Full Disk Encryption

All installation and configuration problems and questions

Moderators: gerski, enjay, williamconley, Op3r, Staydog, gardo, mflorell, MJCoate, mcargile, Kumba, Michael_N

Full Disk Encryption

Postby sammysam1 » Sun Aug 07, 2016 11:57 am

HI

I was wondering if anyone has implemented full disk encryption on a database server (Vicidial Cluster setup) and if there is a performance hit or any other complications?

https://en.opensuse.org/SDB:Encrypted_root_file_system

We need to implement encryption of data at rest for PCI compliance.

Thanks
Sam
sammysam1
 
Posts: 4
Joined: Wed Sep 09, 2015 4:01 pm

Re: Full Disk Encryption

Postby mflorell » Mon Aug 08, 2016 6:22 am

We have one client that tried disk encryption on their database, it did introduce significant delay with unpredictable sessions of inaccessibility of a few seconds each time. Vicidial was basically unusable for them under that scenario.

As for PCI compliance, full disk encryption is NOT a requirement, but there are a lot of other requirements, depending on the size of your business and how many credit card transactions you process.

On our hosted service, we do offer encrypted custom fields for VICIdial, where the data is stored as encrypted in the database(not using MySQL encryption), But it is not a part of the public VICIdial codebase,
http://www.vicihost.com/?p=131

Another option is to use native MySQL encryption to only encrypt the fields that need to be protected,
https://dev.mysql.com/doc/refman/5.5/en ... tions.html
mflorell
Site Admin
 
Posts: 18386
Joined: Wed Jun 07, 2006 2:45 pm
Location: Florida

Re: Full Disk Encryption

Postby sammysam1 » Mon Aug 08, 2016 2:04 pm

Thank you Matt.

Is it alright to do full disk encryption on the archive server?

Btw the hosted solution looks very reasonable. I'll talk to my clients to see if they will move some servers over.
sammysam1
 
Posts: 4
Joined: Wed Sep 09, 2015 4:01 pm

Re: Full Disk Encryption

Postby mflorell » Mon Aug 08, 2016 8:18 pm

I can't say I've ever tried using disk encryption on an archive server. I would suggest testing it first before moving a production server to it.
mflorell
Site Admin
 
Posts: 18386
Joined: Wed Jun 07, 2006 2:45 pm
Location: Florida


Return to Support

Who is online

Users browsing this forum: No registered users and 148 guests