Hi Alan, I wish it were that simple, but aren't there Windows based "key-servers" involved that hold the keys? One of my concerns is replicating the contents of those Winblows "key servers" (somehow) to your DR site. Maybe you can answer this for me, if you have your encrypted tapes but no key-servers, is there a way (from a 3270 console) to provide a "master key/passphrase" or something to make the tapes usable/readable?
By the way, what software is required on z/VM? I see lot's of references in the doc to RACF (which we don't use), but can't tell if that's required for this to work or not. I had access to a TS1120 recently, but couldn't test it because z/VM 5.3 is the first release to support the drive, and that doesn't go GA for a couple of weeks yet. Michael Coffin, President MC Consulting Company, Inc. 57 Tamarack Drive Stoughton, Massachusetts 02072 Voice: (781) 344-9837 FAX: (781) 344-7683 [EMAIL PROTECTED] www.mccci.com -----Original Message----- From: The IBM z/VM Operating System [mailto:[EMAIL PROTECTED] On Behalf Of Alan Altmark Sent: Wednesday, June 13, 2007 9:11 AM To: [email protected] Subject: Re: Encryption options for DDR On Tuesday, 06/12/2007 at 04:11 MST, Thomas Kern <[EMAIL PROTECTED]> wrote: > The hardware solution of encrypted tape drives is pushed alot because z/OS has > so much data that should be encrypted and z/VM can use them too, but > not as > friendly as if you were strictly z/OS. Huh? Using an encrypting tape drive on z/VM is as easy as specifying the key label on ATTACH. > What I haven't figured out about them is > how to prove to the security auditors that the data is REALLY > encrypted. Quoting some news articles on the web, IBM is in the process of having the TS1120 FIPS 140-2 certified. Alan Altmark z/VM Development IBM Endicott
