Description
Transparent Data Encryption (TDE) encrypts stored data files at the database layer. A supported RDS instance without TDE lacks this layer of protection. Separate storage encryption may exist, so the TDE setting alone does not establish that all stored data is plaintext.
TDE transparently decrypts data for normal database connections. It does not replace account permissions or encryption in transit.
Potential impact
- Protection against an attacker reading acquired database files may be insufficient.
- The database may not meet the organization’s encryption requirements.
Remediation
- Check engine, version and edition support and KMS permissions, then set
tde_status = "Enabled". The provider documentation says TDE cannot be disabled after activation, so assess the change first. - Enabling TDE does not automatically encrypt existing MySQL tables. Encrypt the required tables using the documented procedure and verify their actual state.
- Check backup, recovery and key availability, and manage account permissions and TLS separately.
Examples
These excerpts compare MySQL 5.6 settings. Verify a TDE-supported minor version and edition, and supply instance-type and storage-capacity values supported in the target environment. Other creation settings, including networking, are omitted.
Before
resource "alicloud_db_instance" "db_instance" {
engine = "MySQL"
engine_version = "5.6"
instance_type = var.tde_instance_type
instance_storage = var.db_storage_gb
tde_status = "Disabled"
}
TDE is disabled. Review any separate protection for stored data as well.
After
resource "alicloud_db_instance" "db_instance" {
engine = "MySQL"
engine_version = "5.6"
instance_type = var.tde_instance_type
instance_storage = var.db_storage_gb
tde_status = "Enabled"
}
The TDE feature is enabled. Existing MySQL tables still require separate encryption and verification.