NetBackup™ Web UI Administrator's Guide
- Introducing NetBackup
- Section I. Monitoring and notifications
- Monitoring NetBackup activity
- Activity monitor
- Job monitoring
- Notifications
- Monitoring NetBackup activity
- Section II. Configuring hosts
- Managing host properties
- Managing credentials for workloads and systems that NetBackup accesses
- Managing deployment
- Section III. Configuring storage
- Section IV. Configuring backups
- Section V. Managing security
- Security events and audit logs
- Managing security certificates
- Managing host mappings
- Managing user sessions
- Managing the security settings for the primary server
- About trusted primary servers
- Using access keys, API keys, and access codes
- Configuring authentication options
- Managing role-based access control
- Configuring RBAC
- Add a custom RBAC role
- Section VI. Detection and reporting
- Detecting malware
- Detecting anomalies
- Usage reporting and capacity licensing
- Detecting malware
- Section VII. NetBackup workloads and NetBackup Flex Scale
- Section VIII. Disaster recovery and troubleshooting
Configure smart card authentication with domain
If you want to map smart cards or certificates with AD or LDAP domain for user validation, add the AD or the LDAP domains that are associated with your NetBackup users. See the NetBackup Security & Encryption Guide.
Note:
Ensure that you complete the role-based access control (RBAC) configuration for the NetBackup users before you configure smart card or certificate authentication.
See Configuring RBAC.
To configure NetBackup to authenticate users with a smart card or digital certificate
- At the top right, select Settings > Smart card authentication.
- Turn on Smart card authentication.
- Select the required AD or LDAP domain from the Select the domain option.
- Select a Certificate mapping attribute: Common name (CN) or Universal principal name (UPN).
- Optionally, enter the OCSP URI.
If you do not provide the OCSP URI, the URI in the user certificate is used.
- Click Save.
- To the right of CA certificates, click Add.
- Browse for or drag and drop the CA certificates and click Add.
Smart card authentication requires a list of trusted root or intermediate CA certificates. Add the CA certificates that are associated with the user digital certificates or the user smart cards.
Certificate file types must be
.crt
,.cer
,.der
,.pem
, orPKCS #7
format and less than 64KB in size. - On the Smart card authentication page, verify the configuration information.
- Before users can use a digital certificate that is not installed on a smart card, the certificate must be uploaded to the browser's certificate manager.
See the browser documentation for instructions or contact your certificate administrator for more information.
- When users sign in, they now see an option to Sign in with certificate or smart card.
If you do not want users to have this sign-in option yet, turn off Smart card authentication. (For example, if all users do not yet have their certificates configured on their hosts.). The settings that you configured are retained even if you turn off smart card authentication.
For such users, the domain name and domain type are smart card.