NetBackup™ Commands Reference Guide

Last Published:
Product(s): NetBackup & Alta Data Protection (10.4)
  1. Introduction
    1.  
      About NetBackup commands
    2.  
      Navigating multiple menu levels
    3.  
      NetBackup command conventions
    4.  
      NetBackup Media Manager command notes
    5.  
      IPV6 updates
  2. Appendix A. NetBackup Commands
    1.  
      acsd
    2.  
      backupdbtrace
    3.  
      backuptrace
    4.  
      bmrc
    5.  
      bmrconfig
    6.  
      bmrepadm
    7.  
      bmrprep
    8.  
      bmrs
    9.  
      bmrsrtadm
    10.  
      bp
    11.  
      bparchive
    12.  
      bpbackup
    13.  
      bpbackupdb
    14.  
      bpcatarc
    15.  
      bpcatlist
    16.  
      bpcatres
    17.  
      bpcatrm
    18.  
      bpcd
    19.  
      bpchangeprimary
    20.  
      bpcleanrestore
    21.  
      bpclient
    22.  
      bpclimagelist
    23.  
      bpclntcmd
    24.  
      bpclusterutil
    25.  
      bpcompatd
    26.  
      bpconfig
    27.  
      bpdbjobs
    28.  
      bpdbm
    29.  
      bpdgclone
    30.  
      bpdown
    31.  
      bpduplicate
    32.  
      bperror
    33.  
      bpexpdate
    34.  
      bpfis
    35.  
      bpflist
    36.  
      bpgetconfig
    37.  
      bpgetdebuglog
    38.  
      bpimage
    39.  
      bpimagelist
    40.  
      bpimmedia
    41.  
      bpimport
    42.  
      bpinst
    43.  
      bpkeyfile
    44.  
      bpkeyutil
    45.  
      bplabel
    46.  
      bplist
    47.  
      bpmedia
    48.  
      bpmedialist
    49.  
      bpminlicense
    50.  
      bpnbat
    51.  
      bpnbaz
    52.  
      bppficorr
    53.  
      bpplcatdrinfo
    54.  
      bpplclients
    55.  
      bppldelete
    56.  
      bpplinclude
    57.  
      bpplinfo
    58.  
      bppllist
    59.  
      bpplsched
    60.  
      bpplschedrep
    61.  
      bpplschedwin
    62.  
      bppolicynew
    63.  
      bpps
    64.  
      bprd
    65.  
      bprecover
    66.  
      bprestore
    67.  
      bpretlevel
    68.  
      bpschedule
    69.  
      bpschedulerep
    70.  
      bpsetconfig
    71.  
      bpstsinfo
    72.  
      bpstuadd
    73.  
      bpstudel
    74.  
      bpstulist
    75.  
      bpsturep
    76.  
      bptestbpcd
    77.  
      bptestnetconn
    78.  
      bpup
    79.  
      bpverify
    80.  
      cat_convert
    81.  
      cat_export
    82.  
      cat_import
    83.  
      configureCerts
    84.  
      configureMQ
    85.  
      configureWebServerCerts
    86.  
      create_nbdb
    87.  
      csconfig cldinstance
    88.  
      csconfig cldprovider
    89.  
      csconfig meter
    90.  
      csconfig reinitialize
    91.  
      csconfig throttle
    92.  
      duplicatetrace
    93.  
      importtrace
    94.  
      jbpSA
    95.  
      jnbSA
    96.  
      ltid
    97.  
      mklogdir
    98.  
      msdpcldutil
    99.  
      nbauditreport
    100.  
      nbcallhomeproxyconfig
    101.  
      nbcatsync
    102.  
      NBCC
    103.  
      NBCCR
    104.  
      nbcertcmd
    105.  
      nbcertupdater
    106.  
      nbcldutil
    107.  
      nbcmdrun
    108.  
      nbcomponentupdate
    109.  
      nbcplogs
    110.  
      nbcredkeyutil
    111.  
      nbdb_admin
    112.  
      nbdb_backup
    113.  
      nbdb_move
    114.  
      nbdb_ping
    115.  
      nbdb_restore
    116.  
      nbdb_unload
    117.  
      nbdb2adutl
    118.  
      nbdbms_start_server
    119.  
      nbdbms_start_stop
    120.  
      nbdc
    121.  
      nbdecommission
    122.  
      nbdelete
    123.  
      nbdeployutil
    124.  
      nbdevconfig
    125.  
      nbdevquery
    126.  
      nbdiscover
    127.  
      nbdna
    128.  
      nbemm
    129.  
      nbemmcmd
    130.  
      nbepicfile
    131.  
      nbfindfile
    132.  
      nbfirescan
    133.  
      nbfp
    134.  
      nbftadm
    135.  
      nbftconfig
    136.  
      nbgetconfig
    137.  
      nbhba
    138.  
      nbholdutil
    139.  
      nbhostidentity
    140.  
      nbhostmgmt
    141.  
      nbhypervtool
    142.  
      nbidpcmd
    143.  
      nbimageshare
    144.  
      nbinstallcmd
    145.  
      nbjm
    146.  
      nbkmiputil
    147.  
      nbkmscmd
    148.  
      nbkmsutil
    149.  
      nboraadm
    150.  
      nborair
    151.  
      nboracmd
    152.  
      nbpem
    153.  
      nbpemreq
    154.  
      nbmariadb
    155.  
      nbmlb
    156.  
      nbperfchk
    157.  
      nbplupgrade
    158.  
      nbrb
    159.  
      nbrbutil
    160.  
      nbreplicate
    161.  
      nbrepo
    162.  
      nbrestorevm
    163.  
      nbseccmd
    164.  
      nbserviceusercmd
    165.  
      nbsetconfig
    166.  
      nbshvault
    167.  
      nbsmartdiag
    168.  
      nbsnapimport
    169.  
      nbsnapreplicate
    170.  
      nbsqladm
    171.  
      nbsqlite
    172.  
      nbstl
    173.  
      nbstlutil
    174.  
      nbstop
    175.  
      nbsu
    176.  
      nbsvrgrp
    177.  
      netbackup_deployment_insights
    178.  
      resilient_clients
    179.  
      restoretrace
    180.  
      stopltid
    181.  
      tldd
    182.  
      tldcd
    183.  
      tpautoconf
    184.  
      tpclean
    185.  
      tpconfig
    186.  
      tpext
    187.  
      tpreq
    188.  
      tpunmount
    189.  
      verifytrace
    190.  
      vltadm
    191.  
      vltcontainers
    192.  
      vlteject
    193.  
      vltinject
    194.  
      vltoffsitemedia
    195.  
      vltopmenu
    196.  
      vltrun
    197.  
      vmadd
    198.  
      vmchange
    199.  
      vmcheckxxx
    200.  
      vmd
    201.  
      vmdelete
    202.  
      vmoprcmd
    203.  
      vmphyinv
    204.  
      vmpool
    205.  
      vmquery
    206.  
      vmrule
    207.  
      vmupdate
    208.  
      vnetd
    209.  
      vssat
    210.  
      vwcp_manage
    211.  
      vxlogcfg
    212.  
      vxlogmgr
    213.  
      vxlogview
    214.  
      W2KOption

