Use the TBEMIGRT utility to copy keys from CKDS to the BES database for use at a disaster recovery site when the disaster recovery site does not have a cryptographic coprocessor. You can then use TBEMIGRT to clear the keys from the BES database.
To copy keys for disaster recovery
PARM='BES=BESn,FROMCKDS'
Indicates the subsystem of the BES database you are backing up.
This copies the keys stored in the CKDS to the specified BES database.
This makes a backup of the BES database that you can use at the disaster recovery site.
The primary and mirror databases at the disaster recovery site are restored with the most recent data.
CA Tape Encryption runs at the disaster recovery site in a normal manner.
The backup mirror database is updated with any new keys that may have been generated.
PARM='BES=BESn,TOCKDS,MOVE'
Indicates the subsystem of the BES database you backed up.
This moves the keys to the CKDS and removes them from the BES database.
Note: Generally, the keys are already in the CKDS, so the effect of this command is to delete the keys from the BES database. However, any new keys generated from an extended disaster recovery operation would be added to the CKDS, so do not skip this step.
| Copyright © 2011 CA. All rights reserved. | Tell Technical Publications how we can improve this information |