Forum Discussion

itcsge's avatar
itcsge
Level 3
11 years ago

KMS with tape (no OST) - best practice around offsite recovery

We are looking to implement KMS -  does anyone have experience with this and offsite recovery - specifically how to recovery the key database on the DR master server?
  • Mark_Solutions's avatar
    11 years ago

    Doing exactly this for a customer at the moment..

    Things to really help...

    1. Same version of NetBackup at both sites

    2. Same tape drive manufacturer and firmware release

    3. Same ENCR_ volume pool names

    Once all this is in place you use the nbkmsutil -recoverkey on the DR site to put the key in place on that system after which things should work

    We have an issue at the moment with our as we are importing tapes into another live system rather than a DR one and are getting status 19 on the phase 2 import (write protect error but actually indicates that it does not think the encryption key is correct)

    We have IBM drives on one site and HP on the other so wonder if that is part of the issue but we have a case open at the moment and i will update this for you when we have it solved in case it helps you in the future

    #EDIT#

    obviously you will need to know all of the key details for the DR site!

  • jim_dalton's avatar
    11 years ago

    Or you can copy out the key information using the  tools provided / follow the documented process.

    Mark_S says same drives at both sites: I dont agree: you need drives capable of supporting the standard. Ive got IBM at source and HP at target. It works. But on the flip side when it doesnt work you have an added complication, so if given a choice I would buy same.

    Just curious as to why you are importing tapes..that could be done on either the source or the DR no? It's not strictly DR, but your work practices may dictate such a move.

    Jim