|
RSS Feed - WebSphere MQ Support
|
RSS Feed - Message Broker Support
|
|
|
Disaster Recovery Mode - why not? |
« View previous topic :: View next topic » |
Author |
Message
|
PeterPotkay |
Posted: Mon Aug 12, 2013 6:43 am Post subject: Disaster Recovery Mode - why not? |
|
|
Poobah
Joined: 15 May 2001 Posts: 7719
|
|
Back to top |
|
|
rekarm01 |
Posted: Sat Aug 17, 2013 11:13 am Post subject: Re: Disaster Recovery Mode - why not? |
|
|
Grand Master
Joined: 25 Jun 2008 Posts: 1415
|
PeterPotkay wrote: |
Choosing Secure Mode (a.k.a. Disaster Recover Mode) allows you to do secure backups. There is no mention of any negative considerations when choosing this mode. Makes me wonder why this wouldn't be the default then. |
Secure Mode wasn't originally available; it was introduced in v3.8.1.0. It's possible that it's disabled by default for backwards compatibility. Or, because enabling it is actually less secure than disabling it.
PeterPotkay wrote: |
Does anyone know of any reasons one would NOT put their appliance into Disaster Recovery Mode at build time? |
"secure" is relative. If Secure Mode is disabled, then it's not possible to export private data (certificates, keys, and user data) at all. "unexportable" is a lot more secure than "exportable, but encrypted".
DataPower appliances are typically placed in a DMZ, reachable from an untrusted network. Allowing DataPower appliances to export private data, even if encrypted, may introduce an unacceptable security risk. In that case, a site should manage its private data elsewhere (behind the DMZ firewalls, or off the network), and provide an alternate Disaster Recovery plan for restoring DataPower appliance configurations. It all depends on how paranoid a given site needs to be. |
|
Back to top |
|
|
PeterPotkay |
Posted: Sat Aug 17, 2013 1:22 pm Post subject: |
|
|
Poobah
Joined: 15 May 2001 Posts: 7719
|
Thank you, rekarm01. _________________ Peter Potkay
Keep Calm and MQ On |
|
Back to top |
|
|
|
|
|
|
Page 1 of 1 |
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
|
|
|