Ransomware attackers specifically target and attempt to destroy backup systems to increase the probability of payment. Hardening your system is critical. Please ensure you have reviewed your platform security using the Security Hardening Checklist
Cohesity

COHESITY Documentation

Explore our documentation to get started, discover products & new features, access troubleshooting guides, register sources, platforms support.

Products
Data Security Alliance
Visit Cohesity.com
Demos
Support
Blogs
Developers
Partner Portals
Cohesity Community
© 2026 Cohesity, Inc. All Rights Reserved.
Terms of Use|
Privacy Policy|
Legal|
  1. Home
  2. NetBackup™ Marketplace Deployment on Azure Cloud
  3. Deploying NetBackup on Azure Cloud using the marketplace offer
  4. Additional steps on CRS if encryption is enabled NetBackup primary server
NetBackup™ Marketplace Deployment on Azure Cloud

Additional steps on CRS if encryption is enabled NetBackup primary server

Below are the additional steps to be done on Cloud Recovery Server, if the encryption is enabled on Netbackup primary server.

When KMS encryption is enabled, you can share the images in S3 bucket to the Cloud Recovery Server host with manual KMS key transfer.

On-premises KMS key changes:

In case of KMS key changes, for the given group for on-premises storage server after the Cloud Recovery Server host is set up, you must export the key file from on-premises KMS server and import that key file on the cloud recovery host.

On-premises NetBackup master server: Exports the key group with a passphrase to a file:

/usr/openv/netbackup/bin/admincmd/nbkmsutil -export -key_groups <key-group-name> -path <key file path>

Cloud Recovery Server host (cloud side):

  1. Copy the exported key to the Cloud Recovery Server host.

  2. Config KMS server:

    /usr/openv/netbackup/bin/nbkms -createemptydb /usr/openv/netbackup/bin/nbkms /usr/openv/netbackup/bin/nbkmscmd -discovernbkms -autodiscover

  3. Import keys to KMS service.

    /usr/openv/netbackup/bin/admincmd/nbkmsutil -import -path <key file path> -preserve_kgname

  4. Once this is done we need to restart the NetBackup.

    Refer below link for more details.

Feedback

Was this page helpful?
Previous

Malware Scan Host Details tab

Next

Accessing the NetBackup Web UI

Feedback

Was this page helpful?