About certificate deployment security levels
NetBackup offers several levels that determine the nature of the CA checks that are performed when the CA receives a certificate request. The level determines the checks that are performed before the CA issues a certificate to a NetBackup host. It also determines how frequently the Certificate Revocation List (CRL) is refreshed on the host.
See About the host ID-based certificate revocation list.
Choose a certificate deployment level that corresponds with the security constraints and requirements of your NetBackup environment.
Table: Description of certificate deployment security levels lists and describes the three deployment levels.
Table: Description of certificate deployment security levels
Security Level | Description |
|---|---|
Very High | Certificates are deployed on hosts during installation after confirming the master server fingerprint or through the nbcertcmd command. An authorization token is required for every new certificate request. See Creating authorization tokens. The Certificate Revocation List (CRL) that is present on the host is refreshed after every one hour. |
High (default) | Certificates are deployed on hosts during installation after confirming the master server fingerprint or through the nbcertcmd command. No authorization token is required if the host is known to the master server. A host is considered to be known to the master server if the host can be found in the following entities:
See Creating authorization tokens. The Certificate Revocation List (CRL) that is present on the host is refreshed after every four hours. |
Medium | Certificates are deployed on hosts during installation after confirming the master server fingerprint or through the nbcertcmd command. The certificates are issued without an authorization token if the master server can resolve the host name to the IP address from which the request was originated. The Certificate Revocation List (CRL) that is present on the host is refreshed after every eight hours. |