Configuring by using the default security settings (fast path)
Fast path details the configuration options that impact the security of the data mover and VMCLI node connection to the server and the behavior for various use cases when default values are accepted. The fast path scenario minimizes the steps in the configuration process at endpoints.
This scenario automatically obtains certificates from the server when the node connects the first time, assuming that the IBM Storage Protect server SESSIONSECURITY parameter is set to TRANSITIONAL, which is the default value at first connection. You can follow this scenario whether you first upgrade the IBM Storage Protect server to version 7.1.8 and later version 7 levels, or version 8.1.2 and later version 8 levels, and then upgrade Data Protection for VMware to these levels, or vice versa.
Data mover node options that affect session security
- SSLREQUIRED. The default value Default enables existing session-security connections to servers earlier than version 7.1.8 or version 8.1.2, and automatically configures the Data Protection for VMware data mover to securely connect to a version 7.1.8 or version 8.1.2 or later server by using TLS for authentication.
- SSLACCEPTCERTFROMSERV. The default value Yes enables the data mover to automatically accept a self-signed public certificate from the server, and to automatically configure the data mover to use that certificate when the data mover connects to a version 7.1.8 or version 8.1.2 or later server.
- SSL. The default value No indicates that encryption is not used when data is transferred between the data mover and a server earlier than version 7.1.8 or version 8.1.2. When the data mover connects to a version 7.1.8 or version 8.1.2 or later server, the default value No indicates that object data is not encrypted. All other information is encrypted, when the data mover communicates with the server. The value Yes indicates that TLS is used to encrypt all information, including object data, when the data mover communicates with the server.
- SSLFIPSMODE. The default value No indicates that a Federal Information Processing Standards (FIPS) certified TLS library is not required.
- SSLDISABLELEGACYTLS. A value of No indicates that the data mover does not require TLS 1.2 for SSL sessions. It allows connection at TLS 1.1 and lower SSL protocols. When the data mover communicates with an IBM Storage Protect server that is version 7.1.7 or version 8.1.1 or earlier, No is the default.
- LANFREESSL. The default value No indicates that the data mover does not use TLS when communicating with the Storage Agent when LAN-free data transfer is configured.
- REPLSSLPORT. Specifies the TCP/IP port address that is enabled for TLS when the data mover communicates with the replication target server.
VMCLI node options that affect session security
- VE_TSM_SSL. The default value NO indicates that encryption is not used when data is transferred between the data mover and a server earlier than version 7.1.8 or version 8.1.2. Set this value to YES if you want to use TLS is to encrypt all information when connecting to a server earlier than version 7.1.8.
- VE_TSM_SSLACCEPTCERTFROMSERV. The default value YES enables the interface to automatically accept a self-signed public certificate from the server, and to automatically configure the interface to use that certificate when the data mover connects to a version 7.1.8 or version 8.1.2 or later server.
- VE_TSM_SSLREQUIRED. The default value DEFAULT enables existing session-security connections to servers earlier than version 7.1.8 or version 8.1.2, and automatically configures the interface to securely connect to a version 7.1.8 or version 8.1.2 or later server by using TLS for authentication.
Uses cases for default security settings
- First, the server is upgraded to version 7.1.8 or version 8.1.2 or later. Then, Data Protection for VMware is upgraded. The existing data mover and VMCLI
nodes are not using SSL communications:
- No changes are required to the security options for the data mover and VMCLI nodes.
- The configuration is automatically updated to use TLS when the nodes authenticate with the server.
- First, the server is upgraded to version 7.1.8 or version 8.1.2 or later. Then, Data Protection for VMware is upgraded. The existing data mover and VMCLI
nodes are using SSL communications:
- No changes are required to the security options for the data mover and VMCLI nodes.
- SSL communication with existing server public certificate continues to be used.
- SSL communication is automatically enhanced to use the TLS level that is required by the server.
- First, Data Protection for VMware is upgraded to version 7.1.8
or version 8.1.2 or later. Then, the server is upgraded later. The existing data mover and VMCLI
nodes are not using SSL communications:
- No changes are required to the security options for the data mover and VMCLI nodes.
- Existing authentication protocol continues to be used to servers at levels earlier than version 7.1.8 or version 8.1.2.
- The configuration is automatically updated to use TLS when the nodes authenticate with the server after the server is updated to version 7.1.8 or version 8.1.2 or later.
- First, Data Protection for VMware is upgraded to version 7.1.8
or version 8.1.2 or later. Then, the server is upgraded later. The existing data mover and VMCLI
nodes are using SSL communications:
- No changes are required to the security options for the data mover and VMCLI nodes.
- SSL communication with existing server public certificate continues to be used with servers at levels earlier than version 7.1.8 or version 8.1.2.
- SSL communication is automatically enhanced to use the TLS level that is required by the server after the server is updated to version 7.1.8 or version 8.1.2 or later.
- First, Data Protection for VMware is upgraded to version 7.1.8
or version 8.1.2 or later. Then, the data mover and VMCLI nodes connect to multiple servers. The
servers are upgraded at different times:
- No changes are required to the security options for the data mover and VMCLI nodes.
- The data mover and VMCLI nodes use existing authentication and session security protocol to servers at versions earlier than version 7.1.8 or version 8.1.2, and automatically upgrade to use TLS authentication when initially connecting to a server at version 7.1.8 or version 8.1.2 or later. Session security is managed per server.
- New client installation, server is at version 7.1.8 or version 8.1.2 or later:
- Configure Data Protection for VMware according to a new installation.
- Default values for the security options automatically configure the data mover and VMCLI nodes for TLS-encrypted session authentication.
- Set the SSL parameter to the Yes value if encryption of all data transfers between the client and the server is required.
- New client installation, server is at a version earlier than version 7.1.8 or version 8.1.2:
- Configure the client according to a new client installation.
- Accept the default values for client session-security parameters if SSL encryption of all data
transfers is not required.
- Non-SSL authentication protocol is used until the server is upgraded to version 7.1.8 or version 8.1.2 or later.
- Set the SSL parameter to the Yes value if encryption of all data transfers
between the data mover and the server is required, and proceed with the manual configuration for SSL.
- See Configuring Tivoli Storage Manager client/server communication with Secure Sockets Layer for configuration instructions.
- SSL communication is automatically enhanced to use the TLS level that is required by the server after the server is updated to version 7.1.8 or version 8.1.2 or later.