Agent-based backup of Windows, Linux, Max, AIX and Solaris machines.
Post Reply
tbksoco2020
Novice
Posts: 3
Liked: never
Joined: Feb 06, 2020 10:19 pm
Full Name: Brandon Killingsworth
Contact:

Security concern Internal CA signed Certificates with Veeam Agent for Microsoft Windows.

Post by tbksoco2020 »

We opened Veeam Support - Case # 07725251 for unsupported certificate error when trying to backup Windows Agent. Working through Veeam's Managing TLS Certificates documentation we were able to finally get CA certificate modified where it allowed the Agent to communicate with VBR server. However, the changes we had to make for the certificate that the VBR server uses to push client certificate has built-in Subordinate Certification Authority. Which allows too much privileges to create certificates. We already have internal CA Certificates that have built-in Subordinate Certification Authority for Veeam that we would want our CA server creating the client certificates. We would think that other dark site companies like us would not want to allow other applications to control creating certificates. Has anyone else experienced this situation? Was anyone else able to find another workaround? Can there be a feature that Veeam allows customers to use their own CA Certificates and CA Server to control creation of client certs?
Mildur
Product Manager
Posts: 10512
Liked: 2820 times
Joined: May 13, 2017 4:51 pm
Full Name: Fabian K.
Location: Switzerland
Contact:

Re: Security concern Internal CA signed Certificates with Veeam Agent for Microsoft Windows.

Post by Mildur »

Hi Brandon

It's currently not possible to allow external Certificate Authorities to create certificates for our Veeam Agents.
We know about the request, but there is no ETA.
I'll add your voice to the feature request.

Best,
Fabian
Product Management Analyst @ Veeam Software
Post Reply

Who is online

Users browsing this forum: smexiko and 5 guests