If you want to backup an the Policy Agent on an encrypted disk, you need to make sure the entire disk is backed up (for example, the entire VMDK file in a VMware vSphere environment). This ensures that the Entrust GUIDs representing the keys are also backed up so the data can be decrypted if it is restored from the backup. Once the backup is reauthorized with Cryptographic Security Platform Vault, Cryptographic Security Platform Vault can use the restored GUIDs to determine which keys apply to the restored data.

To create the backup, see your hypervisor documentation. Entrust does not provide any tools for backing up a VM.

Warning: Before you back up your VM, make sure you check the expiration date for the data encryption keys on the disk. If you restore a backup with expired keys and the expiration option is set to SHRED, Cryptographic Security Platform Vault will destroy the keys immediately and the data will be inaccessible. If you set the expiration option to NO USE, the keys can be reactivated after the back up is restored. For more information, see Encrypting a Disk Using the CLI.