Nutanix Security Guide documentation on Data-at-Rest Encryption (DARE) specifies strict hardware compatibility rules. For Hardware Encryption, the cluster must exclusively use Self-Encrypting Drives (SEDs). The documentation states that you cannot mix SEDs and non-SEDs (standard drives) within the same cluster if you intend to use hardware-based encryption.
However, Software Encryption (AOS Software Encryption) is hardware-agnostic. It uses the CPU (leveraging AES-NI instructions) to encrypt data before writing it to the disk. Software encryption supports any drive type and is the only supported method for clusters containing a mix of SEDs and standard drives. Therefore, the administrator must use cluster-level software encryption.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit