z/OS DFSMS Software Support for IBM System Storage TS1140, TS1130, and TS1120 Tape Drives (3592)
Previous topic | Next topic | Contents | Contact z/OS | Library | PDF


DFSMSdss handling of dump encryption requests

z/OS DFSMS Software Support for IBM System Storage TS1140, TS1130, and TS1120 Tape Drives (3592)
SC23-6854-00

With this support, hardware encryption joins software (or host-based) encryption as a means of encrypting your installation's tape volumes. Because DFSMSdss avoids performing double encryption of tape data, you must determine which type of encryption, if any, is to be used for your tape volumes. DFSMSdss prevents you from combining both types of encryption to perform double encryption of tape volumes.

Table 1 shows how DFSMSdss handles potential double encryption requests, specified through the DFSMSdss DUMP command.
Table 1. DFSMSdss handling of dump encryption requests
Dump encryption request DFSMSdss action
Your DUMP command specifies host-based encryption (through the RSA or KEYPASSWORD keywords), and all of the available tape drives are encryption-capable tape drives. Your request might also specify host-based compression (through the HWCOMPRESS keyword).
  • DFSMSdss issues informational message ADR518I to indicate that hardware encryption was used instead of host-based encryption
  • DFSMSdss ignores the compression request, if any.
Your DUMP command specifies host-based encryption and one or more of the available tape drives are not enabled for hardware encryption. Your request might also specify host-based compression.
  • DFSMSdss issues error message ADR519E to indicate that one or more of the available tape drives cannot perform hardware encryption. To avoid performing double encryption of data, DFSMSdss uses only encryption-capable tape drives. DFSMSdss issues error message ADR324E to list the unused output devices.
  • DFSMSdss ignores the compression request, if any.
  • DFSMSdss continues processing the DUMP request as long as there are usable tape drives. On completion, DFSMSdss ends the task with return code 8.
Your DUMP command does not specify host-based encryption and all of the available tape drives are encryption-capable tape drives. Your request might also specify host-based compression.
  • Encryption-capable tape drives perform encryption
  • DFSMSdss performs host-based compression, if requested.
Your DUMP command does not specify host-based encryption and one or more of the available tape drives are not enabled for hardware encryption. Your request might also specify host-based compression.
  • DUMP requests for encryption-capable tape drives are encrypted by the tape drive hardware
  • DUMP requests for non-encrypting tape drives are processed without encryption of any type
  • DFSMSdss performs host-based compression, if requested.

Go to the previous page Go to the next page




Copyright IBM Corporation 1990, 2014