Communications Encryption Standards

To encrypt communication, Veeam Backup & Replication supports the following libraries, modules, and algorithms:

  • SHA-256 — for digital signature generation and SSH fingerprint verification.
  • SHA-1 — for HMAC generation, backward compatibility, and certificate thumbprint generation.
  • OpenSSL, cryptographic libraries provided by the operating system — for random number generation.
  • Veeam Cryptographic Module — for Linux-based components and services. This module is also used for Veeam Data Mover Service installed on Microsoft Windows-based machines.
  • Microsoft Crypto API — for other Microsoft Windows-based components and services.
  • Microsoft Base Cryptographic Provider. For more information, see Microsoft Docs.
  • Microsoft Enhanced RSA and AES Cryptographic Provider. For more information, see Microsoft Docs.
  • Microsoft Enhanced Cryptographic Provider. For more information, see Microsoft Docs.

Note

If you need Veeam Cryptographic Module and Microsoft Crypto API to be compliant with the Federal Information Processing Standards (FIPS 140), enable FIPS compliance as described in section FIPS Compliance.

Veeam Backup & Replication encrypts certificates stored in the configuration database using Data Protection API (DPAPI) mechanisms. For more information, see Microsoft Docs.

Page updated 10/16/2024

Page content applies to build 12.3.0.310