NetBackup™ for Cloud Object Store Administrator's Guide
- Introduction
- Managing Cloud object store assets
- Adding Cloud object store accounts
- Scan for malware
- Protecting Cloud object store assets
- About accelerator support
- Configuring the Start window
- Managing Cloud object store policies
- Recovering Cloud object store assets
- Troubleshooting
Backup failed and shows a certificate error with Amazon S3 bucket names containing dots (.)
Workaround
Use any of these two workarounds:
Use path-style URL to access the bucket: Since the path-style URL adds the bucket as a part of the URL path and not as a host name, we do not get any SSL issues even for buckets with a . (dot) in the name. However, NetBackup default configuration uses Virtual style for all dual-stack URLs like
s3.dualstack.<region-id>.amazonaws.com
. We can add an older S3 URL as a path style and can connect with a bucket with a (.) in the name. To do this, you can add a region with a plain S3 endpoint (s3.<region-id>.amazonaws.com
) and select the URL Access Style as the path style.Disable SSL: This workaround is not the recommended one, since it replaces the secure endpoint with an unsecure/unencrypted endpoint. After turning off SSL, it disables the peer-host validation of the server certificate. It bypasses the host name match for the virtual host-style URL of bucket (bucket.123.s3.dualstack.us-east-1.amazonaws.com) with the subject name in the certificate (*. s3.dualstack.us-east-1.amazonaws.com).