cancel
Showing results for 
Search instead for 
Did you mean: 

Report Encryption Information

ShaMan
Level 2

Need to somehow report if an image and or media is encypted. According to a Symantec Tech support Engineer:

 The easiest and fastest way to verify that MSEO encryption is working is to review the MSEO logs and watch the CPU cycles during an encrypted backup.

The problem with this is that it doesn't prove that the data on the tape is encrypted.

A better test would be to make a backup copy of the encryption keys and then move them out from their directory on the disk, then run a restore of the encrypted data.
The restore attempt should fail after a short period of time.

This only shows that the restore job failed because it looked for an encryption key and there is no encryption key present.....it still does not conclusively prove that the data is physically encrypted on the tape.

The only way to do that would be to use a TAR program to try and read the data on the tape itself.

Because MSEO is a separate program install from NetBackup, NetBackup has no way to notify or confirm if MSEO encryption is being used. NetBackup is completely unaware of MSEOs presence. 

I would strongly encourage you to participate in the enhancement request process.

 

 

--Not being able to verify Encryption can be a very big security/insurance liability for our company.

1 REPLY 1

a_la_carte
Level 5

MSEO encryption reporting indeed sounds tiresome job.

However, if we have KMS set up with NetBackup and tape drives then it can be easily seen from the NetBackup console that images are indeed encrypted by going to NetBackup Management -> Tape reports -> Images on Tape -> Selecting a tape ID. It will show the encryption key tag which verifies that the tape and the images on it are encrypted.