Ransomware attackers specifically target and attempt to destroy backup systems to increase the probability of payment. Hardening your system is critical. Please ensure you have reviewed your platform security using the Security Hardening Checklist
Cohesity

COHESITY Documentation

Explore our documentation to get started, discover products & new features, access troubleshooting guides, register sources, platforms support.

Products
Data Security Alliance
Visit Cohesity.com
Demos
Support
Blogs
Developers
Partner Portals
Cohesity Community
© 2026 Cohesity, Inc. All Rights Reserved.
Terms of Use|
Privacy Policy|
Legal|
  1. Home
  2. NetBackup™ Security and Encryption Guide
  3. Section III. Encryption of data at rest
  4. Hardware Security Module (HSM) support in NetBackup
  5. Migrating from one HSM to another HSM
NetBackup™ Security and Encryption Guide

Migrating from one HSM to another HSM

If you want to migrate from one HSM to another, use the following procedure:

To migrate from one HSM to another

  1. Move to file store-based encryption by rotating passphrase key.

    See Moving back to file store-based encryption.

  2. Configure new HSM using the nbhsmcmd command.

    See Configuring Hardware Security Module on a NetBackup host .

  3. Encrypt private key of host ID certificate using new HSM.

    See Protecting host ID artefacts in NetBackup using HSM.

Feedback

Was this page helpful?
Previous

Moving back to file store-based encryption

Next

Ciphers used in NetBackup for secure communication

Feedback

Was this page helpful?