IBM Support

Encrypting VMware VM backups

Question & Answer


Question

What steps are needed to encrypt VM backups using the Tivoli Storage Manager client?

Answer

Encrypting virtual machine (VM) backups using the Tivoli Storage Manager client encryption is only possible with FULL & INCR (-mode=full/incr). Encrypting the VM backups with the incremental forever methodology (-mode=IFFull/IFIncr) is not supported.

See APAR IC95972 for more information.

If incremental forever backups are being used, the backups can be sent encrypted,using VMware NBDSSL transport, to the Spectrum Protect server. This is done by setting the "VMVSTORTRANSPORT NBDSSL" in the client options file.

The Tivoli Data Protection for Virtual Environments Recovery Agent cannot be used for encrypted FULL/INCR backups.

As the data is encrypted, client or server side deduplication will have no benefit.

Steps to setup encrypted VM backups with FULL or INCR backups (-mode=full/incr):

The following items must be set in the dsm.opt file:

1 - encryptkey generate

2 - One of the following include.encrypt lines:


    "include.encrypt *\...\*"

    "include.encrypt *:|...\*"

    "include.encrypt *"


The -mode=full or -mode=incr must be included in the schedule options or backup command.

[{"Product":{"code":"SSGSG7","label":"Tivoli Storage Manager"},"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Component":"Client","Platform":[{"code":"PF016","label":"Linux"},{"code":"PF033","label":"Windows"}],"Version":"All Supported Versions","Edition":"","Line of Business":{"code":"LOB26","label":"Storage"}}]

Product Synonym

TSM

Document Information

Modified date:
17 June 2018

UID

swg21669218