Ransomware attackers specifically target and attempt to destroy backup systems to increase the probability of payment. Hardening your system is critical. Please ensure you have reviewed your platform security using the Security Hardening Checklist
Cohesity

COHESITY Documentation

Explore our documentation to get started, discover products & new features, access troubleshooting guides, register sources, platforms support.

Products
Data Security Alliance
Visit Cohesity.com
Demos
Support
Blogs
Developers
Partner Portals
Cohesity Community
© 2026 Cohesity, Inc. All Rights Reserved.
Terms of Use|
Privacy Policy|
Legal|
  1. Home
  2. Veritas NetBackup™ AdvancedDisk Storage Solutions Guide
  3. Configuring AdvancedDisk
  4. About key management for encryption of NetBackup AdvancedDisk storage
Veritas NetBackup™ AdvancedDisk Storage Solutions Guide

About key management for encryption of NetBackup AdvancedDisk storage

NetBackup uses the Key Management Service (KMS) to manage the keys for the data encryption for disk storage. KMS is a NetBackup master server-based symmetric key management service. The service runs on the NetBackup master server. An additional license is not required to use the KMS functionality.

NetBackup uses KMS to manage the encryption keys for AdvancedDisk storage.

See About data encryption for AdvancedDisk storage.

The following table describes the encryption keys that are required for the KMS database.

Table: Encryption keys required for the KMS database

Key

Description

Host Master Key

The Host Master Key protects the key database. The Host Master Key requires a pass phrase and an ID. KMS uses the pass phrase to generate the key.

Key Protection Key

A Key Protection Key protects individual records in the key database. The Key Protection Key requires a pass phrase and an ID. KMS uses the pass phrase to generate the key.

The following table describes the encryption keys that are required for each storage server and volume combination.

Table: Encryption keys required for each storage server and volume combination

Key

Description

A key group

A key group key protects the key group. Each storage server and volume combination requires a key group, and each key group key requires a pass phrase. The key group name must use the format for the storage type that is described as follows:

For AdvancedDisk storage, the format depends on the operating system type that hosts the storage, as follows:

  • UNIX storage: storage_server_name:volume_name

    The following items describe the requirements for the key group name components for AdvancedDisk storage on UNIX:

    • storage_server_name: You must use the same name that you use for the storage server. The name can be a fully-qualified domain name or a short name, but it must be the same as the storage server.

    • The colon (:) is required after the storage_server_name.

    • volume_name: Use the last directory name in the storage path for the volume_name. For example, use backups if the storage path is /mnt/disk/backups.

  • Windows storage: storage_server_name:

    The following items describe the requirements for the key group name components for AdvancedDisk storage on Windows:

    • storage_server_name: You must use the same name that you use for the storage server. The name can be a fully-qualified domain name or a short name, but it must be the same as the storage server.

    • The colon (:) is required after the storage_server_name.

A key record

Each key group that you create requires a key record. A key record stores the actual key that protects the data for the storage server and volume.

See Configuring key management for NetBackup AdvancedDisk storage encryption.

More information about KMS is available in the NetBackup Security and Encryption Guide:

http://www.veritas.com/docs/DOC5332

Feedback

Was this page helpful?
Previous

About data encryption for AdvancedDisk storage

Next

Configuring key management for NetBackup AdvancedDisk storage encryption

Feedback

Was this page helpful?