FCBIS should throw a warning if it is running on a cluster with encryption at rest enabled.

XMLWordPrintableJSON

    • Type: Task
    • Resolution: Unresolved
    • Priority: Major - P3
    • None
    • Affects Version/s: None
    • Component/s: None
    • Replication
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      This was related to HELP-85252. In that case, we were trying to make FCBIS work, but later realized the customer had encryption at rest enabled, which was causing FCBIS to fail. Even though we say we support FCBIS with encryption at rest, in practice it seems quite fragile. If key rotation is also happening, the chances of it succeeding get even worse.

      We're updating the playbook and the TSE wiki to recommend not using FCBIS when encryption at rest is enabled (See CLOUDOPS-12782). In addition, I think we should log a warning on the server side if someone still tries to use FCBIS with encryption enabled.

            Assignee:
            Unassigned
            Reporter:
            Suganthi Mani
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated: