Skip to main content
NetApp Response to Russia-Ukraine Cyber Threat
In response to the recent rise in cyber threat due to the Russian-Ukraine crisis, NetApp is actively monitoring the global security intelligence and updating our cybersecurity measures. We follow U.S. Federal Government guidance and remain on high alert. Customers are encouraged to monitor the Cybersecurity and Infrastructure Security (CISA) website for new information as it develops and remain on high alert.
NetApp Knowledge Base

How to explicitly trust a private CA certificate in Altavault

Last Updated:

Applies to

  • NetApp Cloud Backup (AltaVault)
  • SteelStore


  • Private or public CA for cloud provider's SSL certificate must have an existing public certificate trusted on the SteelStore/Altavault.
  • If this is not the case, CA certificate errors will appear in the system log and replication will fail.
  • SteelStore/Altavault's connections to the cloud provider are over SSL and in order to trust the cloud provider's certificate, the signing Certificate Authority (CA) needs to be explicitly trusted.
  • For this purpose,the SteelStore/Altavault like most devices, uses a ca-bundle file, which is a concatenated list of public CA's X.509 certificates.
  • If a customer uses private cloud storage using a certificate signed by a corporate Certificate Authority, the private CA's public certificate needs to be explicitly trusted for the SteelStore to accept it as valid.
  • The way to accomplish this is by appending the certificate to the file to the SteelStore's ca-bundle file.
  • Additionally, a public CA's certificate can expire and be updated, that update may not be reflected in the currently bundled SteelStore/Altavault CA certificate package.
  • If this occurs, then all certificates signed by that CA will fail to validate.

Example errors that may be seen when CA certificate cannot be validated against trusted certificates:

Peer certificate could not be authenticated with known CA certificates. You may proceed by disabling ssl certificate verification if you are sure about the authenticity of the server. Run "no replication ssl verify-certs" from the cli. An error has occurred while replicating data to the cloud. SteelStore (config) # cloudctl exec "-a list" Failed to get bucket list: 60: Peer certificate cannot be authenticated with given CA certificates : Peer certificate cannot be authenticated with known CA certificate




Scan to view the article on your device