BRMS Encrypted Restore

20 pts.
Tags:
AS/400
BRMS
Encryption
iSeries
Has anyone performed a single library restore from a BRMS encrypted tape on one server to another?  Here's my dilemna...I can encrypt fine and restore partition to partition on the same iSeries server.  However when I try to restore from a partition on another iSeries server I'm unable to restore.  My key on both servers is the same.  Any help/suggestions is greatly appreciated.

Software/Hardware used:
iSeries BRMS Encryption

Answer Wiki

Thanks. We'll let you know when a new response is added.

I believe your problem would be cause because of different serial numbers of the machines. Even thought you set up your keys the same way on both servers, when the key is built, it uses the serial number. Your key is stored in a a KeyStore area. This is what is used to decrypt. They would be different on each machine.

For anyone needing additional information IBM, while working with me, had me create the following data area with the following values:
CRTDTAARA DTAARA(QTEMP/QTADECRYPT) TYPE(*CHAR) LEN(62)
CHGDTAARA DTAARA(QTEMP/QTADECRYPT (1 10)) VALUE(‘TAPMLB01′)
CHGDTAARA DTAARA(QTEMP/QTADECRYPT (11 10)) VALUE(‘Q1AKEYFILE’)
CHGDTAARA DTAARA(QTEMP/QTADECRYPT (21 10)) VALUE(‘QUSRBRM’)
CHGDTAARA DTAARA(QTEMP/QTADECRYPT (31 32)) VALUE(‘KEYRECORD’)

As shown in this example the library is QTEMP but you can also create these in QUSRSYS permanently. When you perform a restore from one server to another with different serial numbers BRMS trys to create this data area. Also you must have media monitor turned off to do the restore. Lastly, of course, you need to have the Q1AKEYFILE and Key Stores setup the same as the source partition. All of these will allow for a successful restore.

Discuss This Question: 1  Reply

 
There was an error processing your information. Please try again later.
Thanks. We'll let you know when a new response is added.
Send me notifications when members answer or reply to this question.

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy
  • saturno
    Hi everyone, I think the previous answer might need a little more clarification. What I think you might need is to export the primary master key from the system you are doing the back up and import it to the system you are making the restore. The following document might be useful to you (this document mostly from point 7 to 11) HTH, Luís
    4,585 pointsBadges:
    report

Forgot Password

No problem! Submit your e-mail address below. We'll send you an e-mail containing your password.

Your password has been sent to:

To follow this tag...

There was an error processing your information. Please try again later.

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy

Thanks! We'll email you when relevant content is added and updated.

Following