Unsolved
This post is more than 5 years old
1 Rookie
•
7 Posts
0
1631
March 13th, 2018 03:00
DD Boost for SAP HANA 2.0 and encrypted Backups?
Hello folks,
Would someone mind posting information about what DD Boost offers in terms of encrypting backups for SAP HANA 2.0 (SPS01+) deployments please?
SAP HANA 2.0 brings in native backup encryption and I am curious about what integration DD Boost has to that or does it's own thing in terms of encryption.
Essentially, we want to be able to;
- Encrypt the data stream from SAP HANA 2.0 > DD Appliance
- The actual data must be encrypted on the DD Appliance (Data at Rest encryption does not help here)
- Prevent unauthorized restores by backup admins by way of a vaulted encryption password, held by the business owner
- Try to keep the best TCO of the DD appliance (de-dup rate) if that is possible at all when the source is encrypted
thanks!
James


rugby01
85 Posts
0
March 13th, 2018 07:00
If you turn on encryption of the Data Domain, and the DDBEA client - the packet and storage will be encrypted end-to-end using the native HANA backup tools. The access to the backup is controlled by a lockbox file and permissions to open the lockbox can be limited to specific users via standard ACLs. Encryption using the DDBEA client to the DD doesn't effect deduplication rates, but does sometimes effect perfomrance (Based on change rates).
Keys can be management can be found here:
https://www.emc.com/collateral/white-papers/h11561-data-domain-encryption-wp.pdf
JamesBaldwin
1 Rookie
•
7 Posts
0
March 13th, 2018 09:00
Thanks rugby01 for the reply.
When you refer to the lockbox, do you mean a lockbox on the DD appliance, controlled by an added security role?
- Is there a lockbox available on the DDBEA client to secure access to that backup from the client itself?
Is there any documentation/TTT material relative to the DDBEA configuration and information around it for HANA 2.0, please?
thanks!
James
rugby01
85 Posts
0
March 14th, 2018 05:00
The Lockbox is local to every machine and it's a encrypted file create as part of the installation of DDBEA.
https://support.emc.com/docu85245_Data_Domain_Boost_for_Enterprise_Applications_and_ProtectPoint_Database_Application_Agent_4.0_Installation_and_Administration_Guide.pdf?language=en_US