Ransomware attackers specifically target and attempt to destroy backup systems to increase the probability of payment. Hardening your system is critical. Please ensure you have reviewed your platform security using the Security Hardening Checklist
Cohesity

COHESITY Documentation

Explore our documentation to get started, discover products & new features, access troubleshooting guides, register sources, platforms support.

Products
Data Security Alliance
Visit Cohesity.com
Demos
Support
Blogs
Developers
Partner Portals
Cohesity Community
© 2026 Cohesity, Inc. All Rights Reserved.
Terms of Use|
Privacy Policy|
Legal|
  1. Home
  2. Veritas NetBackup™ Administrator's Guide, Volume I
  3. Section II. Configuring hosts
  4. Configuring Host Properties
  5. Configuration options for NetBackup servers
  6. ECA_PRIVATE_KEY_PATH for NetBackup servers and clients
Veritas NetBackup™ Administrator's Guide, Volume I

ECA_PRIVATE_KEY_PATH for NetBackup servers and clients

The ECA_PRIVATE_KEY_PATH option specifies the file path to the private key for the external CA-signed certificate of the host.

This option is mandatory for file-based certificates.

If the private key of the certificate is encrypted, you should specify the ECA_KEY_PASSPHRASEFILE option.

See ECA_KEY_PASSPHRASEFILE for NetBackup servers and clients.

NetBackup supports PKCS #1 and PKCS #8 formatted private keys that are either plain text or encrypted. These may either be PEM or DER encoded. However, if it is PKCS #1 encrypted, it must be PEM encoded.

For encrypted private keys, NetBackup supports the following encryption algorithms:

  • DES, 3DES, and AES if the private key is in the PKCS #1 format

  • DES, 3DES, AES, RC2, and RC4 if the private key is in the PKCS #8 format

Note:

You should not specify the ECA_PRIVATE_KEY_PATH option if Windows certificate store is specified for the ECA_CERT_PATH option.

See ECA_CERT_PATH for NetBackup servers and clients.

Table: ECA_PRIVATE_KEY_PATH information

Usage

Description

Where to use

On NetBackup servers or clients.

How to use

Use the nbgetconfig and the nbsetconfig commands to view, add, or change the option.

For information about these commands, see the NetBackup Commands Reference Guide.

Use the following format:

ECA_PRIVATE_KEY_PATH = Path to the private key of the external certificate

For example: c:\key.pem

If you use this option on a Flex Appliance application instance, the path must be /mnt/nbdata/hostcert/.

Equivalent Administration Console property

No equivalent exists in the NetBackup Administration Console host properties.

Feedback

Was this page helpful?
Previous

ECA_KEY_PASSPHRASEFILE for NetBackup servers and clients

Next

ECA_TRUST_STORE_PATH for NetBackup servers and clients

Feedback

Was this page helpful?