Disaster recovery when catalog backup is encrypted using an external KMS server
As part of a catalog backup, an email notification is sent that contains the disaster recovery (DR) package information. If the catalog backup image is encrypted, the email also contains KMS information. You need to configure the KMS servers that are listed in the email before the catalog restore.
To restore a catalog when the catalog backup is encrypted using an external KMS server
- Install NetBackup using the appropriate DR package.
- The disaster recovery email contains KMS-specific information as follows:
The primary server ms1.example.veritas.com is configured to use the following Key Management Servers.
KMS Server Name = kms1.example.veritas.com, KMS Server Type = KMIP
KMS Server Name = kms2.example.veritas.com, KMS Server Type = KMIP
KMS Server Name = ms1.example.veritas.com, KMS Server Type = NBKMS
Configure the KMS servers that are listed in the email.
- Perform catalog restore.
Refer to the NetBackup Troubleshooting Guide.