This chapter contains descriptions for the components in an Oracle Key Manager encryption solution.
The following components can be ordered to support customer requirements and configurations for an Oracle Key Manager encryption solution:
"Key Management Appliance" This is a required component for key creation, management, and assignments.
When implementing an encryption solution using one of Oracle's StorageTek libraries, review the following:
Customers have a choice in the type of tape drive they want to use for encryption:
T10000A, T10000B, T10000C, and T10000D
T9840D
HP LTO4, LTO5, and LTO6
IBM LTO4, LTO5, and LTO6
See "Firmware Levels" for the supported tape drive firmware versions.
When implementing an encryption solution using one of Oracle's databases, review the following:
Interfaces with Transparent Data Encryption (TDE) suite in Oracle Database 11gR2
Oracle Database products
Oracle Real Application Clusters (Oracle RAC)
Oracle Data Guard
Oracle Exadata Database Machine
Oracle Recovery Manager (RMAN)
Oracle Data Pump
All editions are built using the same common code base, which means your database applications can easily scale from small, single-processor servers to clusters of multi-processor servers.
Compare the following features:
The current Key Management Appliance is a Netra SPARC T4-1 server.
Rack-mountable Key Management Appliance (KMA); order: CRYPTO-KMA-23 or 597-1095-01
If an SCA6000 card is required; order: 375-3424-06. This card provides FIPS 140-2 level 3-compliance for the encryption keys.
This server comes with a pre-loaded Solaris 11 operating system and special key management system software.
Power supplies (PS1 - PS0 top to bottom) (AC supplies shown)
Power supply status LEDs:
OK (output): (green)
Service Action Required: (amber)
AC or DC (input power): (green).
Alarm port
Expansion slot 0 (PCIe 2.0 x8 or XAUI)
Expansion slot 3 (PCIe 2.0 x8)
Expansion slot 1 (PCIe 2.0 x8 or XAUI)
Expansion slot 4 (PCIe 2.0 x8)
Expansion slot 2 (PCIe 2.0 x8)
Service LEDs:
Locator LED/Locator button (white)
Service Action Required LED (amber)
Main Power/OK LED (green).
SER MGT RJ-45 serial port
NET MGT RJ-45 network port
Network 10/100/1000 ports (NET0 to NET3) for host
Physical Presence button access hole
USB 2.0 ports (USB 0, USB 1)
Video connector (HD-15)
Grounding studs
Locator LED/Locator button: white
Service Action Required LED: amber
Main Power/OK LED: green
Power button
Alarm LEDs: Critical (red), Major (red), Minor (amber), and User (amber)
Fan Fault (FM 0 to FM4) LEDs: green (normal), amber (fault)
USB 2.0 port (USB 3, USB 4)
USB 2.0 port (USB 3, USB 4)
DVD drive
Radio Frequency Identification (RFID) tag
Fan modules (FM0 - FM4)
Hard drives (HDD0- HDD3)
Hard drive fan module (FM 5) (internal - not shown)
High-level Description:
A single SL8500 library can store up to:
1,448 to 10,000 tape cartridges
64 tape drives.
An SL8500 Library Complex of 10 libraries can store:
Up to 100,000 tape cartridges
Up to 640 tape drives.
Operating System Support:
The SL8500 supports all major operating systems: enterprise and open systems.
Host-to-Library Interface:
Single Ethernet* (TCP/IP) 1x
Dual TCP/IP* (optional feature) 2x
Multi-host (optional feature) 4x
This library supports Partitioning with up to 4 partitions using the rail boundaries.
Table 4-2 SL8500 Ordering Information
Order Number | Description |
---|---|
CRYPTO-2X-SL8500-N |
Sun StorageTek crypto kit for use with SL8500 libraries. A 24-port ethernet switch, cables, and rack mount HW for installation within SL8500 library |
XSL8500-ETHRNT-Z |
PUE Ethernet card/switch (PN: 419951602) |
Table 4-3 SL8500 Firmware Levels
Library |
|
StreamLine Library Console |
FRS_4.00 |
Tape Drives:
|
|
Virtual Operator Panel (VOP) |
Version 1.0.14 or higher to support LTO4 Version 1.0.16 (current) |
High-level Description:
The SL3000 library offers customers the benefits of:
Scalability in storage capacity from 200 to 5800 slots
Performance from 1 to 56 tape drives
Heterogeneous attachments using standard interfaces (Ethernet and Fibre Channel)
Multiple library management software options
Operating System Support:
The SL3000 supports all major operating systems: enterprise and open systems.
