About authorizing NetBackup users
NetBackup offers Access Control through the Access Management utility in the NetBackup Administration Console.
Instructions on how to install the necessary components to use Access Management are available in the NetBackup Security and Encryption Guide.
If NetBackup Access Control is not configured, you can still authorize users of the NetBackup Administration Console for specific applications. NetBackup Access Control always takes precedence over the capabilities authorization of the console.
If a user is not an authorized administrator by NetBackup Access Control, the actions that the user can perform in the Backup, Archive, and Restore application are limited. The user can perform the actions that are defined in the auth.conf file on the host that is specified in the logon dialog box.
The auth.conf file contains the authorization data for accessing NetBackup applications.
On Windows NetBackup servers, a template file named auth.conf.win.template is present at NB_Install/Java. Use this template file to create an auth.conf file at the same location.
The template file contains an example of giving permissions to a user.
See About authorizing nonroot users for specific applications.
On UNIX NetBackup servers, the auth.conf file is located at NB_Install/Java. This file provides the following authorizations:
On NetBackup servers | Administration capabilities for the root user and user backup and restore capabilities for all other users. |
On NetBackup clients | User backup and restore capabilities for all users. |
To perform remote administration or user operations with jbpSA, a user must have valid accounts on the NetBackup UNIX server or client computer.
Note:
If NetBackup Access Control is not configured for the users, by default the NetBackup application server provides authorization data. The authorization data allows all users who are members of the local administrator group on the NetBackup master server to use all of the NetBackup applications. Other users are allowed to access only Backup, Archive, and Restore.