I am completely new to Transparent Data encryption and please help me on below questions related to enabling the TDE on existing PRODUCTION Databases.
Primary Question:
What are the things which I should keep in mind before enabling the TDE on PRODUCTION servers ?
NOTES
- I have SQL Server 2014 AOAG Databases PROD site. The number of DBs is close to 10.
- I read about DEK , SMK , Certificate creation process and backup of Key's and certificates.
Questions:
- Now the Databases are TDE free ,what will be the new changes or effects which I will be seeing post enablement of TDE in my PROD site.
- What is the performance impact on my existing PRODUCTION database accessibility.
- Will there be any performance impact at all ? What is the range of impact after enabling TDE on my DBs ?
- What will be the effect on the AOAG component Failover part ? Will I face issues while the Databases are with TDE enabled ?
- What will be the affect while Backing up or Restoring the Databases to different SQL Server ?
- If I enable TDE on Primary Replica and all secondaries will I be able to add the DBs to AOAG 2014 using the Wizard.
Please guide me , I was not completely sure of the consequences of this change handling , please help me know the disadvantages related to existing situation and post enabling TDE and performance related issues and points.
Many thanks.