Comprehensive data protection for all workloads
Post Reply
tim_829
Lurker
Posts: 2
Liked: never
Joined: Apr 28, 2020 3:11 pm
Full Name: Tim S
Contact:

Veeam and FIPS 140-2 Compliance Clarification

Post by tim_829 »

So, I need some clarification of Veeam and FIPS 140-2 Compliance.

Are all versions from Veeam Backup & Replication 9.5 Update 4 and newer compliant or is there a "special" Federal version you have to download and install? The https://www.veeam.com/federal.html page almost makes it sound like there's different version.

If anything on or above 9.5 Update 4 is, what makes it compliant? Does it just mean that algorithms used for the network traffic encryption and the "at rest" encryption now meet the standards to make it FIPS 140-2 Compliant?

Any clarification would be appreciated! Thanks
Gostev
Chief Product Officer
Posts: 31814
Liked: 7302 times
Joined: Jan 01, 2006 1:01 am
Location: Baar, Switzerland
Contact:

Re: Veeam and FIPS 140-2 Compliance Clarification

Post by Gostev »

Yes, there's in fact a special U.S. Federal build, particularly because there are performance implications of using FIPS-certified modules... from what I remember, they perform a bunch of extra checks which slow things down, for example validating its own integrity etc.

This build is not available for public download, so you should contact your Veeam sales rep for delivery.

Thanks.
tim_829
Lurker
Posts: 2
Liked: never
Joined: Apr 28, 2020 3:11 pm
Full Name: Tim S
Contact:

Re: Veeam and FIPS 140-2 Compliance Clarification

Post by tim_829 »

Thanks for the response, I'll contact our Veeam Rep.
squebel
Service Provider
Posts: 153
Liked: 14 times
Joined: Sep 27, 2019 5:06 pm
Contact:

Re: Veeam and FIPS 140-2 Compliance Clarification

Post by squebel »

This post is obviously 3.5 years old at this point and we're all the way up to version 12.1 now but is there still any truth to this that there is some special build that we need to obtain?
Gostev
Chief Product Officer
Posts: 31814
Liked: 7302 times
Joined: Jan 01, 2006 1:01 am
Location: Baar, Switzerland
Contact:

Re: Veeam and FIPS 140-2 Compliance Clarification

Post by Gostev »

Starting from V11, we use our FIPS-certified modules also for the standard product build.
Post Reply

Who is online

Users browsing this forum: Google [Bot], Semrush [Bot] and 60 guests