Skip to main content
Question

Create new DDB every 30days

  • September 17, 2026
  • 4 replies
  • 28 views

Forum|alt.badge.img+1

Hello guys,

we have installed a new Commvault environment for a customer a few months ago. The customer now says he wants encryption enabled for all backups. I found the option “Create new DDB every 30 days” in the deduplication engine settings and was wondering if that can solve our problem.

In my understanding, this option will write every backup after 30days as new blocks which also should make them encrypted. So my question is:

can I just enable encryption on the DDB engines and check the “Create new DDB every 30days” box and keep everything else running? Will this solve our encryption problem?

 

Thanks in advance

4 replies

Forum|alt.badge.img+2
  • Apprentice
  • September 17, 2026

Hi, backup encryption is not related to deduplication in any way.

https://documentation.commvault.com/11.44/software/configuring_software_encryption_on_disk_storage.html. Go to this section and configure encryption.

Keys are rotated automatically, and there are some implications to consider in the Commvault environment's DR when using encryption.

 

I hope this clarifies things for you.


Forum|alt.badge.img+1
  • Author
  • Apprentice
  • September 17, 2026

Hi Mirko,

what about already written backups? Which will be retained until 10years. How can I encrypt them?


Forum|alt.badge.img+2
  • Apprentice
  • September 17, 2026

You must enable encryption at the library level; new data will then be encrypted.

For historical data, you will need to copy it from the current destination to a new one with encryption enabled because the data is only encrypted when written.

Good luck!


Scott Moseman
Vaulter
Forum|alt.badge.img+23


To avoid a full re-baseline all at once, you can probably use the above setting.

Set it for some arbitrary value -- e.g., 30 days -- and then turn it off after 30 days.

Thanks,
Scott