Ransomware attackers specifically target and attempt to destroy backup systems to increase the probability of payment. Hardening your system is critical. Please ensure you have reviewed your platform security using the Security Hardening Checklist
Cohesity

COHESITY Documentation

Explore our documentation to get started, discover products & new features, access troubleshooting guides, register sources, platforms support.

Products
Data Security Alliance
Visit Cohesity.com
Demos
Support
Blogs
Developers
Partner Portals
Cohesity Community
© 2026 Cohesity, Inc. All Rights Reserved.
Terms of Use|
Privacy Policy|
Legal|
  1. Home
  2. NetBackup™ Security and Encryption Guide
  3. Section II. Encryption of data-in-transit
  4. External CA and external certificates
  5. About external certificate configuration for a clustered primary server
  6. Workflow to use external certificates for a clustered primary server
NetBackup™ Security and Encryption Guide

Workflow to use external certificates for a clustered primary server

To configure NetBackup to use external CA-signed certificates for secure communication, you should carry out the following steps in the given order:

Table: Workflow to use external certificates in a cluster setup

Step

Process

1

Ensure the following:

  • The certificate for the virtual name is placed at the appropriate location on the shared disk.

  • The external certificates for cluster nodes are placed at the appropriate locations on the nodes.

  • The CRLs are placed at the required locations on the nodes as per their CRL configuration options and are accessible.

    See About certificate revocation lists for external CA.

2

Install NetBackup software or upgrade the existing software on each cluster node.

3

Enable the NetBackup domain to use external certificates by configuring the NetBackup web server.

See Configuring an external certificate for the NetBackup web server.

4

Configure an external certificate for the virtual name and for each cluster node.

See Configuring an external certificate for a clustered primary server.

Feedback

Was this page helpful?
Previous

About external certificate configuration for a clustered primary server

Next

Configuration options for external CA-signed certificates for a virtual name

Feedback

Was this page helpful?