When you enable S3 Storage Encryption:
-
Communication between FileCloud and AWS uses SSL encryption to protect data in transit.
-
Once S3 is set up correctly, the S3 Encryption field becomes available under Amazon S3 Storage Settings.
FileCloud supports the following Server Side Encryption types:
-
Server-Side Encryption with Amazon S3-Managed Keys (SSE-S3)
All data is encrypted at rest using AES-256 encryption. The data can only be accessed using the AWS access key and secret key credentials. The data is accessible through the Amazon S3 console.
Note: Although encrypted data is accessible through the Amazon S3 console, do not modify data created by FileCloud Managed Storage, as doing so can corrupt the FileCloud repository. In this case, the data should only be modified by FileCloud.
-
Server-Side Encryption with Customer-Provided Keys (SSE-C)
The data is encrypted using the customer-supplied 32-byte encryption key. This option has slower performance due to restrictions on how this data can be decrypted (Amazon S3 cannot decrypt the data. The data must first be downloaded to FileCloud server and then decrypted). The data is also inaccessible through the Amazon S3 console.
Notes:-
When you choose SSE-C, any backups created before SSE-C was enabled will become invalid, and therefore that data will not be recoverable.
-
When SSE-C encryption is enabled, optimized upload is not available for S3 storage and S3 network shares.
-
WARNINGS:
-
Enabling encryption starts a process that encrypts all available data in the bucket as well as all new data.
-
This process may take some time depending on the amount of existing data in the bucket.
-
It is recommended that you modify the encryption setting during periods of low server activity.
Although you can change the Encryption setting can be done at any time, we recommend doing so during off-peak hours to minimize the risk of disrupting user access.