NetBackup and Veritas Appliances Hardening Guide
- Top recommendations to improve your NetBackup and Veritas appliances security posture
- Steps to protect Flex Appliance
- Managing multifactor authentication
- Managing multifactor authentication on a primary or a media server instance
- Managing multifactor authentication on a WORM storage server
- Managing single sign-on (SSO)
- About lockdown mode
- Configuring an isolated recovery environment using the web UI
- Steps to protect NetBackup Appliance
- About single sign-on (SSO) authentication and authorization
- About authentication using smart cards and digital certificates
- About data encryption
- About forwarding logs to an external server
- Steps to protect NetBackup
- About multifactor authentication
- Configure NetBackup for single sign-on (SSO)
- Configure user authentication with smart cards or digital certificates
- Workflow to configure multi-person authorization for NetBackup operations
- Access codes
- Workflow to configure immutable and indelible data
- Add a configuration for an external CMS server
- Configuring an isolated recovery environment on a NetBackup BYO media server
- About FIPS support in NetBackup
- Workflow for external KMS configuration
- Workflow to configure data-in-transit encryption
- Workflow to use external certificates for NetBackup host communication
- About certificate revocation lists for external CA
- Configuring an external certificate for a clustered primary server
- Configuring a NetBackup host (media server, client, or cluster node) to use an external CA-signed certificate after installation
- Configuration options for external CA-signed certificates
- ECA_CERT_PATH for NetBackup servers and clients
- About protecting the MSDP catalog
- How to set up malware scanning
- About backup anomaly detection
- Steps to protect NetBackup Flex Scale
- STIG overview for NetBackup Flex Scale
- FIPS overview for NetBackup Flex Scale
- Support for immutability in NetBackup Flex Scale
- Deploying external certificates on NetBackup Flex Scale
- About multifactor authentication
- About single sign-on (SSO) configuration
- Steps to protect Access Appliance
- FIPS 140-2 conformance for Access Appliance
- Managing the login banner using the UI
- Managing the password policy using the UI
- Support for immutability in Access Appliance
- About system certificates on Access Appliance
- About single sign-on (SSO) configuration
- Configuring user authentication using digital certificates or smart cards
- About multifactor authentication
- Configuring an isolated recovery environment using the command line
- Forwarding logs to an external server
NetBackup operations that need multi-person authorization
The following operations require multi-person authorization and therefore a ticket is generated for these operations:
Configuring multi-person authorization
Enabling and disabling operations that require multi-person authorization
Adding exempted users
Changing any multi-person authorization settings
Expiring images
Updating image expiration time
Changing the MSDP WORM configuration
Removing the MSDP WORM retention lock
Removing hold applied on the images
Updating CLI expiration period
Adding, updating, and deleting an API key
Adding, updating, and deleting KMS configuration, keys, and key groups
Adding, updating, deleting malware scan host
Adding, updating, deleting, copying backup and deployment policies
Updating the following global security settings:
Enabling and disabling NetBackup host communication with insecure hosts
Adding host aliases with or without NetBackup administrator's approval
Setting automatic deployment of certificates on a host
Enabling and disabling CAC/PIV authentication
Setting values for CAC/PIV certificate mapping attribute
Setting the value of the CAC/PIV certificate mapping attribute that is used to perform a search in active directory
Setting the value of the CAC/PIV certificate mapping attribute that is used to perform a search in LDAP directory
Enabling and disabling AD/LDAP domain mapping
Setting the value of the domain name that is used for user look-ups in active directory or LDAP
Setting the value of the OCSP URI that is used for certificate revocation checks with respect to CAC/PIV authentication
Enabling and disabling the data-in-transit encryption (DTE)
Setting unique identifier for external certificates
Allowing or disallowing the NetBackup web UI access to Operating System Administrators
Allowing or disallowing the default CLI access to OS administrators
Pausing client protection
Pausing client image expiration
Enabling and disabling TLS session resumption
Enabling and disabling rule engine for anomaly detection
Changing multifactor authentication configuration settings
Setting audit retention period for audit report
Even if multi-person authorization is configured for image expiry, the following operations do not require multi-person authorization:
Changing values for image retention level
Modifying retention levels in policy and SLP
Canceling incomplete SLPs using the nbstlutil command:
Refer to the NetBackup Commands Reference Guide.