Jump to content

Recommended Posts

Posted

We plan to migrate our SIMS server to Server 2016 this Easter and also take the opportunity to encrypt the data drive holding the MIS databases and shares used by finance, which will tick a few boxes.

I've successfully completed a test in a VM on a backup with Bitlocker, although as I can't emulate a TPM in ESX, the test was via password.

I'm happy to go ahead based on that test but thought I'd put the feelers out to see if anyone has done the same, or if anyone knows of any gotchas or handy information.

 

Cheers :)

Posted
So if the server reboots, you have to enter a password??

 

It depends on the machine. IIRC if you have a TPM then no, it boots normally. Otherwise yes, you need to enter a pre-boot PIN (or use a USB pen thingy)

Posted (edited)

Try Bitlocker Network Unlock? Provided you've got a TPM chip, it provides an "if I'm connected/can talk to the domain network, boot normally, otherwise prompt for credentials" option.

 

I came across it when moving our laptops to Bitlocker but haven't had time to play with it: https://docs.microsoft.com/en-us/windows/device-security/bitlocker/bitlocker-how-to-enable-network-unlock and I'm not sure if "VM on server with TPM chip" counts as meeting the requirements.

Edited by pete
Posted

Nonononono all misunderstood entirely!

 

The plan is simple. Physical server with SIMS on it. Encrypted. No VM's or anything.

The VM mentioned was just my test, and has no impact.

 

I just want to be sure I'm not going to hit any other issues by doing this; I know it will boot normally and correctly with the TPM setup on bitlocker.

Posted
Ahh k, the "test was via password" which confused me, SIMS\any MIS won't care, it just sees an encrypted disc. The only caveat would be performance, SQL loves disc IO and encrypting spinning rust KO disc IO. SSD are a must. Out of interest, what are you trying to achieve? Protection for when a hdd dies and needs recycling? I guess it isn't from physical theft - cause you'd need the whole server - TPM and all, also worth remembering its another thing that could go wrong. Still a good thing to do of course!
Posted

The idea of doing this is to indeed mitigate data loss a little; should the whole system get stolen, without passwords people would still be able to get much of the information from it by booting 3rd party software or removing the drives & shifting off data. With the drive encrypted, that would obviously not be possible.

It's already SSD'd up thankfully, we wanted to make sure SIMS had absolutely no more excuses to be slow. It's run out of excuses, it's just slow ;)

  • 3 weeks later...
Posted
Shame Capita don't support SQL server encryption as this would add a second layer of protection at the OS layer if it was compromised and data "stolen".

 

Capita do support SQL Server encryption as they mandate it if you are self hosting SLG and is also when using the Active Directory Provisioning Service

Posted
Capita do support SQL Server encryption as they mandate it if you are self hosting SLG and is also when using the Active Directory Provisioning Service

 

We self host slg and have have ADP and have never been mandated to encrypt our database...

When I spoke to the helpdesk only last week they said its unlikely to be supported anytime soon, Transparent Data Encryption or any form of SLG encryption. Do you have any documentation @Esteban_Child_of_the_Sun?

Posted
We self-host SLG and have have ADP and have never been mandated to encrypt our database...

When I spoke to the helpdesk only last week they said its unlikely to be supported anytime soon, Transparent Data Encryption or any form of SLG encryption. Do you have any documentation @Esteban_Child_of_the_Sun?

 

Unfortunately not, as we had CApita do the installation and they didn't leave anything about how they did things, also they don't have any public facing documents about setup on MyAccount. They just gave us the encryption keys and told us to keep them safe and secure and we'd need them when doing SQL migrations etc.

All I can find on MyAccount is https://myaccount.capita-cs.co.uk/hot-topics/sims-slg/ which states "Getting started - SIMS Learning Gateway installation and set-up is completed by Capita SIMS."

Posted
Transparent Data Encryption

 

Not sure any school could afford Enterprise licenses. Also it's kinda ironic they don't "support" transparent encryption

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...