NetBackup™ Web UI Administrator's Guide
- Introducing NetBackup
- About NetBackup
- NetBackup documentation
- NetBackup web UI features
- NetBackup administration interfaces
- Terminology
- First-time sign in to the NetBackup web UI
- Sign in to the NetBackup web UI
- Sign out of the NetBackup web UI
- Documentation for Catalog Recovery Wizard, disk array hosts, disk pools, and Host Properties in the NetBackup web UI
- Section I. Monitoring and notifications
- Monitoring NetBackup activity
- The NetBackup dashboard
- Activity monitor
- Job monitoring
- Workloads that require a custom RBAC role for specific job permissions
- View a job
- View the jobs in the List view
- View the jobs in the Hierarchy view
- Jobs: cancel, suspend, restart, resume, delete
- Search for or filter jobs in the jobs list
- Create a jobs filter
- Edit, copy, or delete a jobs filter
- Import or export job filters
- Troubleshooting the viewing of jobs
- Notifications
- Monitoring NetBackup activity
- Section II. Configuring hosts
- Managing host properties
- Managing credentials for workloads and systems that NetBackup accesses
- Overview of credential management in NetBackup
- Add a credential in NetBackup
- Add a credential for an external KMS
- Add a credential for NetBackup Callhome Proxy
- Edit or delete a named credential
- Add a credential for CyberArk
- Configuring external credentials
- Add a configuration for an external CMS server
- Edit or delete the configuration for an external CMS server
- Add a credential for Network Data Management Protocol (NDMP)
- Edit or delete Network Data Management Protocol (NDMP) credentials in NetBackup
- Troubleshooting the external CMS server issue
- Managing deployment
- Section III. Configuring storage
- Section IV. Configuring backups
- Section V. Managing security
- Security events and audit logs
- Managing security certificates
- Managing host mappings
- Managing user sessions
- Managing the security settings for the primary server
- Certificate authority for secure communication
- Disable communication with NetBackup 8.0 and earlier hosts
- Disable automatic mapping of NetBackup host names
- Configure the global data-in-transit encryption setting
- About NetBackup certificate deployment security levels
- Select a security level for NetBackup certificate deployment
- About TLS session resumption
- Set a passphrase for disaster recovery
- About trusted primary servers
- Using access keys, API keys, and access codes
- Configuring authentication options
- Managing role-based access control
- RBAC features
- Authorized users
- Configuring RBAC
- Notes for using NetBackup RBAC
- Add AD or LDAP domains
- View users in RBAC
- Add a user to a role (non-SAML)
- Add a smart card user to a role (non-SAML, without AD/LDAP)
- Add a user to a role (SAML)
- Remove a user from a role
- Disable web UI access for operating system (OS) administrators
- Disable command-line (CLI) access for operating system (OS) administrators
- Default RBAC roles
- Add a custom RBAC role
- Role permissions
- Manage access permission
- View access definitions
- Section VI. Detection and reporting
- Section VII. NetBackup workloads and NetBackup Flex Scale
- Section VIII. Disaster recovery and troubleshooting
Certificate revocation lists for CyberArk server
Certificate revocation list (CRL) for an external certificate authority (CA) contains a list of digital certificates that the external CA has revoked before the scheduled expiration date and should no longer be trusted. NetBackup supports PEM and DER formats for CRLs for external CA. CRL's for all CRL issuers or external CA's are stored in the NetBackup CRL cache that resides on each host. During secure communication, NetBackup host verifies the revocation status of the peer host's external certificate with the CRL that is available in the NetBackup CRL cache, based on the CRL check level configuration option. For external CMS server, NetBackup supports CDP based server certificates.
NetBackup downloads the CRLs from the URLs that are specified in the peer host certificate's CDP and caches them in the NetBackup CRL cache.
To use CRL's from CDP:
Ensure that the host can access the URLs that are specified in the peer host's CDP.
Ensure that the configuration option is set to a value other than .
By default, CRLs are downloaded from the CDP after every 24 hours and updated in the CRL cache. To change the time interval, set the configuration option to a different value. To manually delete the CRL's from the CRL cache, run the nbcertcmd -cleanupCRLCache command. The NetBackup CRL cache contains only the latest copy of a CRL for each CA (including root and intermediate CAs). The bpclntcmd -crl_download service updates the CRL cache during host communication in the following scenarios irrespective of the time interval set for the options:
When CRLs in the CRL cache are expired.
If CRLs are available in the CRL source, but they are missing from the CRL cache.
For details of , refer to ECA_CRL_REFRESH_HOURS for NetBackup servers and clients section from Veritas NetBackup™ Security and Encryption Guide.
Note:
By default, the flag is enabled (set to true). If this flag is enabled, the certificate deployed on the external CMS server must have Common Name or Subject Alternative Name that matches the host name of the external CMS server. Else, the connection to the external CMS server fails. For more information, see the ECMS_HOSTS_SECURE_CONNECT_ENABLED section in NetBackup™ Administrator's Guide, Volume I.