IBM FlashSystem

 View Only
  • 1.  Inquiries regarding IBM SKLM(IBM Guardium Key Lifecycle Mgr)

    Posted Sun December 15, 2024 10:43 PM

    Hello Team, 

    I would like to inquire about SKLM.

    Currently, the customer is trying to migrate from IBM SVC to IBM FS7300.

    And IBM SVC is using SKLM with USB encryption.

    However, when purchasing FS7300, the customer did not purchase a license for the encryption function.

    So the customer inquired whether can purchase and apply a license for SKLM after the migration.

    And the customer asked whether there could be a data corruption issue when applying SKLM after applying data migration.

    Thanks



    ------------------------------
    SUNG EUN KIM
    ------------------------------


  • 2.  RE: Inquiries regarding IBM SKLM(IBM Guardium Key Lifecycle Mgr)

    Posted Mon December 16, 2024 01:36 AM
    Edited by Nezih Boyacioglu Mon December 16, 2024 01:37 AM

    Hi Sung,
    encryption is a feature that is enabled when the pool is created. Therefore, you need to enable it before migration. 



    ------------------------------
    Nezih Boyacioglu
    ------------------------------



  • 3.  RE: Inquiries regarding IBM SKLM(IBM Guardium Key Lifecycle Mgr)

    Posted Thu December 19, 2024 05:04 AM

    Hi, Nezih

    Thank you for your detailed and helpful explanation



    ------------------------------
    SUNG EUN KIM
    ------------------------------



  • 4.  RE: Inquiries regarding IBM SKLM(IBM Guardium Key Lifecycle Mgr)

    Posted Mon December 16, 2024 01:49 AM

    Hi Sung, 

    re your inquiry:

    So the customer inquired whether can purchase and apply a license for SKLM after the migration.

    Basically, the answer is yes.

    However, as Nezih had mentioned, an existing pool can not be turned into an encrypted pool after its creation.

    There is no need to worry about potential data corruption by using encryption.

    That said, either a new, encrypted pool needs to be created, and the existing vdisks can be migrated from the original, unencrypted pool into the new encrypted pool, for instance by adding a vdisk copy (vdisk mirroring). This, of course, does require sufficient unused capacity / drives.

    If the FS7300 is not in production yet, the better choice definitely would be to start over with an encrypted pool and start the migration off the SVC again.



    ------------------------------
    Best regards, 

    Christian Schroeder
    IBM Storage Virtualize Support with Passion
    ------------------------------



  • 5.  RE: Inquiries regarding IBM SKLM(IBM Guardium Key Lifecycle Mgr)

    Posted Thu December 19, 2024 05:05 AM

    Hi, Christian

    Thank you for your detailed and helpful explanation



    ------------------------------
    SUNG EUN KIM
    ------------------------------