Question & Answer
Question
ISKLM for z/OS is not supported as external key manager for TS7700 External Disk Encryption Support..
Cause
Background:
Generally speaking, when encryption functionally is enabled the required encryption keys are stored in what is called an EKM (Encryption Key Manager).
Over the years various Key Manager applications have been developed. The first version was simply called EKM.
Later the Tivoli Key Lifecycle Manager (TKLM) was developed, which was then re-branded as IBM Security Key Lifecycle Manager (SKLM).
These Key Manager options were typically available for open systems environment. In addition there are Key Manager options available specifically for System z.
TS7700 supports different types of encryption:
- Tape encryption, with external key management
https://www.ibm.com/support/knowledgecenter/STFS69_4.1.0/ts7740_encryption_overview.html
Both Tivoli Key Lifecycle Manager (TKLM) and IBM Security Key Lifecycle Manager (SKLM) for open systems, as well as IBM Security Key Lifecycle Manager for z/OS (ISKLM) are supported as Encryption Key Manager.
- Disk encryption, with internal key management
https://www.ibm.com/support/knowledgecenter/STFS69_4.1.0/ts7740_encryption_intkeymgmt.html
No external Key Manager utilized as key's are managed internally.
- Disk encryption, with external key management
https://www.ibm.com/support/knowledgecenter/STFS69_4.1.0/ts7740_encryption_extkeymgmt.html
In contrast to current documentation, the IBM Security Key Lifecycle Manager for z/OS (ISKLM) is not supported to be used as Encryption Key Manager with TS7700 Disk encryption.
The only supported options are the open systems version of Tivoli Key Lifecycle Manager (TKLM) and IBM Security Key Lifecycle Manager (SKLM).
Answer
Solution (Procedure):
IBM Security Key Lifecycle Manager for z/OS (ISKLM) must not be used as Encryption Key Manager with TS7700 Disk encryption.
Only the available open systems version of Tivoli Key Lifecycle Manager (TKLM) and IBM Security Key Lifecycle Manager (SKLM) must be used.
Was this topic helpful?
Document Information
Modified date:
17 June 2018
UID
ssg1S1010120