IBM Support

In HADR can we have one of Primary/Standby as encrypted DB while other is not?

Technical Blog Post


Abstract

In HADR can we have one of Primary/Standby as encrypted DB while other is not?

Body

Our recommendation is that both primary and standby are encrypted. However, running
with an encrypted primary and a non-encrypted standby is supported, but only for enabling
Native encryption in existing setup without complete outage.(i.e. Online implementation)
It’s not intended to be a long term solution.

if we enforced that both primary and standby had to be encrypted, you would not be able to
use this online method of enabling encryption.  You’d have to shutdown both primary and
standby (whole system offline), enable encryption, and then bring the system back up.

In general it will work, but there may be edge cases come up that run into trouble, such as
if the standby need to read an archived transaction log file (not a shipped replay log)
that is encrypted, but it does not have access to the keystore.
Also practically we need to keep both Primary and standby as Encrypted to maintain security.

[{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SSEPGG","label":"Db2 for Linux, UNIX and Windows"},"Component":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"","Edition":"","Line of Business":{"code":"LOB10","label":"Data and AI"}}]

UID

ibm11140286