Primary Storage

 View Only
  • 1.  IBM FlashCore Modules Encryption

    Posted Sun February 26, 2023 08:45 AM

    In Redpaper IBM FlashSystem 9500 Product Guide is written:

    The IBM FlashCore Modules and NVMe Flash SSD type drives, including the SCMs, in the IBM FlashSystem 9500 control enclosure are self-encrypting drives (SEDs). 
    With SEDs, you can encrypt the data on the drive within the hardware.
    You can use SEDs without enabling encryption on the system, but SEDs are unlocked by default unless they are configured with extra protection.

    Q: How do we configure the extra protection?



    ------------------------------
    T Masteen
    ------------------------------


  • 2.  RE: IBM FlashCore Modules Encryption

    User Group Leader
    Posted Mon February 27, 2023 04:19 AM

    You need to order the following feature code:

    • (#ACE9) Encryption Enablement

    Reference: Family 4666+02 IBM FlashSystem 9500 - IBM United States Sales Manual, Revised: January 24, 2023



    ------------------------------
    Keigo Matsubara, Storage Solution CTS, IBM Japan
    ------------------------------



  • 3.  RE: IBM FlashCore Modules Encryption

    User Group Leader
    Posted Tue February 28, 2023 04:21 AM

    As Stated previously, you need to order the feature code to enable encryption and you will need to create the arrays as encrypted.  If you have already configured your pools and Arrays, you cannot convert from non encrypted to encrypted without recreating those objects.  

    For more information on this and other security topics, please reference the documentation: 

    https://www.ibm.com/docs/en/flashsystem-9x00/8.5.x?topic=planning-security

    https://www.ibm.com/docs/en/flashsystem-9x00/8.5.x?topic=configuring-encryption

    https://www.redbooks.ibm.com/abstracts/redp5678.html



    ------------------------------
    Evelyn Perez
    ------------------------------



  • 4.  RE: IBM FlashCore Modules Encryption

    Posted Tue February 28, 2023 12:57 PM

    Just a little add, i see from some deployments that you can create a pool with "mkmdiskgrp -encrypt no" and then add an array with "mkarray/mkdistributedarray" without specify encrypt yes, the system will automatically verify if the encryption is enabled in the system so it will make the array encrypted and also the pool if no other mdisks are already configured.



    ------------------------------
    Davide Galbussera
    ------------------------------