Ransomware attackers specifically target and attempt to destroy backup systems to increase the probability of payment. Hardening your system is critical. Please ensure you have reviewed your platform security using the Security Hardening Checklist
Cohesity

COHESITY Documentation

Explore our documentation to get started, discover products & new features, access troubleshooting guides, register sources, platforms support.

Products
Data Security Alliance
Visit Cohesity.com
Demos
Support
Blogs
Developers
Partner Portals
Cohesity Community
© 2026 Cohesity, Inc. All Rights Reserved.
Terms of Use|
Privacy Policy|
Legal|
  1. Home
  2. Veritas NetBackup™ for DB2 Administrator's Guide
  3. Appendix C. Register authorized locations
  4. Registering authorized locations used by a NetBackup database script-based policy
Veritas NetBackup™ for DB2 Administrator's Guide

Registering authorized locations used by a NetBackup database script-based policy

During a backup, NetBackup checks for scripts in the default script location and any authorized locations. The default, authorized script location for UNIX is usr/openv/netbackup/ext/db_ext and for Windows is install_path\netbackup\dbext. If the script is not in the default script location or an authorized location, the policy job fails. You can move any script into the default script location or any additional authorized location and NetBackup recognizes the scripts. You need to update the policy with the script location if it has changed. An authorized location can be a directory and NetBackup recognizes any script within that directory. An authorized location can also be a full path to a script if an entire directory does need to be authorized.

If the default script location does not work for your environment, use the following procedure to enter one or more authorized locations for your scripts. Use nbsetconfig to enter an authorized location where the scripts reside. You can also use bpsetconfig, however this command is only available on the master or the media server.

Note:

One recommendation is that scripts should not be world-writable. NetBackup does not allow scripts to run from network or remote locations. All scripts must be stored and run locally. Any script that is created and saved in the NetBackup db_ext (UNIX) or dbext (Windows) location needs to be protected during a NetBackup uninstall.

For more information about registering authorized locations and scripts, review the knowledge base article:

To add an authorized location

  1. Open a command prompt on the client.
  2. Use nbsetconfig to enter values for an authorized location. The client privileged user must run these commands.

    The following examples are for paths you may configure for the Oracle agent. Use the path that is appropriate for your agent.

    • On UNIX:

      [root@client26 bin]# ./nbsetconfig
      nbsetconfig>DB_SCRIPT_PATH = /Oracle/scripts
      nbsetconfig>DB_SCRIPT_PATH = /db/Oracle/scripts/full_backup.sh
      nbsetconfig>
      <ctrl-D>
    • On Windows:

      C:\Program Files\Veritas\NetBackup\bin>nbsetconfig
      nbsetconfig> DB_SCRIPT_PATH=c:\db_scripts
      nbsetconfig> DB_SCRIPT_PATH=e:\oracle\fullbackup\full_rman.sh
      nbsetconfig>
      <ctrl-Z>
      

    Note:

    Review the NetBackup Command Reference Guide for options, such as reading from a text file and remotely setting clients from a NetBackup server using bpsetconfig. If you have a text file with the script location or authorized locations listed, nbsetconfig or bpsetconfig can read from that text file. An entry of DB_SCRIPT_PATH=none does not allow any script to execute on a client. The none entry is useful if an administrator wants to completely lock down a server from executing scripts.

  3. (Conditional) Perform these steps on any clustered database or agent node that can perform the backup.
  4. (Conditional) Update any policy if the script location was changed to the default or authorized location.

Feedback

Was this page helpful?
Previous

Appendix C. Register authorized locations

Next

Index

Feedback

Was this page helpful?