NetBackup™ Web UI Cloud Object Store Administrator's Guide
- Introduction
- Managing Cloud object store assets
- Protecting Cloud object store assets
- About accelerator support
- Managing Cloud object store policies
- Recovering Cloud object store assets
- Troubleshooting
Check certificate for revocation
For all the cloud providers, NetBackup provides a capability to verify the revocation status of SSL certificates using Online Certificate Status Protocol (OCSP). If SSL and the
option, both are enabled, NetBackup verifies each SSL certificate. To verify, NetBackup makes an OCSP request to the CA to check revocation status of certificate presented during SSL handshake. NetBackup does not connect to the cloud provider, if the status is returned as revoked, or it failed to connect to the OCSP endpoint present in the SSL certificate.To enable validation, update the USE_CRL property from the Cloud object store account dialog.
OCSP endpoints are HTTP thus, turn off any firewall rule that block HTTP (port 80) connection to external network. For example, http://ocsp.sca1b.amazontrust.com
OCSP URL is dynamically retrieved from the certificate thus, disable any firewall rule that blocks unknown URLs.
Typically, OCSP URLs endpoint support IPV4. For IPV6 environments disable the 'Check certificate revocation' option.
Private Clouds typically have a self-signed certificate. Thus, for private clouds, Check certificate revocation is not required. Disable this check while configuring the account, otherwise, account creation fails.
OSCP URL of CA should be present in certificate's 'Authority Information Access' extension.