IBM Support

TS7700 - ISKLM for z/OS not supported for External Disk Encryption Support

Question & Answer


Question

ISKLM for z/OS is not supported as external key manager for TS7700 External Disk Encryption Support..

Cause

Background:
Generally speaking, when encryption functionally is enabled the required encryption keys are stored in what is called an EKM (Encryption Key Manager).
Over the years various Key Manager applications have been developed. The first version was simply called EKM.
Later the Tivoli Key Lifecycle Manager (TKLM) was developed, which was then re-branded as IBM Security Key Lifecycle Manager (SKLM).
These Key Manager options were typically available for open systems environment. In addition there are Key Manager options available specifically for System z.

TS7700 supports different types of encryption:
- Tape encryption, with external key management
https://www.ibm.com/support/knowledgecenter/STFS69_4.1.0/ts7740_encryption_overview.html
Both Tivoli Key Lifecycle Manager (TKLM) and IBM Security Key Lifecycle Manager (SKLM) for open systems, as well as IBM Security Key Lifecycle Manager for z/OS (ISKLM) are supported as Encryption Key Manager.
- Disk encryption, with internal key management
https://www.ibm.com/support/knowledgecenter/STFS69_4.1.0/ts7740_encryption_intkeymgmt.html
No external Key Manager utilized as key's are managed internally.
- Disk encryption, with external key management
https://www.ibm.com/support/knowledgecenter/STFS69_4.1.0/ts7740_encryption_extkeymgmt.html
In contrast to current documentation, the IBM Security Key Lifecycle Manager for z/OS (ISKLM) is not supported to be used as Encryption Key Manager with TS7700 Disk encryption.
The only supported options are the open systems version of Tivoli Key Lifecycle Manager (TKLM) and IBM Security Key Lifecycle Manager (SKLM).

Answer

Solution (Procedure):
IBM Security Key Lifecycle Manager for z/OS (ISKLM) must not be used as Encryption Key Manager with TS7700 Disk encryption.
Only the available open systems version of Tivoli Key Lifecycle Manager (TKLM) and IBM Security Key Lifecycle Manager (SKLM) must be used.

[{"Product":{"code":"STFS69","label":"TS7700"},"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Component":"Not Applicable","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"Version Independent","Edition":"N\/A","Line of Business":{"code":"LOB26","label":"Storage"}},{"Product":{"code":"STFS69","label":"TS7700"},"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Component":" ","Platform":[{"code":"","label":""}],"Version":"","Edition":"","Line of Business":{"code":"LOB26","label":"Storage"}}]

Document Information

Modified date:
17 June 2018

UID

ssg1S1010120