Ransomware attackers specifically target and attempt to destroy backup systems to increase the probability of payment. Hardening your system is critical. Please ensure you have reviewed your platform security using the Security Hardening Checklist
Cohesity

COHESITY Documentation

Explore our documentation to get started, discover products & new features, access troubleshooting guides, register sources, platforms support.

Products
Data Security Alliance
Visit Cohesity.com
Demos
Support
Blogs
Developers
Partner Portals
Cohesity Community
© 2026 Cohesity, Inc. All Rights Reserved.
Terms of Use|
Privacy Policy|
Legal|
  1. Home
  2. Veritas NetBackup™ Administrator's Guide, Volume I
  3. Section V. Configuring backups
  4. Protecting the NetBackup catalog
  5. Disaster recovery packages
Veritas NetBackup™ Administrator's Guide, Volume I

Disaster recovery packages

For increased security, a disaster recovery package is created during each catalog backup. The disaster recovery package file has .drpkg extension.

The disaster recovery (DR) package stores the identity of the master server host. NetBackup requires this package to get the identity of the master server back after a disaster. Once you have recovered the host identity, you can perform the catalog recovery.

The disaster recovery package contains the following information:

  • NetBackup CA-signed certificates and private keys of the master server certificate and the NetBackup certificate authority (CA) certificate

  • Information about the hosts in the domain

  • Security settings

  • External CA-signed certificates

    External CA-signed certificates from Windows certificate store, if applicable

  • NetBackup configuration options that are specific to external CA-signed certificates

  • Key management service (KMS) configuration

    Note:

    By default, the KMS configuration is not backed up during catalog backup. Set the KMS_CONFIG_IN_CATALOG_BKUP configuration option to 1 to include the KMS configuration as part of the disaster recovery package during catalog backup.

Note:

You must set a passphrase for the disaster recovery package for the catalog backups to be successful.

See About catalog backups.

See About disaster recovery settings.

See Setting a passphrase to encrypt disaster recovery packages.

Feedback

Was this page helpful?
Previous

Disaster recovery emails and the disaster recovery files

Next

About disaster recovery settings

Feedback

Was this page helpful?