Thursday, September 20, 2012

AIX Encryption Notes

Benefits:

  • The encryption is done by the OS, so no application reconfiguration is required

  • The encryption is a feature included with AIX, so it is available at no cost

  • The encryption is performed at the file system level, so encryption for main application could be phased in gradually as they have 8 distinct file systems


Concerns:

  • With the encryption being done on the server side, there are CPU cycles expended to perform the encryption

  • The estimated CPU cost is 2-5%, which is within our current idle usage availability (i.e. no additional CPUs are required in order to implement)

  • There would be downtime required to perform the encryption, but that might be able to be done multi-threaded for main application.


Unknown:

  • The AIX mechanism for encryption is geared to granting access by users and groups; in this case we would be doing group level encryption

  • The encryption key store is unique per user and has a second layer of encryption using the user’s password, so as the user changes their password, their encryption key store is re-encrypted. After the initial encryption key store has been created, an additional step is required once a user’s password changes

  • Do not yet know if processes spawned by a parent process inherit access to the encryption key store; in all likelihood they would – but if not, that would be a showstopper; however initial testing would be able to verify this almost immediately