This section provides general notes on tape backup operations.
WORM (Write-Once, Read-Many) media cannot be used for drive encryption.
The TSM "define devclass" and the "update devclass" commands do not support settings in which "worm=yes" and "driveencryption=on" are both specified.
All drives in the library must support the new encryption format. In addition, all drives in a logical library must use the same encryption method.
The ACM tape backup function does not support environments in which some drives use application methods of encryption, and other drives use library or system methods of encryption.
Only LTO Ultrium4 media can be encrypted by the G4 drive encryption function. Do not have a mixture of tape library media generations if you plan to encrypt volumes in the tape library in future.
If "driveencryption" is set to "on" when setting the device class and the hardware is configured to use a different encryption method, then backup operations will fail.
The encryption key used for data encryption and decryption is stored in the TSM database. Therefore, particular care is required to protect backups of the TSM database. The correct TSM database backup and the appropriate encryption key to access information are required in order to restore the data.
Do not perform tape backup operations if there is a mixture of encrypted and non-encrypted drives.
When G4 encrypted data is written to a tape volume, the new format is used. After data has been written to a volume in the new format, a label is included in the volumes returned to scratch indicating that reading is possible only at drives that support encryption.
In order to re-use a scratch volume at a drive that does not support G4 encryption after it has been used for G4 encryption, the checkout libvolume command must be used to delete the relevant tape volume from the TSM database and re-label it.
For details on how to specify a new label, refer to "4.2.2.1 Checking in a new tape".