About keystore backups
Whenever Trust Protection Foundation performs a certificate or private key operation, it creates a backup copy of the crypto file in the same directory where the original keystore resides.
If a backup operation fails, Trust Protection Foundation logs an event and halts processing. For example, if a backup operation fails for the JKS driver, the JKS - Backup KeyStore Failed event (ID 400E0020) is logged.
CAUTION If a CyberArk driver cannot back up a crypto file, it will not attempt any further certificate and private key operations.