Encryption at Rest Informix Feature
Posted in 2018
A DBA on 11.70 asked about moving to 12.10.xC8's Encryption at Rest (EAR) for a 2.5TB instance: performance cost, application impact, and documentation. Replies explained encryption is transparent to applications (no code changes), table fragmentation is irrelevant, and you can encrypt only selected dbspaces; buffer pool pages stay unencrypted so overhead is mainly on disk I/O and is small with a high cache hit rate. Pointers were given to the IBM Knowledge Center and a Roadshow presentation, plus a warning never to lose or overwrite the keystore files (updated when adding a dbspace or changing the keystore password), since data is unrecoverable without them. Questions about restore-with--encrypt timing and whole-system vs physical/logical restore went unanswered, and a suggestion to have onbar back up the keystore was only floated as a possible RFE.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
Topics: Performance & Tuning, Server Administration, Security, Permissions & Auditing
Hello All, We have an application which is considering using the EAR feature that became available in IDS12.10.FC8. We are currently running IDS11.70.FC8 on HP 11.3. Is anyone using this feature? If so, could I get some feedback on your experience with it in terms of the following? What is the impact on read/write performance? Are any application changes needed? This is a 2.5+ TB instance with many large fragmented tables. Can anyone point me to thorough documentation on this feature? Thanks for any input. Pam Ekstrand Database Administrator Email: pamela.a.ekstrand.-nd@disney.com Home Office: 727-729-8210 Cell: 727-365-3781
Only partial answers: 1- There are no application changes needed because from the application (or authenticated and authorized user) perspective the data is not encrypted. The encryption is transparent to all layers above the database which access the data through the database. 2- I don't see how the fragmentation would have any relevance on this. Note however that you can choose to only encrypt certain dbspace(s) and put the sensitive data in those dbspaces. If not all your data is sensitive (at least to the point you need to encrypt it), you can selectively encrypt your data, by moving some tables/fragments to encrypted dbspaces. 3- Regarding the documentation. Follow the link below: https://www.ibm.com/support/knowledgecenter/SSGU8G_12.1.0/com.ibm.po.doc/new_fea tures_ce.htm#newxc8__xc8_ear Regards. On Tue, Jan 23, 2018 at 4:31 PM, Ekstrand, Pamela A. -ND < Pamela.A.Ekstrand.-ND@disney.com> wrote: > Hello All, > > We have an application which is considering using the EAR feature that > became > available in IDS12.10.FC8. We are currently running IDS11.70.FC8 on HP > 11.3. > > Is anyone using this feature? If so, could I get some feedback on your > experience with it in terms of the following? > > What is the impact on read/write performance? > > Are any application changes needed? > > This is a 2.5+ TB instance with many large fragmented tables. > > Can anyone point me to thorough documentation on this feature? > > Thanks for any input. > > Pam Ekstrand > Database Administrator > Email: pamela.a.ekstrand.-nd@disney.com > Home Office: 727-729-8210 > Cell: 727-365-3781 > > > ************************************************************ > ******************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently...
Hello. A very nice and detailed explanation can be found at the Informix RoadShow presentation, shown and shared by Mr Scott Pickett. https://www.ibm.com/developerworks/community/files/app#/file/e883fb7e-d420-4291- 85f8-61c399c16b07 Continue to Files - IBM<https://www.ibm.com/developerworks/community/files/app#/file/e883fb7e-d420-4 291-85f8-61c399c16b07> File sharing on developerWorks lets you exchange information and ideas with your peers without sending large files through email. You can browse public files, files ... www.ibm.com About performance: it would be exactly the same performance demanded by any other encrypt/decrypt DBMS. Maybe some IBM/HCL friend can explain in a deeper level, if there is any specific benefit/lose from Informix engine, but the theory is the same as AES encryption anywhere. Presentation says, for example, that buffer pool pages are not encrypted, so only way of getting too much performance impact would be during read and writes on disk. If your engine has more than 95% of bufreads and bufwrits in cache, this can be almost transparent. Hope it helps. Best regards. Alexandre Marini IBM Informix Certified Professional v10 / v11.50 / v11.70 / v12.10 IBM Informix on Cloud - Database Administrator - 2017 IBM dashDB Managed Service for Analytics and Transactions - 2017 DB2 Advanced DBA - v10.5 for LUW IBM Information Management Informix Technical Professional IBM Certified Developer - Informix Genero Informix independent consultant ________________________________ De: ids-bounces@iiug.org <ids-bounces@iiug.org> em nome de Fernando Nunes <domusonline@gmail.com> Enviado: terça-feira, 23 de janeiro de 2018 14:39 Para: ids@iiug.org Assunto: Re: Encryption at Rest Informix Feature [40542] Only partial answers: 1- There are no application changes needed because from the application (or authenticated and authorized user) perspective the data is not encrypted. The encryption is transparent to all layers above the database which access the data through the database. 2- I don't see how the fragmentation would have any relevance on this. Note however that you can choose to only encrypt certain dbspace(s) and put the sensitive data in those dbspaces. If not all your data is sensitive (at least to the point you need to encrypt it), you can selectively encrypt your data, by moving some tables/fragments to encrypted dbspaces. 3- Regarding the documentation. Follow the link below: https://www.ibm.com/support/knowledgecenter/SSGU8G_12.1.0/com.ibm.po.doc/new_fea tures_ce.htm#newxc8__xc8_ear Regards. On Tue, Jan 23, 2018 at 4:31 PM, Ekstrand, Pamela A. -ND < Pamela.A.Ekstrand.-ND@disney.com> wrote: > Hello All, > > We have an application which is considering using the EAR feature that > became > available in IDS12.10.FC8. We are currently running IDS11.70.FC8 on HP > 11.3. > > Is anyone using this feature? If so, could I get some feedback on your > experience with it in terms of the following? > > What is the impact on read/write performance? > > Are any application changes needed? > > This is a 2.5+ TB instance with many large fragmented tables. > > Can anyone point me to thorough documentation on this feature? > > Thanks for any input. > > Pam Ekstrand > Database Administrator > Email: pamela.a.ekstrand.-nd@disney.com > Home Office: 727-729-8210 > Cell: 727-365-3781 > > > ************************************************************ > ******************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently... ******************************************************************************* Forum Note: Use "Reply" to post a response in the discussion forum.
Thanks, all, for your input. If we were to encrypt all dbspaces in our 2.5 TB instance via a restore with the -encrypt flag, would the encryption cause the restore to run significantly longer than a normal restore? Does it matter whether we do a whole system backup and restore with the -w flag versus a physical and logical restore? Are there any negatives or special considerations anyone is aware of regarding EAR? Thanks again for your help. Pam ________________________________________ From: ids-bounces@iiug.org [ids-bounces@iiug.org] on behalf of Alexandre Marini [alexandre_marini@hotmail.com] Sent: Tuesday, January 23, 2018 12:15 PM To: ids@iiug.org Subject: RE: Encryption at Rest Informix Feature [40544] Hello. A very nice and detailed explanation can be found at the Informix RoadShow presentation, shown and shared by Mr Scott Pickett. https://www.ibm.com/developerworks/community/files/app#/file/e883fb7e-d420-4291- 85f8-61c399c16b07 Continue to Files - IBM<https://www.ibm.com/developerworks/community/files/app#/file/e883fb7e-d420-4 291-85f8-61c399c16b07> File sharing on developerWorks lets you exchange information and ideas with your peers without sending large files through email. You can browse public files, files ... www.ibm.com About performance: it would be exactly the same performance demanded by any other encrypt/decrypt DBMS. Maybe some IBM/HCL friend can explain in a deeper level, if there is any specific benefit/lose from Informix engine, but the theory is the same as AES encryption anywhere. Presentation says, for example, that buffer pool pages are not encrypted, so only way of getting too much performance impact would be during read and writes on disk. If your engine has more than 95% of bufreads and bufwrits in cache, this can be almost transparent. Hope it helps. Best regards. Alexandre Marini IBM Informix Certified Professional v10 / v11.50 / v11.70 / v12.10 IBM Informix on Cloud - Database Administrator - 2017 IBM dashDB Managed Service for Analytics and Transactions - 2017 DB2 Advanced DBA - v10.5 for LUW IBM Information Management Informix Technical Professional IBM Certified Developer - Informix Genero Informix independent consultant ________________________________ De: ids-bounces@iiug.org <ids-bounces@iiug.org> em nome de Fernando Nunes <domusonline@gmail.com> Enviado: terça-feira, 23 de janeiro de 2018 14:39 Para: ids@iiug.org Assunto: Re: Encryption at Rest Informix Feature [40542] Only partial answers: 1- There are no application changes needed because from the application (or authenticated and authorized user) perspective the data is not encrypted. The encryption is transparent to all layers above the database which access the data through the database. 2- I don't see how the fragmentation would have any relevance on this. Note however that you can choose to only encrypt certain dbspace(s) and put the sensitive data in those dbspaces. If not all your data is sensitive (at least to the point you need to encrypt it), you can selectively encrypt your data, by moving some tables/fragments to encrypted dbspaces. 3- Regarding the documentation. Follow the link below: https://www.ibm.com/support/knowledgecenter/SSGU8G_12.1.0/com.ibm.po.doc/new_fea tures_ce.htm#newxc8__xc8_ear Regards. On Tue, Jan 23, 2018 at 4:31 PM, Ekstrand, Pamela A. -ND < Pamela.A.Ekstrand.-ND@disney.com> wrote: > Hello All, > > We have an application which is considering using the EAR feature that > became > available in IDS12.10.FC8. We are currently running IDS11.70.FC8 on HP > 11.3. > > Is anyone using this feature? If so, could I get some feedback on your > experience with it in terms of the following? > > What is the impact on read/write performance? > > Are any application changes needed? > > This is a 2.5+ TB instance with many large fragmented tables. > > Can anyone point me to thorough documentation on this feature? > > Thanks for any input. > > Pam Ekstrand > Database Administrator > Email: pamela.a.ekstrand.-nd@disney.com > Home Office: 727-729-8210 > Cell: 727-365-3781 > > > ************************************************************ > ******************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently... ******************************************************************************* Forum Note: Use "Reply" to post a response in the discussion forum. ******************************************************************************* Forum Note: Use "Reply" to post a response in the discussion forum.
