Hello Everyone,

        I do have a PMR outstanding with IBM indicating that the TKLM
needs to be configured differently.

BUT I am going after a second opinion.

        We are attempting to use a 3592-E05 using a 

TKLM (Tivoli Key Lifecycle Manager) on a LINUX system
Instead of an  
EKM (Encryption Key Manager) on Java Platform (z/VSE Admin chapter 42).

        I have the drives attached under z/VM to my BETA system with a
default of x'0B' in the add statement.

ADD 680:681,TPA,0B,EML 
        
X'0B' Encryption and IDRC (compression) Write Mode

        If I attempt to use tape without issuing a KEKL statement (I
have been told that it would use the TKLM system default key),
0P18I P Comm Rejct is presented.

        I just did a LIBR backup by forcing a x'08' (no encryption), and
everything worked.

        Where can I find out about TKLM and z/VSE?  The Admin manual
only discusses EKM.

        I am working on 3592 that configured off-site.

        By the way, I attempted to enter a KEKL (z/VSE statement) and
got the following.

0 // KEKL UNIT=SYS010,KEKL1='3592CUST01',KEM1=L
BG-0000 1YQ2D  DEVICE SYS010 NOT ENCRYPTION CAPABLE

A volume command shows following.

VOLUME 680                                                    
AR 0015 CUU  CODE DEV.-TYP   VOLID  USAGE   SHARED    STATUS    CAPACITY
AR 0015 680  560B 3592-E05  300009  USED                          BOV  1

        Any information would be helpful.

  
Ed Martin
Aultman Health Foundation
330-363-5050
ext 35050

Reply via email to