Protecting data in transit.
WHAT IT PROTECTS
Credentials and data between the application and the database.
WHEN IT MATTERS MOST
When they are on different machines or networks.
WHEN IT MATTERS LESS
Connections over a loopback interface on the same machine.
WHAT TO CONFIGURE
A certificate on the server Clients configured to use encryption Verification of the certificate
WHY VERIFICATION SPECIFICALLY
Encryption without verification protects against passive listening but not interception.
WHAT TO REQUIRE
Encryption on accounts connecting over a network.
HOW
A requirement attached to the account itself.
WHY AT THE ACCOUNT LEVEL
It cannot be bypassed by a misconfigured client.
WHAT IT COSTS
A small overhead, negligible on modern hardware.
WHAT TO BE CAREFUL WITH
Self-signed certificates and clients configured to accept anything Certificates expiring, breaking every connection at once
WHAT TO MONITOR
Certificate expiry.
WHAT TO ALSO ENCRYPT
Replication between servers Backups in transit and at rest
WHY REPLICATION SPECIFICALLY
It carries every change, in full.
WHAT TO VERIFY
That connections are actually encrypted.
HOW
Check the session status, rather than assuming configuration took effect.