https://login.veeam.com/en/oauth?client_id=nXojRrypJ8&redirect_uri=https%3A%2F%2Fwww.veeam.com%2Fservices%2Fauthentication%2Fredirect_url&response_type=code&scope=profile&state=eyJmaW5hbFJlZGlyZWN0TG9jYXRpb24iOiJodHRwczovL3d3dy52ZWVhbS5jb20va2IzMDUxIiwiaGFzaCI6ImRkYmY3NGU3LTdiNzAtNDA3NC04OGRhLTBmOTg0MmRmZWY1MSJ9
1-800-691-1991 | 9am - 8pm ET
EN

Backup jobs targeted at Linux backup repository fail after enabling FIPS 140-2 mode on repository server

Challenge

After enabling FIPS mode on a Linux repository server, backup jobs fail; log review reveals that Veeam Backup & Replication is unable to make an SSH connection to the repository:
 
[31.08.2019 00:00:00] Warning Failed to create SSH connection to host: '<hostname>', port: 22, user: '<username>', elevation to root: 'yes', autoSudo: no, use su if sudo fails: no, auth type: 'Password', host name: <hostname>, IPs: [<ipaddress>].. Server does not support diffie-hellman-group1-sha1 for keyexchange

Cause

Veeam Backup & Replication connects to the Linux repository server using the Granados SSH library that does not support FIPS mode.

Veeam Backup & Replication can use one of the following SSH libraries to connect to a Linux server: 
  • Granados SSH — this library does not support FIPS 140-2 compliant key exchange methods. Veeam uses this library if FIPS mode was not enabled on the Linux server at the time when the server was added in the Veeam backup console. 
  • Renci SSH — this library supports FIPS 140-2 compliant key exchange methods. Veeam uses this library if FIPS mode was enabled on the Linux server at the time when the server was added in the Veeam backup console. 
After you add a Linux server in the Veeam backup console, Veeam Backup & Replication selects which SSH library to use to connect to the server and uses the selected library for all subsequent connections.

For example, you add a Linux server in the Veeam backup console at the time when FIPS mode is not enabled on this server. In this case, Veeam Backup & Replication connects to the server using the Granados SSH library. If you then enable FIPS mode on the server, Veeam Backup & Replication will still attempt to make connections to the server using Granados SSH, and these connections will fail.

Solution

After you enable FIPS mode on a Linux repository server, add the server once again in the Veeam backup console:
  1. In the Veeam Backup console, click Backup Infrastructure > Managed Servers > Linux.
  2. Right-click the server in the list and click Properties....
  3. Follow the steps of the Edit Linux Server wizard without changing the server properties — just click Next, and then click Finish.
Veeam Backup & Replication will start using the Renci SSH library to connect to the Linux server.

More information

If you are unable to get through the properties of the Linux repository server without an error, check that the credentials used to connect to the server are valid and that there are no firewalls blocking port 22 between the Veeam backup server and the Linux server.

Try using PuTTY to make an SSH connection to the Linux server from the Veeam backup server using the same credentials that are specified in the Veeam backup console. This will help to ensure that it is possible to connect to the server outside of the Veeam software.

If issues remain, please contact Veeam Support.
KB ID:
3051
Product:
Veeam Backup & Replication
Published:
2019-11-14
Last Modified:
2020-08-13
Please rate how helpful this article was to you:
5 out of 5 based on 1 ratings
Thank you for helping us improve!
An error occurred during voting. Please try again later.

Couldn't find what you were looking for?

Below you can submit an idea for a new knowledge base article.
Report a typo on this page:

Please select a spelling error or a typo on this page with your mouse and press CTRL + Enter to report this mistake to us. Thank you!

Spelling error in text

Knowledge base content request
By submitting, you agree that your personal data will be managed by Veeam in accordance with the Privacy Policy.
Your report was sent to the responsible team. Our representative will contact you by email you provided.
We're working on it please try again later