Enabling Veritas Data Deduplication encryption
Access Appliance supports Veritas Data Deduplication encryption for all backup and deduplication jobs. This section describes how to enable encryption for the backup jobs.
You can do it in two different ways.
Method 1:
Note:
In NetBackup long-term data retention (LTR) use case, the server side refers to Access Appliance and the client refers to the media server.
For details on the MSDP compression and encryption settings, see the MSDP compression and encryption settings matrix section in the Configuring deduplication chapter in the Veritas NetBackup Deduplication Guide on SORT.
For details on configuring encryption for MSDP backups, see the Configuring encryption for MSDP backups section in the Configuring deduplication chapter in the Veritas NetBackup Deduplication Guide on SORT.
Method 2:
You can also enable encryption in the contentrouter.cfg file. If encryption is enabled in the contentrouter.cfg file, then any data coming from any media server is encrypted.
If Veritas Data Deduplication is configured with WORM
Log on to the restricted shell and type setting encryption enable.
Restart Veritas Data Deduplication services through the restricted shell.
Disable the health monitor and restart MSDP.
If Veritas Data Deduplication is configured without WORM
Log on to the appliance console by connecting to the management IP and elevate to shell using support elevate.
Enable Encryption on the Veritas Access cluster.
Append the encrypt keyword in
contentrouter.cfgfile which is located in the first Veritas Data Deduplication file system. For example:/vx/D3_588101/dedupe/etc/puredisk/contentrouter.cfg.Before appending the encrypt keyword, it appears as ServerOptions=verify_so_references,fast. After appending the encrypt keyword, it appears as ServerOptions=verify_so_references,fast,encrypt.
Restart the Veritas Data Deduplication services from the Access CLISH.