Data Domain: DD Boost Authentication and Encryption Configuration for STIG Compliance

概要: STIG Compliance – STIG Requirement SV-279028r1138077: This requirement states that information transfer mechanisms must uniquely identify and authenticate source systems before permitting data access. To align with this requirement, DD Boost global-authentication-mode and global-encryption-strength should not be configured as none. Configure DD Boost to use two-way or two-way-password authentication and medium or high encryption strength, and verify that connected DD Boost clients such as PPDM support the selected settings. ...

この記事は次に適用されます: この記事は次には適用されません: この記事は、特定の製品に関連付けられていません。 すべての製品パージョンがこの記事に記載されているわけではありません。

現象

DD Boost global settings are configured as:

sysadmin@ddve-lts# ddboost option show
Option                           Value
------------------------------   -------
distributed-segment-processing   enabled
virtual-synthetics               enabled
global-authentication-mode       none
global-encryption-strength       none
------------------------------   -------


Guidance is required to align DD Boost communication settings with STIG requirement SV-279028r1138077.
Environment contains DD Boost clients communicating with Data Domain systems, such as PPDM.

原因

DD Boost global authentication and encryption settings were configured with:

sysadmin@ddve-lts# ddboost option show
Option                           Value
------------------------------   -------
distributed-segment-processing   enabled
virtual-synthetics               enabled
global-authentication-mode       none
global-encryption-strength       none
------------------------------   -------


STIG requirement SV-279028r1138077 requires information transfer mechanisms to uniquely identify and authenticate source systems before permitting data access.
The existing DD Boost configuration did not align with the authentication and encryption requirements defined by the STIG.
This is a configuration alignment issue and not a product defect.

Resolution: Configure DD Boost to use authenticated and encrypted communications by setting:

sysadmin@DD6900-2# ddboost option set global-authentication-mode two-way-password global-encryption-strength medium
**   Changing these global settings may affect per-client authentication and encryption settings.
DD Boost option "global-authentication-mode" set to two-way-password and "global-encryption-strength" set to medium.
sysadmin@DD6900-2# ddboost option show
Option                           Value
------------------------------   ----------------
distributed-segment-processing   enabled
virtual-synthetics               enabled
fc                               disabled
global-authentication-mode       two-way-password
global-encryption-strength       medium
------------------------------   ----------------

解決方法

Verify that all DD Boost clients, including PPDM, support and are configured for the selected authentication method.
Clients currently using anonymous authentication may require additional configuration after the change.
Enabling encryption introduces processing overhead for encryption and decryption operations; the impact varies based on workload size and throughput requirements.
Refer to the applicable Data Domain DD Boost and PPDM documentation for supported authentication and encryption configurations.

Data Domain: DD Boost global authentication and encryption

 

対象製品

Data Domain
文書のプロパティ
文書番号: 000492526
文書の種類: Solution
最終更新: 28 7月 2026
バージョン:  1
質問に対する他のDellユーザーからの回答を見つける
サポート サービス
お使いのデバイスがサポート サービスの対象かどうかを確認してください。