Name

nbidpcmd — configure an identity provider (IDP), SAML certificate, and keystore on the NetBackup master server to use with the Single Sign-On (SSO) method.

SYNOPSIS

For IDP configuration and NetBackup CA SAML keystore configuration, use the following command:

nbidpcmd -ac -n IDP configuration name -mxp IDP XML metadata file [-t SAML2] [-e true | false] [-u IDP user field] [-g IDP user group field] [-M master_server] [-cCert] [-f]

For IDP configuration and ECA SAML keystore configuration, either of the commands shown can be used:

Use NetBackup ECA configured keystore for SAML keystore configuration:

nbidpcmd -ac -n IDP configuration name -mxp IDP XML metadata file [-t SAML2] [-e true | false] [-u IDP user field] [-g IDP user group field] [-M master_server] -cECACert -uECA [-f]

Use ECA certificate chain and private key provided by user for SAML keystore configuration:

nbidpcmd -ac -n IDP configuration name -mxp IDP XML metadata file [-t SAML2] [-e true | false] [-u IDP user field] [-g IDP user group field] [-M master_server] -cECACert -certPEM Certificate Chain File -privKeyPath Private Key File [-ksPassPath Keystore Passkey File] [-f]

nbidpcmd -cCert [-f]

nbidpcmd -cECACert -uECA use existing ECA configuration [-f force_option] [-M master_server]

nbidpcmd -cECACert -certPEM Certificate Chain File -privKeyPath Private Key File -ksPassPath Keystore Passkey File [-f force_option] [-M master_server]

nbidpcmd -dc -n IDP configuration name [-M master_server]

nbidpcmd -dCert

nbidpcmd -dECACert

nbidpcmd -rCert

nbidpcmd -sc -n IDP configuration name [-M master_server]

nbidpcmd -scl [-M master_server]

nbidpcmd -uc -n IDP configuration name {-mxp IDP XML metadata file| -e true | false} [-M master_server]

nbidpcmd -v [-M master_server]

On UNIX systems, the directory path to this command is /usr/openv/netbackup/bin/

On Windows systems, the directory path to this command is install_path\NetBackup\bin\

DESCRIPTION

The nbidpcmd command can add, modify, list, and delete the configuration for identity providers on the NetBackup master server. Additionally, use the command to add, update, renew, and delete NetBackup CA and ECA SAML certificate and keystore.

OPTIONS

-ac

Adds a configuration for an identity provider. Use the -e option to enable an IDP configuration.

-cCert

Configures SAML certificates and keystore.

-cECACert

Configures SAML external CA keystore.

-certPEM Certificate Chain File

Specifies certificate chain file path. The file must be in PEM format and must be accessible to the master server that performs the configuration.

-dc

Deletes the configuration of the identity provider with the specified ID.

-dCert

Remove the SAML certificate and keystore.

-dECACert

Remove the SAML external CA configured keystore.

-e true | false

Enables or disables the identity provider configuration. An IDP must be available and enabled otherwise users cannot sign in with the Single Sign-On (SSO) option.

  • true = Enable

  • false = Disable

-f

Specifies whether to overwrite the existing SAML keystore.

-ksPassPath Keystore Passkey File

Specifies the password file path for the keystore. The file must be accessible to the master server that performs the configuration.

-M master_server

The master server to which you want to add or modify the identity provider configuration. The default is the NetBackup server master where you run the command.

-mxp IDP XML metadata file

The metadata file that contains configuration details for the identity provider, in Base64-encoded format.

-n IDP configuration name

The unique name of the identity provider.

-privKeyPath Private Key File

Specifies the private key file path for the certificate. The file must be in PEM format and must be accessible to the master server that performs the configuration.

-rCert

Renews the SAML certificate and key-pair and updates the SAML keystore with the renewed key-pair certificate.

-sc

Display the details for the configured identity provider with the specified ID. If the ID is not provided the details of all the configured identity providers are listed. Or, use -scl to display a specific identity provider.

-scl

Display the details for all the configured identity providers. Use -sc -n to display a specific identity provider.

-t SAML2

Indicates the type of protocol that the identity provider supports. The following types are supported: SAML2.

-u IDP user field, -g IDP user group field

Retrieves the fields from the SAML assertion that are the primary keys for the user and the user group. You can specify these fields together or individually.

If these fields are not provided, the default values are userPrincipalName and memberOf.

The IDP user field and the IDP user group field are the IDP SAML attribute names mapped to the userPrincipalName and the memberOf attributes of the AD or LDAP.

The values entered for the -u IDP user field and -g IDP user group field are case sensitive and must exactly match the corresponding mapped SAML attributes on the IDP Host.

Ensure that the SAML attribute names are defined in the format of username@domainname and (CN=group name, DC=domainname) respectively.

-uc

Updates the details for the configured identity provider with the specified ID. In addition to the -n option, you must use the -mxp or the -e option, or both options.

-uECA

Specifies whether to configure external CA-signed SAML keystore from the existing external CA certificate that is configured in NetBackup.

-v

Shows the version of the nbidpcmd utility.