Host-to-Library Interface:
Single EthernetFoot 1 (TCP/IP) 1x
Dual TCP/IPFootref 1 (optional feature) 2x
Fibre Channel (dual port optional feature) 2x
Table 4-4 SL3000 Ordering Information
Order Number | Description |
---|---|
|
The SL3000 uses four different part numbers for Ethernet switches and cables to 1 to 56 tape drives. Note: The SL3000 has limited internal rack space. Depending on the number of drives, customers may need to order an external rack. |
Table 4-5 SL3000 Firmware Levels
Library |
|
StreamLine Library Console |
FRS_4.0 |
Tape Drives:
|
|
Virtual Operator Panel (VOP) |
Version 1.0.14 or higher Version 1.0.16 |
High-level Description:
The SL500 library is a self contained, fully automated, cartridge tape storage system that is scalable and mounts into a standard 483 mm (19 in.) rack or cabinet. The library can consist of 1 to 5 modules (one base and up to four expansion modules). Because of the scalability, the capacity of an SL500 library can store:
From 2 tape drives with 530 data cartridge slots to 18 tape drives with 395 data cartridge slots
A cartridge access port that holds 5 to 45 slots (depending on the number of modules)
with a variety of tape drives and cartridges slots in-between.
Operating System Support:
The SL500 supports all major operating systems; enterprise and open systems.
Host-to-Library Interface:
Single EthernetFoot 2 (TCP/IP) 1x
Fibre Channel
Note: Encryption hardware can be installed in the same rack as the library, depending on the number of modules installed. |
Table 4-6 SL500 Ordering Information
Order Number | Description |
---|---|
CRYPTO-2X-SL500B-N |
Base module (required) Crypto kit for use with SL500 library base. Ethernet switch and cables for installation within SL500 library. In addition, one expansion module kit CRYPTO-2X-SL500X-N for each Drive Expansion Module is required. |
CRYPTO-2X-SL500X-N |
Expansion module (optional) crypto kit for use with SL500 library expansion. Ethernet cables for installation within SL500 library Up to 4 additional expansion modules may be added. Note: The SL500 is a rack-installed library. With 3 or fewer expansion modules, encryption hardware can be installed in the same rack. |
Table 4-7 SL500 Firmware Levels
Library |
i15 — 1300, i16 — 1373, i17 — 139x, i18 — 1407 |
Tape Drives:
|
|
Virtual Operator Panel (VOP) |
Version 1.0.14 or higher for LTO4 Version 1.0.16 |
Base module (Module 1)
Expansion module
Left cartridge magazine
Right cartridge magazine
Front control panel
Mailslot.
Note: Encryption hardware can be installed in the same rack as the library; depending on the number of modules installed. |
High-level Description:
The SL150 Modular Tape Library System is a 3U (5.25 inches) to 21U (36.75 inches) rack-mounted, modular automated tape library. It offers storage capacity of 30 to 300 Linear Tape Open (LTO) cartridges, from 1 to 20 half-height LTO5 Fibre Channel (FC) or Serial Attached SCSI (SAS) tape drives, and a bridged drive FC or SAS control path. The robot control is a SCSI Medium Changer device that appears as LUN 1 on a tape drive.
The minimum configuration consists of a 3U (5.25 inches) base module, designated Module 1, containing: the front control panel, one robotic hand, a mailslot with four slots, a power supply, and one tape drive (with options to add a second drive tray, a second power supply, or both). It stores up to 30 tapes in two, removable 15-slot magazines (one on the left side and the other on the right side). You can designate up to three reserved slots in the base module left magazine for storing cleaning or diagnostic tapes.
Operating System Support:
The SL150 supports all major operating systems; enterprise and open systems.
