Click here to monitor SSC
SQLServerCentral is supported by Redgate
Log in  ::  Register  ::  Not logged in
Home       Members    Calendar    Who's On

Add to briefcase «««123

TDE and Tempdb Expand / Collapse
Posted Thursday, July 1, 2010 9:50 AM


Group: General Forum Members
Last Login: Tuesday, June 30, 2015 9:47 AM
Points: 2,160, Visits: 2,204
Steve Jones - Editor (7/1/2010)
You can't run TDE on laptops practically. It's in Enterprise Edition only (a mistake, IMHO)

I thought TDE was in the Developer edition as well, which is what I think gets run on laptops a lot.

TDE ensures that not only your data and logs files are secure while "at rest", your backup files are secure as well.
Post #946283
Posted Thursday, July 1, 2010 9:54 AM



Group: Administrators
Last Login: Today @ 2:55 PM
Points: 34,371, Visits: 18,589
Sorry, yes, in developer as well. I was thinking about production level stuff. I think it ought to be in Standard, web, Express.

Follow me on Twitter: @way0utwest

Forum Etiquette: How to post data/code on a forum to get the best help
Post #946288
Posted Thursday, July 1, 2010 11:26 AM

Old Hand

Old HandOld HandOld HandOld HandOld HandOld HandOld HandOld Hand

Group: General Forum Members
Last Login: Tuesday, January 19, 2016 9:20 AM
Points: 386, Visits: 630
Festeron (7/1/2010)

I'd be interested in your answer to these questions:

If you're using TDE in a production environment, what do you think you are protecting yourself from?

The is a great TDE tutorial on

What you will discover from it is all of the data stored in your MDF file is viewable in a text editor.

So if you have a tape backup go missing, if a hacker gains access to your hard drive, or if a disgruntaled or careless employee takes a copy of a backup and has it on thier local computer and the computer gets stolen your data is at risk.

Might not seem like a big deal, but banks and credit card companies have requirements on them to store PII, Personal Identifiable Information, in an encrypted format. Typically this involves purchasing expesive 3rd party tools.

SQL 2008 doesn't require a 3rd party tool to accomplish this so job done and money saved.

One other thing to keep in mind, as this is the area I work in, in the Government if you loose a database that has PII on it, you have to inform Congress and send out letters to everyone whose information was in that database letting them know that thier information may be compromised.

TDE works on the MDF & Log files as well as the Backup Files. It is transparent so it does not encrypt data on the instance nor does it encrypt files in memory. So if someone has access to your database they can see what you can see.

Once again any way you look at it this is bad for your career, as you don't want to be interviewing for a job saying I just worked at XYZ, and the interviewer go "Oh weren't they just in the news because a lot of PII got stolen froom there?"

So this is a CYA thing on a multitude of levels, for a business, for customers, and for the DBA's

And are you using TDE on any laptop-based SQL Servers?

TDE is also enabled on SQL 2008 Developer Edition. There are drive level encryptions that should be used on Hardware where senative info would be stored. So if you needed to have a local copy of a sensitive database you should have an encrypted hard drive, and if it is a copy of a prod database that uses TDE you would have to have the certificates on that instance from production to restore a copy of the database.

I use TDE on my home laptop, but that is cause I work with it. But I would never put production data on a laptop, I would hate to be like the guy at the VA that lost the laptop with millions of Veterans private info on it, he probably had every enlisted man from generals to privates trying to get a peice of him.

Twitter: @SQLBalls
Post #946364
« Prev Topic | Next Topic »

Add to briefcase «««123

Permissions Expand / Collapse