IBM i Global

IBM i 

A space for professionals working with IBM’s integrated OS for Power systems to exchange ideas, ask questions, and share expertise on topics like RPG and COBOL development, application modernization, open source integration, system administration, and business continuity.


#Power


#IBMi
#Power
 View Only
  • 1.  LTO-9 backup tape encryption via hardware encryption

    Posted Fri September 26, 2025 02:49 AM

    Anyone here implemented Application-Managed Hardware Encryption via IBM i Native Tools (No BRMS)? I want to know how to setup this. Thanks

    Your help is greatly appreciated.

    Aldrin



    ------------------------------
    Aldrin Dela Cruz
    Senior IBM i System Administrator
    BCSI - VeteransBank
    ------------------------------


  • 2.  RE: LTO-9 backup tape encryption via hardware encryption

    Posted Sat September 27, 2025 03:36 AM

    Dear Aldrin

    I'm not sure I understand what you meant by "Application-Managed Hardware Encryption".  Could you explain what you meant by "application-managed"? 

    In my experience with many IBM i servers using IBM tape devices that support HW data encryption, the tape HW encryption feature is turned on and encryption key is enabled in the tape device setup and it works transparently to IBM i.  You just run all IBM i SAVXXXX commands as usual. The decryption works transparently with RSTXXXX commands as well. 

    But if your tape device does not come with HW encryption feature, you can optionally install and use IBM i installable option Encrypted Backup Enablement (57xx-SS1 Option 44) but this feature consumes Power Server's CPU and it prolongs the entire data backup time somewhat because this feature does not compress or compact data as well as non-encrypted data.  This Technote describes how to enable this feature in IBM i :  How to Set up Encryption Environment to Perform Software Encryption at https://www.ibm.com/support/pages/how-set-encryption-environment-perform-software-encryption.          


     



    ------------------------------
    Satid S
    ------------------------------



  • 3.  RE: LTO-9 backup tape encryption via hardware encryption

    Posted Sat September 27, 2025 03:57 AM

    I found an old presentation on IBM i encrypted data backup support from 2011 that indicated that IBM i did not support application-managed encryption (AME). It only supports library-managed encryption (LME), and system-managed encryption (SME) as of IBM i 6.1 with the Encrypted Backup Enablement option.  Not sure if there is any change on AME since then.    



    ------------------------------
    Satid S
    ------------------------------