Chapter 7 Encryption Key ManagementConfiguring Encryption Key Management on the LibraryScalar i500 User’s Guide 1873 SKM Only — FIPS (Federal Information Processing Standard) is aU.S. government standard relating to computer security andencryption. To enable FIPS mode on an SKM partition, select the FIPScheck box. To disable FIPS, clear the FIPS check box.See FIPS-Certified Encryption Solution on page 203 for moreinformation. FIPS mode is only available with SKM.4 Click Apply.5 Save the library configuration.Using EKM PathDiagnostics 7 The EKM Path Diagnostics consists of a series of short tests to validatewhether the key servers are running, connected, and able to serve keys asrequired.Run the Manual EKM Path Diagnostics any time you change the keyserver settings or library encryption settings. If you are running Q-EKM,you should also run the Manual EKM Path Diagnostics whenever youreplace a tape drive. It is recommended that you test each tape drive thatcommunicates with Q-EKM key servers.The diagnostics consists of the following tests:• Ping — Verifies the Ethernet communication link between the libraryand the key servers.• Drive (Q-EKM only) — Verifies the tape drive’s path in the library(communication from library to tape drive sled and from tape drivesled to tape drive). The tape drive must be unloaded, ready, andonline in order to run this test. If this test fails, the Path and Configtests are not performed.• Path — Verifies that EKM services are running on the key servers.• Config — Verifies that the key servers are capable of servingencryption keys.Note: For Q-EKM only: The tape drive used for the test must beunloaded, ready, and online in order to run any of the tests.Note: For Q-EKM only: This test cannot run if the Drive test fails.