OK Guys,
I started writing this on my phone last night but it was a bit much.
So this is my first time on ML with my laptop.
Anyways I have a job coming up later this week and I want to make sure I do this right.
I have a company they have 2 servers and 6 workstations onsite.
*Server 1 is a physical 2008R2 hosting AD\DNS, roaming profiles, and File shares. Raid 10
*Server 2 is a VM of 2008R2 hosting AD\DNS secondary
The owner is migrating his Database to the Cloud with the software vendor. (I'm not involved)
He wants me to:
*demote\decommission the #2 server
*Enable Bitlocker on Server #1 for data security while at rest.
*demote this system as he just wants to shut it down. Where it can be powered up to access to the "Archives" from the network.
My thoughts are to move the pertinent software and data to the VM and mothball the physical server. As this will help us with future OS access in the event of hardware failure.
Or
Maybe perform a P2V on server#1 but may take longer?
I haven't used Bit-locker ever so I don't have experience to pull from, I have some thoughts about it.
-
The software vendor said "not to use encryption" on the server as it will cause problems. He didn't know why, he just repeated it to me.
*Question
With Bit-locker the data is encrypted while the machine is off. So the data is only protected as long it is off. Correct?
I'm not sure why this is an issue. If the data remains where it belongs and is unencrypted (while running) then the program should be able to access the data base without issues. -
What kind of logon is there to access the server with Bit-locker.
- I have used Symantec PGP FDE, with that you have to authenticate to PGP before the OS will load. I get that, I just haven't seen anything else.
I have several Network Shares on Server 1 with permissions for just the domain admin, and the creator to be able to access it. (Roaming Profiles) With that said I believe I would need to change all file permissions before any changes are made to the primary DC So that they would have continued access in the future. I believe all access might be lost if I "Forget this step, and then "DCPROMO."
Ultimately I will have to migrate everyone back to local profiles. So I guess this doesn't matter so much. I just wanted to know more for my mind on what would happen.
I have been interrupted so many times now (The kids) that I can't think anymore.
I'm going to wrap this up I have to head to work. Thank you for your thoughts.
Chad