RE: Use of Informix with Protegrity/Omnisecure Encryption
Posted in 2007
Topics: Server Administration, Security, Permissions & Auditing, Platform-Specific Issues
I'm a little confused by your question. How would you use a disk encryption software with a relational database? ;-) Now what I'm really saying is that does using an encryption layer make sense with Informix? IMHO, not really. The encryption would be an i/o wrapper and would most likely need Informix to use cooked files. But why? Ok, if the IDS instance is on a laptop or portable computer then you have to worry about someone gaining access to the physical device and doing a dd of the data to gain access. Maybe then you'll have a business case. But encryption to the disk is a lot of overhead that doesn't provide security of anyone who has access to the database. (This is done by field level encryption and permissions). Now since you said HP-UX and AIX, I'm going to assume these are not databases that are on portable machines and are areas that have limited physical access. So I would have to say that there are better ways at securing your data. HTH, -G >From: Pamela Ekstrand <ekstrand@us.ibm.com> > >Has anyone used informix version 10 with the encryption software VP Disk >from Protegrity (formerly Omnisecure)? If so, can you please tell me if >you have run into any issues with it? > >We run informix 10.0.FC4 on both HP-UX 11 and AIX 5.3. > >Thanks for any feedback. > >Pam Ekstrand >DBA, Database Administration - Disney SO Acct >Strategic Outsourcing - Server Systems Operations >Dept LJBK >email: ekstrand@us.ibm.com >Home Office: 727-729-8210 >Cell: 602-418-6141 > >_______________________________________________ >Informix-list mailing list >Informix-list@iiug.org >http://www.iiug.org/mailman/listinfo/informix-list _________________________________________________________________ Check out all that glitters with the MSN Entertainment Guide to the Academy Awards' http://movies.msn.com/movies/oscars2007/?icid=ncoscartagline2
Ian Michael Gumby wrote: > I'm a little confused by your question. > > How would you use a disk encryption software with a relational database? > ;-) > > Now what I'm really saying is that does using an encryption layer make > sense with Informix? > > IMHO, not really. > > The encryption would be an i/o wrapper and would most likely need > Informix to use cooked files. > But why? > > Ok, if the IDS instance is on a laptop or portable computer then you > have to worry about someone gaining access to the physical device and > doing a dd of the data to gain access. Maybe then you'll have a business > case. > > But encryption to the disk is a lot of overhead that doesn't provide > security of anyone who has access to the database. (This is done by > field level encryption and permissions). > > Now since you said HP-UX and AIX, I'm going to assume these are not > databases that are on portable machines and are areas that have limited > physical access. > > So I would have to say that there are better ways at securing your data. > > HTH, > > -G > > > >> From: Pamela Ekstrand <ekstrand@us.ibm.com> >> >> Has anyone used informix version 10 with the encryption software VP Disk >> from Protegrity (formerly Omnisecure)? If so, can you please tell me if >> you have run into any issues with it? >> >> We run informix 10.0.FC4 on both HP-UX 11 and AIX 5.3. >> >> Thanks for any feedback. >> How do you secure Informix Data from root access? It's not easy to read of course, but root can do a simple "dd | strings" :) If this product could handle this kind of situation I'd be interested to know if someone uses it (even with other databases...) Regards. -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently...
>From: Fernando Nunes <spam@domus.online.pt> > >How do you secure Informix Data from root access? It's not easy to read of >course, but root can do a simple "dd | strings" :) >If this product could handle this kind of situation I'd be interested to >know if someone uses it (even with other databases...) Well, How does root do a dd of a live database? ;-) Actually if you have root, then you can su - informix and then access everything. Or su - to any user that can be authenticated on the system, so that negates everything. The issue is that these types of tools work by putting a wrapper around the unix low level I/O and do the encryption on the fly. Only problem is the overhead and that the tools won't let you use KAIO or raw partitions. So it will kill performance and doesn't really offer any true security. If you want to secure your data, determine which fields can/should be encrypted. >Regards. > > >-- >Fernando Nunes >Portugal > >http://informix-technology.blogspot.com >My email works... but I don't check it frequently... >_______________________________________________ >Informix-list mailing list >Informix-list@iiug.org >http://www.iiug.org/mailman/listinfo/informix-list _________________________________________________________________ Turn searches into helpful donations. Make your search count. http://click4thecause.live.com/search/charity/default.aspx?source=hmemtagline_donation&FORM=WLMTAG