Configure Hardware Encryption for a Data Path

Updated

You can modify the hardware encryption options for a data path that is configured using a tape library.

Procedure

  1. From the CommCell Browser, expand Policies > Storage Policies > storage_policy.

  2. Right-click the storage_policy_copy and click Properties.

  3. In the Copy Properties dialog box, on the Data Paths tab, select the appropriate data path, and then click Properties.

  4. In the Data Path Properties dialog box, select the Use Hardware Encryption check box to enable.

    Clear the checkbox to disable.

  5. A message appears that asks if the drives in the library supports data encryption, click Yes.

  6. If you want to encrypt the chunkmap trailers that contains the metadata of the chunks created for the backup data, select Enable Encryption on Chunkmap trailers. When this option is selected, Via Media Password and No Access options in the Direct Media Access (External Restore Tools) area are disabled.

    Note: If you enable chunkmap trailer encryption, the data cannot be restored by using the Media Explorer and the Tape catalog feature.

  7. If Enable Encryption on Chunkmap trailers option is not selected, choose whether to allow access for external restore tools by selecting one of the following options in the Direct Media Access (External Restore Tools) area:

    • To enable the encryption keys store on the media, select Via Media Password.

    • To disable the encryption keys store on the media, select No Access.

      Note

      For a CommServe Disaster Recovery storage policy, the Via Media Password is the default option and you cannot change the option. The DR backups require the keys store on the media.

  8. Click OK and then click OK to close the Storage Policy Copy Properties dialog box.

    Note: When hardware encryption is enabled, decryption always occurs on hardware device.

Was this page helpful?