
Page 13 of 51
© Copyright 2017 Oracle Corporation
This document may be freely reproduced and distributed whole and intact including this Copyright notice.
An operator of the module can determine if the module is operating in the
Encryption Disabled Mode by using the VOP to view the drive settings and verify
that the “Encryption Active” label is set to “No”. Finally, the operator shall
confirm that the “Use OKM or DPKM” label is set to “UNKN
8
”. Instructions to
place the module into the Encryption Disabled Mode are provided in Section 3.1.2
(Encryption Disabled Approved Mode Set-Up).
2.2.4 Mixed Mode
The StorageTek T10000D Tape Drive is capable of operating in a Mixed mode of
operation. The Mixed mode of operation is defined as a mode of operation that
allows both FIPS approved and non-approved services. Mixed mode of operation
supports the following approved services, SSH and firmware update. No other
cryptographic services are considered approved in Mixed mode.
Mixed mode of operation supports non-approved key import and export (in
plaintext). These methods of key import and export provide no cryptographic
security. Any data encrypted with this keying material is considered plaintext.
Mixed mode is entered when DPKM is enabled through the VOP. DPKM allows
an operator to use the SCSI
9
commands
SPIN
and
SPOUT
in order to import
and export keying material to and from the module in plaintext.
Keys and CSPs established in any of the other Approved modes are zeroized prior
to operating in the Mixed mode. Additionally, keys and CSPs established in
Mixed Mode are zeroized prior to operating in the any of the other Approved
modes. An operator of the module can determine if the module is operating in
the Mixed mode by using the VOP to confirm that the “Use OKM or DPKM”
label is set to “DPKM”. Instructions to place the module into the Mixed are
provided in Section 3.1.5. An operator will be able to switch to the Encryption
Disabled Mode while operating the module in the Mixed Mode.
2.3 Module Interfaces
The following is a list of the FIPS 140-2 logical interfaces supported by the
StorageTek T10000D Tape Drive:
Data Input
Data Output
8
UNKN - Unknown
9
SCSI – Small Computer System Interface