KMS install on 6.5.2?
I have installed KMS on a Solaris 8 Master/Media server, connected to an ADIC i2000 with LTO4 drives. I am running NBU 6.5.2 on the box. I have created followed the guide in the notes on "New data at rest key management" section. I have created my key group, key record (which is active). I cam list those out with the nbkmsutil command. I see nbkms running as a process. I created the volume pool and moved one tape into it (ENCR_test) and created a policy that uses that vol pool. So far so good.
When I run the policy, it runs and completes, but there is no indication that it has encrypted anything. I look at the image list reports and the encryption column still says 'no', regardless of what I do.
Any help here? Is the support line equipped yet to handle KMS questions?
Thanks.
Jeff Sundin
Comments
Can you see it if you run bpimmedia or bpmedialist from the comand line?
IE: bpmedialist -U -mlist -ev L74004
bpimmedia -U -mediaid L74004
Maybe it is encrypting. I see the following in the bpmedialist command.
<root@hioshspsbck01:/:16>$ bpmedialist -U -mlist -ev H03056
Server Host = hioshspsbck02
id rl images allocated last updated density kbytes restores
vimages expiration last read <------- STATUS ------->
--------------------------------------------------------------------------------
H03056 0 9 09/26/2008 16:24 09/26/2008 16:44 hcart 14502720 0
9 10/03/2008 16:44 N/A ENCRYPTION
<root@hioshspsbck01:/:!>$ bpimmedia -U -mediaid H03056
Backup-ID Policy Type RL Files C E T PC Expires
Copy Frag KB Type Density FNum Off Host DWO MPX Expires RL MediaID
------------------------------------------------------------------------------------------------
hioshspsbck01_122247 test_nbu_e FULL 0 12099 N N R 1 16:44 10/03/2008
1 1 2000000 RMed hcart 8 191158 hioshspsbc 601 N 16:44 10/03/2008 0 H03056
1 2 269632 RMed hcart 9 222410 hioshspsbc 601 H03056
hioshspsbck02_122247 test_nbu_e FULL 0 193059 N N R 1 16:24 10/03/2008
1 1 2000000 RMed hcart 1 2 hioshspsbc 300 N 16:24 10/03/2008 0 H03056
1 2 2000000 RMed hcart 2 31254 hioshspsbc 300 H03056
1 3 2000000 RMed hcart 3 62506 hioshspsbc 300 H03056
1 4 2000000 RMed hcart 4 93758 hioshspsbc 300 H03056
1 5 2000000 RMed hcart 5 125010 hioshspsbc 300 H03056
1 6 2000000 RMed hcart 6 156262 hioshspsbc 300 H03056
1 7 233088 RMed hcart 7 187514 hioshspsbc 300 H03056
<root@hioshspsbck01:/:!>$
While, a tape I know is not encrypted will show the following information, without an "ENCRYPTED" label.
<root@hioshspsbck01:/:!>$ bpmedialist -U -mlist -ev H03104
Server Host = hioshspsbck01
id rl images allocated last updated density kbytes restores
vimages expiration last read <------- STATUS ------->
--------------------------------------------------------------------------------
H03104 0 39 09/30/2008 07:17 09/30/2008 07:18 hcart 74225312 0
39 10/07/2008 07:18 N/A SUSPENDED
It's strange that it's not showing in the GUI report images on media or tape. They need better documentation if you ask me. I am also getting ready to use this.
If I read you correctly, where you're looking for "Encryption," you're seeing data referring to the NetBackup Client Encryption Option, which isn't what you're wanting info on.
According to our documentation*, you check for encrypted backups by running the "Images on Media" report and looking for something in the "Encryption Key Tag" column. Do you have that column in your GUI?
*Veritas NetBackup 6.5.2 Documentation Updates (pages 170-171):
http://support.veritas.com/docs/302438
DISCLAIMER: I know zero about KMS but I have (sometimes too much) faith in our documentation ;-)
I've just perform this problem to. I've update my administration console to 6.5.2 and the Encryption Key Tag is now avaiable from the report Images on Media
Would you like to reply?
Login or Register to post your comment.