Encrypting backups from the deduplication shell
To encrypt backups on a WORM storage server, you can configure MSDP encryption with or without the Key Management Service (KMS).
Use the following procedures to configure encryption for your backups from the deduplication shell.
To configure MSDP encryption with KMS
- Open an SSH session to the server as the msdpadm user.
- Run the following command:
setting encryption enable-kms kms_server=<server> key_group=<key group>
Where <server> is the host name of the external KMS server and <key group> is the KMS server key group name.
- To verify the KMS encryption status, run the setting encryption kms-status command.
To configure MSDP encryption without KMS
- Open an SSH session to the server as the msdpadm user.
- Run the following command:
setting encryption enable
- To verify the MSDP encryption status, run the setting encryption status command.