- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
eOn-prem data encryption AES-256-XTS
Greetings
I learned that all the data which is at rest on Meraki devices is encrypted with AES-256-XTS. The question from our security department came now up where the key is stored and who has the control of it. In other words, where is the possibility to decrypt this existing data on the on-prem devices if this goes offline or will be disposed? Is the key to decrypt this data under Meraki's control and where is it stored?
Thanks a lot
Markus
Solved! Go to solution.
- Labels:
-
Other
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi PhilipDAth
I was not able to find any hint about this encryption. I will get back to my Meraki representative from where I got the information about the encryption.
Thanks, Markus
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@markus_albisser there shouldn't be any data stored on the MX devices, or are you referring to the configuration that might include hostnames etc. in firewall rules?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Or are you using the old cache feature?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It might be more the information on the devices which relates to the configuration as you mentioned (hostname, IP addresses, VLANs, interface descr. etc.), if a device becomes obsolete or gets lost (stolen), how can this type of information be decrypted? Is there only Meraki who knows the key and is this safe?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I don't know the answer, but try checking out the Meraki "Trust" section:
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi PhilipDAth
I was not able to find any hint about this encryption. I will get back to my Meraki representative from where I got the information about the encryption.
Thanks, Markus
