Ransomware attackers specifically target and attempt to destroy backup systems to increase the probability of payment. Hardening your system is critical. Please ensure you have reviewed your platform security using the Security Hardening Checklist
Cohesity

COHESITY Documentation

Explore our documentation to get started, discover products & new features, access troubleshooting guides, register sources, platforms support.

Products
Data Security Alliance
Visit Cohesity.com
Demos
Support
Blogs
Developers
Partner Portals
Cohesity Community
© 2026 Cohesity, Inc. All Rights Reserved.
Terms of Use|
Privacy Policy|
Legal|
  1. Home
  2. NetBackup™ Security and Encryption Guide
  3. Section III. Encryption of data at rest
  4. NetBackup key management service
  5. Configuring KMS
  6. Configuring NetBackup to work with KMS
  7. NetBackup and key records from KMS
NetBackup™ Security and Encryption Guide

NetBackup and key records from KMS

The first step in configuring NetBackup to work with KMS is to set up a NetBackup-supported, encryption-capable tape drive and the required tape media.

The second step is to configure NetBackup as you would normally, except that the encryption-capable media must be placed in a volume pool with the identical name as the key group you created when you configured KMS.

Note:

For AdvancedDisk and tape storage, the Key Management feature requires the key group name and NetBackup volume pool name match identically and both be prefixed with ENCR_. For Cloud Storage and PureDisk key group name should be storage_server_name:volume_name. This method of configuration-enabled encryption support to be made available without requiring major changes to the NetBackup system management infrastructure.

Feedback

Was this page helpful?
Previous

Configuring NetBackup to work with KMS

Next

Example of setting up NetBackup to use tape encryption

Feedback

Was this page helpful?