NetBackup™ Troubleshooting Guide
- Introduction
- Troubleshooting procedures
- About troubleshooting procedures
- Troubleshooting NetBackup problems
- Troubleshooting installation problems
- Troubleshooting configuration problems
- Device configuration problem resolution
- Testing the primary server and clients
- Testing the media server and clients
- Resolving network communication problems with UNIX clients
- Resolving network communication problems with Windows clients
- Troubleshooting vnetd proxy connections
- vnetd proxy connection requirements
- Where to begin to troubleshoot vnetd proxy connections
- Verify that the vnetd process and proxies are active
- Verify that the host connections are proxied
- Test the vnetd proxy connections
- Examine the log files of the connecting and accepting processes
- Viewing the vnetd proxy log files
- Troubleshooting security certificate revocation
- Troubleshooting cloud provider's revoked SSL certificate issues
- Troubleshooting cloud provider's CRL download issues
- How a host's CRL affects certificate revocation troubleshooting
- NetBackup job fails because of revoked certificate or unavailability of CRLs
- NetBackup job fails because of apparent network error
- NetBackup job fails because of unavailable resource
- Primary server security certificate is revoked
- Determining a NetBackup host's certificate state
- Troubleshooting issues with external CA-signed certificate revocation
- About troubleshooting networks and host names
- Verifying host name and service entries in NetBackup
- Example of host name and service entries on UNIX primary server and client
- Example of host name and service entries on UNIX primary server and media server
- Example of host name and service entries on UNIX PC clients
- Example of host name and service entries on UNIX server that connects to multiple networks
- About the bpclntcmd utility
- Using the Host properties to access configuration settings
- Resolving full disk problems
- Frozen media troubleshooting considerations
- Troubleshooting problems with the NetBackup web services
- Troubleshooting problems with the NetBackup web server certificate
- Resolving PBX problems
- Troubleshooting problems with validation of the remote host
- Troubleshooting Auto Image Replication
- Troubleshooting network interface card performance
- About SERVER entries in the bp.conf file
- About unavailable storage unit problems
- Resolving a NetBackup Administration operations failure on Windows
- Resolving garbled text displayed in NetBackup Administration Console on a UNIX computer
- Troubleshooting error messages in the NetBackup web UI and the NetBackup Administration Console
- Extra disk space required for logs and temporary files for the NetBackup Administration Console
- Unable to logon to the NetBackup Administration Console after external CA configuration
- Troubleshooting file-based external certificate issues
- Troubleshooting issues with external certificate configuration
- Troubleshooting Windows certificate store issues
- Troubleshooting backup failures
- Troubleshooting backup failure issues with NAT clients or NAT servers
- Troubleshooting issues with the NetBackup Messaging Broker (or nbmqbroker) service
- Troubleshooting issues with email notifications for Windows systems
- Troubleshooting issues with KMS configuration
- Troubleshooting issues with initiating the NetBackup CA migration because of large key size
- Troubleshooting issues with the non-privileged user (service user) account
- Troubleshooting issues with group name format in the auth.conf file
- Troubleshooting the VxUpdate add package process
- Troubleshooting issues with FIPS mode
- Troubleshooting issues with malware scanning
- Troubleshooting issues with NetBackup jobs that are enabled for data-in-transit encryption
- Troubleshooting issues with Unstructured Data Instant Access
- Troubleshooting issues with multifactor authentication
- Troubleshooting issues with multi-person authorization
- Troubleshooting connections to the NetBackup Scale-Out Relational Database
- Troubleshooting issues with private key encryption
- Troubleshooting issues with the security configuration risk feature
- Troubleshooting issues with the risk engine-based anomaly detection options
- Using NetBackup utilities
- About NetBackup troubleshooting utilities
- About the analysis utilities for NetBackup debug logs
- About the Logging Assistant
- About network troubleshooting utilities
- About the NetBackup support utility (nbsu)
- About the NetBackup consistency check utility (NBCC)
- About the NetBackup consistency check repair (NBCCR) utility
- About the nbcplogs utility
- About the robotic test utilities
- About the NetBackup Smart Diagnosis (nbsmartdiag) utility
- About log collection by job ID
- Disaster recovery
- About disaster recovery
- Recommended backup practices
- Requirements and notes for disaster recovery
- Disaster recovery packages
- About disaster recovery settings
- About disk recovery procedures for UNIX and Linux
- About clustered NetBackup server recovery for UNIX and Linux
- About disk recovery procedures for Windows
- About clustered NetBackup server recovery for Windows
- Generating a certificate on a clustered primary server after disaster recovery installation
- About the DR_PKG_MARKER_FILE environment variable
- Restoring the disaster recovery package on Windows
- Restoring the disaster recovery package on Linux
- Options to recover the NetBackup catalog
- Prerequisites for recovering the NetBackup catalog or NetBackup catalog image files
- About NetBackup catalog recovery on Windows computers
- About NetBackup catalog recovery from disk devices
- About NetBackup catalog recovery and symbolic links
- NetBackup disaster recovery email example
- About recovering the entire NetBackup catalog
- About recovering the NetBackup catalog image files
- About recovering the NetBackup databases
- Recovering the NetBackup catalog when NetBackup Access Control is configured
- Recovering the NetBackup catalog from a nonprimary copy of a catalog backup
- Recovering the NetBackup catalog without the disaster recovery file
- Recovering a NetBackup user-directed online catalog backup from the command line
- Restoring files from a NetBackup online catalog backup
- Unfreezing the NetBackup online catalog recovery media
- Steps to carry out when you see exit status 5988 during catalog recovery
Troubleshooting issues with private key encryption
This topic provides information on how to troubleshoot issues that are specific to private key encryption.
