Forum Discussion
mframpton_60606
Nimbostratus
Oct 31, 2008Encrypted database?
Does anyone know if the backend database that stores the learned information is encrypted? We have sensitive information going through our ASM that needs to either be x'ed out or encrypted to keep with our PCI compliance. We noticed that this information was being logged as clear text. I found the option to x out via parameter name, however I cannot seem to find anything that tells me if the backend database is encrypted or also clear text.
TIA!
- Bill_Beverley_7Historic F5 AccountHi,
- Ido_Breger_3805Historic F5 AccountBill is correct, if you define the parameter that carries the encrypted information as "sensitive", ASM will not log its data anywhere, not in the log file and not in the internal learning database. This will solve your compliance issue.
- mframpton_60606
Nimbostratus
Thanks for the responses! - hoolio
Cirrostratus
I think it would be prohibitively expensive in terms of performance to do some kind of wildcard or regex match against all parameter values to mask potentially sensitive data in logs/database. But maybe it would still be a worthwhile enhancement request to make to F5. - I'm pretty sure there is an existing enhancement request open to add the ability to define sensitive parameters by wildcards (thus defining a single "*" would give you the functionality you're looking for), so I'd definitely suggest firing up a support case to at least have your voice added to that request.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects