The ZDLRA introduced a new feature with release 23.1 that can both encrypt backups (if they are not already encrypted from TDE) and compress the backups . The combing of both encryption and compression with this feature is unique to the ZDLRA.
I talked about this new exciting feature in a blog post on Oracle.com you can find here.
What I am am going to cover in this blog post is how to audit the RMAN catalog on the ZDLRA to validate that your backups are completely RMAN encrypted.
There are two big advantages of ensuring your backups are fully encrypted
1) With the prevalence of data exfiltration, and the advent of new regulations in many industries, full encryption of backups is mandatory
2) When sending a backup to the Oracle cloud (either in OCI or to object storage on ZFS) full encryption is required to protect the backup data.
The question I often get asked with this feature is..
"How do you tell if your backups are encrypted ?"
You can can determine that your backups are encrypted by looking at the RMAN catalog.
The RC_BACKUP_PIECE view contains a column identifying if the backup is encrypted. This column is set to "YES" only when the backup piece is encrypted.
Keep in mind that there multiple types of backups pieces contained in the catalog
- Controlfile backups
- Spfile backups
- Archive log sweeps
- Archive log backups from real-time redo
- Datafile backups
- Virtual Full backups created from incremental backups.
- Real-time redo backups. Real-time redo backups are identified in the RMAN catalog as encrypted when the destination setting on the protected database has ENCRYPTION=ENABLE set.
- Virtual Full backups. Virtual full backups are identified, for each datafile backup set, as encrypted ONLY after a new L0 is taken with RMAN encryption on, and all subsequent L1 backups are encrypted. I know that is a lot of stipulations on identifying the virtual full backup as encrypted. Only when a new FULL encrypted backup is taken, and all future incremental backups are encrypted can the ZDLRA be sure the backup has remained completely encrypted.
Checking the catalog
The script below takes 2 parameters (&db_name, and &days_to_compare) and it will check the RMAN catalog and display the status of the backups, by backup type making it easier to identify any backup pieces that may not be encrypted.
This provides a nicely formatted output as you can see below.
Database backup summary for last 15 days database: DBSG23AI
Encrypted Compressed Backup
Yes or No Yes or No pieces Backup piece type
========== ========== ====== ========================================
YES YES 69 Full backup
YES NO 39 Archive Log - log sweep
NO YES 1 Incremental L1 backup
YES NO 3958 Archive Log - real-time redo
YES YES 67 Incremental L1 backup
NO YES 3 Full backup
NO NO 1 Controlfile/SPFILE backup
YES NO 26 Controlfile/SPFILE backup
YES NO 221 Incremental L1 backup
In the report you can see that there a few backups that not encrypted, along with some controlfile/spfile backups.
NOTE: In order to run this report, I created a REPORT user in the database on the ZDLRA. A report has enough permissions to create this report.
No comments:
Post a Comment