Veritas-bu

[Veritas-bu] Disable alternate client restores

2008-07-30 23:32:58
Subject: [Veritas-bu] Disable alternate client restores
From: spaldam <netbackup-forum AT backupcentral DOT com>
To: VERITAS-BU AT mailman.eng.auburn DOT edu
Date: Wed, 30 Jul 2008 23:21:47 -0400
If you can't trust your Backup administrator(s) - regardless of what backup 
software you are using - then you are in big trouble.  You can lock NetBackup 
down so that only certain people can access the backup/restore functionality on 
the master; but that also means they can't have "root" or "admin" access on the 
master.

Encrypting the backed up data might be an option to reduce (not eliminate) any 
risks you're concerned about, if you do it in such a way that it requires 
multiple people controlling multiple keys (I only know of one key management 
systems that provides this functionality) but it would be a nightmare to manage 
all those keys as they would have to be rotated very frequently.

+----------------------------------------------------------------------
|This was sent by spaldam AT spaldam DOT com via Backup Central.
|Forward SPAM to abuse AT backupcentral DOT com.
+----------------------------------------------------------------------


_______________________________________________
Veritas-bu maillist  -  Veritas-bu AT mailman.eng.auburn DOT edu
http://mailman.eng.auburn.edu/mailman/listinfo/veritas-bu

<Prev in Thread] Current Thread [Next in Thread>
  • [Veritas-bu] Disable alternate client restores, spaldam <=