Drive-Enrolled Encryption

Drive-enrolled encryption uses VOP to individually enroll drives as agents with OKM. Some drive types require an encryption card and an encryption activation permit to use drive-enrolled encryption.

Supported Drive Types

All T10000 drives and HP LTO drives are encryption ready. IBM LTO 5, 6, 7, and 8 drives require an encryption card in the drive tray to interface directly with OKM.

Each LTO and T10000A/B encrypting drive must have an encryption permit. T10000 C/D drives no longer require permits.

Configuration

Use VOP to individually enroll drives with OKM. Before enrolling the drives, make sure that library-managed encryption is disabled and all drives within the library have encryption disabled. You cannot use both drive-enrolled encryption and library-managed encryption.

How do I know if a drive tray has an encryption card?

The Encr card Type column of the Drives table shows if the tray contains a BEL, LKM, or LKMD card. If the field is blank, this means the drive tray does not contain an encryption card.


Sample Drives table showing encryption card type.