- Sun Storage Virtual Tape Library VTL User Guide

Encrypting and shredding data
128 VTL User Guide May 2008 G • 96267
Eachkeyconsistsofasecretphrase.For addit ion alsecurity,eachkeyispassword
protected . Youmustprovidethispasswordin ordertochangethekeyname,
password,orpasswordhint,ortodeleteorexportthekey.
Youcanapplyasinglekeytoallvi rt u altapeswhenyouexport
themtophysical
tape,oryoucancreateauniquekeyforeachone.Creatingmultiplekeysprovides
moresecurity;intheunlikelyeventthat akeyiscompromised,onlythetapesthat
usethatkeywouldbeaffected. However,ifyouusemultiplekeys,youmustkeep
trackofwhich
ke yappliestoeachtapesothat youusethecorrectkeytodecryptthe
datawhenyou impo rtthephysicaltapeback tovirtualtape.
Note:Ifyouapplyanincorrectkeywhenimportinga tape,thedataimpo rtedfrom
thattapewillbeindecipherable.
Onceyouhavecreatedone
ormorekeys,you canexportthemto aseparatefile
calledakeypackage.Ifyou se nd encryptedtapestootherlocationsthatrunVTL,
youcanalsosend themthekeypackage.Byimportingthekeypackage,
administratorsattheothersitescanthendecryptthetapeswhenthey
areimported
backintovirtualtapelibraries manage dbyVTL.
Youcanenableencryptionandspecifywhichkeytousewh enyoueithermanually
importorexportatapeorwhenyouusetheautoarchive/replicationfeature.
Forinstructions,seethefollowing:
“Creatinga ke y”onpage 128
“Changinga key name orpassword”onpage 129
“Deletingakey”onpage 130
“Exportingakey”onpage 131
“Importinga key” onpage 132
“Shreddingavirtualtape”onpage 133.
Creatinga key
1. Inthenavigationtree,rightclicktheservernameandclickKey Management.
2. ClickNew.
3. IntheKey Name textbox(
A below),typeauniquenameforthekey(1–32
characters).
4. IntheSecret Phrase textbox(
B below),type thephrase(25–32characters,
includingnumbersandspaces)thatwillbeusedtoencryptthedata.
Saveyoursecretphrase.Onceyouhavecre ate dakey,youcannotchangethesecret
phraseassociatedwiththatkey.