Important Update: Cohesity Products Documentation
All Cohesity product documentation are now managed via the Cohesity Docs Portal: https://docs.cohesity.com/HomePage/Content/home.htm. Some documentation available here may not reflect the latest information or may no longer be accessible.
NetBackup™ Troubleshooting Guide
- Introduction
- Troubleshooting procedures
- About troubleshooting procedures
- Troubleshooting NetBackup problems
- Troubleshooting installation problems
- Troubleshooting configuration problems
- Device configuration problem resolution
- Testing the primary server and clients
- Testing the media server and clients
- Resolving network communication problems with UNIX clients
- Resolving network communication problems with Windows clients
- Troubleshooting vnetd proxy connections
- vnetd proxy connection requirements
- Where to begin to troubleshoot vnetd proxy connections
- Verify that the vnetd process and proxies are active
- Verify that the host connections are proxied
- Test the vnetd proxy connections
- Examine the log files of the connecting and accepting processes
- Viewing the vnetd proxy log files
- Troubleshooting security certificate revocation
- Troubleshooting cloud provider's revoked SSL certificate issues
- Troubleshooting cloud provider's CRL download issues
- How a host's CRL affects certificate revocation troubleshooting
- NetBackup job fails because of revoked certificate or unavailability of CRLs
- NetBackup job fails because of apparent network error
- NetBackup job fails because of unavailable resource
- Primary server security certificate is revoked
- Determining a NetBackup host's certificate state
- Troubleshooting issues with external CA-signed certificate revocation
- About troubleshooting networks and host names
- Verifying host name and service entries in NetBackup
- Example of host name and service entries on UNIX primary server and client
- Example of host name and service entries on UNIX primary server and media server
- Example of host name and service entries on UNIX PC clients
- Example of host name and service entries on UNIX server that connects to multiple networks
- About the bpclntcmd utility
- Using the Host properties to access configuration settings
- Resolving full disk problems
- Frozen media troubleshooting considerations
- Troubleshooting problems with the NetBackup web services
- Troubleshooting problems with the NetBackup web server certificate
- Resolving PBX problems
- Troubleshooting problems with validation of the remote host
- Troubleshooting Auto Image Replication
- Troubleshooting network interface card performance
- About SERVER entries in the bp.conf file
- About unavailable storage unit problems
- Resolving a NetBackup Administration operations failure on Windows
- Resolving garbled text displayed in NetBackup Administration Console on a UNIX computer
- Troubleshooting error messages in the NetBackup web UI and the NetBackup Administration Console
- Extra disk space required for logs and temporary files for the NetBackup Administration Console
- Unable to logon to the NetBackup Administration Console after external CA configuration
- Troubleshooting file-based external certificate issues
- Troubleshooting issues with external certificate configuration
- Troubleshooting Windows certificate store issues
- Troubleshooting backup failures
- Troubleshooting backup failure issues with NAT clients or NAT servers
- Troubleshooting issues with the NetBackup Messaging Broker (or nbmqbroker) service
- Troubleshooting issues with email notifications for Windows systems
- Troubleshooting issues with KMS configuration
- Troubleshooting issues with initiating the NetBackup CA migration because of large key size
- Troubleshooting issues with the non-privileged user (service user) account
- Troubleshooting issues with group name format in the auth.conf file
- Troubleshooting the VxUpdate add package process
- Troubleshooting issues with FIPS mode
- Troubleshooting issues with malware scanning
- Troubleshooting issues with NetBackup jobs that are enabled for data-in-transit encryption
- Troubleshooting issues with Unstructured Data Instant Access
- Troubleshooting issues with multifactor authentication
- Troubleshooting issues with multi-person authorization
- Troubleshooting connections to the NetBackup Scale-Out Relational Database
- Troubleshooting issues with private key encryption
- Troubleshooting issues with the security configuration risk feature
- Troubleshooting issues with the risk engine-based anomaly detection options
- Troubleshooting NetBackup WebSocket server connection
- Problems validating the endpoint server in the WebSocket Server dialog
- Problems saving the NetBackup endpoint credentials in the WebSocket Server dialog
- Problems deleting the WebSocket server endpoint from NetBackup
- Problems displaying the list of WebSocket servers that were added in NetBackup
- Problems activating or deactivating the endpoint server
- Additional NBWSS issues
- Troubleshooting issues with the network access control feature
- Troubleshooting issues with freeze mode
- Troubleshooting issues with rotation of external CA-issued certificates
- Using NetBackup utilities
- About NetBackup troubleshooting utilities
- About the analysis utilities for NetBackup debug logs
- About the Log collection utility
- About network troubleshooting utilities
- About the NetBackup support utility (nbsu)
- About the NetBackup consistency check utility (NBCC)
- About the NetBackup consistency check repair (NBCCR) utility
- About the nbcplogs utility
- About the robotic test utilities
- About the NetBackup Smart Diagnosis (nbsmartdiag) utility
- About log collection by job ID
- Disaster recovery
- About disaster recovery
- Recommended backup practices
- Requirements and notes for disaster recovery
- Disaster recovery packages
- About disaster recovery settings
- About disk recovery procedures for UNIX and Linux
- About clustered NetBackup server recovery for UNIX and Linux
- About disk recovery procedures for Windows
- About clustered NetBackup server recovery for Windows
- Generating a certificate on a clustered primary server after disaster recovery installation
- About the DR_PKG_MARKER_FILE environment variable
- Restoring the disaster recovery package on Windows
- Restoring the disaster recovery package on Linux
- Options to recover the NetBackup catalog
- Prerequisites for recovering the NetBackup catalog or NetBackup catalog image files
- About NetBackup catalog recovery on Windows computers
- About NetBackup catalog recovery from disk devices
- About NetBackup catalog recovery and symbolic links
- NetBackup disaster recovery email example
- About recovering the entire NetBackup catalog
- About recovering the NetBackup catalog image files
- About recovering the NetBackup databases
- Recovering the NetBackup catalog when NetBackup Access Control is configured
- Recovering the NetBackup catalog from a nonprimary copy of a catalog backup
- Recovering the NetBackup catalog without the disaster recovery file
- Recovering a NetBackup user-directed online catalog backup from the command line
- Restoring files from a NetBackup online catalog backup
- Unfreezing the NetBackup online catalog recovery media
- Steps to carry out when you see exit status 5988 during catalog recovery
Troubleshooting issues with rotation of external CA-issued certificates
This topic provides troubleshooting information about the issues that are specific to rotation of external CA-issued certificates.
For more information on freeze mode, see the NetBackup Security and Encryption Guide.
Table:
Sr. No. | Issue | Possible reason | Resolution |
|---|---|---|---|
1 | Exception with message: "Cannot connect nbsl" Web service logs show the following log statement: Cannot retrieve hostName from system property | NetBackup Service Layer service might not be running. CLIENT_NAME or SERVER in bp.conf is not correct for the given primary server. | Check if the NetBackup Service Layer (NBSL) service is up and running. Later, increase verbosity, and retry the operations. Contact Cohesity technical support if the issue still persists. |
2 | Exception with error code 8752: "The requested operation is not supported for the NetBackup version of the remote host." Web service logs show the following log statement: ECA automatic host cert rotation is not allowed on FLEX-SCALE | The host for which certificates are being uploaded is Flex Scale deployment. The API is not supported for Flex Scale deployment. | Use the Flex Scale-specific methods to configure external CA-issued certificates. |
Web service logs show the following log statement: ECA automatic host cert rotation is not allowed on Cloudscale. | The host for which certificates are being uploaded is a Cloud Scale deployment. | External CA-issued certificates are not supported for host communication on Cloud Scale deployment, therefore the rotation of ECA certificates cannot be configured on a Cloud Scale setup. | |
3 | Exception with message: Invalid operation in the API request body. The operation is not supported or disabled. Web service logs show the following log statement: isValidNBUVersion : 0 | The host for which certificates are being uploaded is earlier than NetBackup 11.0 This API is not supported for earlier versions. | Renew the certificates manually for hosts earlier than 11.0. |
