Skip to main content
Question

How often and what makes customers require TLS for Vertica?

  • September 4, 2019
  • 4 replies
  • 17 views

dgrumann
Forum|alt.badge.img+2

Our ITOM software has proven much more difficult to set up for customers when their external (but dedicated to our app) Vertica DB is configured with SSL enabled. I would like to understand from the Vertica experts exactly how common it is for customers to enable TLS/SSL, and what rationale is used to require this complexity. Obviously, "its more secure", but I am talking about an internal IT DB here, not something exposed to the internet. Personally, unless I hear different, I would recommend to my customers to avoid the certificate complexities and leave their ITOM-specific Vertica DBs without SSL. Thanks in advance for the perspective.

4 replies

skeswani
Forum|alt.badge.img
  • Participating Frequently
  • September 5, 2019

Without TLS anyone who can sniff the network gets your database password. i.e. your db password is exposed to anyone
1. on your wifi network,
2. not on your wifi, but in proximity to your Access Point (with some moderate amount of cracking)
3. with physical access to a network drop that shares the same network segment with your client or the server. (i.e. everyone in your office space and data center, and anyone in between. hopefully not over the internet)

If the data isn't that valuable then dont bother. if there is PII data then i assume there is something that may mandate it.

Its not that hard to setup, about 8 odd commands, here are the instructions.
(you can skip the validation part since that is optional for debugging, only if things go bad)
https://www.vertica.com/kb/Using-SSL-Server-Authentication-with-Vertica-Validating-Your-SSL/Content/BestPractices/Using-SSL-Server-Authentication-with-Vertica-Validating-Your-SSL.htm


dgrumann
Forum|alt.badge.img+2
  • Author
  • Participating Frequently
  • September 10, 2019

Thank you for the reply, Sumeet, however I was not looking for reasons why SSL is more secure than non-SSL. Again, I would like to understand from the Vertica experts who work with customers exactly how common it is for customers to enable vertica connection TLS/SSL (EnableSSL = 1). For example "10% of our customers enable SSL" or "98% of our customers enable SSL", and what rationale is used to require this complexity. Trust me, it is NOT a simple thing to exchange external certificates into the ITOM CDF platform.


skeswani
Forum|alt.badge.img
  • Participating Frequently
  • September 11, 2019

15% have SSL enabled, 85 % have it disabled


dgrumann
Forum|alt.badge.img+2
  • Author
  • Participating Frequently
  • September 11, 2019

Sumeet - GREAT to know! So - for our customers using the ITOM CDF platform, it is not out-of-the-ordinary for them to NOT enable SSL. Now - for the 15% of Vertica customers enabling SSL, are they doing it because their DBs are exposed outside the secure data center? Or perhaps because they store PII data? For CDF-ITOM we are just storing metrics and IT events. Thanks!