Hello Everyone,
I do have a PMR outstanding with IBM indicating that the TKLM
needs to be configured differently.
BUT I am going after a second opinion.
We are attempting to use a 3592-E05 using a
TKLM (Tivoli Key Lifecycle Manager) on a LINUX system
Instead of an
EKM (Encryption Key Manager) on Java Platform (z/VSE Admin chapter 42).
I have the drives attached under z/VM to my BETA system with a
default of x'0B' in the add statement.
ADD 680:681,TPA,0B,EML
X'0B' Encryption and IDRC (compression) Write Mode
If I attempt to use tape without issuing a KEKL statement (I
have been told that it would use the TKLM system default key),
0P18I P Comm Rejct is presented.
I just did a LIBR backup by forcing a x'08' (no encryption), and
everything worked.
Where can I find out about TKLM and z/VSE? The Admin manual
only discusses EKM.
I am working on 3592 that configured off-site.
By the way, I attempted to enter a KEKL (z/VSE statement) and
got the following.
0 // KEKL UNIT=SYS010,KEKL1='3592CUST01',KEM1=L
BG-0000 1YQ2D DEVICE SYS010 NOT ENCRYPTION CAPABLE
A volume command shows following.
VOLUME 680
AR 0015 CUU CODE DEV.-TYP VOLID USAGE SHARED STATUS CAPACITY
AR 0015 680 560B 3592-E05 300009 USED BOV 1
Any information would be helpful.
Ed Martin
Aultman Health Foundation
330-363-5050
ext 35050