NetBackup™ Web UI Administrator's Guide
- Introducing the NetBackup web user interface
- Monitoring NetBackup
- Notifications
- Section I. Managing role-based access control
- About role-based access control in NetBackup
- Configuring RBAC roles
- Configuring RBAC
- Default RBAC roles
- Administrator
- Default AHV Administrator
- Default Cloud Administrator
- Default Kubernetes Administrator
- Default NetBackup Kubernetes Operator Service
- Default RHV Administrator
- Default Resiliency Administrator
- Default Microsoft SQL Server Administrator
- Default Security Administrator
- Default Storage Administrator
- Default VMware Administrator
- RBAC permissions
- About role permissions
- Global > NetBackup management
- NetBackup Web Management Console Administration
- Access hosts
- Agentless hosts
- Anomalies
- Data classifications
- Email notifications
- Event logs
- NetBackup hosts
- Image sharing
- NetBackup backup images
- Jobs
- Licensing
- Media server
- Remote primary server certificate authority
- Resiliency
- Resource limits
- Retention levels
- Servers > Trusted primary servers
- Cloud providers
- CloudPoint servers
- WebSocket servers
- Global > Protection
- Global > Security
- Global > Storage
- Assets
- Protection plans
- Credentials
- Manage access
- Section II. Managing security
- Security events and audit logs
- Managing security certificates
- Managing user sessions
- Managing master server security settings
- Certificate authority for secure communication
- Disable communication with NetBackup 8.0 and earlier hosts
- Disable automatic mapping of NetBackup host names
- About NetBackup certificate deployment security levels
- Select a security level for NetBackup certificate deployment
- Set a passphrase for disaster recovery
- About trusted primary servers
- Creating and managing API keys for users (Administrators)
- Adding and managing your API key (Users)
- Configuring authentication options
- Managing hosts
- Section III. Managing storage and backups
- Configuring storage
- About storage configuration
- Create a Media Server Deduplication Pool (MSDP) storage server
- Create a Cloud storage, OpenStorage, or AdvancedDisk storage server
- Create a disk pool
- Create a storage unit
- Create a universal share
- Using image sharing from the NetBackup web UI
- Troubleshooting storage configuration
- Troubleshooting universal share configuration issues
- Create a Media Server Deduplication Pool (MSDP) storage server for image sharing
- Managing protection plans
- Managing classic policies
- Usage reporting and capacity licensing
- Configuring storage
- Section IV. Veritas Resiliency Platform
- Section V. Credentials
- Troubleshooting the NetBackup Web UI
Reissue a NetBackup certificate
Note:
The information here only applies to the security certificates that are issued by the NetBackup certificate authority (CA). External certificates must be managed outside of NetBackup.
In some cases a host's NetBackup certificate is no longer valid. For example, if a certificate is expired, revoked, or is lost. You can reissue a certificate either with or without a reissue token.
A reissue token is a type of authorization token that is used to reissue a NetBackup certificate. When you reissue a certificate, the host gets the host ID same as the original certificate.
If you need to reissue a host's NetBackup certificate and want a more secure method to do so, you can create an authorization token that the host administrator must use to obtain a new certificate. This reissue token retains the same host ID as the original certificate. The token can only be used once. Because it is associated to a specific host, the token cannot be used to request certificates for other hosts.
To reissue a NetBackup certificate for a host
- On the left, select Security > Hosts.
- Click NetBackup certificates.
- Select the host and click Generate reissue token.
- Enter a token name and indicate how long the token should be valid for.
- Click Create.
- Click Copy to clipboard and click Close.
- Share the authorization token so the host's administrator can obtain a new certificate.
In certain scenarios, like BMR client restore, you need to reissue a certificate without a reissue token. The option enables you to reissue a certificate without requiring a token.
To allow a NetBackup certificate reissue, without a token
- On the left, select Security > Hosts.
- Click NetBackup certificates.
- Select the host and click Allow auto reissue certificate > Allow.
Once you set the Allow auto reissue certificate option, a certificate can be reissued without a token within the next 48 hours, which is the default setting. After this window to reissue expires, the certificate reissue operation requires a reissue token.
- Notify the host's administrator that you allowed a NetBackup certificate reissue without a token.
After you allow a NetBackup certificate reissue without a token, you can revoke this ability before the window to reissue expires. By default, the window is 48 hours.
To revoke the ability to reissue a NetBackup certificate without a token
- On the left, select Security > Hosts.
- Click NetBackup certificates.
- Select the host and click Revoke auto reissue certificate > Revoke.