Ransomware attackers specifically target and attempt to destroy backup systems to increase the probability of payment. Hardening your system is critical. Please ensure you have reviewed your platform security using the Security Hardening Checklist
Cohesity

COHESITY Documentation

Explore our documentation to get started, discover products & new features, access troubleshooting guides, register sources, platforms support.

Products
Data Security Alliance
Visit Cohesity.com
Demos
Support
Blogs
Developers
Partner Portals
Cohesity Community
© 2026 Cohesity, Inc. All Rights Reserved.
Terms of Use|
Privacy Policy|
Legal|
  1. Home
  2. NetBackup™ Security and Encryption Guide
  3. Section II. Encryption of data-in-transit
  4. NetBackup CA and NetBackup certificates
  5. Host ID-based certificate deployment in a clustered setup
  6. Revoking a host ID-based certificate for a clustered NetBackup setup
NetBackup™ Security and Encryption Guide

Revoking a host ID-based certificate for a clustered NetBackup setup

NetBackup administrators may consider revoking a host ID-based certificate under various conditions. For example, if the administrator detects that client security has been compromised, if a client is decommissioned, or if NetBackup is uninstalled from the host. A host with a revoked certificate cannot communicate with other hosts. Every NetBackup host must have a valid security certificate and a valid Certificate Revocation List (CRL) for successful communication.

See About the host ID-based certificate revocation list.

The NetBackup administrator can revoke certificates for a cluster node or the virtual name from any host in a NetBackup domain.

Ensure that you revoke the appropriate certificate.

After the certificate is revoked, you may need to deploy a new host ID-based certificate. Create a reissue token on the clustered node and deploy a new certificate using the reissue token.

See Creating a reissue token for a clustered NetBackup setup.

See Deploying a host ID-based certificate on a clustered NetBackup setup using reissue token.

To revoke a certificate from a cluster node

  1. Log in to the NetBackup Web Management Service:

    bpnbat -login -logintype WEB

    See Web login requirements for nbcertcmd command options.

  2. Run the following command to revoke a certificate for a cluster node:

    nbcertcmd -revokeCertificate -host host_name

    See Revoking a host ID-based certificate.

To revoke a certificate for the virtual name

  1. Log in to the NetBackup Web Management Service:

    bpnbat -login -logintype WEB

  2. Run the following command to revoke a host ID-based certificate for the virtual name:

    nbcertcmd -revokeCertificate -host virtual_name

    See Revoking a host ID-based certificate.

Feedback

Was this page helpful?
Previous

Deploying host ID-based certificates on cluster nodes

Next

Deploying a host ID-based certificate on a clustered NetBackup setup using reissue token

Feedback

Was this page helpful?