Data encryption

Last Updated : Jun 08, 2023 |

You can enable or disable data encryption when deploying the Avaya Aura® Web Gateway OVA. When data encryption is enabled, all operational data and log files are encrypted.

You can only enable data encryption on Avaya Aura® Web Gateway if you use Avaya Solutions Platform or a VMware Virtualized Environment. For software-only deployments, you must enable data encryption on the virtualization platform itself. For more information about enabling data encryption on Amazon Web Services, see How to Protect Data at Rest with Amazon EC2 Instance Store Encryption.

Once data encryption is enabled, you cannot disable it using the configuration utility or the Avaya Aura® Web Gateway administration portal. To disable data encryption, you must redeploy the Avaya Aura® Web Gateway OVA.

If you enabled data encryption and selected the Require Encryption Pass-Phrase at Boot-Time option, then you will need to enter the data encryption passphrase after every Avaya Aura® Web Gateway reboot. If you do not select this option, Avaya Aura® Web Gateway enables the local key store to store encryption keys, so you do not need to enter the passphrase manually. However, this is a less secure solution. Alternatively, you can set up a remote key server to store encryption keys.

Encryption of Avaya Aura® Web Gateway partitions

When you enable data encryption for Avaya Aura® Web Gateway, the following partitions are encrypted:

  • sdb: /var/log/Avaya

  • sdc: /media/data

  • sdd: /media/cassandra

The sda boot disk is always unencrypted.

Data encryption management

After deploying the Avaya Aura® Web Gateway OVA with data encryption enabled, you can manage data encryption settings using system layer commands. For information about managing data encryption settings, see the Security options chapter in Administering the Avaya Aura® Web Gateway.