About multi-person authorization
NetBackup Security Administrator can configure multi-person authorization that helps protect primary servers from an undesirable or a malicious act, in a proactive manner. Multi-person authorization ensures that a second authorized user approves actions before they are performed.
To configure multi-person authorization in NetBackup, you need to have two users: one is the requester and other is the approver.
A requester cannot be an approver of his or her own tickets.
Multi-person authorization is not supported in a domain where NetBackup access control (NBAC) is enabled.
Multi-person authorization is not supported for catalog maintenance operations by certain database agents.
As part of the database catalog synchronization, the database may initiate an image expiration request through command-line or other interfaces to the NetBackup catalog, which does not generate multi-person authorization ticket.
To prevent the direct expiration of backup images by database agents see the 'About preventing the direct expiration of backup images' topic in the NetBackup for Oracle Administrator's Guide.
Ticket - Ticket is a multi-person authorization request to perform a critical operation.
Requester - Requester is an end user who wants to perform a critical operation that requires multi-person authorization.
Approver - Approver is an individual who reviews and allows an operation that requires multi-person authorization by approving a ticket.
Exempted user - An exempted user does not require to go through the multi-person authorization workflow, and must be used only to perform critical operations like image expiry and image hold removal.
For additional security, it is recommended that there should not be any exempted users.
The following operations and the associated command-line options need multi-person authorization:
Expiring images expiry:
bpexpdate
nbdecommission
bpimage -deleteCopy
Removing image hold:
nbholdutil -delete
Modifying global security settings:
nbcertcmd -setsecconfig
nbseccmd -setsecurityconfig