Host-to-Library Interface:
Single EthernetFoot 3 (TCP/IP) 1x
Fibre Channel, SAS
Table 4-8 SL150 Ordering Information
Order Number | Description |
---|---|
CRYPTO-2X-SL500B-N |
Base module (required) Crypto kit for use with SL150 library base. Ethernet switch and cables for installation within SL150 library. |
CABLE10187033-Z-N |
Ethernet cable (8-foot CAT5e) for each drive in the expansion module. |
High-level Description:
The 9310, also called PowderHorn, can store:
From 2,000 up to 6,000 tape cartridges
Up to 4 drive cabinets with space for up to 20 drives per cabinet (80 drives total)
Operating System Support:
The 9310 library supports all major operating systems; enterprise and open systems.
Host-to-Library Interface:
TCP/IP
The 9310 requires additional hardware consisting of Ethernet switches and 19-inch rack.
Table 4-10 9310 Ordering Information
Order Number | Description |
---|---|
CRYPTO-2X-9310-Z-N |
Sun StorageTek crypto kit for use with 9310 libraries. A 24-port ethernet switch and cables for installation in 9310 plus 16-port ethernet switch and cables for connection to KMA externally. Rack mounting HW. |
CRYPTO-2X-9741E-N |
Sun StorageTek crypto kit for use with 9310 libraries. A 24-port ethernet switch, cables, and rack mount HW for installation within 9741E cabinet. One required for each additional 9741E cabinet used for crypto. RoHS 5 compliant. Note: Each 9741E cabinet may contain up to 20 tape drives and requires the use of a 24-port Ethernet switch. |
Table 4-11 9310 Firmware Levels
Library Prerequisites |
The 9310 requires upgrades to support the T10000 tape drive. |
Feature Codes: |
93T1—LSM upgrade (firmware and hardware) 93T1—LMU upgrade (firmware only) XT10—Hardware kit upgrade (9741E cabinet) |
Library Firmware (minimum) |
9311: 4.4.06 9330: TCP/IP - 2.1.02 code 9330: 3270 - 1.9.73 code |
Tape Drives:
|
|
Virtual Operator Panel (VOP) |
Version 1.0.11 or higher Version 1.0.16 |
High-level Description:
L700 and L1400 libraries support two models:
Single frame libraries can hold:
From 678 tape cartridges and
Up to 12 tape drives.
Dual frame libraries holds
From 1,344 tape cartridges and
Up to 24 tape drives.
Operating System Support:
Supports open system platforms, such as UNIX, Windows NT, Novel, and Linux.
Host-to-Library Interface:
LVD or HVD SCSI
Fibre Channel option
The L700e/L1400M libraries have internal rack space for the encryption hardware.
Note: The SL24 and SL48 libraries do not support T-Series tape drives for the Oracle Key Manager encryption solution. |
Native capacity of 36 TB with StorageTek LTO5 tape drives.
Native capacity of 72 TB with a StorageTek LTO5 tape drives.
High-level Description:
Oracle's StorageTek SL24 tape autoloader provides high-capacity automated backup and recovery in a space-efficient, highly manageable product.
With one drive this autoloader includes two removable 12-slot magazines with one mail slot dedicated to import and export of data cartridges.
Oracle's StorageTek SL48 tape library can meet the data storage demands—including unattended backup, archiving, and disaster recovery.
The SL48 tape library is a 4-U form factor product. With one drive, this library includes four removable 12-slot magazines with three mail slots dedicated to the import and export of data cartridges.
Operating System Support:
Supports a broad variety of servers, operating systems, and ISV packages.
Host-to-Library Interface:
Both products provide SCSI, SAS, and FC interfaces for flexible integration into any storage environment.
The StorageTek rack can hold up to 12 manual-mount tape drives in 6 trays.
This figure shows the T10000 rack module.
The top (A) operator panel works with the drive on the left.
The bottom (B) operator panel works with the drive on the right.
When only one drive is installed, it must be installed on the left.
Recommendation:
The customer should purchase a Sun Rack II cabinet with this configuration.
See the specific library Systems Assurance Guides for information.
