Forum Discussion

JTBSANADMIN's avatar
11 years ago

Port 2821 Low level encryption

I'm getting a positive hit on a retina scan for low level encryption (Audit ID:
12237)
. The scan states that it is set to 56 bit. I need to change to
128-bit to comply.

It is getting the hit on port 2821 and the service on the port is
vrts-at-port. This is on the server that I am getting the hit.

Any idea as to how I can change this or why I should not change?

Everything I am finding is pointing me to the client application.

  • Port 2821 is VERITAS Authentication Service. Netbackup access control used that port before netbackup 7.5. In 7.5 and newer the authentication service uses 1556.

    But 2821 may be used for at lot of other Symantec software. So what Symantec software do you have on the client ?

7 Replies

  • Port 2821 is VERITAS Authentication Service. Netbackup access control used that port before netbackup 7.5. In 7.5 and newer the authentication service uses 1556.

    But 2821 may be used for at lot of other Symantec software. So what Symantec software do you have on the client ?

  • First, thank you for your reply.

    NetBackup 7.0 Linux as far as I know.  Don't think Norton is on there.

     

  • I found this tech note - it is for Windows. You mentioned the client is Linux:

    OpsCenter 7.x Server installations may be fail vulnerability assessments due to low strength SSL ciphers being supported by the Symantec Product Authentication Service(VRTSat) component.

    http://www.symantec.com/docs/TECH142600

  • Storage Foundation uses port 2821 (VrtsAT) as well. 

    http://www.symantec.com/docs/TECH158411

     

  • I think the "fix" is to upgrade to at least 7.5.  (Preferably 7.6.0.2!)

  • I am not sure the VRTSat problem is related to the Netbackup client at all.

    Can you do a 

    # rpm -qa

    and attach the output as a file to a post ?