An external key server whose asymmetric keys can replace password-based keys for backup encryption. Setup is only in the desktop console, and the server itself rotates and manages keys.
Also called KMS.
Read more: Veeam Help Center
In the Ultra Transcenders books
Each book explains Key Management System in context, with comparison tables and the common traps.
Terms in this definition
- External
API Management virtual network mode in which the gateway stays public but can call private back ends inside the VNet.
- Index field attributes
Settings applied to each field in an Azure AI Search index:
searchablefor full text,retrievableto return it,filterablefor exact-match$filter,sortable,facetablefor counts, andkeyfor the unique document ID. - Encryption
Scrambling data so it cannot be read without the correct secret key, which is then used to turn it back again. Hashing, by contrast, cannot be reversed.
Related terms
- KMS
Legacy AKS plug-in using an Azure Key Vault key to encrypt Kubernetes Secrets at rest in etcd. On Kubernetes 1.33 onwards, Microsoft Learn points to the newer KMS data encryption experience instead.
- password loss protection
An Enterprise Manager capability that includes its own keyset when backups are encrypted, so the data can still be unlocked if the password is forgotten or the KMS cannot be reached. A paid licence is needed to use it.
- Standard key provider
Uses an outside KMIP key management server as the source of encryption keys for vCenter. Since vSphere 9.0, wrapped key mode is the default, so many keys sit under a single wrapping key held by the KMS (the Native Key Provider needs no KMS at all).
- vSphere Native Key Provider
Built into vCenter, this provider generates encryption keys itself, so no external KMS is needed; back it up before first use.