Table 4-19 Library Ordering Instructions
Publication Description | Part Number | |
---|---|---|
SL8500 Modular Library Systems Assurance Guide |
E24254-06 |
|
SL3000 Modular Library Systems Assurance Guide |
E20876-05 |
|
SL500 Modular Library Systems Assurance Guide |
E21060-05 |
|
L700/1400 Library Ordering and Configuration Guide |
MT9112N |
|
L180 Library Ordering and Configuration Guide |
MT9112N |
|
9310 PowderHorn Library Systems Assurance Guide |
ML6500R |
For more information and additional part numbers, go to:
http://scss280r1.singapore.sun.com/handbook_internal/Devices/AC_Power/ACPOWER_AC_Power_Cords.html
ATO Power Cord | PTO Equivalent | Description | Amps | Voltage | Cable |
333A-25-10-AR | X312F-N | Pwrcord, Argentina,2.5m, IRAM2073,10A,C13 | 10 | 250 | 180-1999-02 |
333A-25-10-AU | X386L-N | Pwrcord, Australian,2.5m, SA3112,10A,C13 | 10 | 250 | 180-1998-02 |
333A-25-10-BR | X333A-25-10-BR-N | Pwrcord, Brazil,2.5m,NBR14136,10A,C13 | 10 | 250 | 180-2296-01 |
333A-25-10-CH | X314L-N | Pwrcord, Swiss,2.5m,SEV1011, 10A,C13 | 10 | 250 | 180-1994-02 |
333A-25-10-CN | X328L | Pwrcord, China,2.5m,GB2099, 10A,C13 | 10 | 250 | 180-1982-02 |
333A-25-10-DK | X383L-N | Pwrcord, Denmark,2.5m, DEMKO107,10A,C13 | 10 | 250 | 180-1995-02 |
333A-25-10-EURO | X312L-N | Pwrcord, Euro,2.5m,CEE7/VII, 10A,C13 | 10 | 250 | 180-1993-02 |
333A-25-10-IL | X333A-25-10-IL-N | Pwrcord, Israel,2.5m,SI-32, 10A,C13 | 10 | 250 | 180-2130-02 |
333A-25-10-IN | X333A-25-10-IN-N | Pwrcord, India,2.5m,IS1293,10A,C13 | 10 | 250 | 180-2449-01 |
333A-25-10-IT | X384L-N | Pwrcord, Italian,2.5m,CEI23, 10A,C13 | 10 | 250 | 180-1996-02 |
333A-25-10-KR | X312G-N | Pwrcord, Korea,2.5m,KSC8305, 10A,C13 | 10 | 250 | 180-1662-03 |
333A-25-10-TW | X332A-N | Pwrcord, Taiwan,2.5m, CNS10917,10A,C13 | 10 | 125 | 180-2121-02 |
333A-25-10-UK | X317L-N | Pwrcord, UK,2.5m,BS1363A, 10A,C13 | 10 | 250 | 180-1997-02 |
333A-25-10-ZA | X333A-25-10-ZA-N | Pwrcord, South Africa,2.5m,SANS164,10A,C13 | 10 | 250 | 180-2298-01 |
333A-25-15-JP | X333A-25-15-JP-N | Pwrcord, Japan,2.5m,PSE5-15, 15A,C13 | 15 | 125 | 180-2243-01 |
333A-25-15-NEMA | X311L | Pwrcord, N.A./Asia,2.5m, 5-15P,15A,C13 | 15 | 125 | 180-1097-02 |
333A-25-15-TW | X333A-25-15-TW-N | Pwrcord, Taiwan,2.5M, CNS10917,15A,C13 | 15 | 125 | 180-2333-01 |
333F-20-10-NEMA | X320A-N | Pwrcord, N.A./Asia,2.0m, 6-15P,10A,C13 | 10 | 250 | 180-2164-01 |
333F-25-15-JP | X333F-25-15-JP-N | Pwrcord, Japan,2.5m,PSE6-15, 15A,C13 | 15 | 250 | 180-2244-01 |
333J-40-15-NEMA | X336L | Pwrcord, N.A./Asia,4.0m, L6-20P,15A,C13 | 15 | 250 | 180-2070-01 |
333R-40-10-309 | X332T | Pwrcord, INTL,4.0m, IEC309-IP44,10A,C13 | 10 | 250 | 180-2071-01 |
For use in non Sun Racks | |||||
333V-20-15-C14 | X333V-20-15-C14-N | Pwrcord, Jmpr,Straight,2.0m,C14,15A,C13 | 15 | 250 | 180-2442-01 |
333V-30-15-C14 | X333V-30-15-C14-N | Pwrcord, Jmpr,Straight,3.0m,C14,15A,C13 | 15 | 250 | 180-2443-01 |
For use in Sun Rack (NGR) | |||||
333W-10-13-C14RA | X9237-1-A-N | Pwrcord, Jmpr,1.0m,C14RA,13A,C13 | 13 | 250 | 180-2082-01 |
333W-25-13-C14RA | X9238-1-A-N | Pwrcord, Jmpr,2.5m,C14RA,13A,C13 | 13 | 250 | 180-2085-01 |
For use in Sun Rack II (Redwood) | |||||
