Skip to main content

My name is Michael Belme, and I'm a Technical Support Engineer III with Rocket working out of Denver, Colorado. In this 8-part video series, I'll be covering the basics of why SSL is imperative for your business operations and how to easily protect data in transit flowing into and out of your U2 DataServers. I will cover the latest OpenSSL release used in U2 products and the changes it brings along... We'll take a look at Rocket's newly released U2 Certificate Management Tool, as well as the U2 Root Certificate Store and token-based authentication... both of which are found in the latest U2 database releases. Finally, the newly released secure-only UniRPCD port will also be explained along with steps to set up an SSL secured U2 REST server. 

If you ever wanted to better understand the available security options found in UniVerse and UniData, then this video playlist is for you!

 

Note: The video playlist below can be accessed using the menu at the upper right of the frame. Click the icon to access additional videos in this series.

#MVU #UniVerse #UniData #Security #Compliance

​​​​​​​

------------------------------
Michael Belme
Rocket Software
------------------------------

My name is Michael Belme, and I'm a Technical Support Engineer III with Rocket working out of Denver, Colorado. In this 8-part video series, I'll be covering the basics of why SSL is imperative for your business operations and how to easily protect data in transit flowing into and out of your U2 DataServers. I will cover the latest OpenSSL release used in U2 products and the changes it brings along... We'll take a look at Rocket's newly released U2 Certificate Management Tool, as well as the U2 Root Certificate Store and token-based authentication... both of which are found in the latest U2 database releases. Finally, the newly released secure-only UniRPCD port will also be explained along with steps to set up an SSL secured U2 REST server. 

If you ever wanted to better understand the available security options found in UniVerse and UniData, then this video playlist is for you!

 

Note: The video playlist below can be accessed using the menu at the upper right of the frame. Click the icon to access additional videos in this series.

#MVU #UniVerse #UniData #Security #Compliance

​​​​​​​

------------------------------
Michael Belme
Rocket Software
------------------------------

Hi Michael, I realise this is a few years old, but I have a question relating to securing data in transit.

We have a lead interested in replication but want to ensure that the data transferred between the publisher and subscriber is encrypted (they're Unidata on AIX). I noted the existence of the "-s" option for unirpcd, but when I force unirpcd to start on pub and sub with this option, replication does not operate. I've been told that there is no "official" way to encrypt the replication data travelling between pub and sub(s), but that using a ssh tunnel may be an option.

I'm pretty decent at setting up tunnels - I do it all the time, but I have yet to work out how to get replication to go through a tunnel. Any suggestions?



------------------------------
Martin Shields
Senior Technical Consultant
Meier Business Systems PTY LTD
Carnegie VIC AU
------------------------------

Hi Michael, I realise this is a few years old, but I have a question relating to securing data in transit.

We have a lead interested in replication but want to ensure that the data transferred between the publisher and subscriber is encrypted (they're Unidata on AIX). I noted the existence of the "-s" option for unirpcd, but when I force unirpcd to start on pub and sub with this option, replication does not operate. I've been told that there is no "official" way to encrypt the replication data travelling between pub and sub(s), but that using a ssh tunnel may be an option.

I'm pretty decent at setting up tunnels - I do it all the time, but I have yet to work out how to get replication to go through a tunnel. Any suggestions?



------------------------------
Martin Shields
Senior Technical Consultant
Meier Business Systems PTY LTD
Carnegie VIC AU
------------------------------

Hi, 

I thought encryption takes place before replication. If the subscriber wants to read the data, they must have the same encryption key.

Interesting to check !

Manu



------------------------------
Manu Fernandes
------------------------------

Hi, 

I thought encryption takes place before replication. If the subscriber wants to read the data, they must have the same encryption key.

Interesting to check !

Manu



------------------------------
Manu Fernandes
------------------------------

@Manu Fernandes You are correct, if a record / field is encrypted on the publisher the replication log will only contain the cypher text. The subscriber must have the same encryption key to be able to decypher it as the subscriber record / field will only contain the cypher text.



------------------------------
Jonathan Smith
UniData ATS
Rocket Support
------------------------------