Data Domain: Default Authentication Mode for DD Boost Clients Does Not Provide Over-The-Wire Encryption

Shrnutí: After upgrading DDOS, receive the error "Default authentication mode for DD Boost clients does not provide over-the-wire encryption."

Tento článek se vztahuje na Tento článek se nevztahuje na Tento článek není vázán na žádný konkrétní produkt. V tomto článku nejsou uvedeny všechny verze produktu.

Příznaky

Applicable versions:
DDOS 7.10.1.10, DDOS 7.7.5.20, or DDOS 7.12, or a later version

The following Security alert is observed in the autosupport file:
Current Alerts

--------------

Id       Post Time                  Severity   Class               Object              Message

------   ------------------------   --------   -----------------   -----------------   -------------------------------------------------------------------------------------------------------------

m0-53    Wed May 10 00:06:41 2023   ALERT      Security                                EVT-DDBOOST-00001: Default authentication mode for DDBoost clients does not provide over-the-wire encryption.

------   ------------------------   --------   -----------------   -----------------   -------------------------------------------------------------------------------------------------------------

Příčina

If DD Boost encryption strength is set to none in the previous DDOS release, and DDOS is upgraded to 7.10.1.10, 7.7.5.20, or 7.12, or a later version, then a security alert is raised to remind the user to enable encryption.

Command to check current encryption strength:

ddboost option show global-encryption-strength

Řešení

Steps using CLI:

  1. Clear the alert manually:
    alerts clear alert-id <alert-id-list>
  2. Set the global-encryption-strength to medium or high:

    Syntax:

    ddboost option set global-authentication-mode none global-encryption-strength {medium | high}
  3. Reset global authentication mode and global encryption strength to none:
ddboost option set global-authentication-mode none global-encryption-strength none

Steps using UI:

  1. Log in to the Data Domain System Manager (UI).
  2. Go to Protocols.
  3. Go to DD Boost.
  4. Click More Tasks in the upper right corner.
  5. Select Set Option.
  6. Under Security, select encryption strength to medium or high.
  7. Click OK.
  8. Go to Health.
  9. Go to Alert.
  10. Select the alert and click Clear.

To reset Global Authentication Mode back to 'none':

  1. Go to Protocols.
  2. Go to DD Boost.
  3. Click Configure before Global Authentication Mode.
  4. Select none and click OK. This resets the global authentication mode and global encryption strength to none.
Note: Keeping the current global-encryption setting may trigger a reminder alert "Default authentication mode for DD Boost clients does not provide over-the-wire encryption," but DD Boost operation successfully continues. Setting global-encryption to medium or high may result in a drop in Boost I/O performance. If over-the-wire encryption is required, change global-encryption to medium or high.

 

Note: If using Avamar Integrated Data Protection Appliance with Session Security Settings enabled, it is safe to disregard this alert. Avamar is already encrypting the data and there is no necessity to use DD Boost encryption. Use the below command to disregard the alert from the Data Domain.
alert clear alert-id

How to Reset Global Encryption Strength & Clear Errors in Dell Data Domain

Duration: 00:03:32 (hh:mm:ss)
When available, closed caption (subtitles) language settings can be chosen using the CC icon on this video player.

Další informace

Dotčené produkty

Data Domain

Produkty

Data Domain Encryption, DD OS
Vlastnosti článku
Číslo článku: 000215316
Typ článku: Solution
Poslední úprava: 16 čvn 2026
Verze:  10
Najděte odpovědi na své otázky od ostatních uživatelů společnosti Dell
Služby podpory
Zkontrolujte, zda se na vaše zařízení vztahují služby podpory.