TDE versus Bitlocker for SQL2012 on Win2012R2

With all of the PCI and compliance regulations being placed on DBA's, I have been looking for the best method to encrypt data at rest.  Our options are TDE and BitLocker, so I just wanted to get some opinions on which to use. Since TDE is at the database
level, and has several gotcha's, this will add to our administrative overhead.  So the other option is to use BitLocker which is at the volume level.  Therefore, I could encrypt all databases on that volume without all of the SQL overhead. I
have been researching these two options for a while, so I understand the performance hit, and I have my own opinions... However, it is time for me to make a decision...  So please keep this civil, and let me know your real life pros and cons
you have experienced...
TIA
Ozone

One thing to keep in mind is that if you encrypt the database with TDE, the backups will also be encrypted, as will any copy you restore to test/QA/dev. Obviously, this can be catered for with Bitlocker, but it needs to be done separately.
Erland Sommarskog, SQL Server MVP, [email protected]

Similar Messages

  • Where can I find the xsd file for SQL2012 .dtsx files?

    Where can I find the xsd file for SQL2012 .dtsx files?
    Tom G.

    I would start here. 
    http://msdn.microsoft.com/en-us/library/gg587789(v=sql.105).aspx The xsd is spread out over several of the appendices.
    Russel Loski, MCT, MCSE Data Platform/Business Intelligence. Twitter: @sqlmovers; blog: www.sqlmovers.com

  • A new tab always opens Yahoo versus wait for an address

    I downloaded an MP4 player and it did something to Mozilla such that every time I open a new tab it opens yahoo versus wait for a site address to find. How do I get rid of this nuisance?
    == Operating system ==
    Windows XP2002 SP 3

    Hello Jack C. Anderson,
    this problem could probably be caused by a Firefox extension.
    To make sure that no extension is causing the problems,
    start Firefox in Safe Mode by following the instructions in the [[Safe Mode]] article.
    Kind regards,
    Tobbi
    Firefox Support Volunteer

  • Netbeans versus Eclipse for JNI

    We have a significant about of code to rehost on solaris 8, from xview, to new java guis interfacing legacy C code. Current develpment environment is vi and make. We want to evolve to Junit, Ant, CVS and eand IDE either Netbeans or Eclipse (maybe JbuilderX). Have used both for java but never for JNI. Now exploring Eclipse. Can anyone lead us to a forum on Netbeans versus Eclipse for this type of effort?

    Hi Ivar, thanks for your reply.
    Actually both Netbeans and Eclipse provide a C/C++ plug-in, so you can develop the C side as well. I'm using it in Eclipse. There is a C Ant task also, so you can build the C and Java together. (Ideally, we want to be able to step, in the source level debugger, from the java into the C native method, but I don't believe that has been worked out in any IDE.) I am working with Eclipse now, and you can edit java in the java perspective, click a C file, and automatically switch to the C perspective. That seems to work pretty well. On the other hand, Netbeans is a Sun sponsored project, and we are on Solaris, so maybe Netbeans has some platform dependent goodies that might tip the balance.
    You and I both know that while a tool may have a capability, that does not mean it does the job well. Somebody else must be doing the same thing that I am, so I'm looking to learn from the experience of others who are farther into the process. Maybe I can avoid having to get deeply into one tool, only to find I should have used another.

  • How do I encrypt a second hard drive using BitLocker for Windows 8.1?

    Hi there,
    I've encrypted my 1st HDD with BitLocker, however, I can't seem to find a way to encrypt my 2nd HDD too.
    More specifically, on my laptop I've got a SSD (successfully encrypted) and a HDD (yet to be encrypted).
    Any ideas on how this would be achievable? 
    Also, what if I want to encrypt an external backup HDD? 
    Thanks!
    Robert

    Hi,
    Could you check the file system of the system partition in the disk management, to see if it is NTFS or Fat32? If it is not NTFS, try to change it to NTFS.
    Two partitions are required to run BitLocker because pre-startup authentication and system integrity verification must occur on a separate partition from the encrypted operating system drive. This configuration helps protect the operating system and the
    information in the encrypted drive. In Windows Vista, the system drive must be 1.5 gigabytes (GB), but in Windows 7 this requirement has been reduced to 100 MB for a default installation. The system drive may also be used to store the Windows Recovery
    Environment (Windows RE) and other files that may be specific to setup or upgrade programs. Computer manufacturers and enterprise customers can also store system tools or other recovery tools on this drive, which will increase the required size of the system
    drive. For example, using the system drive to store Windows RE along with the BitLocker startup file will increase the size of the system drive to 300 MB. The system drive is hidden by default and is not assigned a drive letter. The system drive is created
    automatically when Windows 7 is installed.
    Best Regards,
    Jason Zeng

