RE: encryption

  • From: Upendra N <nupendra@xxxxxxxxxxx>
  • To: "Brian.Zelli@xxxxxxxxxxxxxxx" <brian.zelli@xxxxxxxxxxxxxxx>, Oracle-L <oracle-l@xxxxxxxxxxxxx>
  • Date: Tue, 19 Mar 2013 13:52:03 -0400

If you are looking at encrypting at the host level, there are a few 3rd party 
tools available to transparently encrypt the data. One such tool is Vormetric. 
It uses an appliance which holds the encryption keys. The databases you want to 
encrypt will be running a Vormetric agent which handles communication between 
the appliance and the encryption. This tool encrypts data at the file system 
level as well as limit file system level access for folks who aren't supposed 
to access the datafiles/logs/binaries etc. 
Here is the link to their white papers:
http://www.vormetric.com/resources/white-papers
We recently implemented in our environment, the conversion to encryption is a 
process which requires downtime, rest of the steps are fairly transparent. 
Since we are have complex replication going, we couldn't use native Oracle 
tools, also this is a fraction of cost compared to TDE.

As everyone else already told, you may want to find out requirements and see if 
the solution you pick meets them.

Good luck!
-Upendra


> From: Brian.Zelli@xxxxxxxxxxxxxxx
> To: oracle-l@xxxxxxxxxxxxx
> Subject: encryption
> Date: Tue, 19 Mar 2013 14:53:00 +0000
> 
> So is TDE the only way to encrypt from the db level?  And is that an added 
> expense?  I am on HPUX.
> ciao,
> Brian
> 
> ----------------------------------
> Brian Zelli
> Senior Database Administrator
> Enterprise Apps/Sys Integration
> Roswell Park Cancer Institute
> (716) 845-4460
> brian.zelli@xxxxxxxxxxxxxxx
> ----------------------------------
> 
> 
> 
> This email message may contain legally privileged and/or confidential 
> information.  If you are not the intended recipient(s), or the employee or 
> agent responsible for the delivery of this message to the intended 
> recipient(s), you are hereby notified that any disclosure, copying, 
> distribution, or use of this email message is prohibited.  If you have 
> received this message in error, please notify the sender immediately by 
> e-mail and delete this email message from your computer. Thank you.
> --
> //www.freelists.org/webpage/oracle-l
> 
> 
                                          
--
//www.freelists.org/webpage/oracle-l


Other related posts: