Page 3
Preface Fujitsu would like to thank you for purchasing our Key Management Function Option for the FUJITSU Storage ETERNUS LT260 tape library (hereinafter referred to as "LT260"). This manual describes the setup methods and the operation procedures that are required to use the Key Management Function Option as well as notes and other information.
This chapter provides notes on the Key Management Function Option. Additional information on "Appendix A Logs Related to the Key Management Function" is provided as an appendix. FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED P3AG-1192-02ENZ0...
This symbol indicates important points to note when using this product. This mark indicates additional information regarding things such as convenient functions and procedures while performing operations and settings with this product. FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED P3AG-1192-02ENZ0...
2.3.3 Setting Information of the Key Management Function for the Drive ............. 59 2.3.4 Encryption Setting Information of the Data Cartridge ..................60 FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED P3AG-1192-02ENZ0...
Page 7
How to Download Logs Related to the Key Management Function........74 Checking the Contents of the Logs Related to the Key Management Function ....74 FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED...
Page 8
Deletion confirmation of the imported encryption key................55 Figure 2.41 Confirmation screen if an attempt at restoring the settings file for the library configuration is performed ..............................56 FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED P3AG-1192-02ENZ0...
The encryption logic is implemented by hardware, which means that encryption has less effect on read- write performance. FIPS 140-2 defines the U.S. government's security requirements for cryptographic modules used for data. FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED P3AG-1192-02ENZ0...
During a data backup from a backup server, the tape library automatically assigns an encryption key to the specified data cartridge, encrypts the data (plaintext), and saves the data. The encryption process is performed transparently during this time. FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED P3AG-1192-02ENZ0...
• LTO Ultrium4 (G4) or later tape cartridges For other required optional products, refer to "FUJITSU Storage ETERNUS LT260 Tape Library Product List". For more details about tape cartridges, refer to "A.1 Ultrium Tape Cartridge" in "FUJITSU Storage ETERNUS LT260 Tape Library User’s Guide -Installation &...
"2.1.3 Setting the Master Key" (page 33). For information on exporting the master key, refer to "2.1.3.2 Exporting the Master Key" (page 35). FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED P3AG-1192-02ENZ0...
However, note that if the encryption key is lost, the data can no longer be restored. To share data among tape libraries, Fujitsu recommends operation with a common master key. •...
For information on the storage and contents of the security-related logs, refer to "Appendix A Logs Related to the Key Management Function" (page 74). FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED P3AG-1192-02ENZ0...
This chapter explains the settings that are related to the key management function. The setup and operations for each function are performed from the operator panel or the remote panel. For details about the setup and operations, refer to "FUJITSU Storage ETERNUS LT260 Tape Library User's Guide -Panel Operation-".
Since the license sheet that has the license key may be required for maintenance work, be sure to keep it in a safe place. FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED...
Keep the security administrator password in a safe place because even a maintenance engineer cannot change the password. Click [Logout] to log out of the operator panel. End of procedure FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED P3AG-1192-02ENZ0...
Changing the Initial Password of the Security Administrator Account" (page 23) and click [Login]. Figure 2.4 Logging in to the remote panel End of procedure FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED P3AG-1192-02ENZ0...
After SSL is enabled, the method for connecting to the remote panel changes. For the connection method, refer to "2.1.2.4 Connecting to the Remote Panel after Enabling SSL" (page 28). FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED P3AG-1192-02ENZ0...
Changing the Initial Password of the Security Administrator Account" (page 23) and click [Login]. Figure 2.9 Logging in to the security administrator account End of procedure FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED P3AG-1192-02ENZ0...
On the confirmation screen, click [Yes] to confirm the setting. Figure 2.12 Confirming the key management function setting The key management function is enabled by default. FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED P3AG-1192-02ENZ0...
• When the key management function for the tape library is disabled, data encryption depends on the backup software setting. FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED P3AG-1192-02ENZ0...
Click [Submit] to update the setting. Figure 2.14 Example of enabling the key management function Figure 2.15 Example of disabling the key management function End of procedure FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED P3AG-1192-02ENZ0...
Select the partition where the master key is to be set. If no logical libraries (or partitions) are configured, only "Partition_1" is displayed in the drop down list. FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED P3AG-1192-02ENZ0...
If a master key is not set and the imported master key does not exist, a master key is automatically created when the data is first written to the data cartridge in each partition. FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED...
The password is required to import the master key. Keep the password in a safe place. Figure 2.18 Setting a password for the master key FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED...
Step 4 and onward. Partitions cannot be selected if the master key is not set. Figure 2.19 Exporting the master key FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED P3AG-1192-02ENZ0...
Move to the [Configuration > Encryption > LT Encryption] screen. Select [Master Keys] > [Import Key] on the center pane. Select the master key file to be imported. FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED P3AG-1192-02ENZ0...
Enter the password that was set when the master key was exported. For details, refer to "2.1.3.2 Exporting the Master Key" (page 35). Click [Submit]. Figure 2.21 Importing the master key FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED P3AG-1192-02ENZ0...
If the "Master Key was successfully imported" message disappears, the master key has been imported. Figure 2.23 Status of importing the master key End of procedure FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED P3AG-1192-02ENZ0...
Only a single master key can be deleted at a time. When deleting the master keys of multiple partitions, repeat the procedure from Step 3 and onward. Figure 2.24 Deleting the master key FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED P3AG-1192-02ENZ0...
Deleted master keys cannot be restored even by a maintenance engineer or the manufacturing plant. Carefully consider whether to delete the master key. Figure 2.25 Confirmation screen for deleting the master key End of procedure FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED P3AG-1192-02ENZ0...
The password is required to import the encryption key. Keep the password in a safe place. Figure 2.26 Encryption key password settings FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED P3AG-1192-02ENZ0...
If no logical libraries (or partitions) are configured, only "Partition_1" is displayed in the drop down list. Figure 2.27 Selecting the partition to export the target data cartridges FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED P3AG-1192-02ENZ0...
Multiple data cartridges can be moved at the same time. Figure 2.28 Selecting the data cartridges that are to be exported FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED...
To remove the data cartridges from the export target field, select the relevant data cartridge. The color of the selected data cartridge changes. Click [] to remove the selected data cartridge. Figure 2.29 Removing the export target data cartridges FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED P3AG-1192-02ENZ0...
The default file name for the exported encryption key is determined by the "ID_x_EncryptionKey_yymmdd_xxxxxxxxxx.key" format. The file size is 128 bytes. Figure 2.31 Saving the encryption key to export End of procedure FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED P3AG-1192-02ENZ0...
Enter the password that was set when the encryption key was exported. For details about the password, refer to "2.1.4.1 Exporting the Encryption Key" (page 43). Click [Submit]. Figure 2.32 Importing the encryption key FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED P3AG-1192-02ENZ0...
If the "Encryption key/s were successfully imported" message disappears, the encryption key has been imported. Figure 2.34 Progress status screen for importing the encryption key End of procedure FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED P3AG-1192-02ENZ0...
If no logical libraries (or partitions) are configured, only "Partition_1" is displayed in the drop down list. Figure 2.35 Selecting the partition where the deletion target encryption key exists FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED P3AG-1192-02ENZ0...
In this screen, only the data cartridges with an imported encryption key are displayed. Figure 2.36 Selecting data cartridges with deletion target encryption keys FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED...
Information of the data cartridge disappears. The deletion of the imported encryption keys is complete. Figure 2.40 Deletion confirmation of the imported encryption key End of procedure FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED P3AG-1192-02ENZ0...
For the procedure to back up the setting information, refer to "Saving the library configuration to a file" of "2.5.2 Saving, Restoring and Resetting the Library Configuration" in "FUJITSU Storage ETERNUS LT260 Tape Library User's Guide -Panel Operation-".
In [Security Encryption Status], if "Enabled" is displayed for [LT Encryption], the key management function is enabled. Figure 2.42 [Status > Security > Security Encryption Status] screen End of procedure FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED P3AG-1192-02ENZ0...
An imported encryption key is used. An encryption key is not assigned. Figure 2.46 [Status > Cartridge Inventory > List View (detailed)] screen FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED P3AG-1192-02ENZ0...
Page 62
LT Encryption Key Auto An automatically generated encryption key is used. Import An imported encryption key is used. An encryption key is not assigned. FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED P3AG-1192-02ENZ0...
Figure 2.47 [Status > Cartridge Inventory > Graphical View] screen For Ultrium3 or earlier data cartridges, all the items above are displayed as "N/A". End of procedure FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED P3AG-1192-02ENZ0...
For information on how to set the master key, refer to "2.1.3 Setting the Master Key" (page 33). Management console Tape library 01 Tape library 02 Tape library 03 FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED P3AG-1192-02ENZ0...
Export the set master key to the management console. For information on how to export the master key, refer to "2.1.3.2 Exporting the Master Key" (page 35). FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED P3AG-1192-02ENZ0...
Page 67
However, if the encryption key is deleted or lost by mistake, the data can no longer be read. Therefore, Fujitsu recommends that the same master key be set for the tape libraries sharing data. For information on the encryption key export or import function, refer to "2.1.4...
Page 68
For information on how to eject a data cartridge, refer to "3.3 Loading and Ejecting Cartridges" in "FUJITSU Storage ETERNUS LT260 Tape Library User’s Guide -Installation & Operation-". Primary-site Master key A FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED P3AG-1192-02ENZ0...
Page 69
For information on how to import an encryption key, refer to "2.1.4.2 Importing the Encryption Key" (page 50). For information on how to insert a data cartridge, refer to "3.3 Loading and Ejecting Cartridges" in "FUJITSU Storage ETERNUS LT260 Tape Library User’s Guide -Installation & Operation-". Primary-site Secondary-site...
Refer Encryption] screen could not be displayed. "2.1.2.2 Logging in to the Remote Panel" (page 25) FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED P3AG-1192-02ENZ0...
Page 71
SAS): V01L03(33AB) and later All firmware versions for the following models support the Key Management Function Option. LT26BSKE, LT26BFKE, LT26BSME, LT26BFME, LT26BSKL, LT26BFKL, LT26BSML, LT26BFML FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED P3AG-1192-02ENZ0...
A drive, tape library, or media may be faulty. Reuse of Data Cartridges To reuse an encrypted data cartridge, use backup software to erase the data. FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED P3AG-1192-02ENZ0...
4.4 Connectivity with Backup Software Connectivity with Backup Software On a system using the key management function, Fujitsu recommends using verified backup software. If unverified backup software is used, encryption may not work normally. For more information, contact your sales representative.
For information on how to download logs, refer to "2.6.6 Downloading Log and Trace Files" in "FUJITSU Storage ETERNUS LT260 Tape Library User’s Guide -Panel Operation-".
LT Encryption encryption keys deleted The encryption keys were deleted. 9059 LT encryption Key retrieved by tape drive The tape drive received the encryption key. FUJITSU Storage ETERNUS LT260 Tape Library Key Management Function Option User’s Guide Copyright 2016 FUJITSU LIMITED P3AG-1192-02ENZ0...
Page 78
However, Fujitsu shall assume no responsibility for any operational problems as the result of errors, omissions, or the use of information in this manual. • Fujitsu assumes no liability for damages to third party copyrights or other rights arising from the use of any information in this manual.