Veritas-bu

Re: [Veritas-bu] KMS Key Rotation

2010-03-08 19:01:29
Subject: Re: [Veritas-bu] KMS Key Rotation
From: "Adams, Dwayne" <AdamsDC AT medsch.ucsf DOT edu>
To: veritas-bu AT mailman.eng.auburn DOT edu
Date: Mon, 8 Mar 2010 16:00:53 -0800

Hello,

 

I am working on setting up KMS.  If you are using KMS in your environment, do you rotate keys with your data sets? (Monthly, Yearly???) I have read that it is a “Best Practice” to rotate your keys as the data encrypted with that key expires.  Are people really doing this with KMS?  It is a tradeoff between security and restore complexity.  What are Netbackup Admins doing in the “Real World”?

 

Thanks

 

Dwayne Adams

_______________________________________________
Veritas-bu maillist  -  Veritas-bu AT mailman.eng.auburn DOT edu
http://mailman.eng.auburn.edu/mailman/listinfo/veritas-bu