- The encryption is done by the OS, so no application reconfiguration is required
- The encryption is a feature included with AIX, so it is available at no cost
- The encryption is performed at the file system level, so encryption for main application could be phased in gradually as they have 8 distinct file systems
Concerns:
- With the encryption being done on the server side, there are CPU cycles expended to perform the encryption
- The estimated CPU cost is 2-5%, which is within our current idle usage availability (i.e. no additional CPUs are required in order to implement)
- There would be downtime required to perform the encryption, but that might be able to be done multi-threaded for main application.
Unknown:
- The AIX mechanism for encryption is geared to granting access by users and groups; in this case we would be doing group level encryption
- The encryption key store is unique per user and has a second layer of encryption using the user’s password, so as the user changes their password, their encryption key store is re-encrypted. After the initial encryption key store has been created, an additional step is required once a user’s password changes
- Do not yet know if processes spawned by a parent process inherit access to the encryption key store; in all likelihood they would – but if not, that would be a showstopper; however initial testing would be able to verify this almost immediately