...
id | 202684107 |
---|
...
id | 202684119 |
---|
Section | ||||||
---|---|---|---|---|---|---|
| ||||||
Topics Discussed
|
...
id | 202684109 |
---|
This article explains how to encrypt data using the in-place data transformation, which is also known as dataxform.
At a high level, you will:
Shut down the database software
Place a transformation policy in the directory
Implement encryption
Remove the transformation policy
Add the operational policy
Restart the database software
Note |
---|
During this process, the database software will shut down, which means access to the files in the database will be prevented. |
Note |
---|
Armor recommends that you use the Copy Method for encryption because this method:
|
Prerequisites
...
Before you begin, you must have:
General understanding of the Vormetric product
Strong understanding of how to create GuardPoints in DSM
Strong
...
understanding of how to create policies in DSM
A production key available to use
Encrypt with Data Transform
...
Log into your DSM as a Security Administrator.
In the top menu bar, click Policies.
Click Add Online Policies.
For Name, enter DataXform_Policy.
(Optional) For Description, enter In Place Data Transformation Policy.
Locate the Effect field.
In the Add Online Policy screen, click Add to add a second rule.
Under Key Section Rules, click Add.
Locate the Data Transformation Rules section.
In the top menu bar, click Hosts.
Under Host Name, select the host you want to encrypt.
In the Guard File System screen, click the Policy drop-down menu.
Locate and select the desired path that you want to protect.
In the image below, the sample GuardPoint is: C:\Program Files\Microsoft SQL Server\MSSQL11.MSSQLSERVER\MSSQL\Log\
The GuardPoint you selected will populate the Path field.
Under Status, click the refresh button for the newly created GuardPoint.
On the Windows server where you are going to apply the GuardPoint, right-click on the PowerShell icon, and then select Run as Administrator.
Before you can run the encryption command, you must change into the directory where the Vormetric dataXform utility is located (C:\Program Files\).
Change the directory path where the utility is located (C:\Program Files\Vometric\DataSecurityExpert\agent\vmd\bin).
The utility has a feature that allows you to scan the indended GuardPoint before you run the DataXform command, which can be useful to verify that the GuardPoint can be encrypted and also to offer an estimate on how long the encryption configuration will take.
The DataXform data command function is: .\dataxform ••--deep_scan ••--gp <guard point path>
When you are in the DataXform utility path, you can run the DataXform command with various added arguments. The standard command is: .\dataxform --rekey --gp <directory path>
You can add the .\dataxform --rekey flag to read data with the clear key and write back in with the production key (encrypting the data in place).
You can add --print_state to retrieve a printout of how many files are going to be encrypted and periodic updates of how much data has been encrypted so far.
The command would be .\dataxform --rekey --print_stat --gp <directory path>
You can add the --cleanup_on_success flag to clean up the temporary files created during the DataXform process and are not necessarily needed in the future.
The command would be: .\dataxform --rekey --print_stat --cleanup_on_success —gp <direcotry path>
You can add the --preserve_modified_time flag to preserve the current time stamp of the files being encrypted, instead of changing the time stamp to when DataXform ran.
The command would be: .\dataxform ••--rekey ••--print_stat --cleanup_on_success --
preserve_modified_time
--gp <directory>
After you enter the command, press Enter.
If successful, you will see a text output similar to the screenshot below.
If unsuccessful, make sure there are two dashes before each flag and that the words are spelled correctly.
Assuming your data is already backed up, then press y to continue.
To remove the data transformation status files created earlier, press y, and then press Enter.
Return to the DSM console, and mark the box for the GuardPoint that contains the DataXform policy.
If you are logged out of the DSM console, after you login, click the Hosts tab, select the desired Host Name, and then click Guard FS.
Mark the box next to DataXForm_Policy.
You may need to click Refresh several times before the GuardPoint disappears.
When the GuardPoint disappears, click Guard.
In the pop-up window, in the Policy drop-down menu, select your operational policy in learn mode. (In the screenshots below, the example is R1_Testing_VMW12.
Expand the directory to the path, and then highlight the path you previously encrypted. (In the screenshots below, the example is C:\Program Files\Microsoft SQL Server\MSSQL11.MSSQLSERVER\MSSQ\Log.
Click the Refresh button.
...
Topics Discussed
Table of Contents | ||||
---|---|---|---|---|
|