I am just running the encryption directive on all my backups.
I wonder if there is a way to store the "key" on a different server so in the the event that my backup tape gets misplaced I am not giving the criminals both the data and the key at the same time
Are you saying it is metadata because it is encrypted?
If so, back to the original concern - Maybe a little more explaination would be helpful, so
If I backup my server using the encryption directive and somehow someone get a hold of my tape would they be able to restore all the data once they loaded Networker?
Assume that the phase phrase is the default setting.
Well, you said what if bad guys got your server, right? They would have backup server and what do they do with it? Without access to data on tape, vtl or disk appliance they can't do anything. Without proper DNS they would most likely had issues starting up backup application in the first place.
Your encryption directive protects your network traffic. Encryption on tape should be done with other software (most likely you use LTO so to protect data on tape you just need key management station - note that this is something happening outside NW world).
Imagine that you data is encrypted on tape. Now, in case you loose backup server how do you scan it? You need old password, right? OK, imagine you have one. Where is password option for scanner? There isn't one. Your data traffic is encrypted, but not data on tapes. That's my understanding. If you have two servers, give it a try:
- create text file
- do backup of text file to tape
- move tape to second server
- scan it
- restore text file and see if you can read it in plain text
Of course I could be wrong, but I believe I remember it has been mentioned on this forum that encryption used by NW is solely used for traffic from client to storage node. Wonder how that works with DD Boost. I can only assume that if this is valid for ssid on tape that scanner would check against phrase set on server properties, but scanner was always acting outside server so there is enough place for doubt. If I were you, I would test it first.
Hi, there. I'm pretty concern about this topic, but still have some different questions to ask.
a. Where is the metadata stored?
b. Is it stored encrypted?
And the last, sorry if it sounds foolish:
c. Can I apply an Encryption Directive if my networker server don't have a Restricted Zone difined? Where do I see if its applied to a client, for example?
Hi, The answers below are assuming that you want to use encryption using directives. Incase you are using hardware encryption via encryption card on the tape drives then NetWorker no information about this, you can check the KMS documents for more info.
a. Where is the metadata stored?
The pass phrase is stored in the res database and the information regarding the encrypted saveset is stored in the media database.
b. Is it stored encrypted?
The media database is a SQLite database, i hope that answers your question.
And the last, sorry if it sounds foolish:
c. Can I apply an Encryption Directive if my networker server don't have a Restricted Zone difined? Where do I see if its applied to a client, for example?
I assume by "Restricted Zone" do you mean multi tenancy. You don't need multi tenancy for applying encryption. The client with the AES encryption directive is the one that is being encrypted.
ble1
6 Operator
•
14354 Posts
•
56186 Points
1231
0
Posted April 8th, 2014 10:00
What encryption are you using? They "key" (password) is part of local database.