Modifying encryption for a Replication Gateway pair
The Veritas Resiliency Platform Data Mover Replication Gateway supports encryption using OpenSSL for data transfer. When creating or modifying a Replication Gateway pair, you can choose whether to apply an encryption scheme to the data replication.
When you change an encryption scheme, the Replication Gateway transceiver component is restarted. When the transceiver restarts, it resumes sending or receiving update sets from where it left off, hence full synchronization is not required. The gateway pair may be in a disconnected state temporarily during the process of restarting.
AES128-GCM-SHA256 and AES256-GCM-SHA384 are the available encryption schemes. The default scheme is None.
Note:
If you are using Object Storage for replication then the default encryption scheme is AES128-GCM-SHA256 which cannot be edited.
After upgrading to 3.1 Update 1, AES256-GCM-SHA384 is the only available encryption scheme. Hence if AES128-GCM-SHA256 is applied to any Replication Gateway, you need to modify. The encryption scheme can be modified after the Resiliency Manager is updated and must be done before Replication Gateway is updated.
To modify a Replication Gateway pair
- Navigate
Infrastructure Pairing (navigation pane) > Replication Appliance tab
- Select the vertical ellipses next to the pair name and select Edit.
- In the wizard, change the encryption scheme selection and submit.
More Information