Central configuration and the nsscmd command
NetBackup Self Service stores shared settings and secrets in the central configuration folder, {ProgramFolder}\Config\.
Table: Central configuration files
File | Purpose |
|---|---|
| Main and Adapter SQL connection strings; DapiConnectionString |
| DPAPI-protected secrets, including ApplicationKey and JWT key material |
| Development or plaintext only; not used in production installs |
Services load configuration from this folder at runtime. After Phase 2 migration, do not edit connection strings in individual service appsettings.json files.
After installation or upgrade, connection strings are no longer stored in the per-service appsettings.json files under Website, API, DirectaService, or WebService.
Run these commands from {ProgramFolder}\Install Files\.
Table: nsscmd configuration commands
Command | Use |
|---|---|
nsscmd -getconfig | Export configuration for backup, load balancing, or disaster recovery. |
nsscmd -readconfig -configDir "{ProgramFolder}\Config" | Read secrets, including the ApplicationKey, on this machine. |
nsscmd -setconfig "<string from getconfig>" | Apply configuration from another node for load balancing. |
nsscmd -initconfig -programFolder ... | Create central Config from |
nsscmd -migrateconfig -programFolder ... | Migrate the legacy layout during upgrade and preserve the ApplicationKey. |
nsscmd -validateconfig -configDir "{ProgramFolder}\Config" | Validate secrets and connection strings. |
nsscmd -showsecrets -configDir ... -name ApplicationKey | Verify that the key is present. Output is masked. |
Fresh install with a new database: The installer generates the ApplicationKey automatically.
Existing database: The ApplicationKey must match the database when UseExistingDatabase=1.
Upgrade: The ApplicationKey is preserved. You cannot change it with nsscmd -setsecret after initial configuration.
Disaster recovery:
UnInstall.batpreservesConfig\. Back up the configuration with nsscmd -getconfig after every production install and upgrade.Load-balanced servers: Do not copy
machine.secrets.encbetween servers because DPAPI is machine-specific. Use the same ApplicationKey hex value and run -initconfig or -setconfig on each node.
Edit {ProgramFolder}\Install Files\Install.ini only for non-GUI or automation scenarios. For details, see NetBackup™ Self Service Installation Guide..
For the option in the 11.2 Configurator, enter the ApplicationKey in the UI. Add or maintain an ApplicationKey= line only when you bypass the Configurator.
If machine.secrets.enc already exists and the supplied -applicationKey matches, the installer keeps the existing secrets. When -fromInstallIni is used, connectionStrings.json is refreshed from Install.ini.