Configuring a third-party certificate for the web server on the NetBackup master server
You can configure the NetBackup web server to use a third-party certificate. The web server instance uses the Java KeyStore (JKS) as a repository of security certificates that are used in Secure Socket Layer (SSL) encryption.
Note:
The following steps also apply for the NetBackup and the Flex Appliance software installation. For the NetBackup Appliance, refer to the appliance documentation.
To configure a third-party certificate for the NetBackup web server
- Ensure that you have a valid third-party certificate and a matching private key.
- Convert the third-party certificate and the private key into a password-protected Java KeyStore file.
- Create a keystore password file that contains the password, which can be used to access the Java KeyStore file.
- Stop the NetBackup Web Management Console service.
Note:
In a clustered master server setup, run the following command on the active node to avoid a failover before you stop the service:
- For a master server cluster, to avoid a failover, on the active node run the following command:
install_path/netbackup/bin/bpclusterutil -freeze
- To configure the third-party certificate, run the following command:
install_path/wmc/bin/install/configureTPCerts -keystorefile KeyStore_File_path -keystorepassfile KeyStore_Password_File_Path
For example:
/usr/openv/wmc/bin/install/configureTPCerts -keystorefile /home/keystore.jks -keystorepassfile /home/keystorepassfile
Refer to the NetBackup Commands Reference Guide, for more details on the command-line options.
- For a clustered master server, complete the previous step on all nodes.
- Start the NetBackup Web Management Console service.
Note:
In a clustered setup, unfreeze the cluster using the following command on the active node:
install_path/netbackup/bin/bpclusterutil -unfreeze
- Verify that you can access the NetBackup web user interface using a browser, without a certificate warning message .