Data Domain: DD Boost Authentication and Encryption Configuration for STIG Compliance

Summary: STIG Compliance – STIG Requirement SV-279028r1138077: This requirement states that information transfer mechanisms must uniquely identify and authenticate source systems before permitting data access. To align with this requirement, DD Boost global-authentication-mode and global-encryption-strength should not be configured as none. Configure DD Boost to use two-way or two-way-password authentication and medium or high encryption strength, and verify that connected DD Boost clients such as PPDM support the selected settings. ...

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Symptoms

DD Boost global settings are configured as:

sysadmin@ddve-lts# ddboost option show
Option                           Value
------------------------------   -------
distributed-segment-processing   enabled
virtual-synthetics               enabled
global-authentication-mode       none
global-encryption-strength       none
------------------------------   -------


Guidance is required to align DD Boost communication settings with STIG requirement SV-279028r1138077.
Environment contains DD Boost clients communicating with Data Domain systems, such as PPDM.

Cause

DD Boost global authentication and encryption settings were configured with:

sysadmin@ddve-lts# ddboost option show
Option                           Value
------------------------------   -------
distributed-segment-processing   enabled
virtual-synthetics               enabled
global-authentication-mode       none
global-encryption-strength       none
------------------------------   -------


STIG requirement SV-279028r1138077 requires information transfer mechanisms to uniquely identify and authenticate source systems before permitting data access.
The existing DD Boost configuration did not align with the authentication and encryption requirements defined by the STIG.
This is a configuration alignment issue and not a product defect.

Resolution: Configure DD Boost to use authenticated and encrypted communications by setting:

sysadmin@DD6900-2# ddboost option set global-authentication-mode two-way-password global-encryption-strength medium
**   Changing these global settings may affect per-client authentication and encryption settings.
DD Boost option "global-authentication-mode" set to two-way-password and "global-encryption-strength" set to medium.
sysadmin@DD6900-2# ddboost option show
Option                           Value
------------------------------   ----------------
distributed-segment-processing   enabled
virtual-synthetics               enabled
fc                               disabled
global-authentication-mode       two-way-password
global-encryption-strength       medium
------------------------------   ----------------

Resolution

Verify that all DD Boost clients, including PPDM, support and are configured for the selected authentication method.
Clients currently using anonymous authentication may require additional configuration after the change.
Enabling encryption introduces processing overhead for encryption and decryption operations; the impact varies based on workload size and throughput requirements.
Refer to the applicable Data Domain DD Boost and PPDM documentation for supported authentication and encryption configurations.

Data Domain: DD Boost global authentication and encryption

 

Affected Products

Data Domain
Article Properties
Article Number: 000492526
Article Type: Solution
Last Modified: 28 تموز 2026
Version:  1
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.