Recovering a lost application key
Important: Always back up the application key before an upgrade or immediately after an installation. You cannot recover the application key from the database. NetBackup Self Service stores the key only in the Config folder in a DPAPI-protected file, which can be read only on the machine where it was created. To support disaster recovery and future installations, keep a secure backup copy of the application key.
The ApplicationKey encrypts third-party integration passwords in the database. If the key is lost, users might still be able to sign in, but encrypted adapter and integration passwords cannot be decrypted. You must re-enter those passwords in the NetBackup Self Service UI.
Primary location:
{ProgramFolder}\Config\machine.secrets.enc. This file is DPAPI-protected and can be read on the same machine by running the command nsscmd -readconfig.Backup reference: Save the output from nsscmd -getconfig after every installation or upgrade.
Database connection strings: The
connectionStrings.jsonfile in the sameConfigfolder contains database connection strings and is also required for disaster recovery.
Web server failure: Restore the web server or
{ProgramFolder}from backup. Alternatively, restore theConfigfolder from backup to a replacement server.Move to a new web server: Before uninstalling the old site, obtain the ApplicationKey from the old server or from the saved nsscmd -getconfig output. On the new server, install with UseExistingDatabase=1 and the same key.
Restore the web server,
{ProgramFolder}, or at minimum theConfigfolder from backup to the target server.Confirm the ApplicationKey on that server by running one of the following commands from
{ProgramFolder}\Install Files.nsscmd.exe -readconfig -programFolder "{ProgramFolder}"
nsscmd.exe -readconfig -configDir "{ProgramFolder}\Config"
Note:
The machine.secrets.enc file is DPAPI-protected. If you copy the Config folder to a different machine, DPAPI might prevent the new host from reading the secrets. In that case, use the saved nsscmd -getconfig output, or provide the known ApplicationKey by using -initconfig or -setconfig on the new server.
When you install NetBackup Self Service on a replacement web server, provide the existing ApplicationKey by using one of the following methods:
Configurator: Enter the application key in the workflow.
Install.ini: Set ApplicationKey=<hex key from nsscmd -getconfig on the source server>.
Install.ini file reference: Set ApplicationKeyFile=C:\secure\nss-getconfig.txt.
Legacy program folder: Set LegacyProgramFolder=C:\path\to\copied\old ProgramFolder. The copied folder must contain a readable
Config\machine.secrets.encfile from the source installation.
Before the installation continues, the installer verifies the ApplicationKey against SYS_APP_KEY_CHECK.
Load-balanced nodes: Copy the configuration from the primary node by running nsscmd -getconfig on the source server and nsscmd -setconfig on each additional node. For more information, see Appendix D.
The ApplicationKey cannot be recovered from the SQL database alone. Encrypted passwords stored in the database, such as integration settings and adapter credentials, cannot be decrypted. After you restore database connectivity and establish a new or known ApplicationKey, re-enter those values in the NetBackup Self Service administration UI.
Note:
Important: You cannot change the ApplicationKey by using nsscmd -setsecret. Do not attempt to rotate the key after initial configuration because doing so breaks access to existing encrypted data.
Run the following commands from {ProgramFolder}\Install Files.
If the
Configfolder does not contain secrets:nsscmd.exe -initconfig -programFolder "{ProgramFolder}" -applicationKey "{known-hex-key}"
If
connectionStrings.jsonexists and you have a full saved getconfig string:nsscmd.exe -setconfig "ApplicationKey=...;MainDBServer=...;..."
Validate the configuration:
nsscmd.exe -validateconfig -configDir "{ProgramFolder}\Config"
As part of the standard NetBackup Self Service backup process, back up the entire Config folder and the saved nsscmd -getconfig output.