most important warning: don't loose your keystore files, or have them overwritten. No way to get at your data once that has happened, beside= s a new restore. From: "Ekstrand, Pamela A. -ND" <Pamela.A.Ekstrand.-ND@disney.com> To: ids@iiug.org Date: 01/23/2018 10:39 PM Subject: RE: Encryption at Rest Informix Feature [40554] Sent by: ids-bounces@iiug.org Thanks, all, for your input. If we were to encrypt all dbspaces in our 2.5 TB instance via a restore= with the -encrypt flag, would the encryption cause the restore to run significantly longer than a normal restore? Does it matter whether we do a whole system backup and restore with the= -w flag versus a physical and logical restore? Are there any negatives or special considerations anyone is aware of regarding EAR? Thanks again for your help. Pam ________________________________________ From: ids-bounces@iiug.org [ids-bounces@iiug.org] on behalf of Alexandr= e Marini [alexandre_marini@hotmail.com] Sent: Tuesday, January 23, 2018 12:15 PM To: ids@iiug.org Subject: RE: Encryption at Rest Informix Feature [40544] Hello. A very nice and detailed explanation can be found at the Informix RoadS= how presentation, shown and shared by Mr Scott Pickett. https://www.ibm.com/developerworks/community/files/app#/file/e883fb7e-d= 420-4291-85f8-61c399c16b07 Continue to Files - IBM< https://www.ibm.com/developerworks/community/files/app#/file/e883fb7e-d= 420-4291-85f8-61c399c16b07 > File sharing on developerWorks lets you exchange information and ideas = with your peers without sending large files through email. You can browse pu= blic files, files ... www.ibm.com About performance: it would be exactly the same performance demanded by= any other encrypt/decrypt DBMS. Maybe some IBM/HCL friend can explain in a deeper level, if there is an= y specific benefit/lose from Informix engine, but the theory is the same = as AES encryption anywhere. Presentation says, for example, that buffer pool pages are not encrypte= d, so only way of getting too much performance impact would be during read an= d writes on disk. If your engine has more than 95% of bufreads and bufwri= ts in cache, this can be almost transparent. Hope it helps. Best regards. Alexandre Marini IBM Informix Certified Professional v10 / v11.50 / v11.70 / v12.10 IBM Informix on Cloud - Database Administrator - 2017 IBM dashDB Managed Service for Analytics and Transactions - 2017 DB2 Advanced DBA - v10.5 for LUW IBM Information Management Informix Technical Professional IBM Certified Developer - Informix Genero Informix independent consultant ________________________________ De: ids-bounces@iiug.org <ids-bounces@iiug.org> em nome de Fernando Nun= es <domusonline@gmail.com> Enviado: ter=E7a-feira, 23 de janeiro de 2018 14:39 Para: ids@iiug.org Assunto: Re: Encryption at Rest Informix Feature [40542] Only partial answers: 1- There are no application changes needed because from the application= (or authenticated and authorized user) perspective the data is not encrypte= d. The encryption is transparent to all layers above the database which ac= cess the data through the database. 2- I don't see how the fragmentation would have any relevance on this. = Note however that you can choose to only encrypt certain dbspace(s) and put = the sensitive data in those dbspaces. If not all your data is sensitive (at= least to the point you need to encrypt it), you can selectively encrypt= your data, by moving some tables/fragments to encrypted dbspaces. 3- Regarding the documentation. Follow the link below: https://www.ibm.com/support/knowledgecenter/SSGU8G_12.1.0/com.ibm.po.do= c/new_features_ce.htm#newxc8__xc8_ear Regards. On Tue, Jan 23, 2018 at 4:31 PM, Ekstrand, Pamela A. -ND < Pamela.A.Ekstrand.-ND@disney.com> wrote: > Hello All, > > We have an application which is considering using the EAR feature tha= t > became > available in IDS12.10.FC8. We are currently running IDS11.70.FC8 on H= P > 11.3. > > Is anyone using this feature? If so, could I get some feedback on you= r > experience with it in terms of the following? > > What is the impact on read/write performance? > > Are any application changes needed? > > This is a 2.5+ TB instance with many large fragmented tables. > > Can anyone point me to thorough documentation on this feature? > > Thanks for any input. > > Pam Ekstrand > Database Administrator > Email: pamela.a.ekstrand.-nd@disney.com > Home Office: 727-729-8210 > Cell: 727-365-3781 > > > ************************************************************ > ******************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently... ***********************************************************************= ******** Forum Note: Use "Reply" to post a response in the discussion forum. ***********************************************************************= ******** Forum Note: Use "Reply" to post a response in the discussion forum. ***********************************************************************= ******** Forum Note: Use "Reply" to post a response in the discussion forum. =
Thanks, Andreas. Are those files ever updated after they are created when encryption is originally established? ________________________________________ From: ids-bounces@iiug.org [ids-bounces@iiug.org] on behalf of Andreas Legner1 [Andreas.Legner1@de.ibm.com] Sent: Wednesday, January 24, 2018 8:25 AM To: ids@iiug.org Subject: RE: Encryption at Rest Informix Feature [40559] most important warning: don't loose your keystore files, or have them overwritten. No way to get at your data once that has happened, beside= s a new restore. From: "Ekstrand, Pamela A. -ND" <Pamela.A.Ekstrand.-ND@disney.com> To: ids@iiug.org Date: 01/23/2018 10:39 PM Subject: RE: Encryption at Rest Informix Feature [40554] Sent by: ids-bounces@iiug.org Thanks, all, for your input. If we were to encrypt all dbspaces in our 2.5 TB instance via a restore= with the -encrypt flag, would the encryption cause the restore to run significantly longer than a normal restore? Does it matter whether we do a whole system backup and restore with the= -w flag versus a physical and logical restore? Are there any negatives or special considerations anyone is aware of regarding EAR? Thanks again for your help. Pam ________________________________________ From: ids-bounces@iiug.org [ids-bounces@iiug.org] on behalf of Alexandr= e Marini [alexandre_marini@hotmail.com] Sent: Tuesday, January 23, 2018 12:15 PM To: ids@iiug.org Subject: RE: Encryption at Rest Informix Feature [40544] Hello. A very nice and detailed explanation can be found at the Informix RoadS= how presentation, shown and shared by Mr Scott Pickett. https://www.ibm.com/developerworks/community/files/app#/file/e883fb7e-d= 420-4291-85f8-61c399c16b07 Continue to Files - IBM< https://www.ibm.com/developerworks/community/files/app#/file/e883fb7e-d= 420-4291-85f8-61c399c16b07 > File sharing on developerWorks lets you exchange information and ideas = with your peers without sending large files through email. You can browse pu= blic files, files ... www.ibm.com About performance: it would be exactly the same performance demanded by= any other encrypt/decrypt DBMS. Maybe some IBM/HCL friend can explain in a deeper level, if there is an= y specific benefit/lose from Informix engine, but the theory is the same = as AES encryption anywhere. Presentation says, for example, that buffer pool pages are not encrypte= d, so only way of getting too much performance impact would be during read an= d writes on disk. If your engine has more than 95% of bufreads and bufwri= ts in cache, this can be almost transparent. Hope it helps. Best regards. Alexandre Marini IBM Informix Certified Professional v10 / v11.50 / v11.70 / v12.10 IBM Informix on Cloud - Database Administrator - 2017 IBM dashDB Managed Service for Analytics and Transactions - 2017 DB2 Advanced DBA - v10.5 for LUW IBM Information Management Informix Technical Professional IBM Certified Developer - Informix Genero Informix independent consultant ________________________________ De: ids-bounces@iiug.org <ids-bounces@iiug.org> em nome de Fernando Nun= es <domusonline@gmail.com> Enviado: ter=E7a-feira, 23 de janeiro de 2018 14:39 Para: ids@iiug.org Assunto: Re: Encryption at Rest Informix Feature [40542] Only partial answers: 1- There are no application changes needed because from the application= (or authenticated and authorized user) perspective the data is not encrypte= d. The encryption is transparent to all layers above the database which ac= cess the data through the database. 2- I don't see how the fragmentation would have any relevance on this. = Note however that you can choose to only encrypt certain dbspace(s) and put = the sensitive data in those dbspaces. If not all your data is sensitive (at= least to the point you need to encrypt it), you can selectively encrypt= your data, by moving some tables/fragments to encrypted dbspaces. 3- Regarding the documentation. Follow the link below: https://www.ibm.com/support/knowledgecenter/SSGU8G_12.1.0/com.ibm.po.do= c/new_features_ce.htm#newxc8__xc8_ear Regards. On Tue, Jan 23, 2018 at 4:31 PM, Ekstrand, Pamela A. -ND < Pamela.A.Ekstrand.-ND@disney.com> wrote: > Hello All, > > We have an application which is considering using the EAR feature tha= t > became > available in IDS12.10.FC8. We are currently running IDS11.70.FC8 on H= P > 11.3. > > Is anyone using this feature? If so, could I get some feedback on you= r > experience with it in terms of the following? > > What is the impact on read/write performance? > > Are any application changes needed? > > This is a 2.5+ TB instance with many large fragmented tables. > > Can anyone point me to thorough documentation on this feature? > > Thanks for any input. > > Pam Ekstrand > Database Administrator > Email: pamela.a.ekstrand.-nd@disney.com > Home Office: 727-729-8210 > Cell: 727-365-3781 > > > ************************************************************ > ******************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently... ***********************************************************************= ******** Forum Note: Use "Reply" to post a response in the discussion forum. ***********************************************************************= ******** Forum Note: Use "Reply" to post a response in the discussion forum. ***********************************************************************= ******** Forum Note: Use "Reply" to post a response in the discussion forum. = ******************************************************************************* Forum Note: Use "Reply" to post a response in the discussion forum.
Whenever you add a dbspace... or if you change the keystore password... I think that's all. On Wed, Jan 24, 2018 at 2:50 PM, Ekstrand, Pamela A. -ND < Pamela.A.Ekstrand.-ND@disney.com> wrote: > Thanks, Andreas. > > Are those files ever updated after they are created when encryption is > originally established? > > ________________________________________ > From: ids-bounces@iiug.org [ids-bounces@iiug.org] on behalf of Andreas > Legner1 > [Andreas.Legner1@de.ibm.com] > Sent: Wednesday, January 24, 2018 8:25 AM > To: ids@iiug.org > Subject: RE: Encryption at Rest Informix Feature [40559] > > most important warning: don't loose your keystore files, or have them > overwritten. No way to get at your data once that has happened, beside= > s a > new restore. > > From: "Ekstrand, Pamela A. -ND" <Pamela.A.Ekstrand.-ND@disney.com> > To: ids@iiug.org > Date: 01/23/2018 10:39 PM > Subject: RE: Encryption at Rest Informix Feature [40554] > Sent by: ids-bounces@iiug.org > > Thanks, all, for your input. > > If we were to encrypt all dbspaces in our 2.5 TB instance via a restore= > > with > the -encrypt flag, would the encryption cause the restore to run > significantly > longer than a normal restore? > > Does it matter whether we do a whole system backup and restore with the= > -w > flag versus a physical and logical restore? > > Are there any negatives or special considerations anyone is aware of > regarding > EAR? > > Thanks again for your help. > > Pam > > ________________________________________ > From: ids-bounces@iiug.org [ids-bounces@iiug.org] on behalf of Alexandr= > e > Marini [alexandre_marini@hotmail.com] > Sent: Tuesday, January 23, 2018 12:15 PM > To: ids@iiug.org > Subject: RE: Encryption at Rest Informix Feature [40544] > > Hello. > A very nice and detailed explanation can be found at the Informix RoadS= > how > presentation, shown and shared by Mr Scott Pickett. > > https://www.ibm.com/developerworks/community/files/app#/file/e883fb7e-d= > 420-4291-85f8-61c399c16b07 > > Continue to Files - > > IBM< > https://www.ibm.com/developerworks/community/files/app#/file/e883fb7e-d= > 420-4291-85f8-61c399c16b07 > > > File sharing on developerWorks lets you exchange information and ideas = > with > > your peers without sending large files through email. You can browse pu= > blic > > files, files ... > www.ibm.com > > About performance: it would be exactly the same performance demanded by= > any > > other encrypt/decrypt DBMS. > > Maybe some IBM/HCL friend can explain in a deeper level, if there is an= > y > specific benefit/lose from Informix engine, but the theory is the same = > as > AES > encryption anywhere. > Presentation says, for example, that buffer pool pages are not encrypte= > d, > so > only way of getting too much performance impact would be during read an= > d > writes on disk. If your engine has more than 95% of bufreads and bufwri= > ts > in > cache, this can be almost transparent. > > Hope it helps. > > Best regards. > > Alexandre Marini > IBM Informix Certified Professional v10 / v11.50 / v11.70 / v12.10 > IBM Informix on Cloud - Database Administrator - 2017 > IBM dashDB Managed Service for Analytics and Transactions - 2017 > DB2 Advanced DBA - v10.5 for LUW > IBM Information Management Informix Technical Professional > IBM Certified Developer - Informix Genero > Informix independent consultant > > ________________________________ > De: ids-bounces@iiug.org <ids-bounces@iiug.org> em nome de Fernando Nun= > es > <domusonline@gmail.com> > Enviado: ter=E7a-feira, 23 de janeiro de 2018 14:39 > Para: ids@iiug.org > Assunto: Re: Encryption at Rest Informix Feature [40542] > > Only partial answers: > > 1- There are no application changes needed because from the application= > (or > > authenticated and authorized user) perspective the data is not encrypte= > d. > The encryption is transparent to all layers above the database which ac= > cess > > the data through the database. > > 2- I don't see how the fragmentation would have any relevance on this. = > Note > > however that you can choose to only encrypt certain dbspace(s) and put = > the > sensitive data in those dbspaces. If not all your data is sensitive (at= > > least to the point you need to encrypt it), you can selectively encrypt= > > your data, by moving some tables/fragments to encrypted dbspaces. > > 3- Regarding the documentation. Follow the link below: > > https://www.ibm.com/support/knowledgecenter/SSGU8G_12.1.0/com.ibm.po.do= > c/new_features_ce.htm#newxc8__xc8_ear > > Regards. > > On Tue, Jan 23, 2018 at 4:31 PM, Ekstrand, Pamela A. -ND < > Pamela.A.Ekstrand.-ND@disney.com> wrote: > > > Hello All, > > > > We have an application which is considering using the EAR feature tha= > t > > became > > available in IDS12.10.FC8. We are currently running IDS11.70.FC8 on H= > P > > 11.3. > > > > Is anyone using this feature? If so, could I get some feedback on you= > r > > experience with it in terms of the following? > > > > What is the impact on read/write performance? > > > > Are any application changes needed? > > > > This is a 2.5+ TB instance with many large fragmented tables. > > > > Can anyone point me to thorough documentation on this feature? > > > > Thanks for any input. > > > > Pam Ekstrand > > Database Administrator > > Email: pamela.a.ekstrand.-nd@disney.com > > Home Office: 727-729-8210 > > Cell: 727-365-3781 > > > > > > ************************************************************ > > ******************* > > Forum Note: Use "Reply" to post a response in the discussion forum. > > > > > > -- > Fernando Nunes > Portugal > > http://informix-technology.blogspot.com > My email works... but I don't check it frequently... > > ***********************************************************************= > ******** > > Forum Note: Use "Reply" to post a response in the discussion forum. > > ***********************************************************************= > ******** > > Forum Note: Use "Reply" to post a response in the discussion forum. > > ***********************************************************************= > ******** > > Forum Note: Use "Reply" to post a response in the discussion forum. > > = > > > ************************************************************ > ******************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > > ************************************************************ > ******************* > Forum Note: Use "Reply" to post a response in the discussion forum. > > -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently...
Could onbar be enhanced to backup the keystore file as part of the critical
files?
https://www.ibm.com/support/knowledgecenter/SSGU8G_12.1.0/com.ibm.bar.doc/ids_ba
r_217.htm
Regards,
David.
> On 24 January 2018 at 15:01 Fernando Nunes <domusonline@gmail.com> wrote:
>
>
> Whenever you add a dbspace... or if you change the keystore password...
> I think that's all.
>
> On Wed, Jan 24, 2018 at 2:50 PM, Ekstrand, Pamela A. -ND <
> Pamela.A.Ekstrand.-ND@disney.com> wrote:
>
> > Thanks, Andreas.
> >
> > Are those files ever updated after they are created when encryption is
> > originally established?
> >
> > ________________________________________
> > From: ids-bounces@iiug.org [ids-bounces@iiug.org] on behalf of Andreas
> > Legner1
> > [Andreas.Legner1@de.ibm.com]
> > Sent: Wednesday, January 24, 2018 8:25 AM
> > To: ids@iiug.org
> > Subject: RE: Encryption at Rest Informix Feature [40559]
> >
> > most important warning: don't loose your keystore files, or have them
> > overwritten. No way to get at your data once that has happened, beside=
> > s a
> > new restore.
> >
> > From: "Ekstrand, Pamela A. -ND" <Pamela.A.Ekstrand.-ND@disney.com>
> > To: ids@iiug.org
> > Date: 01/23/2018 10:39 PM
> > Subject: RE: Encryption at Rest Informix Feature [40554]
> > Sent by: ids-bounces@iiug.org
> >
> > Thanks, all, for your input.
> >
> > If we were to encrypt all dbspaces in our 2.5 TB instance via a restore=
> >
> > with
> > the -encrypt flag, would the encryption cause the restore to run
> > significantly
> > longer than a normal restore?
> >
> > Does it matter whether we do a whole system backup and restore with the=
> > -w
> > flag versus a physical and logical restore?
> >
> > Are there any negatives or special considerations anyone is aware of
> > regarding
> > EAR?
> >
> > Thanks again for your help.
> >
> > Pam
> >
> > ________________________________________
> > From: ids-bounces@iiug.org [ids-bounces@iiug.org] on behalf of Alexandr=
> > e
> > Marini [alexandre_marini@hotmail.com]
> > Sent: Tuesday, January 23, 2018 12:15 PM
> > To: ids@iiug.org
> > Subject: RE: Encryption at Rest Informix Feature [40544]
> >
> > Hello.
> > A very nice and detailed explanation can be found at the Informix RoadS=
> > how
> > presentation, shown and shared by Mr Scott Pickett.
> >
> > https://www.ibm.com/developerworks/community/files/app#/file/e883fb7e-d=
> > 420-4291-85f8-61c399c16b07
> >
> > Continue to Files -
> >
> > IBM<
> > https://www.ibm.com/developerworks/community/files/app#/file/e883fb7e-d=
> > 420-4291-85f8-61c399c16b07
> > >
> > File sharing on developerWorks lets you exchange information and ideas =
> > with
> >
> > your peers without sending large files through email. You can browse pu=
> > blic
> >
> > files, files ...
> > www.ibm.com
> >
> > About performance: it would be exactly the same performance demanded by=
> > any
> >
> > other encrypt/decrypt DBMS.
> >
> > Maybe some IBM/HCL friend can explain in a deeper level, if there is an=
> > y
> > specific benefit/lose from Informix engine, but the theory is the same =
> > as
> > AES
> > encryption anywhere.
> > Presentation says, for example, that buffer pool pages are not encrypte=
> > d,
> > so
> > only way of getting too much performance impact would be during read an=
> > d
> > writes on disk. If your engine has more than 95% of bufreads and bufwri=
> > ts
> > in
> > cache, this can be almost transparent.
> >
> > Hope it helps.
> >
> > Best regards.
> >
> > Alexandre Marini
> > IBM Informix Certified Professional v10 / v11.50 / v11.70 / v12.10
> > IBM Informix on Cloud - Database Administrator - 2017
> > IBM dashDB Managed Service for Analytics and Transactions - 2017
> > DB2 Advanced DBA - v10.5 for LUW
> > IBM Information Management Informix Technical Professional
> > IBM Certified Developer - Informix Genero
> > Informix independent consultant
> >
> > ________________________________
> > De: ids-bounces@iiug.org <ids-bounces@iiug.org> em nome de Fernando Nun=
> > es
> > <domusonline@gmail.com>
> > Enviado: ter=E7a-feira, 23 de janeiro de 2018 14:39
> > Para: ids@iiug.org
> > Assunto: Re: Encryption at Rest Informix Feature [40542]
> >
> > Only partial answers:
> >
> > 1- There are no application changes needed because from the application=
> > (or
> >
> > authenticated and authorized user) perspective the data is not encrypte=
> > d.
> > The encryption is transparent to all layers above the database which ac=
> > cess
> >
> > the data through the database.
> >
> > 2- I don't see how the fragmentation would have any relevance on this. =
> > Note
> >
> > however that you can choose to only encrypt certain dbspace(s) and put =
> > the
> > sensitive data in those dbspaces. If not all your data is sensitive (at=
> >
> > least to the point you need to encrypt it), you can selectively encrypt=
> >
> > your data, by moving some tables/fragments to encrypted dbspaces.
> >
> > 3- Regarding the documentation. Follow the link below:
> >
> > https://www.ibm.com/support/knowledgecenter/SSGU8G_12.1.0/com.ibm.po.do=
> > c/new_features_ce.htm#newxc8__xc8_ear
> >
> > Regards.
> >
> > On Tue, Jan 23, 2018 at 4:31 PM, Ekstrand, Pamela A. -ND <
> > Pamela.A.Ekstrand.-ND@disney.com> wrote:
> >
> > > Hello All,
> > >
> > > We have an application which is considering using the EAR feature tha=
> > t
> > > became
> > > available in IDS12.10.FC8. We are currently running IDS11.70.FC8 on H=
> > P
> > > 11.3.
> > >
> > > Is anyone using this feature? If so, could I get some feedback on you=
> > r
> > > experience with it in terms of the following?
> > >
> > > What is the impact on read/write performance?
> > >
> > > Are any application changes needed?
> > >
> > > This is a 2.5+ TB instance with many large fragmented tables.
> > >
> > > Can anyone point me to thorough documentation on this feature?
> > >
> > > Thanks for any input.
> > >
> > > Pam Ekstrand
> > > Database Administrator
> > > Email: pamela.a.ekstrand.-nd@disney.com
> > > Home Office: 727-729-8210
> > > Cell: 727-365-3781
> > >
> > >
> > > ************************************************************
> > > *******************
> > > Forum Note: Use "Reply" to post a response in the discussion forum.
> > >
> > >
> >
> > --
> > Fernando Nunes
> > Portugal
> >
> > http://informix-technology.blogspot.com
> > My email works... but I don't check it frequently...
> >
> > ***********************************************************************=
> > ********
> >
> > Forum Note: Use "Reply" to post a response in the discussion forum.
> >
> > ***********************************************************************=
> > ********
> >
> > Forum Note: Use "Reply" to post a response in the discussion forum.
> >
> > *****************************************
That is an excellent topic for an RFE. Submit it and give us the link for voting.
Also when you change the master key for the keystore:
https://www.ibm.com/support/knowledgecenter/SSGU8G_12.1.0/com.ibm.sec.doc/ids_se
c_030.htm
Also backup the password stash file as well as the keystore file.
https://www.ibm.com/support/knowledgecenter/SSGU8G_12.1.0/com.ibm.sec.doc/ids_se
c_026.htm#ids_sec_026
"The password for the keystore file is stored in a stash file."
https://www.ibm.com/support/knowledgecenter/SSGU8G_12.1.0/com.ibm.adref.doc/ids_
adr_1199.htm#ids_adr_1199
"You must manually back up the keystore and password stash files. These files
are not backed up when you run a back up with the ON-Bar or ontape utilities."
Regards,
David.
> On 24 January 2018 at 15:01 Fernando Nunes <domusonline@gmail.com> wrote:
>
>
> Whenever you add a dbspace... or if you change the keystore password...
> I think that's all.
>
> On Wed, Jan 24, 2018 at 2:50 PM, Ekstrand, Pamela A. -ND <
> Pamela.A.Ekstrand.-ND@disney.com> wrote:
>
> > Thanks, Andreas.
> >
> > Are those files ever updated after they are created when encryption is
> > originally established?
> >
> > ________________________________________
> > From: ids-bounces@iiug.org [ids-bounces@iiug.org] on behalf of Andreas
> > Legner1
> > [Andreas.Legner1@de.ibm.com]
> > Sent: Wednesday, January 24, 2018 8:25 AM
> > To: ids@iiug.org
> > Subject: RE: Encryption at Rest Informix Feature [40559]
> >
> > most important warning: don't loose your keystore files, or have them
> > overwritten. No way to get at your data once that has happened, beside=
> > s a
> > new restore.
> >
> > From: "Ekstrand, Pamela A. -ND" <Pamela.A.Ekstrand.-ND@disney.com>
> > To: ids@iiug.org
> > Date: 01/23/2018 10:39 PM
> > Subject: RE: Encryption at Rest Informix Feature [40554]
> > Sent by: ids-bounces@iiug.org
> >
> > Thanks, all, for your input.
> >
> > If we were to encrypt all dbspaces in our 2.5 TB instance via a restore=
> >
> > with
> > the -encrypt flag, would the encryption cause the restore to run
> > significantly
> > longer than a normal restore?
> >
> > Does it matter whether we do a whole system backup and restore with the=
> > -w
> > flag versus a physical and logical restore?
> >
> > Are there any negatives or special considerations anyone is aware of
> > regarding
> > EAR?
> >
> > Thanks again for your help.
> >
> > Pam
> >
> > ________________________________________
> > From: ids-bounces@iiug.org [ids-bounces@iiug.org] on behalf of Alexandr=
> > e
> > Marini [alexandre_marini@hotmail.com]
> > Sent: Tuesday, January 23, 2018 12:15 PM
> > To: ids@iiug.org
> > Subject: RE: Encryption at Rest Informix Feature [40544]
> >
> > Hello.
> > A very nice and detailed explanation can be found at the Informix RoadS=
> > how
> > presentation, shown and shared by Mr Scott Pickett.
> >
> > https://www.ibm.com/developerworks/community/files/app#/file/e883fb7e-d=
> > 420-4291-85f8-61c399c16b07
> >
> > Continue to Files -
> >
> > IBM<
> > https://www.ibm.com/developerworks/community/files/app#/file/e883fb7e-d=
> > 420-4291-85f8-61c399c16b07
> > >
> > File sharing on developerWorks lets you exchange information and ideas =
> > with
> >
> > your peers without sending large files through email. You can browse pu=
> > blic
> >
> > files, files ...
> > www.ibm.com
> >
> > About performance: it would be exactly the same performance demanded by=
> > any
> >
> > other encrypt/decrypt DBMS.
> >
> > Maybe some IBM/HCL friend can explain in a deeper level, if there is an=
> > y
> > specific benefit/lose from Informix engine, but the theory is the same =
> > as
> > AES
> > encryption anywhere.
> > Presentation says, for example, that buffer pool pages are not encrypte=
> > d,
> > so
> > only way of getting too much performance impact would be during read an=
> > d
> > writes on disk. If your engine has more than 95% of bufreads and bufwri=
> > ts
> > in
> > cache, this can be almost transparent.
> >
> > Hope it helps.
> >
> > Best regards.
> >
> > Alexandre Marini
> > IBM Informix Certified Professional v10 / v11.50 / v11.70 / v12.10
> > IBM Informix on Cloud - Database Administrator - 2017
> > IBM dashDB Managed Service for Analytics and Transactions - 2017
> > DB2 Advanced DBA - v10.5 for LUW
> > IBM Information Management Informix Technical Professional
> > IBM Certified Developer - Informix Genero
> > Informix independent consultant
> >
> > ________________________________
> > De: ids-bounces@iiug.org <ids-bounces@iiug.org> em nome de Fernando Nun=
> > es
> > <domusonline@gmail.com>
> > Enviado: ter=E7a-feira, 23 de janeiro de 2018 14:39
> > Para: ids@iiug.org
> > Assunto: Re: Encryption at Rest Informix Feature [40542]
> >
> > Only partial answers:
> >
> > 1- There are no application changes needed because from the application=
> > (or
> >
> > authenticated and authorized user) perspective the data is not encrypte=
> > d.
> > The encryption is transparent to all layers above the database which ac=
> > cess
> >
> > the data through the database.
> >
> > 2- I don't see how the fragmentation would have any relevance on this. =
> > Note
> >
> > however that you can choose to only encrypt certain dbspace(s) and put =
> > the
> > sensitive data in those dbspaces. If not all your data is sensitive (at=
> >
> > least to the point you need to encrypt it), you can selectively encrypt=
> >
> > your data, by moving some tables/fragments to encrypted dbspaces.
> >
> > 3- Regarding the documentation. Follow the link below:
> >
> > https://www.ibm.com/support/knowledgecenter/SSGU8G_12.1.0/com.ibm.po.do=
> > c/new_features_ce.htm#newxc8__xc8_ear
> >
> > Regards.
> >
> > On Tue, Jan 23, 2018 at 4:31 PM, Ekstrand, Pamela A. -ND <
> > Pamela.A.Ekstrand.-ND@disney.com> wrote:
> >
> > > Hello All,
> > >
> > > We have an application which is considering using the EAR feature tha=
> > t
> > > became
> > > available in IDS12.10.FC8. We are currently running IDS11.70.FC8 on H=
> > P
> > > 11.3.
> > >
> > > Is anyone using this feature? If so, could I get some feedback on you=
> > r
> > > experience with it in terms of the following?
> > >
> > > What is the impact on read/write performance?
> > >
> > > Are any application changes needed?
> > >
> > > This is a 2.5+ TB instance with many large fragmented tables.
> > >
> > > Can anyone point me to thorough documentation on this feature?
> > >
> > > Thanks for any input.
> > >
> > > Pam Ekstrand
> > > Database Administrator
> > > Email: pamela.a.ekstrand.-nd@disney.com
> > > Home Office: 727-729-8210
> > > Cell: 727-365-3781
> > >
> > >
> > > ************************************************************
> > > *******************
> > > Forum Note: Use "Reply" to post a response in the discussion forum.
> > >
> > >
> >
> > --
> > Fernando Nunes
> > Portugal
> >
> > http://informix-te
RFE entered at http://www.ibm.com/developerworks/rfe/execute?use_case=viewRfe&CR_ID=115544 Regards, David. On 24 January 2018 at 21:56 Alexandre Marini <alexandre_marini@hotmail.com> wrote: That is an excellent topic for an RFE. Submit it and give us the link for voting. ******************************************************************************* Forum Note: Use "Reply" to post a response in the discussion forum.
Nice! I will vote now