Data Domain: DD Boost Authentication and Encryption Configuration for STIG Compliance

요약: STIG Compliance – STIG Requirement SV-279028r1138077: This requirement states that information transfer mechanisms must uniquely identify and authenticate source systems before permitting data access. To align with this requirement, DD Boost global-authentication-mode and global-encryption-strength should not be configured as none. Configure DD Boost to use two-way or two-way-password authentication and medium or high encryption strength, and verify that connected DD Boost clients such as PPDM support the selected settings. ...

이 문서는 다음에 적용됩니다. 이 문서는 다음에 적용되지 않습니다. 이 문서는 특정 제품과 관련이 없습니다. 모든 제품 버전이 이 문서에 나와 있는 것은 아닙니다.

증상

DD Boost global settings are configured as:

sysadmin@ddve-lts# ddboost option show
Option                           Value
------------------------------   -------
distributed-segment-processing   enabled
virtual-synthetics               enabled
global-authentication-mode       none
global-encryption-strength       none
------------------------------   -------


Guidance is required to align DD Boost communication settings with STIG requirement SV-279028r1138077.
Environment contains DD Boost clients communicating with Data Domain systems, such as PPDM.

원인

DD Boost global authentication and encryption settings were configured with:

sysadmin@ddve-lts# ddboost option show
Option                           Value
------------------------------   -------
distributed-segment-processing   enabled
virtual-synthetics               enabled
global-authentication-mode       none
global-encryption-strength       none
------------------------------   -------


STIG requirement SV-279028r1138077 requires information transfer mechanisms to uniquely identify and authenticate source systems before permitting data access.
The existing DD Boost configuration did not align with the authentication and encryption requirements defined by the STIG.
This is a configuration alignment issue and not a product defect.

Resolution: Configure DD Boost to use authenticated and encrypted communications by setting:

sysadmin@DD6900-2# ddboost option set global-authentication-mode two-way-password global-encryption-strength medium
**   Changing these global settings may affect per-client authentication and encryption settings.
DD Boost option "global-authentication-mode" set to two-way-password and "global-encryption-strength" set to medium.
sysadmin@DD6900-2# ddboost option show
Option                           Value
------------------------------   ----------------
distributed-segment-processing   enabled
virtual-synthetics               enabled
fc                               disabled
global-authentication-mode       two-way-password
global-encryption-strength       medium
------------------------------   ----------------

해결

Verify that all DD Boost clients, including PPDM, support and are configured for the selected authentication method.
Clients currently using anonymous authentication may require additional configuration after the change.
Enabling encryption introduces processing overhead for encryption and decryption operations; the impact varies based on workload size and throughput requirements.
Refer to the applicable Data Domain DD Boost and PPDM documentation for supported authentication and encryption configurations.

Data Domain: DD Boost global authentication and encryption

 

해당 제품

Data Domain
문서 속성
문서 번호: 000492526
문서 유형: Solution
마지막 수정 시간: 28 7월 2026
버전:  1
다른 Dell 사용자에게 질문에 대한 답변 찾기
지원 서비스
디바이스에 지원 서비스가 적용되는지 확인하십시오.