Veritas NetBackup™ Appliance Security Guide

Last Published:
Product(s): Appliances (4.0)
Platform: NetBackup Appliance OS
  1. About the NetBackup appliance Security Guide
    1.  
      About the NetBackup appliance Security Guide
  2. User authentication
    1. About user authentication on the NetBackup appliance
      1.  
        User types that can authenticate on the NetBackup appliance
    2. About configuring user authentication
      1.  
        Generic user authentication guidelines
    3.  
      About authenticating LDAP users
    4.  
      About authenticating Active Directory users
    5.  
      About authentication using smart cards and digital certificates
    6.  
      About authenticating Kerberos-NIS users
    7.  
      About the appliance login banner
    8. About user name and password specifications
      1.  
        About STIG-compliant password policy rules
  3. User authorization
    1.  
      About user authorization on the NetBackup appliance
    2. About authorizing NetBackup appliance users
      1.  
        NetBackup appliance user role privileges
    3.  
      About the Administrator user role
    4.  
      About the NetBackupCLI user role
    5.  
      About user authorization in NetBackup
  4. Intrusion prevention and intrusion detection systems
    1.  
      About Symantec Data Center Security on the NetBackup appliance
    2.  
      About the NetBackup appliance intrusion prevention system
    3.  
      About the NetBackup appliance intrusion detection system
    4.  
      Reviewing SDCS events on the NetBackup appliance
    5.  
      Running SDCS in unmanaged mode on the NetBackup appliance
    6.  
      Running SDCS in managed mode on the NetBackup appliance
  5. Log files
    1.  
      About NetBackup appliance log files
    2.  
      Viewing log files using the Support command
    3.  
      Where to find NetBackup appliance log files using the Browse command
    4.  
      Gathering device logs on a NetBackup appliance
    5.  
      Log Forwarding feature overview
  6. Operating system security
    1.  
      About NetBackup appliance operating system security
    2.  
      Major components of the NetBackup appliance OS
    3.  
      Vulnerability scanning of the NetBackup appliance
    4.  
      Disable user access to the NetBackup appliance operating system
    5.  
      Manage support access to the maintenance shell
  7. Data security
    1.  
      About data security
    2.  
      About data integrity
    3.  
      About data classification
    4. About data encryption
      1.  
        KMS support
  8. Web security
    1.  
      About SSL usage
    2.  
      Implementing third-party SSL certificates
  9. Network security
    1.  
      About IPsec Channel Configuration
    2.  
      About NetBackup appliance ports
    3.  
      About the NetBackup Appliance firewall
  10. Call Home security
    1. About AutoSupport
      1.  
        Data security standards
    2. About Call Home
      1.  
        Configuring Call Home from the NetBackup Appliance Shell Menu
      2.  
        Enabling and disabling Call Home from the appliance shell menu
      3.  
        Configuring a Call Home proxy server from the NetBackup Appliance Shell Menu
      4.  
        Understanding the Call Home workflow
    3. About SNMP
      1.  
        About the Management Information Base (MIB)
  11. Remote Management Module (RMM) security
    1.  
      Introduction to IPMI configuration
    2.  
      Recommended IPMI settings
    3.  
      RMM ports
    4.  
      Enabling SSH on the Remote Management Module
    5.  
      Replacing the default IPMI SSL certificate
  12. STIG and FIPS conformance
    1.  
      OS STIG hardening for NetBackup appliance
    2.  
      Unenforced STIG hardening rules
    3.  
      FIPS 140-2 conformance for NetBackup appliance
  13. Appendix A. Security release content
    1.  
      NetBackup Appliance security release content
  14.  
    Index

About user name and password specifications

The user name for the NetBackup appliance user account must be in the format that the selected authentication system accepts. Table: User name specifications lists the user name specifications for each user type.

Note:

The Manage > NetBackupCLI > Create command is used to create local users with the NetBackupCLI role. All the local user and password specifications apply to these users.