  • Graphing measurement versus position for a continuous roll based process

    I am working on a DAQ application for a continuous roll-based process.  What I want to do is plot measurement versus position.  What is unique is that the graph x axis has to reset for each new roll that is created for the process.  i.e. I want to plot measurement versus position in a roll.  The attached file shows what I am trying to do.  Has anyone tried this?  Is it even possible to have positive numbers on both sides of a zero point in a graph?
    Thanks,
    John
    Attachments:
    Labview Roll Graph.jpg ‏33 KB

    John,
    Unfortunately, there wouldn't be a way to have an arbitrarily numbered x-axis as you are describing.  In cartesian coordinates, you cannot have repeated points like this.
    If you know how many points are acquired per roll, one way to do this is to clear a charts history after this number of points and for every clear increment a roll counter.  See the attached VI for an idea of what I'm talking about.
    Regards,
    Craig D
    Applications Engineer
    National Instruments
    Attachments:
    Clear Chart History.vi ‏18 KB

  • On Enabling TDE Column Encryption for 11g 11.2.0.4 , will SYS user able to decrypt, encrypted column !

    Hi ,
    we are planning to implement Transparent Data Encryption  for 11.2.0.4 11g DB .
    My Query is Whether SYS  DB user will be able to Decrypt all encrypted Columns.
    we have tested for Virtual Private Database Policy, and found out that it applies Policy for all DB Users except SYS.
    so now we have a query whether encryption will be applied for all DB users except for SYS.?
    regards
    Abdulrahman
    (P.S: attached is document how we tested for Virtual Private Database , if we can somehow disable SYS access to specific tables also our compliance requirement will be met  thanks )

    http://docs.oracle.com/cd/E11882_01/network.112/e40393/asotrans.htm#ASOAG600
    "Transparent Data Encryption(TDE) enables you to encrypt sensitive data, such as credit card numbers, stored in tables and tablespaces. Encrypted data is transparently decrypted for a database user or application that has access to data. TDE helps protect data stored on media in the event that the storage media or data file gets stolen."
    TDE encrypts data blocks.
    Users are not aware that the objects they query are encrypted - this is the reason it is called 'transparent'.

  • ASP versus WebDynpro for Java

    Hello All,
       I would like discuss and know more on the performance issues of WebDynpro 4 Java and Asp. We are planning to develop a news page in WebDynpro, which is presently in asp. The news data would be fed in from a document management system. (The development is done on NW04, EP6.0)
    The main points are :
    1.Since its a straight forward data retrieval and display(w/o validation) from backend, would WebDynpro actually have an edge over asp?
    2.With WebDynpro, since the data is dynamic would dynamic generation of the UI elements have a hit on the performance.
    3.With future in mind, if data is going to be retrieved from KM, then would that be a valid argument for going for WebDynpro.
    4. Since the other applications are also developed in WebDynpro, we should go in for WebDynpro.
    All ideas are welcome and well appreciated(as i haven't beein in ASP world ).
    Thank you,
    Sharath

    Hi Sharath,
    I can contribute something to you in this regard.
    I m interested to give my view on point no:2, 3 and 4
    2.With WebDynpro, since the data is dynamic would dynamic generation of the UI elements have a hit on the performance
    >>Definitly generation of UI elements will hit the performance as for as my knowldege is concerned.
    In webdynpro, you know you just have to use UI elements which are there already. no need to create them. so, even if you don't want to use some UI elements, those are loaded in the server. this obviously adds a load on the performance issue.
    but if you consdier ASP/JSP, where in you have to write a code to develop a single button on the UI. so, it's in your hand as many as UI elements you want. so, this this reduces of having extra UI elemets to be developed and hence performance of loading is better as compared to ASP/JSP.
    I would like to give simple real time ex:(as an analogy) at this point.
    If You want to book room in 5 star hotel, they by default charge for AC, FRIDGE, HEATER..etc  they are available,even if you don't want to use them. so,you need to shell out extra bucks.
    but if you go far some yathri nivas or any common guest house, where you can have value added services infront of you.
    So, Star hotel::::webdynpro
          common hotels::::ASP/JSP
    So, it depends on purely your requirements.
    then I will come to point no:3.& 4
    3.With future in mind, if data is going to be retrieved from KM, then would that be a valid argument for going for WebDynpro.
    4. Since the other applications are also developed in WebDynpro, we should go in for WebDynpro.
    >>> there are numerous advantages of using webdynpro inspite of some performance issue, I can list as follows as an argument over here.
    Improve User Experience through a "High Fidelity Web UI"
    1. Browser based front-end, zero footprint
    2. Flicker-free screen, minimal refreshes
    3. Client-side dynamics
    4. Minimal response times
    5. Personalization of the user interface
    Deliver an Enterprise Quality Web Development Environment
    1. Minimize coding, maximize design
    2. Support reuse of components
    3. Support web services and data-binding
    4. Separate layout and programming logic
    Achieve Independence...
    1. From platform
    2. From UI technology
    above are just a contribution, which are of my interest.

  • Buy Adobe XI Pro versus Subscription for Adobe XI Pro

    I am the owner of a small CPA firm.  We currently use Adobe 9 Pro which is no longer supported.  I have read through the differences between a subscription to XI Pro vs just upgrading and purchasing.  When I look at the comparison chart I do not see much benefit in the additional options gained by subscribing.  We use the product to scan documents as we try to be paperless.  We then use a bookmarking program on some documents.  Our access to fast DSL in limited at present so I believe a cloud solution would be very slow.  It seems to me I would be fine with the purchase option which would mean I should get a least a couple years out of the product vs paying am amount slightly more than the upgrade amount annually.  I would love to get some replies which can help me decide as I cannot find anyway to actually talk to a human at Adobe.  They seem to have eliminated all customer service voice options or at least I cannot find them.

    Thanks for the response - The following is what confused me.  It is an FAQ answer on the Adobe Website
    When you buy Acrobat XI Pro as a one-time purchase, you get only Acrobat software. No online services are included.
    When you subscribe to Acrobat Pro in select countries, you pay a low monthly fee to get:
    Acrobat XI Pro desktop software, including any upgrades
    The FormsCentral Plus online service for creating and distributing web forms
    The Adobe PDF Pack online service that makes it easy to create, convert, and combine PDFs in your browser
    Acrobat.com for storing and sharing files in the cloud

  • Extreme versus Express for computer connection and network extension

    I somehow posted this message in the Windows section, so let me try again:
    I have an older Mac Pro that I have moved to a location that does not have a convenient wired connection to our home network. We do have one Airport Extreme box on the system, so I was thinking that I could kill two birds with one stone and purchase a second box to not only give the Mac Pro a wireless connection, but also to extend the network.
    Will either the Airport Extreme or the Airport Express work equally well for this purpose? Does the Extreme offer some advantage in this situation?

    Yes either the AirPort Extreme base station (AEBS) or AirPort Express (AX) will do the job. In this situation neither offers an advantage.

  • Requesting guidance on repair versus replace for iBook G4 (2005)

    I'm looking for some guidance in deciding to upgrade/repair for my iBook G4, operating Mac OS X 10.4.11. I've gotten to the point where I don't seem to be able to run more than one application at a time (for example be online and listen to music at the same time), download more photos into iPhoto (get an outa short term memory message), or watch most video online. It seems that I can't get the most recent versions of some applications as well, for example can't upgrade to the most recent version of flash player, which rules out online TV. I'm not knowledgeable enough to be able to tell if I should just give up on this old workhorse or not. I'd be totally willing to spend $200 ish and have someone clean things up, delete useless stuff, etc, but I don't even know if that is worth it and I'd just be throwing money away. The only other problems it has is lousy battery (can't really be unplugged for more than 5 minutes) but I can live with that for my purposes. I'm open to suggestions about how to troubleshoot, ie decision matrix for the mostly clueless. Thanks.

    Hi, and welcome to Apple Support Communities.
    I would strongly recommend upgrading to a newer MacBook or MacBook Pro.
    Chances are the hard drive is full (or nearly so), and also getting old, since the very newest iBook is over five years old at this point.
    If you start replacing things, you could soon approach the cost of a newer computer.

  • 3d graph axes labels versus valuepairs for axis

    I have specific labels for each x axis item which contain a text string unique to that position.
    I can not figure out how to write new valuepairs on to the x axis and get rid of the normal integer indices that are on the graph. I get a mixture of the two instead.  Anyone know how to do this?
    In the attached VI below, the string "mylabel" is being written as a valuepair but I cant get rid of the other labels.
    Attachments:
    MyLabel.vi ‏22 KB

    Hi id,
    To give you more control over the 3D Curve, on the front panel right-click the 3D curve and choose CWGraph3D >> Properties...  This will let you test different settings quickly.  However, to my knowledge your last post is your best option. You could use extra value pairs as " " to eliminate the other labels.
    Will
    Certified LabVIEW Architect, Certified Professional Instructor
    Choose Movement Consulting
    choose-mc.com

  • Font Book versus Word for Mac

    I've installed a new font in Font Book.  Now it doesn't show up in MS Word for Mac.  Many other fonts are in Font Book but not Word.  How do I synch them or at least make sure that new fonts in Font Book are available in Word.
    thanks.

    the google gave
    http://www.youtube.com/watch?v=lfxmuuvta-g
    http://macapper.com/2008/02/21/how-to-install-fonts-on-mac/
    more hits
    https://www.google.com/search?sourceid=opera-portal&q=how+to+add+fonts+to+mac+of fice&client=opera-portal&channel=portal

  • Macbook Pro versus Air for university student (pharmacy)

    Hey everyone,
    So I love all my Apple products, and I plan to get some sort of Mac laptop for university in a few weeks. I'm going to be a pharmacy student at UBC, (so I'm not going into design or video graphics or anything) I basically want a fast, reliable computer that will last the extent of my Bachelor's degree, I really don't want to be replacing one every year or so. Battery life is somewhat important. I'm trying to decide between the MacBook Pro, (the $1200 one?) and the newer Macbook Air, (about $1200 as well?).
    Any input is greatly appreciated.
    Thanks guys.

    I'd agree with Kappy, especially if buying for a long haul like a 3 or 4 year degree program.  A MBP is the better choice.
    And don't necessarily feel that pharmacy won't have its own computationally intensive aspects either.  Large databases, especially chemical and drug structural databases and such, can be fairly tasking in terms of cpu use and RAM and harddrive space.
    Don't forget your education discount options - http://www.apple.com/ca/buy/hied/ and ask at the UBC bookstore if they offer any machines with 3year AppleCare options (some educational institutions can do this for machines purchased through them - gives you 4 years of total warranty coverage).
    P.S. I did my M.Sc. at U.Vic in the 1990's - I loved the west coast!

  • SET mode processing versus ROW for Dimension targets

    Hi all,
    In OWB 10.2.0.2 I am using a relational implementation of a Dimension with 9 levels (and 2 hierarchies).
    I selected target load order and have run the mapping with SET processing and ROW based (target only).
    The problem is that the results are not the same! Both run without errors but SET processing does not correctly associate the levels together in the dimension. When I run ROW based, the levels do connect properly. They are supposed to be equivalent - there is nothing in the code that is "row based only" in terms of transformations and Control center reports no errors in either case (though we all know that Control center sucks at error reporting). Logs also show no errors.
    Has anyone else seen this and more importantly is there a workaround?
    The Dimension has 17 million rows and takes 15 hours in SET processing.
    Row processing takes 3 days of processing to complete.
    I've logged an SR but have more faith in the responses here than in Support.
    This has been a 3 SR day for me with OWB - an average day I suppose. I have applied the patch and was hoping for more stability and consistency. Guess not.
    Any help would be appreciated. Also, what escalation procedures do you use when your SRs end up in documented and undocumented BUG numbers with no solutions?

    Mike,
    we have several dimensions that work fine. One is a custom time dimension with day / month / quarter / year levels. The other has 6 levels, split between two hierarchies that are each 4 levels deep.
    Haven't had any problems at all with them. Can't speak to running them in row based mode - because we've never had any issues, I haven't really even tried it.
    One problem that I have run into that may apply in your case - is it possible that you have different parent/child links for a given dimension value in the data? For instance, is it possible that you have one row of "source" data that says JANUARY rolls up to QTR1, but a second row in the same data that has JANUARY rolling up to QTR2? Something like this might produce exactly what you're seeing - you'd get hosed up results in the SET mode, but in ROW mode it would apply those changes one by one and potentially not have the problems (depending on how the data was sorted)
    We saw this when one our our maps tried to map more than 1 description to a single dimension value (we had an "UNKNOWN" dimension value, but we were writing > 1 description to it accidentally). In that case, our loads would usually fail with an error message saying something about "Couldn't get a stable set of source data" or somesuch.
    Hope this helps,
    Scott

Maybe you are looking for

  • No WhatsApp in Nokia Lumia 520

    Why there is no WhatsApp in Nokia Lumia 520 ! Not in Windows Store for Nokia Lumia 520. Seven days back it was there.

  • TDM...having some trouble

    I just got a new external HD. I backed up the whole thing using Data Backup 3 from ProSoft. When I try to boot in Target Disk Mode, it just shows a huge FireWire symbol slowly bouncing around. Like a screensaver. Anyone know how to get past this? My

  • Document Server Technical Details - BMP storage

    Looking for someone with technical details to help me bridge a time gap on how logo uploads are actually stored.  I'm trying to find a workaround to display a jpg instead of a bmp (even if it's stored in a file server, not document server).

  • Third party Management intergration with OEM

    I have various Dell servers that use OpenManage Systems Management (OMSA) by Dell. I have been able to integrate OMSA and the emagent in Linux. I need to see if anyone has managed to get OMSA and OEM agent working in Windows. This integration allows

  • Help with algorithm analysis...

    Big-Oh O(f(n)) means that T(n) <= O(f(n)) (meaning that at this level the growth rate (T(n)) is bounded on top by the growth function f(n)) Big-Omega (f(n)) means that T(n) >= f(n) (meaning that at this level the growth rate is bounded on the bottom