Configure an external certificate for the NetBackup web server
By default, NetBackup uses the security certificates that the NetBackup CA has issued. If you have a certificate that an external CA has issued, you can configure the NetBackup web server to use it for secure communication.
Note:
Windows certificate store is not supported as certificate source for the NetBackup web server.
The API that you can use to configure the external certificate for the NetBackup web server: POST security/web-certificates/{certificate_id}.
If external certificate for the web server is configured using the API, the configuration process is audited.
To configure an external certificate for the web server
- Ensure that you have valid certificate, private key of the certificate, and trusted CA bundle.
- Ensure that the NetBackup Web Management Console service is up and running.
- Run the following command:
configureWebServerCerts -addExternalCert -nbHost -certPath certificate path -privateKeyPath private key path -trustStorePath CA bundle path [-passphrasePath passphrase file path]
The configureWebServerCerts command does not support use of Windows certificate store paths.
Refer to the NetBackup Commands Reference Guide for more details on the command-line options.
In a clustered setup, to avoid a failover run the following command on the active node:
install_path/netbackup/bin/bpclusterutil -freeze
If the FIPS mode is enabled on the primary server, you can use only the PEM-formatted files for the configureWebServerCerts command.
- Restart the NetBackup Web Management Console service to reflect the changes.
On UNIX, run the following commands:
install_path/netbackup/bin/nbwmc -terminate
install_path/netbackup/bin/nbwmc start
On Windows, use the Services application in the Windows Control Panel.
Location of the commands:
Windows
install_path\NetBackup\wmc\bin\install\
UNIX
install_path/wmc/bin/install
In a clustered setup, unfreeze the cluster using the following command on the active node:
install_path/netbackup/bin/bpclusterutil -unfreeze
- Restart the NetBackup Messaging Queue Broker (nbmqbroker) service as follows:
On Windows:
Go to the Services application in the Windows Control Panel and manually restart the NetBackup Messaging Queue Broker service.
On UNIX:
Run the following command:
nbmqbroker stop; nbmqbroker start
- Verify that you can access the NetBackup web user interface using a browser, without a certificate warning message.