Hi Alan,

I wish it were that simple, but aren't there Windows based "key-servers"
involved that hold the keys?  One of my concerns is replicating the
contents of those Winblows "key servers" (somehow) to your DR site.
Maybe you can answer this for me, if you have your encrypted tapes but
no key-servers, is there a way (from a 3270 console) to provide a
"master key/passphrase" or something to make the tapes usable/readable?

By the way, what software is required on z/VM?  I see lot's of
references in the doc to RACF (which we don't use), but can't tell if
that's required for this to work or not.   I had access to a TS1120
recently, but couldn't test it because z/VM 5.3 is the first release to
support the drive, and that doesn't go GA for a couple of weeks yet.

Michael Coffin, President
MC Consulting Company, Inc.
57 Tamarack Drive
Stoughton, Massachusetts  02072
 
Voice: (781) 344-9837    FAX: (781) 344-7683
 
[EMAIL PROTECTED]
www.mccci.com


-----Original Message-----
From: The IBM z/VM Operating System [mailto:[EMAIL PROTECTED] On
Behalf Of Alan Altmark
Sent: Wednesday, June 13, 2007 9:11 AM
To: [email protected]
Subject: Re: Encryption options for DDR


On Tuesday, 06/12/2007 at 04:11 MST, Thomas Kern <[EMAIL PROTECTED]>

wrote:

> The hardware solution of encrypted tape drives is pushed alot because
z/OS has
> so much data that should be encrypted and z/VM can use them too, but 
> not
as
> friendly as if you were strictly z/OS.

Huh?  Using an encrypting tape drive on z/VM is as easy as specifying
the 
key label on ATTACH.

> What I haven't figured out about them is
> how to prove to the security auditors that the data is REALLY 
> encrypted.

Quoting some news articles on the web, IBM is in the process of having
the 
TS1120 FIPS 140-2 certified.

Alan Altmark
z/VM Development
IBM Endicott

Reply via email to