Veritas NetBackup™ Appliance Security Guide
- About the NetBackup appliance Security Guide
- User authentication
- User authorization
- Intrusion prevention and intrusion detection systems
- Log files
- Operating system security
- Data security
- Web security
- Network security
- Call Home security
- Remote Management Module (RMM) I security
- STIG and FIPS conformance
- Appendix A. Security release content
FIPS 140-2 conformance for NetBackup appliances
The Federal Information Processing Standards (FIPS) define U.S. and Canadian Government security and interoperability requirements for computer systems. The National Institute of Standards and Technology (NIST) issued the FIPS 140 Publication Series to coordinate the requirements and standards for validating cryptography modules. The FIPS 140-2 standard specifies the security requirements for cryptographic modules and applies to both the hardware and the software components. It also describes the approved security functions for symmetric and asymmetric key encryption, message authentication, and hashing.
For more information about the FIPS 140-2 standard and its validation program, click on the following links:
https://csrc.nist.gov/csrc/media/publications/fips/140/2/final/documents/fips1402.pdf
https://csrc.nist.gov/projects/cryptographic-module-validation-program
The NetBackup Cryptographic Module is FIPS validated. NetBackup MSDP uses this module and starting with NetBackup Appliance release 3.1.1, you can enable the FIPS 140-2 standard for NetBackup MSDP with the following command:
Main Menu > Settings > Security > FIPS Enable, followed by the maintenance password.
Note:
Enabling or disabling this feature automatically terminates all jobs that are currently in progress and restarts the NetBackup services. As a best practice, it is recommended that you first stop all jobs manually before you enable or disable this feature.
For complete information about FIPS commands, see the NetBackup Appliance Commands Reference Guide.
Note:
The FIPS feature is not currently supported for use with appliances (nodes) in a high availability (HA) setup.