Configuring secure communications with Transport Layer Security

To encrypt data and secure communications in your environment, Secure Sockets Layer (SSL) or Transport Layer Security (TLS) is enabled on the IBM Storage Protect server and backup-archive client. An SSL certificate is used to verify communication requests between the server and client.

About this task

Beginning with IBM Storage Protect Version 8.1.2, SSL is enabled by default, and the IBM Storage Protect server and backup-archive client are automatically configured to communicate with each other by using protocol TLS Version 1.2 or later.

As shown in the following figure, you can manually configure secure communications between the server and backup-archive client by setting options in the server and client options files, and then transferring the self-signed certificate that is generated on the server to the client. Alternatively, you can obtain and transfer a unique certificate that is signed by a certificate authority (CA).
The image is described in the introduction text to the figure.

For more information about configuring the server and clients for SSL or TLS communications, see Configuring storage agents, servers, clients, and the Operations Center to connect to the server by using SSL.