SR-JUMP-1MC13 | XSR-JUMP-1MC13-N | Pwrcord, Jmpr,SR2,1.0m,C14RA,13A,C13 | 13 | 250 | 180-2379-01 |
SR-JUMP-2MC13 | XSR-JUMP-2MC13-N | Pwrcord, Jmpr,SR2,2.0m,C14RA,13A,C13 | 13 | 250 | 180-2380-01 |
Table 4-20 ATO Bill of Materials Part Numbers and Descriptions
Order Number | Description |
---|---|
CRYPTO-2X-SL8500-N |
Sun StorageTek crypto kit for use with SL8500 libraries. A 24-port ethernet switch, cables, and rack mount HW for installation within SL8500 library |
CRYPTO-2X-9310-Z-N |
Sun StorageTek crypto kit for use with 9310 libraries. A 24-port ethernet switch and cables for installation in 9310 plus 16-port ethernet switch and cables for connection to KMA externally. Rack mounting HW |
CRYPTO-2X-9741E-N |
Sun StorageTek crypto kit for use with 9310 libraries. A 24-port ethernet switch, cables, and rack mount HW for installation within 9741E cabinet. One required for each additional 9741E cabinet used for crypto. RoHS 5 compliant. |
CRYPTO-2X-L7/14-N |
Sun StorageTek crypto kit for use with L180/700/1400 libraries. A 16-port ethernet switch, cables, and mounting HW for installation within L-series libraries. |
CRYPTO-2X-SL500X-N |
(expansion module) Sun StorageTek crypto kit for use with SL500 library expansion. Ethernet cables for installation within SL500 library |
CRYPTO-2X-SL500B-N |
(base module) Sun StorageTek crypto kit for use with SL500 library base. Ethernet switch and cables for installation within SL500 library. Note: An encryption capable SL500 requires one base library accessory kit CRYPTO-2X-SL500B-N. In addition, one expansion module accessory kit CRYPTO-2X-SL500X-N for each Drive Expansion Module is required. |
XSL3000-ETHRNT1-N |
StorageTek SL3000 X-Option, Ethernet Switch for Tape Drives, Includes cable harness for 8 drives, Supports 1st Drive Array in BM or DEM, Needed for SDP and Encryption, Includes Power Cable, Includes Ethernet Switch Harness |
XSL3000-ETHRNT2-N |
StorageTek SL3000 X-Option, 8 Drive Ethernet Cable Harness, Requires XSL3000-ETHRNT1-Z, Supports 2nd Drive Array in BM or DEM, Needed for SDP and Encryption, Includes Power Cable and Switch Harness B/C, |
XSL3000-ETHRNT3-N |
StorageTek SL3000 X-Option, Ethernet Switch for Tape Drives, Includes cable harness for 8 drives, Supports 3rd Drive Array in BM or DEM, Needed for SDP and Encryption, Includes Power Cable and Switch Harness A/C |
XSL3000-ETHRNT4-N |
StorageTek SL3000 X-Option, 8 Drive Ethernet Cable Harness, Requires XSL3000-ETHRNT4-Z, Supports 4th Drive Array in DEM, Needed for SDP and Encryption, Includes Power Cable, Includes Ethernet Switch Harness C/C. Note: SL3000 released it's own kits for encryption. There are 4 parts - I think the cabling is just different but not sure. How many and which depends on the number of encryption ready drives to be supported |
CRYPTO-2X-RACK-Z-N |
Sun StorageTek 16-port ethernet switches and rack mounting HW for use with the Oracle Key Manager in redundancy configuration (For rackmount tape) |
Additional switch option: |
|
CRYPTO-X-24PT-Z-N |
Sun StorageTek 24PT ethernet switch. No mounting HW or cables. |
Footnote Legend
Footnote 1: Supports partitioning.