Comprehensive data protection for all workloads
Post Reply
matteu
Veeam Legend
Posts: 823
Liked: 128 times
Joined: May 11, 2018 8:42 am
Contact:

Hardened repository root privilege

Post by matteu »

Hello,

I would like to understand correctly how to do a correct installation of an hardened repository witch user / password.

I create standard account "repouser" and give him full access to my /VeeamRepo01 on my repository server.

My question is on : How to integrate it with Veeam.

In the documentation, it's written to use single use -> ok.
Then I need to check elevate account privileges automatically and use su if sudo fails and enter root account password.

My issue is on Ubuntu 20.04 root account is not allowed to authenticate on the server. This method didn't work.

What I usually do : Add my repouser to sudo group, install services and then remove the user for the group. Is it a good idea ? I see this method on lot of web site not hosted on veeam site.
On veeam site, I don't know how it can work (or I need to enable root account).

Thanks for your answer :)
Gostev
Chief Product Officer
Posts: 31816
Liked: 7302 times
Joined: Jan 01, 2006 1:01 am
Location: Baar, Switzerland
Contact:

Re: Hardened repository root privilege

Post by Gostev »

Hello. You are absolutely correct: temporarily adding repouser to sudo would be the best way to go with Ubuntu. Thanks!
Regnor
VeeaMVP
Posts: 1007
Liked: 314 times
Joined: Jan 31, 2011 11:17 am
Full Name: Max
Contact:

Re: Hardened repository root privilege

Post by Regnor »

Like Anton writes, it is possible to remove the user from the sudo group after setting up the repository.
The following guide describes the process very well:
https://www.starwindsoftware.com/blog/v ... ory-part-1
matteu
Veeam Legend
Posts: 823
Liked: 128 times
Joined: May 11, 2018 8:42 am
Contact:

Re: Hardened repository root privilege

Post by matteu »

Hello,

As i wrote, I just wanted to know if my method is correct or I need to do it in an othrr way but it seems the documentation need to be updated because for ubuntu this cannot write without any action on root user.
Thank you for this confirmation gostev.
Veeam forum is absolutely excellent to improve knowledge and obtain answer :)
Post Reply

Who is online

Users browsing this forum: Bing [Bot] and 84 guests