Step 4. Edit Encryption Settings
Veeam Data Cloud allows you to encrypt backed-up fields and files using data key that is enciphered with either a Veeam Data Cloud master key or an Amazon Web Services Key Management Service (AWS KMS) master key. By default, encryption is enabled for all object fields and file types with a Veeam Data Cloud master key.
At the Data Encryption step of the wizard, you can configure the following encryption settings:
- In the Encryption settings section, choose whether you want to encrypt specific object fields, file types or both. If you do not select any object fields or file types, this data will not be encrypted.
For an object field to be displayed in the list of available fields, both the object and the field must be added to the backup scope specified at the previous step. For a file type to be displayed in the list of available file types, it must be included in the list of backup files and attachments specified at at the previous step.
Important |
|
- In the Encryption key section, choose whether you want to encrypt backed-up data using an AWS master key or a master key generated by Veeam Data Cloud. If you want to use an AWS master key, you must also select the region to which the key belongs.
For an AWS master key to be displayed in the list of available keys, it must be added to the selected region in an AWS account as described in AWS Documentation, and this account must be connected to Veeam Data Cloud as described in section Configuring Encryption Settings. If you have not connected the AWS account beforehand, you can do it without closing the Add Backup Policy window. To do that, click Add AWS KMS Connection and follow the instructions provided in section Adding AWS KMS Connections.
You must not remove the AWS master key from the related AWS account. Otherwise, you will not be able to decrypt and restore backed-up data.