An update to the publication:
"Pervasive Encryption for Data Volumes"
is now available on
https://www.ibm.com/docs/en/linuxonibm/lxdc/lxdc_linuxonz.html
The main enhancements are the support for retrievable secrets on IBM Secure Execution for Linux guests, the ease of use of passphrases, and the improved handling of #EP11 extractable and #CCA exportable keys.
Pervasive Encryption for Data Volumes
This document describes an infrastructure for encrypting volumes using protected and secure keys for encrypting and decrypting data. This infrastructure for protected volume encryption provides end-to-end protection for data at-rest for Linux on IBM Z and IBM LinuxONE.



