Ransomware attackers specifically target and attempt to destroy backup systems to increase the probability of payment. Hardening your system is critical. Please ensure you have reviewed your platform security using the Security Hardening Checklist
Cohesity

COHESITY Documentation

Explore our documentation to get started, discover products & new features, access troubleshooting guides, register sources, platforms support.

Products
Data Security Alliance
Visit Cohesity.com
Demos
Support
Blogs
Developers
Partner Portals
Cohesity Community
© 2026 Cohesity, Inc. All Rights Reserved.
Terms of Use|
Privacy Policy|
Legal|
  1. Home
  2. NetBackup™ Troubleshooting Guide
  3. Disaster recovery
  4. Generating a certificate on a clustered primary server after disaster recovery installation
NetBackup™ Troubleshooting Guide

Generating a certificate on a clustered primary server after disaster recovery installation

After you complete the disaster recovery of a clustered primary server, you must generate a certificate on the active node as well as all inactive nodes. Additionally, failover to the secondary node is expected behavior in a cluster environment. This procedure is required for successful backups and restores of the cluster.

For additional information on deploying certificates on primary server nodes see the NetBackup Security and Encryption Guide.

Generating the local certificate on each cluster node after disaster recovery installation

  1. Add all inactive nodes to the cluster.

    If all the nodes of the cluster are not currently part of the cluster, start by adding them to the cluster. Consult with your operating system cluster instructions for assistance with this process.

    More information about supported cluster technologies is available. See the NetBackup Clustered Primary Server Administrator's Guide.

  2. Run the nbcertcmd command to store the Certificate Authority certificate.

    UNIX: /usr/openv/netbackup/bin/nbcertcmd -getCACertificate

    Windows: install_path\NetBackup\bin\nbcertcmd -getCACertificate

  3. Use the bpnbat command as shown to authorize the necessary changes. When you are prompted for the authentication broker, enter the virtual server name, not the local node name.

    bpnbat -login -loginType WEB

  4. Use the nbcertcmd command to create a reissue token. The hostname is the local node name. When the command runs, it displays the token string value. A unique reissue token is needed for each cluster node.

    nbcertcmd -createtoken -name token_name -reissue -host hostname

  5. Use the reissue token with the nbcertcmd command to store the host certificate. This command prompts you for the token string value. Enter the token string from the nbcertcmd -createToken command.

    nbcertcmd -getCertificate -token

Feedback

Was this page helpful?
Previous

Recovering the entire Windows VCS cluster

Next

About the DR_PKG_MARKER_FILE environment variable

Feedback

Was this page helpful?