ADSM-L

Re: [ADSM-L] Excrypting Exchange Data

2010-01-12 07:18:04
Subject: Re: [ADSM-L] Excrypting Exchange Data
From: Grigori Solonovitch <G.Solonovitch AT BKME DOT COM>
To: ADSM-L AT VM.MARIST DOT EDU
Date: Tue, 12 Jan 2010 15:16:22 +0300
Unfortunately, I have no experience in encryption TDP for Exchange backups.

For Oracle database we are using:



1) in dsm.sys:

   Encryptiontype         AES128

   Encryptkey               generate

   InclExcl                    /backup/tsm/ba/InclExcl.list



2) in Include/Exclude list:

include /ifns_ifns/.../* DBLPAR05



3) from activity log:

ANE4991I (Session: 2536, Node: LPAR05_ORA)  TDP Oracle AIX

ANU0599  TDP for Oracle: (4997220): =>(LPAR05_ORA)

ANU2526I Backup details for backup piece 
/ifns_ifns///LPAR05/ifns.11.1.54535.1.708019250 (database "IFNSDB").

Total bytes sent:         6077546496.

Total processing time: 00:08:05.

Throughput rate:         12237.33Kb/Sec.

Compressed:       Yes , 59%.

Encryption:         AES_128BIT.

LAN-Free:          No.









Grigori G. Solonovitch



Senior Technical Architect



Information Technology  Bank of Kuwait and Middle East  http://www.bkme.com



Phone: (+965) 2231-2274  Mobile: (+965) 99798073  E-Mail: G.Solonovitch AT bkme 
DOT com



Please consider the environment before printing this Email





-----Original Message-----
From: ADSM: Dist Stor Manager [mailto:ADSM-L AT VM.MARIST DOT EDU] On Behalf Of 
Stefan Folkerts
Sent: Tuesday, January 12, 2010 2:58 PM
To: ADSM-L AT VM.MARIST DOT EDU
Subject: [ADSM-L] Excrypting Exchange Data



What is supposed to be a walk in the park (when reading the very limited amount 
of documentation on encryption in the protection for mail (exchange) 
documentation) is turning into a little bit of a headache. :)



I currenty have my exchange dsm.opt setup like this ;



enableclientencryptkey yes

encryptiontype AES128

INCLUDE.ENCRYPT *\...\*





Also tried ;



include.encrypt "SERVERNAME\First Storage Group\...\*"



Doesn't change the situation, it still doesn't work.



I get NO request for key input, I am 100% sure this is not done before and I 
cannot seem to see my error here..please somebody point me at the error in my 
ways!



It would be great if somebody could post his dsm.opt file for an encrypted 
Exchange server.



Regards,



  Stefan



Please consider the environment before printing this Email.

________________________________
"This email message and any attachments transmitted with it may contain 
confidential and proprietary information, intended only for the named 
recipient(s). If you have received this message in error, or if you are not the 
named recipient(s), please delete this email after notifying the sender 
immediately. BKME cannot guarantee the integrity of this communication and 
accepts no liability for any damage caused by this email or its attachments due 
to viruses, any other defects, interception or unauthorized modification. The 
information, views, opinions and comments of this message are those of the 
individual and not necessarily endorsed by BKME."