Ransomware attackers specifically target and attempt to destroy backup systems to increase the probability of payment. Hardening your system is critical. Please ensure you have reviewed your platform security using the Security Hardening Checklist
Cohesity

COHESITY Documentation

Explore our documentation to get started, discover products & new features, access troubleshooting guides, register sources, platforms support.

Products
Data Security Alliance
Visit Cohesity.com
Demos
Support
Blogs
Developers
Partner Portals
Cohesity Community
© 2026 Cohesity, Inc. All Rights Reserved.
Terms of Use|
Privacy Policy|
Legal|
  1. Home
  2. NetBackup™ Security and Encryption Guide
  3. Section III. Encryption of data at rest
  4. NetBackup key management service
  5. Command line interface (CLI) commands
  6. About exporting and importing keys from the KMS database
  7. Importing keys
NetBackup™ Security and Encryption Guide

Importing keys

The -import command helps to import keys and keys groups across domains. The following list contains important information about importing keys and key groups:

  • When importing keys and key groups, you must have the key container file that is created during the export operation. You also need the same pass phrase that is used during the export.

  • Importing keys is an atomic operation. It reverts backs all updates on encounter of any error during operation.

  • Partial import is not supported.

  • A preview of the import output is available. Run the -preview command to preview the results of the import.

  • The import operation can have two modes, one that includes the -preserve_kgname command and another that excludes the -preserve_kgname command.

    By default, the key groups are imported with following name format:

    < Original_Kgname_<timestamp> >

    You can opt to preserve the key group name by explicitly specifying the <-preserve_kgname> option.

  • Duplicate keys such as the keys with the same key tag or the same key are not imported.

  • The import does not support key group merging.

You can however merge the keys, import the key group without using the <-preserve_kgname> command. Run the nbkmsutil -modifykey -keyname <key_name> -kgname <key_group_name> command to move key from current group to the required group.

For more information about moving keys:

See Modify key attributes.

If the same key(s) or key(s) that have the same key tags exist in a key group, they are ignored during import. Run the following commands to import the keys and key groups:

# nbkmsutil -import -path <secure_key_container>

[-preserve_kgname]

[ -desc <description> ]

[ -preview ]

The -preserve_kgname command preserves the key group names during import.

The -desc <description> command is a description that is associated with the key groups during import.

The -preview command display a preview of the import results.

Run the import operation with the -preserve_kgname as follows:

nbkmsutil - import -path

<secure_key_container>

[-preserve_kgname]

When you run the -import command with the -preserve_kgname command, the import operation tries to import the original key groups names from the key container. If a key group with the same name exists, the import operation fails.

Run the import operation without the -preserve_kgname as follows:

nbkmsutil - import -path

<secure_key_container>

When you run the -import command without the -preserve_kgname it imports the key groups, but the key group names are renamed using a suffix, for example a timestamp. Each key group that is renamed always has a unique name.

Feedback

Was this page helpful?
Previous

Troubleshooting common errors during an export

Next

Troubleshooting common errors during an import

Feedback

Was this page helpful?