NetBackup™ Web UI Cloud Administrator's Guide

Last Published:
Product(s): NetBackup & Alta Data Protection (9.0.0.1, 9.0)
  1. Introducing the NetBackup web user interface
    1.  
      About the NetBackup web UI
    2.  
      Terminology
    3.  
      Sign in to the NetBackup web UI
    4.  
      Sign out of the NetBackup web UI
  2. Monitoring and notifications
    1.  
      The NetBackup dashboard
    2.  
      Monitoring jobs
    3.  
      Filter jobs in the job list
  3. Managing and protecting cloud assets
    1.  
      About protecting cloud assets
    2.  
      Limitations and considerations
    3.  
      AWS and Azure government cloud support
    4. About protecting Microsoft Azure resources using resource groups
      1.  
        Before you begin
      2.  
        Limitations and considerations
      3. About resource group configurations and outcome
        1.  
          Examples of resource group configurations
      4.  
        Troubleshoot resource group permissions
    5.  
      CLOUD_AUTODISCOVERY_INTERVAL option for NetBackup servers
    6.  
      Configure snapshot replication
    7.  
      Protect applications in-cloud with application consistent snapshots
    8. Configure CloudPoint servers in NetBackup
      1.  
        Configure a third-party CA certificate
      2.  
        Add a CloudPoint server
      3. Add a cloud provider for a CloudPoint server
        1.  
          IAM Role for AWS Configuration
      4.  
        Associate media servers with a CloudPoint server
      5.  
        Discover assets on CloudPoint server
      6.  
        Edit a CloudPoint server
      7.  
        Enable or disable a CloudPoint server
  4. Recovering cloud assets
    1.  
      Recover a cloud asset to its original location
    2.  
      Recover a cloud asset to an alternate location
    3.  
      Perform rollback recovery of cloud assets
  5. Troubleshooting protection and recovery of cloud assets
    1.  
      Troubleshoot cloud workload protection issues
  6. Performing granular restore
    1.  
      About granular restore
    2.  
      Supported environment list
    3.  
      List of supported file systems
    4.  
      Before you begin
    5.  
      Limitations and considerations
    6.  
      Restoring files and folders cloud virtual machines
    7.  
      Restoring volumes on cloud virtual machines
    8.  
      Troubleshooting snapshot restore process for Microsoft Azure-specific cloud

Configure a third-party CA certificate

You can use a self-signed or a third-party certificate to validate your CloudPoint server.

Consider the following points:

  • For Windows, you can give a certificate as a file path or install the third party certificate in the Trusted Root Certificates authorities.

  • To switch from a self-signed certificate to a third-party certificate for an already added CloudPoint server, you can update the tpconfig command or edit the CloudPoint server API or from NetBackup WebUI.

To configure a third-party CA certificate

  1. Generate the third party certificate and private key for your CloudPoint server.
  2. Run the ./cloudpoint/scripts/cp_certificate_management.sh script to upload your certificate and keys to the CloudPoint server.
  3. In NetBackup, create a certificate file and append the certificate of root and all intermediate CAs in the pem file.
  4. In the bp.conf file, create the following entries:
    • ECA_TRUST_STORE_PATH = /certificate.pem

    • (Optional) VIRTUALIZATION_CRL_CHECK = CHAIN

    • (Optional) ECA_CRL_PATH = /crls

      Note:

      • The ECA_CRL_PATH option specifies the path to the directory where the Certificate Revocation Lists (CRL) of the external certificate authority (CA) are located. All files in ECA_CRL_PATH must be in pem format.

      • VIRTUALIZATION_CRL_CHECK option is only required if you want to check the revocation status of the certificate. By default, the VIRTUALIZATION_CRL_CHECK option is disabled.

      • You can disable, LEAF, or CHAIN the value of the VIRTUALIZATION_CRL_CHECK option. For LEAF, revocation status of the leaf certificate is validated against the CRL. For CHAIN, revocation status of all certificates from the certificate chain are validated against the CRL.

  5. Add the CloudPoint server to NetBackup or run the tpconfig command to update the certificate for a CloudPoint server already added to NetBackup.

    Note:

    Following should be the order in which the certificates are uploaded:

    • Leaf

    • Intermediate

    • Root

If the certificates are not uploaded in the correct order, the CloudPoint might not work.