Veritas-bu

Re: [Veritas-bu] Encrypted backups of already encrypted data

2007-06-25 19:27:09
Subject: Re: [Veritas-bu] Encrypted backups of already encrypted data
From: "Ed Wilts" <ewilts AT ewilts DOT org>
To: "'Kathryn Hemness'" <cckat AT reality.ucdavis DOT edu>
Date: Mon, 25 Jun 2007 18:10:16 -0500
> My assumption was the same.  I didn't think that NetBackup would bother
> to perform any checks to see if a file was already encrypted.

How is NetBackup supposed to check?  An encrypted file just likes like
random binary data, so there's no way for it to really know.  And even if
you did have an encrypted file and the key just happened to be stored in the
same directory, wouldn't you want the data encrypted with a different key
going to tape?  The keys and the data need to be separated or there isn't
any point.

Our approach is to use Decru encryption appliances and simply encrypt
everything.  It may not be the cheapest alternative, but it's guaranteed to
be the most effective.  We can't forget to do a special case encryption for
certain clients or policies.

        .../Ed

--
Ed Wilts, Mounds View, MN, USA
mailto:ewilts AT ewilts DOT org
I GoodSearch for Bundles Of Love:
http://www.goodsearch.com/?charityid=821118 

_______________________________________________
Veritas-bu maillist  -  Veritas-bu AT mailman.eng.auburn DOT edu
http://mailman.eng.auburn.edu/mailman/listinfo/veritas-bu