Support for cloud key management service (KMS)
Along with NetBackup KMS and external KMS, NetBackup now supports cloud KMS to manage data-at-rest encryption keys.
The following cloud providers are supported for cloud KMS configuration in NetBackup:
Amazon Web Services (AWS)
Google Cloud Platform (GCP)
Microsoft Azure
Backup images that are stored on MSDP storage servers can be encrypted using keys that are maintained in the respective cloud KMS server. NetBackup authenticates with the cloud KMS server using credentials that are configured in the NetBackup Credential Management System.
Optionally, you can configure an HTTP or HTTPS proxy server to communicate with cloud KMS. Proxy server credentials are managed through the NetBackup Credential Management System using the NetBackup web UI.
For more information, refer to the NetBackup Security and Encryption Guide.