12.07.2015 Views

IBM Tivoli Storage Manager for UNIX and Linux Backup-Archive ...

IBM Tivoli Storage Manager for UNIX and Linux Backup-Archive ...

IBM Tivoli Storage Manager for UNIX and Linux Backup-Archive ...

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Important: Whenever you run a backup that includes any files encrypted on anEFS, you must ensure that you use the correct specification of the efsdecryptoption. If the efsdecrypt option value changes between two incremental backups,all encrypted files on EFS file systems will be backed up again, even if they havenot changed since the last backup. For example, if you are running an incrementalbackup of encrypted files that were previously backed up as raw, then ensure thatefsdecrypt is specified as no. If you change efsdecrypt to yes, all the files will bebacked up again in clear text even if they are unchanged, so ensure that you usethis option carefully.If you attempt to restore an encrypted file to either a work station that does notsupport EFS, or a file system where EFS is not active, an error message is written<strong>and</strong> the file is skipped.Here are some reasons to back up EFS using clear text encryption:v This type of decryption is useful if you want to use the <strong>Tivoli</strong> <strong>Storage</strong> <strong>Manager</strong><strong>Backup</strong>-<strong>Archive</strong> Client encryption or another type of hardware encryption (<strong>for</strong>tape systems, <strong>for</strong> example).v You can use clear text <strong>for</strong> long term archival of data, because the data is storedindependent of the plat<strong>for</strong>m or encryption scheme.Here are some things to consider when backing up a file in clear text:v The user who invoked <strong>Tivoli</strong> <strong>Storage</strong> <strong>Manager</strong> must be able to decrypt itv The user can have read access to a file, but not have access to the keyIn the following scenarios an error message is issued:1. The user is running in root guard mode, <strong>and</strong> EFS has the concept of two typesof root. Root admin is the traditional mode. A root in guard mode will not haveaccess to the unencrypted data, unless the user is the owner or a member of thefile’s group.2. The user is running with a non-root user ID <strong>and</strong> attempting an archive of a fileto which they have read access, but the user is not the owner or member of thefile’s group. EFS will not allow the data to be decrypted.Here are some considerations when backing up EFS raw data:v <strong>Tivoli</strong> <strong>Storage</strong> <strong>Manager</strong> will not honor the client encryption setting, whichprevents double encryption, but only at the client. The server has no knowledgethat the data is encrypted so any encryption done by a tape drive, <strong>for</strong> example,still occurs.v <strong>Tivoli</strong> <strong>Storage</strong> <strong>Manager</strong> will not honor the compression setting, so the client willnot even try to compress the data.v <strong>Tivoli</strong> <strong>Storage</strong> <strong>Manager</strong> does not automatically back up or restore the keystorefiles. When you are restoring encrypted files, you might also have to restorekeystores in order to decrypt the data.Recommendations:1. To protect the keystore, make sure the contents of /var/efs are included inyour periodic backups.2. For the keystore data, use <strong>Tivoli</strong> <strong>Storage</strong> <strong>Manager</strong> storage policy with anunlimited number of versions.v Encrypted file system (EFS) files backed up in raw mode (default) cannot berestored by a <strong>Tivoli</strong> <strong>Storage</strong> <strong>Manager</strong> Client prior to Version 5.5, or by a clienton another <strong>UNIX</strong> plat<strong>for</strong>m.Chapter 4. Backing up your data 155

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!