<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Enable Data Encryption on Existing Object Data in Object Storage</title>
    <link>https://community.netapp.com/t5/Object-Storage/Enable-Data-Encryption-on-Existing-Object-Data/m-p/434435#M140</link>
    <description>Hi,&lt;BR /&gt;&lt;BR /&gt;according to TR-4598 page 40:&lt;BR /&gt;&lt;BR /&gt;Security:&lt;BR /&gt;All data encrypted by ONTAP NVE/NAE remains encrypted when moved to the cloud tier. Client-side encryption keys are owned by ONTAP. All objects not encrypted using ONTAP NVE/NAE are automatically encrypted by StorageGRID using AES-256-GCM encryption. No additional encryption is necessary. NetApp recommends disabling stored object encryption in StorageGRID.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Best&lt;BR /&gt;Oliver</description>
    <pubDate>Tue, 26 Apr 2022 15:02:58 GMT</pubDate>
    <dc:creator>OliverSchubert</dc:creator>
    <dc:date>2022-04-26T15:02:58Z</dc:date>
    <item>
      <title>Enable Data Encryption on Existing Object Data</title>
      <link>https://community.netapp.com/t5/Object-Storage/Enable-Data-Encryption-on-Existing-Object-Data/m-p/434431#M138</link>
      <description>&lt;P&gt;We have a SG appliance running 11.5. We have 2 load-balanced admin nodes and 8 storage nodes. We have the SG front-ended with an AFF-400. When we installed the SG we did not enable data encryption. We do have Volume Encryption enabled on the AFF. From what I read, if we enable data encryption on the SG now, it will only encrypt new data added to the SG and it will not encrypt any existing data. Is there a way to encrypt existing data? The ultimate goal is to have the data encrypted at rest.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 10:01:43 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Object-Storage/Enable-Data-Encryption-on-Existing-Object-Data/m-p/434431#M138</guid>
      <dc:creator>jimb32</dc:creator>
      <dc:date>2025-06-04T10:01:43Z</dc:date>
    </item>
    <item>
      <title>Re: Enable Data Encryption on Existing Object Data</title>
      <link>https://community.netapp.com/t5/Object-Storage/Enable-Data-Encryption-on-Existing-Object-Data/m-p/434432#M139</link>
      <description>&lt;P&gt;FabricPool encrypts the data stored to the cloud tier.&amp;nbsp; From the FabricPool Best Practices TR:&lt;/P&gt;&lt;P&gt;Cloud tier&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;All objects encrypted by NVE/NAE remain encrypted when moved to the cloud tier. Client-side encryption keys are owned by ONTAP. All objects not encrypted using NVE/NAE are automatically encrypted server-side using AES-256-GCM encryption. No additional encryption is necessary. Server-side encryption keys are owned by the respective object store.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Apr 2022 14:47:05 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Object-Storage/Enable-Data-Encryption-on-Existing-Object-Data/m-p/434432#M139</guid>
      <dc:creator>aronk</dc:creator>
      <dc:date>2022-04-26T14:47:05Z</dc:date>
    </item>
    <item>
      <title>Re: Enable Data Encryption on Existing Object Data</title>
      <link>https://community.netapp.com/t5/Object-Storage/Enable-Data-Encryption-on-Existing-Object-Data/m-p/434435#M140</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;according to TR-4598 page 40:&lt;BR /&gt;&lt;BR /&gt;Security:&lt;BR /&gt;All data encrypted by ONTAP NVE/NAE remains encrypted when moved to the cloud tier. Client-side encryption keys are owned by ONTAP. All objects not encrypted using ONTAP NVE/NAE are automatically encrypted by StorageGRID using AES-256-GCM encryption. No additional encryption is necessary. NetApp recommends disabling stored object encryption in StorageGRID.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Best&lt;BR /&gt;Oliver</description>
      <pubDate>Tue, 26 Apr 2022 15:02:58 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Object-Storage/Enable-Data-Encryption-on-Existing-Object-Data/m-p/434435#M140</guid>
      <dc:creator>OliverSchubert</dc:creator>
      <dc:date>2022-04-26T15:02:58Z</dc:date>
    </item>
    <item>
      <title>Re: Enable Data Encryption on Existing Object Data</title>
      <link>https://community.netapp.com/t5/Object-Storage/Enable-Data-Encryption-on-Existing-Object-Data/m-p/434438#M141</link>
      <description>&lt;P&gt;Thanks aronk. That's a big help. One follow-on question. If we create a tenant account with a S3 bucket - can that be encrypted at the bucket level and if so, can it be encrypted after the data is added to the SG?&lt;/P&gt;</description>
      <pubDate>Tue, 26 Apr 2022 15:06:07 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Object-Storage/Enable-Data-Encryption-on-Existing-Object-Data/m-p/434438#M141</guid>
      <dc:creator>jimb32</dc:creator>
      <dc:date>2022-04-26T15:06:07Z</dc:date>
    </item>
    <item>
      <title>Re: Enable Data Encryption on Existing Object Data</title>
      <link>https://community.netapp.com/t5/Object-Storage/Enable-Data-Encryption-on-Existing-Object-Data/m-p/434441#M142</link>
      <description>&lt;P&gt;Yes, StorageGRID supports the put-bucket-encryption API. No, encryption is only set on newly ingested objects.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Example&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;aws s3api put-bucket-encryption --bucket encryptme --server-side-encryption-configuration '{"Rules": [{"ApplyServerSideEncryptionByDefault": {"SSEAlgorithm": "AES256"}}]}' --profile encrypt --endpoint-url &lt;A href="https://192.169.0.100" target="_blank"&gt;https://192.169.0.100&lt;/A&gt; --no-verify-ssl&lt;/P&gt;</description>
      <pubDate>Tue, 26 Apr 2022 15:17:11 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Object-Storage/Enable-Data-Encryption-on-Existing-Object-Data/m-p/434441#M142</guid>
      <dc:creator>aronk</dc:creator>
      <dc:date>2022-04-26T15:17:11Z</dc:date>
    </item>
  </channel>
</rss>

