Encrypting existing Search indexes
Encrypting DSE Search indexes turns on encryption only for new files. Additional steps are required to encrypt existing data. When you encrypt existing DSE Search indexes, a node restart is required.
There are several ways to encrypt existing DSE Search indexes. Choose the method that is appropriate for your environment.
Prerequisites
When using TDE on a secure local file system, encryption keys are stored remotely with KMIP encryption or locally with on-server encryption.
Procedure
Encryption is enabled per core.
-
To enable encryption for an existing core, edit the solrconfig.xml file to change the class for directoryFactory to
solr.EncryptedFSDirectoryFactory:<directoryFactory name="DirectoryFactory" class="solr.EncryptedFSDirectoryFactory"/> -
Upload the changed solrconfig.xml file.
For example, you can use dsetool to upload the changed resource file:
dsetool reload_core <keyspace_name>.<table_name> -
Restart the DataStax Enterprise node.
Enabling encryption does not require a node restart. However, the directoryFactory changes require a node restart.
Encryption is on only for new files. Additional steps are required to encrypt existing data.
-
To encrypt existing files, use one of these methods:
- Reload while the node is running
-
This is a slow but immediate option. It reindexes while the node is running.
dsetool reload_core <keyspace_name>.<table_name> deleteAll=true reindex=true - Rebuild from a remote node
-
Offline index encryption is fastest. However, the local node must be offline, and you must have access to a remote node that is running and has the index configuration available.
The encryption configuration is read from the remote node; the user that runs the command must have read and write permissions to the directory that contains the index files.
For options, see the
dsetool upgrade_index_filesreference.-
Enable encryption for all nodes that have a search index.
-
Run the
dsetool upgrade_index_filescommand:dsetool upgrade_index_files <keyspace_name>.<table_name> -h <IP_address> [<options>]
-
- Eventual reindexing
-
This option requires the least effort but it is indeterminate.
If you take no action, the index will eventually be encrypted during compaction or merging of indexes. When this happens depends on new write activity. Because new files are encrypted, your files will eventually be encrypted.
-
To verify which files are encrypted, use this command to list all DSE Search index files for the specified search core on the local node:
dsetool list_index_files <keyspace_name>.<table_name> [--index <directory>]where
--index <directory>specifies the data directory that contains the search index files. When not specified, the default directory is inferred from the search core name. -
After you verify which files are encrypted, you can encrypt existing files using a different option.
Next steps
To disable encryption, disable encryption for the backing CQL table. No node restart is required.