Data Domain: DD Boost Authentication and Encryption Configuration for STIG Compliance

摘要: STIG Compliance – STIG Requirement SV-279028r1138077: This requirement states that information transfer mechanisms must uniquely identify and authenticate source systems before permitting data access. To align with this requirement, DD Boost global-authentication-mode and global-encryption-strength should not be configured as none. Configure DD Boost to use two-way or two-way-password authentication and medium or high encryption strength, and verify that connected DD Boost clients such as PPDM support the selected settings. ...

本文章適用於 本文章不適用於 本文無關於任何特定產品。 本文未識別所有產品版本。

症狀

DD Boost global settings are configured as:

sysadmin@ddve-lts# ddboost option show
Option                           Value
------------------------------   -------
distributed-segment-processing   enabled
virtual-synthetics               enabled
global-authentication-mode       none
global-encryption-strength       none
------------------------------   -------


Guidance is required to align DD Boost communication settings with STIG requirement SV-279028r1138077.
Environment contains DD Boost clients communicating with Data Domain systems, such as PPDM.

原因

DD Boost global authentication and encryption settings were configured with:

sysadmin@ddve-lts# ddboost option show
Option                           Value
------------------------------   -------
distributed-segment-processing   enabled
virtual-synthetics               enabled
global-authentication-mode       none
global-encryption-strength       none
------------------------------   -------


STIG requirement SV-279028r1138077 requires information transfer mechanisms to uniquely identify and authenticate source systems before permitting data access.
The existing DD Boost configuration did not align with the authentication and encryption requirements defined by the STIG.
This is a configuration alignment issue and not a product defect.

Resolution: Configure DD Boost to use authenticated and encrypted communications by setting:

sysadmin@DD6900-2# ddboost option set global-authentication-mode two-way-password global-encryption-strength medium
**   Changing these global settings may affect per-client authentication and encryption settings.
DD Boost option "global-authentication-mode" set to two-way-password and "global-encryption-strength" set to medium.
sysadmin@DD6900-2# ddboost option show
Option                           Value
------------------------------   ----------------
distributed-segment-processing   enabled
virtual-synthetics               enabled
fc                               disabled
global-authentication-mode       two-way-password
global-encryption-strength       medium
------------------------------   ----------------

解析度

Verify that all DD Boost clients, including PPDM, support and are configured for the selected authentication method.
Clients currently using anonymous authentication may require additional configuration after the change.
Enabling encryption introduces processing overhead for encryption and decryption operations; the impact varies based on workload size and throughput requirements.
Refer to the applicable Data Domain DD Boost and PPDM documentation for supported authentication and encryption configurations.

Data Domain: DD Boost global authentication and encryption

 

受影響的產品

Data Domain
文章屬性
文章編號: 000492526
文章類型: Solution
上次修改時間: 28 7月 2026
版本:  1
向其他 Dell 使用者尋求您問題的答案
支援服務
檢查您的裝置是否在支援服務的涵蓋範圍內。