On Wednesday, 06/13/2007 at 09:27 AST, "Imler, Steven J" 
<[EMAIL PROTECTED]> wrote:
> z/OS has
> >> so much data that should be encrypted and z/VM can use them too, but
> not
> as
> >> friendly as if you were strictly z/OS.
> 
> > Huh?  Using an encrypting tape drive on z/VM is as easy as specifying
> the
> > key label on ATTACH.
> 
> Only if you're willing to completely ignore all of the hardware and
> software PRE-REQs necessary to establish an "out-of-band connection".
> Our storage management group (and my z/OS counterparts) thought I had
> lost my mind when I gave them the list.

There has to be a key manager *somewhere*.  z/OS already has one in the 
form of ICSF, but for everyone else there's the Encryption Key Manager 
(EKM).  It can run on Linux (incl. z), Windows, AIX, HP, Sun, or z/OS. 
Once you set up the EKM, all of your encrypting drives can use it.  It's 
not just a "VM thing".

But I appreciate that installing an encrypting tape drive is more time 
consuming than a non-encrypting drive for non-z/OS use.  Like everything, 
there's a first-time additional effort.

Alan Altmark
z/VM Development
IBM Endicott

Reply via email to