Configuring Server as Hardened Repository

For post-installation, follow these steps:

  1. Log in to the server using the vhradmin account. By default, the password is vhradmin.
  2. Select a new password for the account. It must meet the following DISA STIG requirements:
  1. 15 characters minimum.
  2. 1 upper case character.
  3. 1 numeric character.
  4. 1 special character.
  5. No more than 3 characters of the same class in a row. For example, more than 3 lowercase or 3 numerical characters in sequence.
  6. Minimum password lifetime – 24 hours.
  1. Accept the license agreement.
  2. In the Veeam Hardened Repository Configurator, configure the following settings as required:
  • Network settings — Select Standard configuration to set IPv4 addresses, DHCP, and DNS for network interfaces. Alternatively, select Advanced configuration to use nmtui.
  • Proxy settings — Specify an HTTP or HTTPS proxy. Note that self-signed HTTPS proxies are not supported.
  • Time settings — Add an NTP server. When adding the NTP server, consider the following:
  • chronyd is used as the NTP client.
  • NTP servers over DHCP are allowed. This setting cannot be disabled.
  • NTP servers are added with the iburst parameter. No additional options can be specified.
  1. Select the Start SSH option. This will generate credentials for the veeamsvc user that will be used to add the hardened repository to Veeam Backup & Replication. To generate new credentials, restart the SSH service.
  2. Add the server as a hardened repository. For more information, see Adding Hardened Repositories.
  3. After you add the hardened repository, select Stop SSH in the configurator.

Page updated 12/19/2024

Page content applies to build 12.3.0.310