Ransomware attackers specifically target and attempt to destroy backup systems to increase the probability of payment. Hardening your system is critical. Please ensure you have reviewed your platform security using the Security Hardening Checklist
Cohesity

COHESITY Documentation

Explore our documentation to get started, discover products & new features, access troubleshooting guides, register sources, platforms support.

Products
Data Security Alliance
Visit Cohesity.com
Demos
Support
Blogs
Developers
Partner Portals
Cohesity Community
© 2026 Cohesity, Inc. All Rights Reserved.
Terms of Use|
Privacy Policy|
Legal|
  1. Home
  2. NetBackup™ Security and Encryption Guide
  3. Section III. Encryption of data at rest
  4. NetBackup key management service configuration
  5. Configuring KMS
  6. About backing up the KMS database files
NetBackup™ Security and Encryption Guide

About backing up the KMS database files

Backing up the KMS database involves backing up the KMS files.

The KMS utility has an option for quiescing the database files or temporarily preventing anyone from modifying the data files. It is important to run the quiesce option if you plan to copy the KMS_DATA, KMS_HMKF, and KMS_KPKF files to another location for backing up purposes.

During quiesce, NetBackup removes write access from these files; only read access is allowed.

When you run nbkmsutil -quiescedb, it returns with a quiesce successful statement and an indication of the number of outstanding calls. The outstanding calls number is more of a count. A count is placed on the file for the number of outstanding requests on this file.

After quiesce, you can then back up the files by copying them to another directory location.

After you have copied the files, you can unquiesce the KMS database files by using nbkmsutil -unquiescedb.

After the outstanding quiesce calls count goes to zero, the KMS can run the commands that can modify the KMS_DATA, KMS_HMKF, and KMS_KPKF files. Write access is once again returned to these files.

Feedback

Was this page helpful?
Previous

Terminated key record state

Next

About recovering KMS by restoring all data files

Feedback

Was this page helpful?