Table: User name specifications

Description

Administrator (local user)

NetBackupCLI (local user)

Registered remote user

Maximum length

No restrictions applied

No restrictions applied

Determined by the LDAP, AD, or NIS policy

Minimum length

2 characters

2 characters

Determined by the LDAP, AD, or NIS policy

Restrictions

User names must not start with:

  • Number

  • Special character

User names must not start with:

  • Number

  • Special character

Determined by the LDAP, AD, or NIS policy

Space inclusion

User names must not include spaces.

User names must not include spaces.

Determined by the LDAP, AD, or NIS policy

Password specifications

The NetBackup appliance password policy has been updated to increase security on the appliance. The password for the appliance user account must be in the format that the selected authentication system accepts. Table: Password specifications lists the password specifications for each user type.

Table: Password specifications

Description

Administrator (local user)

NetBackupCLI (local user)

Registered remote user

Maximum length

No restrictions applied

No restrictions applied

Determined by the LDAP, AD, or NIS policy

Minimum length

Passwords must contain at least eight characters.

Passwords must contain at least eight characters.

Determined by the LDAP, AD, or NIS policy

Requirements

  • One uppercase letter

  • One lowercase letter (a-z)

  • One number (0-9)

  • Dictionary words are considered as weak passwords and are not accepted.

  • The last seven passwords cannot be reused and the new password cannot be similar to previous passwords.

  • One uppercase letter

  • One lowercase letter (a-z)

  • One number (0-9)

  • Dictionary words are considered as weak passwords and are not accepted.

  • The last seven passwords cannot be reused and the new password cannot be similar to previous passwords.

Determined by the LDAP, AD, or NIS policy

Space inclusion

Passwords must not include spaces.

Passwords must not include spaces.

Determined by the LDAP, AD, or NIS policy

Minimum password age

0 day

0 day

Note:

You can manage the user password age using the Settings > Security > Authentication > LocalUser command from the NetBackup Appliance Shell Menu.

For more information, refer to the NetBackup Appliance Command Reference Guide.

Determined by the LDAP, AD, or NIS policy

Maximum password age

99999 days (doesn't expire)

99999 days (doesn't expire)

Determined by the LDAP, AD, or NIS policy

Password history

The last seven passwords cannot be reused and the new password cannot be similar to previous passwords.

The last seven passwords cannot be reused and the new password cannot be similar to previous passwords.

Determined by the LDAP, AD, or NIS policy

Password expiry

Not applicable as the password does not expire

Use the Settings > Security > Authentication > LocalUser command to manage NetBackupCLI user passwords.

Determined by the LDAP, AD, or NIS policy

Password lockout

None

None

Determined by the LDAP, AD, or NIS policy

Lockout duration

None

None

Determined by the LDAP, AD, or NIS policy

Warning:

Appliances do not support Maintenance account passwords such as passwd. These types of passwords are overwritten once the system is upgraded. Use the NetBackup Appliance Shell Menu to change the Maintenance account password.

Password protection

The NetBackup appliance uses the following password protection measures:

  • The SHA-512 hashing algorithm is used for protecting the passwords of all customer-accessible local appliance users (local users, NetBackupCLI users, the Administrator user, and the Maintenance user). Whenever you create a new local appliance user, or change an existing local appliance user password, the password is hashed using SHA-512.

    Note:

    If you are upgrading from NetBackup appliance software version earlier than 2.6.1.1, Veritas recommends that you eventually change the passwords of all the local appliance users after the upgrade so that they use the latest default SHA-512 hashing algorithm.

  • The password history is set to 7, meaning that the old passwords are protected and logged up to seven times. If you try to use the old password as the new password, the appliance displays a token manipulation error.

  • Passwords in transit include the following:

    • An SSH login where the password is protected by the SSH protocol.

    • A NetBackup Appliance Web Console login where the password is protected by HTTPS communication.

For detailed password instructions, refer to the NetBackup Appliance Administrator's Guide.