Passphrases are used to encrypt and decrypt the private keys of NetBackup host ID-based certificates. Passphrase keys are used to encrypt and decrypt these passphrases.
The private key of the NetBackup certificate is stored in an encrypted format using AES_256_CBC encryption. The password that is used to encrypt the private keys is stored in file storage and is encrypted using AES_256_GCM encryption.
Keystore location:
On Windows: Install path\NetBackup\var\vxss\credentials\keystore
Linux: /usr/openv/var/vxss/credentials/keystore
Keystore location for cluster:
/usr/openv/var/global/vxss/credentials/keystore
Nbcert logs:
On Windows: Install path\NetBackup\logs\nbcert
On Linux: /usr/openv/netbackup/logs/nbcert
Passphrase file path: keystorepath + .yekekp
Passphrase key file path: keystorepath + .yekcneekp
certmapinfo.json file path:
On Windows: Install path\NetBackup\var\vxss\certmapinfo.json
On Linux: /usr/openv/var/vxss/certmapinfo.json
Table:
Sr. No. | Issue | Possible reason | Resolution |
|---|---|---|---|
1 | Command: nbcertcmd -listcertdetails Output: Private Key Encryption State: Encrypted with an unknown passphrase | The private key file is tampered. |
|
2 | For the following problem scenarios, the reason and the resolution are the same: Command: nbcertcmd -listcertdetails Output: Private Key Encryption State: Encrypted with an unknown passphrase Command: nbcertcmd -rotatePassphrasekey The passphrase key rotation failed. EXIT STATUS 1200: Internal error | The passphrase file or the passphrase key file is tampered. |
|
3 | While you perform catalog restore after the fresh NetBackup installation, you can see both the newly-created private keys from the fresh installation and the restored ones. Command: ls -la total 20 drwx------ 2 nbsvcusr nbsvcusr 171 Jun 19 19:38 drwx------ 3 nbsvcusr nbsvcusr 133 Jun 19 19:25 .. -rw------- 1 nbsvcusr nbsvcusr 1858 Jun 19 19:38 015b91f5-74b5-44fb- 865f-6d65827cdb30-key.pem -rw------- 1 nbsvcusr nbsvcusr 1858 Jun 19 19:38 015b91f5-74b5-44fb-865f- 6d65827cdb3r-key.pem | Restoring the catalog reintegrates the existing private keys and passphrase files into the keystore. The keystore then includes both the newly-created private keys from the fresh installation and the restored ones. |
Location of the certmapinfo.json file on Unix: /usr/openv/var/vxss/certmapinfo.json |
4 | The following notification is seen on the NetBackup web UI: Reissuing the host certificates during private key encryption failed for the following hosts: host1 | Reissue of the certificate is attempted during the private key encryption operation. |
If all the keys are not encrypted, run one of the following commands for the private keys with state other than Encrypted:
|
5 | The attempt to rotate the passphrase failed, the private key files and the passphrase file could not be restored. Command: [root@example keystore] nbcertcmd -rotatepassphrase This operation performs the rotation of passphrase that encrypts the private key of the host ID-based certificates. It is strongly recommended that you stop the NetBackup services before you perform this operation. Ensure that you restart the services after the operation is performed. Are you sure you want to proceed with this operation? (y/n) y The passphrase rotation failed. EXIT STATUS 9141: Keystore is in inconsistent state. Command: ls -la total 20 drwx------ 2 nbsvcusr nbsvcusr 176 Jul 16 11:55 . drwx------ 3 nbsvcusr nbsvcusr 133 Jul 4 22:24 .. -rw------- 1 nbsvcusr nbsvcusr 1858 Jul 16 11:51 5176ec69-d3cb-44d7-a229- 799555b7bd7e-key.pem -rw------- 1 nbsvcusr nbsvcusr 1858 Jul 16 11:54 5176ec69-d3cb-44d7-a229- 799555b7bd7e-key.pem_bkup -rw------- 1 nbsvcusr nbsvcusr 1858 Jul 16 11:51 PrivKeyFile-2048.pem -rw-r--r-- 1 nbsvcusr nbsvcusr 1072 Jul 16 11:51 .yekcneekp -rw-r--r-- 1 nbsvcusr nbsvcusr 271 Jul 16 11:52 .yekekp | The restore operation failed because of the absence of backup files or an issue with the file rewrite process. |
|