Users Guide

Table 32. Magazine state (continued)
Magazine state LED state Description
Closed Slow Flash Magazine open is in process.
Closed Fast Flash Magazine is opened.
Closed OFF I/O station is not enabled.
Opened OFF Magazine is opened.
Conguring Library Managed Encryption
Library-Managed Encryption (LME) is a built-in feature that is factory-enabled.
Two versions of Library-Managed Encryption are available for conguration.
Key Management Interoperability Protocol (KMIP) Encryption (v1.2)
Security Key Lifecycle Manager (SKLM) for z/OS
®
Encryption
Access the wizard from the Actions menu with the Manage Encryption option. The Library Managed
Encryption Licensed Feature is already activated on your library, and can’t be deactivated. However, the
feature must be congured before LME can be used.
Notes: Before you run the Encryption wizard.
Conrm that the Library-Managed Encryption license is activated on the Settings > Library > Licensed
Features page.
Verify that the server is available on the network and is congured for use with this library. For
information on conguring servers for use with the library, see the server documentation.
Note: If you plan to use the IBM Security Key Lifecycle Manager (SKLM), go to “Related Publications” on
page xxxi for information on setup and conguration.
If Library Encryption settings are cleared and recongured, you're required to accept the new certicate
on the server when the Library Self-Signed Certicate is used.
Key Management Interoperability Protocol (KMIP) Encryption
1. In the Actions menu, click Manage KMIP Encryption to start the wizard.
2. The Logical Library Selection screen displays the KMIP conguration options that can be set as the
default for all logical libraries, or on a per logical library basis. The second section provides the option
to copy the KMIP conguration settings to all logical libraries (default) or to specied logical libraries.
3. The Wizard Information screen displays information about the wizard. On this screen, it’s also
possible to Reset Encryption Settings. If the library conguration is complete and the KMIP server is
available on the network, click Next.
4. The Certicate Option screen displays the different certicate options that can be used to establish a
secure communication to the KMIP server. You can select from the following options:
Library Self-Signed Certicate (default option) - A self-signed certicate that is generated by the
library is used.
Uploaded Certicate - Upload a PCKS #12 le that includes a certicate and corresponding key.
Generate Certicate Request (CSR) - A CSR is generated by the library that must be signed by a CA
server. This method requires a CA certicate that must be provided during the wizard steps.
a. Certication Conguration
Library Self-Signed Certicate – skip to the next step.
Uploaded Certicate
1) Upload the PKCS #12 le in the certicate area on the Certicate Option screen.
72
Dell EMC ML3 Tape Library: User's Guide