FAQ - Encryption in Commvault

FAQ - Encryption in Commvault

What is the Key Management System (KMS), who operates it, and where is it located?
Is a KMS server only possible per CommCell or also per tenant?
Is the encryption of keys with a passphrase considered equivalent to key management via KMS?
Where exactly is the encrypted DEK stored?
What is the function of the Master Key? How does the Passphrase Key Management work?
Can the master key on the CommServe side decrypt the DEK located there?
What "power" does a superuser have on a Commvault server in terms of encryption?
What is the Passkey for Restore?