Chapter 3 Configuring Your Library
Configuring Quantum Encryption Key Manager (Q-EKM)
Scalar i500 User’s Guide
85
Step 4: Configure Q-EKM
Server TCP/IP Addresses
3
Make sure you complete Steps 1 through 3 above before proceeding.
1
From the web client, select
Setup > Encryption > System Configuration
.
2
If you want to enable Secure Sockets Layer (SSL) for communication
between the library and the Q-EKM servers, select the
SSL for Q-EKM
Servers
“Enable” checkbox. The default is Disabled. If you enable
SSL, you must make sure that the primary and secondary Q-EKM
Port Numbers (see below) match the SSL port numbers set on the Q-
EKM servers. The default SSL port number is 443.
3
In the
Primary Q-EKM IP Address or Host
text box, enter either:
• The IP address of the primary Q-EKM server (if DNS is not
enabled), or
• The host name of the primary Q-EKM server (if DNS is enabled).
4
Enter the port number for the primary Q-EKM server into the
Primary
Q-EKM port number
text box. The default port number is 3801 unless
SSL is enabled. If SSL is enabled, the default port number is 443.
5
Optionally, enter the IP address or host name of the secondary
Q-EKM server into the
Secondary Q-EKM IP Address or Host
text box.
Note:
Keys are always encrypted before being sent from the
Q-EKM server to a tape drive, whether SSL is enabled or
not. Enabling SSL provides additional security.
Note:
If you change the port number for the Q-EKM server from
the default setting on the library, you must also change the
port number on the Q-EKM server to match or Q-EKM
will not work properly. See the
Quantum Encryption Key
Manager User’s Guide
for information on setting the port
number on the Q-EKM server.
Note:
If you do not plan to use a secondary Q-EKM server, you
may type a zero IP address, 0.0.0.0, into the
Secondary
Q-EKM IP Address or Host
text box, or you may leave this
text box blank.