Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Dell NetWorker 19.9 Administration Guide

Encryption disablement

A new attribute Encryption at rest is introduced in RAP resource NSR to enable or disable saveset encryption. This attribute is enabled by default. You can apply the build-in and custom encryption directive to the clients only if this attribute is enabled.

If Encryption at rest is disabled, the encryption directives are ignored, encryption does not happen, and relevant error messages get logged in the policy backup.

For example, if you use the policy Silver -> FileSystem to back up a folder on a Windows NetWorker server, a message Cannot encrypt <file in save set> because encryption at rest is disabled. is displayed in the file %NSR_HOME_DIR%\logs\policy\Silver\Filesystem\Backup_<jobid>_logs\<jobid>.log.

If you upgrade the NetWorker server to 19.7 version but do not upgrade the NetWorker clients, the server prevents you from applying the integrated encryption directive to the clients. However, if you create new encryption directives and apply one of them to the clients, or use an encryption directive from local directives in the clients, encryption happens.

To configure Encryption at rest:
  1. Go to NMC > NetWorker admin console > NetWorker server properties > Security tab.
  2. Enable or disable Encryption at Rest attribute by selecting or clearing the Encryption at Rest checkbox.

Best practices and recommendations for using Encryption disablement

  • To use the full capability of the encryption disablement, upgrade the NetWorker server and NetWorker client to version 19.7 or later.
  • For 19.7 NetWorker clients, custom created directives with encryption can be created and applied when Encryption at rest is disabled, but encryption will not happen and relevant error messages get logged in the policy backup.
  • For older NetWorker clients with NetWorker server 19.7 or later, the server will prevent or disable encryption only through Encryption directive.
  • Old encrypted saveset cannot be used for recovery, once encryption is disabled. This is because encryption key is cleared.
  • Enter the key when encryption is enabled again.

Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\