Recover inadvertently deleted aptare.ks file
When aptare.ks gets deleted, there are no ways to encrypt/decrypt the keys stored in aptare_message_relay_keystore.properties. This procedure provides the steps to recover an inadvertently deleted keystore (aptare.ks) file.
To recover a keystore file:
- Login to the data collector system and navigate to its installation path:
/Aptare/mbs/conf. - Identify these files inside
/Aptare/mbs/conf:aptare_message_relay_certificate.pemaptare_message_relay_keystore.ksaptare_message_relay_keystore.properties
- Stop the Aptare Agent service on the data collector system.
On a Windows system, you can stop the service from the Services Console, whereas you can use ./aptareagent stop command on Unix.
- Delete these files from
/Aptare/mbs/conf.aptare_message_relay_certificate.pemaptare_message_relay_keystore.ksaptare_message_relay_keystore.properties
- Login to the NetBackup IT Analytics Portal to generate a new keystore file.
Since the certificate was changed, the portal will display a notification which states:
Data Collector SSL certificate has not been downloaded for collector(s): <data_collector_name>.
- Go to Admin > Data Collection > Collector Administration and click the collector name to view its policies.
- Double-click the collector to invoke the Edit Collector window.
- Copy the Passcode value and save it for later use.
- Click Generate Key and download the key file.
- Copy the key file to
/Aptare/mbs/conffolder on the data collector system. Ensure the file name is same as that of the data collector on the portal. - On the data collector system, open the collector.properties file from
/Aptare/mbs/confand replace the COLLECTOR_PASSWORD value with the Passcode value copied from the Edit Collector window. - Save the
collector.propertiesfile and start the Aptare Agent service.After the service starts:
A new
aptare.ksis generated inside/Aptare/mbs/confwhich consumes the new key file.. The
aptare_message_relay_certificate.pem,aptare_message_relay_keystore.ks, andaptare_message_relay_keystore.propertiesfiles are generated later shortly.Since the certificate was changed, the portal will display a notification which states:
Data Collector SSL certificate has not been downloaded for collector(s): <data_collector_name>.
- On the NetBackup IT Analytics Portal, go to Admin > Data Collection > Collector Administration and click the collector name to view its policies.
- Double-click the policy name for which SSL certificate needs to be downloaded. The policy configuration window is displayed.
- Click Download SSL Certificate. The certificate is downloaded to your system.
- Copy the certificate to the data sender trust store.