Book description
-update for Release 8.5 -
IBM experts recognize the need for data protection, both from hardware or software failures, and also from physical relocation of hardware, theft, and retasking of existing hardware.
The IBM DS8880 supports encryption-capable hard disk drives (HDDs) and flash drives. These Full Disk Encryption (FDE) drive sets are used with key management services that are provided by IBM Security Key Lifecycle Manager software or Gemalto SafeNet KeySecure to allow encryption for data at rest on a DS8880. Use of encryption technology involves several considerations that are critical for you to understand to maintain the security and accessibility of encrypted data.
The IBM Security Key Lifecycle Manager software also supports Transparent Cloud Tiering (TCT) data object encryption, which is part of this publication. With TCT encryption, data is encrypted before it is transmitted to the Cloud. The data remains encrypted in cloud storage and is decrypted after it is transmitted back to the DS8000®.
This IBM Redpaper™ publication contains information that can help storage administrators plan for disk and TCT data object encryption. It also explains how to install and manage the encrypted storage and how to comply with IBM requirements for using the IBM DS8000 encrypted disk storage system.
This edition focuses on IBM Security Key Lifecycle Manager Version 3.0 which enables support Key Management Interoperability Protocol (KMIP) with the DS8000 Release 8.5 code or later and updated GUI for encryption functions. The publication also discusses support for data at rest encryption with Gemalto SafeNet KeySecure Version 8.3.2.
Table of contents
- Front cover
- Notices
- Preface
- Summary of changes
- Chapter 1. Encryption overview
- Chapter 2. IBM DS8000 encryption mechanisms
- Chapter 3. Planning and guidelines for IBM DS8000 encryption
-
Chapter 4. IBM DS8000 encryption implementation
- 4.1 Installing IBM SKLM V3.0 in silent mode
- 4.2 WebSphere, Java and SKLM hardening
-
4.3 IBM Security Key Lifecycle Manager V3.0 configuration
- 4.3.1 Creation of the SSL/KMIP Server Certificate
- 4.3.2 Backup and restore
- 4.3.3 Migration backup and restore operations for earlier versions of IBM Security Key Lifecycle Manager and IBM Tivoli Key Lifecycle Manager
- 4.3.4 Setting up remote replication between SKLM key servers
- 4.3.5 Setting up a Multi-Master environment with two SKLM key servers
- 4.3.6 Defining DS8000 in SKLM for data at rest encryption
- 4.4 Configuring SafeNet KeySecure for data at rest encryption
- 4.5 SKLM configuration for TCT encryption
- 4.6 DS8000 GUI configuration for data at rest encryption
- 4.7 DSCLI configuration for data at rest and TCT encryption
- 4.8 Data at rest encryption and Copy Services functions
- 4.9 NIST SP 800-131a requirements for key servers
- 4.10 Migration from Gen-1 to a Gen-2 certificate for encryption
- 4.11 Using a custom generated Gen-1 or Gen-2 certificate
- Chapter 5. Maintaining the IBM DS8000 encryption environment
- Related publications
- Back cover
Product information
- Title: IBM DS8880 Encryption for data at rest and Transparent Cloud Tiering (DS8000 Release 8.5)
- Author(s):
- Release date: April 2019
- Publisher(s): IBM Redbooks
- ISBN: 9780738457567
You might also like
book
IBM DS8000 Encryption for data at rest, Transparent Cloud Tiering, and Endpoint Security (DS8000 Release 9.0)
IBM® experts recognize the need for data protection, both from hardware or software failures, and from …
article
Reinventing the Organization for GenAI and LLMs
Previous technology breakthroughs did not upend organizational structure, but generative AI and LLMs will. We now …
article
Use Github Copilot for Prompt Engineering
Using GitHub Copilot can feel like magic. The tool automatically fills out entire blocks of code--but …
article
Splitting Strings on Any of Multiple Delimiters
Build your knowledge of Python with this Shortcuts collection. Focusing on common problems involving text manipulation, …