Backup of enterprise applications (Microsoft stack, IBM Db2, MongoDB, Oracle, PostgreSQL, SAP)
Post Reply
D.Lee
Expert
Posts: 121
Liked: 4 times
Joined: Apr 17, 2020 2:45 am
Full Name: Dan Lee
Contact:

connect RMAN plugin with cert base auth?

Post by D.Lee »

Hi gurus,

Working with a case using cert-base authentication to a Oracle Linux running RMAN. Creating protection group and deployment of agent/plugins with cert goes good, but when setting up RMAN plugin backup policy we found the issue the there's no option to leverage cert-base auth for OS user credentials
https://helpcenter.veeam.com/docs/backu ... ml?ver=120

SO user must use SSH (username + pw) to authenticate in OS level?

Support did just replied a yes but was disappointed that even we have a cert but it force the connection to be done via SSH. Can anyone give me a further confirmation here as that's quite confused there's a session to deploy the plugin with cert-base auth, but no way to run the RMAN backup policy with such?
https://helpcenter.veeam.com/docs/backu ... ml?ver=120


Case # 07491516

Thanks.
PetrM
Veeam Software
Posts: 3812
Liked: 643 times
Joined: Aug 28, 2013 8:23 am
Full Name: Petr Makarov
Location: Prague, Czech Republic
Contact:

Re: connect RMAN plugin with cert base auth?

Post by PetrM »

Hi Dan,

In this case, the communication with the Transport service in guest OS will be performed over certificate, and we'll do impersonation under OS user to authenticate against the database. SSH will be used only in case of the Transport service unavailability. It definitely makes sense to describe this case explicitly in the documentation. I will discuss this case with the support team as well, they must be aware of such design specifics.

Thanks!
D.Lee
Expert
Posts: 121
Liked: 4 times
Joined: Apr 17, 2020 2:45 am
Full Name: Dan Lee
Contact:

Re: connect RMAN plugin with cert base auth?

Post by D.Lee » 1 person likes this post

Hi Petr,

Thanks for the confirmation and that's what we expected as the connection was been authenticated with the cert. Unless we got any specific databases that require another credentials for access that should able to done via single cert with sufficient privileges.
Post Reply

Who is online

Users browsing this forum: No registered users and 2 guests