Spectra T950 and T120 Libraries
58
For your site, select one of these as your M-of-N shares:
• 2-of-3
• 2-of-4
• 3-of-4
• 2-of-5
• 3-of-5
• 4-of-5
For example, if you choose 2 of 3, then the encrypted key, already encrypted using a
key-specific password, is split into three shares (i.e., files). You can then export the key shares
using USB devices or through email. If you choose to export using USB devices, you will be
prompted to supply three USB devices, one after the other. To email shares using 2 of 3, select
three different users (configured on the library with email information), each receiving one
share as an email attachment.
Keys that have been split into shares can only be imported using USB devices; they cannot be
uploaded through the RLC. To restore data that has been sent through email, copy the
attachment to a USB device. Building on this example, note that only two of the three USB
devices, along with the password, are needed to import the key.
Selecting the M-of-N shares option when exporting a key is covered below in
Exporting
Encryption Keys
.
Storing Exported Keys
Best practices recommends storing keys offsite in a location other than the site used for
media storage. Make sure that the key has been sent and can be accessed, is stored correctly
on the USB device, or both, before deleting the key from your system. You may want to make
two copies of a key, storing each in a secure location. Note the location of these keys, so that
you can easily find the key when you need to restore or delete data.