Ransomware attackers specifically target and attempt to destroy backup systems to increase the probability of payment. Hardening your system is critical. Please ensure you have reviewed your platform security using the Security Hardening Checklist
Cohesity

COHESITY Documentation

Explore our documentation to get started, discover products & new features, access troubleshooting guides, register sources, platforms support.

Products
Data Security Alliance
Visit Cohesity.com
Demos
Support
Blogs
Developers
Partner Portals
Cohesity Community
© 2026 Cohesity, Inc. All Rights Reserved.
Terms of Use|
Privacy Policy|
Legal|
  1. Home
  2. NetBackup™ Security and Encryption Guide
  3. Section III. Encryption of data at rest
  4. External key management service
  5. Disaster recovery when catalog backup is encrypted using an external KMS server
NetBackup™ Security and Encryption Guide

Disaster recovery when catalog backup is encrypted using an external KMS server

As part of a catalog backup, an email notification is sent that contains the disaster recovery (DR) package information. If the catalog backup image is encrypted, the email also contains KMS information. You need to configure the KMS servers that are listed in the email before the catalog restore.

To restore a catalog when the catalog backup is encrypted using an external KMS server

  1. Install NetBackup using the appropriate DR package.
  2. The disaster recovery email contains KMS-specific information as follows:

    The master server ms1.example.veritas.com is configured to use the following Key Management Servers.

    KMS Server Name = kms1.example.veritas.com, KMS Server Type = KMIP

    KMS Server Name = kms2.example.veritas.com, KMS Server Type = KMIP

    KMS Server Name = ms1.example.veritas.com, KMS Server Type = NBKMS

    Configure the KMS servers that are listed in the email.

  3. Perform catalog restore.

    Refer to the NetBackup Troubleshooting Guide.

Feedback

Was this page helpful?
Previous

Key rotation

Next

Alerts for expiration of KMS credentials

Feedback

Was this page helpful?