Virtual TapeServer 6.04.04 for NonStop Servers Release Notes

Known Issues | 27
SecureVTS
No notification that restore fails because remote key server was not added after
restoring from a disaster recovery site. The local key server should be removed prior
to restoring the key database. The web interface should notify the user when a restore
from a disaster recovery site fails because a local key server already exists. (TL-4399)
Key database restore fails if an IP address is used instead of a hostname. If a key
database was backed up and an IP address was specified, restoring the backup fails.
(TL-4033)
WORKAROUND: Restore the backup using these steps:
a. Delete the IP address entry.
b. Add a new entry for the same backup host but use a hostname instead of IP address.
(If DNS is not used, add an entry to /etc/hosts). A different backup file name must be
used or the previous backup will be overwritten.
c. After the backup server entry has been added and the system has successfully backed
up to that server, copy the original key backup filename that is to be restored to the
new backup filename.
d. Click the restore icon to complete the restore.
If invalid license key is used, SecureVTS appears to be configured though it is
not. If an invalid license key is used, no key generator is created. The server should
indicate that the license key is not valid. (TL-3549)
Encryption key backup must occur before you can add a remote host. Until the
encryption key is backed up, the remote host cannot be set. (TL-3463)
Pool is shown as encrypted though encryption failed. If no key generator is
configured and you set a pool to be encrypted, the operation will fail but the Pool
Maintenance and Virtual Media pages indicate that the pool is encrypted. (TL-3756)
No indication that configuration is incomplete and encryption/decryption will
fail. If no remote key generator backup host is defined and working, encryption or
decryption may fail with no indication other than rc=254 or rc=-2 in a log. The keys are
not cached until a remote host is defined. Encryption and decryption is not possible until a
remote backup host is defined. (TL-3686)
WORKAROUND: Define a remote backup host and then backup the keys to the backup
host.
SecureVTS with remote key generator does not encrypt cartridges. If SecureVTS
is configured to use a remote key generator, the local host cannot encrypt cartridges.
(TL-3171)
WORKAROUND: Backup the remote keyserver database, delete the “localhost”
keyserver on the remote server, re-add the localhost keyserver on the remote server,
restore the keyserver database from backup.
SecureVTS cannot restore key database from remote server if backup file name
contains a period. When trying to restore from a remote host, an error message similar
to the following is generated if the backup file name contains a period. (TL-3168)
Unable to restore backup because remote_host does not exist in the
database.
WORKAROUND: When specifying a file to be used for the destination for a remote
backup of a key database, do not include a period in the file name. If a file with a period is