NetBackup 8.2 does not use the External Certificate Authority (ECA) for port 8443 after enrolling certificates.

Article: 100047284
Last Published: 2020-03-10
Ratings: 2 0
Product(s): NetBackup & Alta Data Protection

Problem

After configuring the External Certificate Authority (ECA) on a NetBackup 8.2 server a port scan still shows it is using the default NetBackup CA on Port 8443. 

Cause

Port 8443 is used by vCenter plugin so the "configureCertsForPlugins" command must be used. 

Solution

The below steps should ONLY BE RAN if you have already configured the NetBackup 8.2 server to use ECA's. For more information on configuring ECA's see Veritas NetBackup™ Security and Encryption Guide: UNIX, Windows, and Linux.
 

  1. Run the ecaHealthCheck to make sure your entries in the configuration files are still good:

    nbcertcmd.exe -ecahealthcheck

     
  2.  To configure the ECA for port 8443:

    Windows:

    <Install_Path>NetBackup\wmc\bin\install\configureCertsForPlugins.bat -registerExternalCert -certPath [Configuration Entry for ECA_CERT_PATH] -privateKeyPath [Configuration Entry for ECA_PRIVATE_KEY_PATH] -trustStorePath [Configuration Entry for ECA_TRUST_STORE_PATH]

    Unix: 

    # /usr/openv/wmc/bin/install/configureCertsForPlugins -registerExternalCert -certPath [Configuration Entry for ECA_CERT_PATH] -privateKeyPath [Configuration Entry for ECA_PRIVATE_KEY_PATH] -trustStorePath [Configuration Entry for ECA_TRUST_STORE_PATH]

    Note: For more information on the configureCertsForPlugins command, please see the configureCertsForPlugins page in our Veritas NetBackup™ Commands Reference Guide.

     
  3.  Restart the "NetBackup Web Management Console" service. 

    Windows: 
    Open Services and manually restart the NetBackup Web Management Console service

    Unix:
    # nbwmc stop; nbwmc start

     
  4.  Run a security scan and/or use the below command to confirm that your NetBackup server is displaying the ECA on port 8443:

    Windows:
    <Install_Path>\NetBackup\bin\goodies\vxsslcmd.exe s_client -connect [master_hostname]:8443 -showcerts

    Unix:
    # /usr/openv/netbackup/bin/goodies/vxsslcmd s_client -connect [master_hostname]:8443 -showcerts

Was this content helpful?