DPM 2012 – Part 4: Certificate based authentication
By Paul Schnackenburg | No Comments | PermalinkIn this fourth and last part of this DPM 2012 review series we’ll look at a new authentication mechanism for servers in untrusted domains or workgroups and we look at some improvements that should be added to DPM and conclude the series with some overall comments.
DPM 2010 provides the ability to protect servers in workgroup or non-trusted domains, using local accounts and NTLM based authentication. This capability proved less than popular in large enterprises because of the inherent weakness in NTLM, auditing difficulties and local account management. DPM 2012 adds another authentication method (the previous capabilities are still available); certificate based authentication. The following workloads are supported; SQL Server, File Server, Hyper-V and these can be clustered as well as standalone (note the missing pieces here, no Exchange, SharePoint, System State / Bare Metal Recovery or client computers). A secondary DPM server for DR can also use this authentication method.
All protection in DPM is done around the concept of Protection Groups.




Subscribe via e-mail: