Skip to main content
Question

S3 disk lib and encryption.

  • December 17, 2025
  • 0 replies
  • 17 views

Forum|alt.badge.img+10

I need to know whether we can connect an S3-compatible repository provided by the customer (“cloud storage”) to Commvault in order to store additional backups as an “off-site” copy. Technically, we know that the connection is possible in principle, but the issue of encryption arose during the project. 

Could Commvault encrypt this backup with a separate key that is only available to the customer? It is crucial for the customer that the data is protected by its own key and can only be managed by the customer, rather than being encrypted with the general Commvault key. Otherwise, in the worst case scenario, the customer would no longer be able to access the data and would not be able to decrypt it due to the lack of a key. The question is whether it is even possible to restore data on S3 storage that has been backed up with Commvault without running Commserve.

Scott Moseman
Vaulter
Forum|alt.badge.img+22

The data is stored in binary chunks on the media.  Encrypted or not, the data cannot be restored without going through the CommServe.

That said, we do support using third-party keys:

Third-Party Key Management
https://documentation.commvault.com/11.40/commcell-console/third_party_key_management.html

Thanks,
Scott