4 | Uploading ECA artifacts take 15-20 seconds and fails for NetBackup servers. Web service logs show the following log statement: Received exception while getting Container deployment type | If services of the host are down (or the bprd service is not running), only PEM files can be uploaded. For example: In case of clustered primary server, on an inactive node, the bprd process is not running. Therefore, only PEM files can be uploaded. In a case where non-PEM files are uploaded, NetBackup needs to connect to the host to check if the files are supported or not. This is valid for NetBackup servers only. | Start all the NetBackup services on the host and retry the upload operation. Ensure that the bprd service is also running. Else use PEM files as they are supported across all the types of deployments. |
5 | Renewal failed with error: Failed to retrieve external certificate artifacts from credential management system. Web service logs show the following log statement: Failed to fetch eca artifacts CMS credentials | Credentials management or database service may not be running. | Ensure that the credentials management and database services are up and running. Later, increase the verbosity. Contact Cohesity technical support if the issue still persists. |
6 | Renewal failed with error: Failed to process the data of external certificate artifacts during download. Web service logs show the following log statement: Failed to decode eca artifacts CMS credentials | Primary server has not sent base64 encoded data to the respective host. | Check if the NetBackup Service Layer (NBSL) service is up and running. Later, increase the verbosity. Contact Cohesity technical support if the issue still persists. |
7 | Renewal failed with error: Failed to save external certificate artifacts to the NetBackup temporary location. Web service logs show the following log statement: Writing ECA host artifacts operation failed | Unable to write uploaded artifacts at the NetBackup temporary location: Install_PATH/tmp | Ensure that the NetBackup services have the write permissions on the NetBackup temporary location Install_PATH/tmp |
8 | Renewal failed with error: Failed to validate external certificate enrollment Web service logs show the following log statement: ECA host certificate enrollment dry run failed Check Web Service logs as well. | Dry run of uploaded artifacts failed. Possible reasons:
|
|
9 | Renewal failed with error: Failed to validate external certificate enrollment. Web service logs show the following log statement: Failed to perform enroll certificate, with error code : 44 | The size of the certificate chain is more than 40 KB around. | Ensure that the certificate chain is not too big in size and is less than 40 KB. |
10 | Renewal failed with error: Failed to save external certificate artifacts to the NetBackup default location. Web service logs show the following log statement: Updating ECA host artifacts at final location operation got failed | Unable to write uploaded artifacts at the NetBackup-managed ECA artifacts location: | Ensure that NetBackup services have the 'write' permissions on the following NetBackup-managed ECA artifacts locations: Install_PATH/var/vxss/credentials/ecaartifacts For cacert: Install_PATH/var/vxss/ |
11 | Renewal failed with error: Failed to update the paths of external certificate artifacts in the NetBackup configuration files. Web service logs show the following log statement: New artifacts path update failed | Unable to update the NetBackup configuration files. For UNIX: bp.conf file For Windows: Registry | Check if NetBackup Service Layer (NBSL) service is up and running. Later, increase the verbosity. Contact Cohesity technical support if the issue still persists. |
12 | Renewal process is blocked at the validation phase. | It is possible that the CRL URLs are not accessible from the host and CRL check level was defined as LEAF/CHAIN while uploading certificates. | Ensure that the CRL URLs are accessible from the host. Else use the commands to set the CRL check level to DISABLE in the bp.conf configuration file. |
13 | After certificate rotation backup or backup from snapshot jobs are failing with error code: 5982 | The host is not able to verify connections using CRL. Possibly because the CRL URLs are not accessible from the host. | Ensure that the CRL URLs are accessible from the host. Else use the commands to set the CRL check level to DISABLE in the bp.conf configuration file. |