Ransomware attackers specifically target and attempt to destroy backup systems to increase the probability of payment. Hardening your system is critical. Please ensure you have reviewed your platform security using the Security Hardening Checklist
Cohesity

COHESITY Documentation

Explore our documentation to get started, discover products & new features, access troubleshooting guides, register sources, platforms support.

Products
Data Security Alliance
Visit Cohesity.com
Demos
Support
Blogs
Developers
Partner Portals
Cohesity Community
© 2026 Cohesity, Inc. All Rights Reserved.
Terms of Use|
Privacy Policy|
Legal|
  1. Home
  2. NetBackup™ Security and Encryption Guide
  3. Section III. Encryption of data at rest
  4. NetBackup key management service
  5. Troubleshooting KMS
NetBackup™ Security and Encryption Guide

Troubleshooting KMS

Use the following procedure to initiate troubleshooting for KMS.

To initiate troubleshooting for KMS

  1. Determine what error code and description are encountered.
  2. Check to determine if KMS is running and that the following KMS data files exist:
    kms/db/KMS_DATA
    kms/key/KMS_HMKF
    kms/key/KMS_KPKF

    If the files do not exist, then KMS has not been configured, or the configuration has been removed. Find out what happened to the files if they do not exist. If KMS has not been configured, the nbkms service is not running. If KMS is not running or is not configured, it does not affect NetBackup operation. If you have previously used the ENCR_ prefix for a volume pool name, this name must be changed as ENCR_ now has special meaning to NetBackup.

  3. Get the KMS configuration information:

    Get a key group listing by running the command nbkmsutil - listkgs. Get a listing of all the keys for a key group by running the command nbkmsutil - listkeys - kgname key_group_name.

  4. Get operational log information such as KMS logs by way of VxUL OID 286 and BPTM logs.
  5. Evaluate the log information. The KMS errors are handed back to BPTM.
  6. Evaluate the KMS errors that are recorded in the KMS log.

Feedback

Was this page helpful?
Previous

Key creation options

Next

Solution for backups not encrypting

Feedback

Was this page helpful?