Transparent Data Encryption (TDE) on External Data Mart

Last Updated : Aug 14, 2023 |
Prolog information
Transparent Data Encryption (TDE) prevents the theft of sensitive data stored in the Context Store External Data Mart (EDM) on the SQL server as part of the Avaya Oceana® solution. TDE encrypts EDM data which includes all EDM files and backups. Support for TDE of EDM data is an alternative to VMWare encryption, particularly for CPOD deployments, where VMWare encryption is impossible.
Important:
TDE can be enabled on the EDM when the EDM is installed on either one SQL server or in a cluster of two SQL servers.

Supported Configurations

Avaya Oceana® supports Transparent Data Encryption (TDE) on the Context Store (CS) EDM in the following configurations:
  • EDM/ACM co-res: EDM is deployed co-resident with the ACM databases on two SQL servers (DB HA).
    Note:
    The supported SQL server versions in the following table are also supported when the EDM is installed on a single SQL server (no DB HA, no AlwaysOn High Availability). However, enabling TDE on a single SQL server for ACM/EDM co-res is only supported as a lab deployment and not a production deployment.
    SQL Server
    Type of Always On High Availability
    (SQL Server DB HA)
    Version
    Edition
    2019
    Enterprise
    Advanced Availability Group (AAG)
    2017
    Enterprise
    Advanced Availability Group (AAG)
  • Standalone EDM: EDM is deployed alone without ACM DBs on one SQL server (non-DB HA) or EDM is deployed alone on two SQL servers (DB HA).
    SQL Server
    Type of AlwaysOn High Availability
    (SQL Server DB HA)
    Version
    Edition
    2019
    Standard
    Basic Availability Group (BAG)
    Note:
    TDE for Standalone EDM is applicable only for Oceana deployments. TDE is not supported for standalone Context Store deployments (non-Oceana deployments).