Ransomware attackers specifically target and attempt to destroy backup systems to increase the probability of payment. Hardening your system is critical. Please ensure you have reviewed your platform security using the Security Hardening Checklist
Cohesity

COHESITY Documentation

Explore our documentation to get started, discover products & new features, access troubleshooting guides, register sources, platforms support.

Products
Data Security Alliance
Visit Cohesity.com
Demos
Support
Blogs
Developers
Partner Portals
Cohesity Community
© 2026 Cohesity, Inc. All Rights Reserved.
Terms of Use|
Privacy Policy|
Legal|
  1. Home
  2. Veritas NetBackup™ Cloud Administrator's Guide
  3. Configuring cloud storage in NetBackup
  4. Deploying host name-based certificates
Veritas NetBackup™ Cloud Administrator's Guide

Deploying host name-based certificates

This is applicable for media server versions 7.7.x to 8.1.2 only.

You can deploy the required host name-based security certificate for the NetBackup media servers that you use for cloud storage. Each media server that you use for cloud storage runs the NetBackup CloudStore Service Container.

See About the NetBackup CloudStore Service Container.

You can deploy a certificate for an individual media server or for all media servers. Media servers that you use for cloud storage must have a host name-based security certificate.

Note:

Deploying a host name-based certificate is a one-time activity for a host. If a host name-based certificate was deployed for an earlier release or for a hotfix, it does not need to be done again.

Ensure the following before you deploy a host-name based certificate:

  • All nodes of the cluster have a host ID-based certificate.

  • All Fully Qualified Domain Names (FQHN) and short names for the cluster nodes are mapped to their respective host IDs.

Deploying a host name-based certificate on media servers

This procedure works well when you deploy host name-based security certificates to many hosts at one time. As with NetBackup deployment in general, this method assumes that the network is secure.

To deploy a host name-based security certificate for media servers

  1. Run the following command on the master server, depending on your environment. Specify the name of an individual media server or specify -AllMediaServers.

    On Windows: install_path\NetBackup\bin\admincmd\bpnbaz -ProvisionCert host_name|-AllMediaServers

    On UNIX: /usr/openv/netbackup/bin/admincmd/bpnbaz -ProvisionCert host_name|-AllMediaServers

    NetBackup appliance (as a NetBackupCLI user): bpnbaz -ProvisionCert Media_server_name

  2. Restart the NetBackup Service Layer (nbsl) service on the media server.

Note:

In you use dynamic IPs on the hosts (DHCP), ensure that the host name and the IP address are correctly listed on the master server. To do so, run the following NetBackup bpclient command on the master server:

On Windows: Install_path\NetBackup\bin\admincmd\bpclient -L -All

On UNIX: /usr/openv/netbackup/bin/admincmd/bpclient -L -All

Feedback

Was this page helpful?
Previous

NetBackup cloudstore.conf configuration file

Next

Deploying host ID-based certificates

Feedback

Was this page helpful?