Prerequisites
Review the given prerequisites before you configure FIPS in your NetBackup environment.
Ensure the following before FIPS mode is enabled in the NetBackup domain and on the NetBackup clients.
The NetBackup primary server and media servers are 10.0 or later.
NetBackup clients are 8.1 or later.
You have reviewed FIPS support information.
Note:
If FIPS mode is enabled and the backups are targeted to the media server deduplication pool (MSDP), the CPU consumption of your system may increase.
For seamless SSL communication among the NetBackup processes while FIPS mode is enabled, ensure the following:
The NetBackup CA private key is in a FIPS-compliant encryption format that is PKCS 8.
The private key is generated with a FIPS-compliant algorithm for example, RSA.
The private key strength of the NetBackup CA is set to 2048 or 3072 bits.
If the private key strength does not match the supported value, migrate the CA.
If you have configured external CA, contact the concerned security administrator.
The ongoing NetBackup CA migration process is complete.
Warning:
If the prerequisites are not met, some of the NetBackup functions may not work.