Networker

Re: [Networker] New libraries with LTO-4 & encryption

2008-07-24 16:54:17
Subject: Re: [Networker] New libraries with LTO-4 & encryption
From: Stan Horwitz <stan AT TEMPLE DOT EDU>
To: NETWORKER AT LISTSERV.TEMPLE DOT EDU
Date: Thu, 24 Jul 2008 16:50:14 -0400
On Jul 24, 2008, at 3:33 PM, A Darren Dunham wrote:

On Thu, Jul 24, 2008 at 12:18:01PM -0400, Clark, Patti wrote:
1 - FC attached library (Quantum i500) with 3 LTO-4 drives (IBM) - at
least 2 drives will have encryption enabled.
Software to perform encryption key management

Well, that bullet point is where all my questions would be.  I've no
problem with doing the encryption on the drive, but exactly how the keys
are managed will usually be the important pieces.

Who has access, what are the access methods, how do you get keys where
you need them, how do avoid loss of keys, etc...

Can I ask what the important factors were in deciding against appliances
for you?  I too like the apparent convenience of encrypting at the
drive, but I'm uncertain how to do the key management at this point. I
think that's one of the stronger areas of the appliances.

If I am not mistaken, IBM has a free key management utility to use with LTO-4 drives. Try googling for something like "IBM LTO-4 key management" and/or check http://www.ibm.com to see what turns up.

To sign off this list, send email to listserv AT listserv.temple DOT edu and type 
"signoff networker" in the body of the email. Please write to networker-request 
AT listserv.temple DOT edu if you have any problems with this list. You can access the 
archives at http://listserv.temple.edu/archives/networker.html or
via RSS at http://listserv.temple.edu/cgi-bin/wa?RSS&L=NETWORKER