# Encryption at rest support

**URL:** <https://discuss.elastic.co/t/encryption-at-rest-support/113537>\
**Category:** Elasticsearch\
**Created:** [December 29, 2017, 6:24am UTC](https://discuss.elastic.co/t/encryption-at-rest-support/113537 "2017-12-29T06:24:58Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![jiali](https://avatars.discourse-cdn.com/v4/letter/j/43a26b/32.png) [@jiali](https://discuss.elastic.co/u/jiali)\
**Post date:** [December 29, 2017, 6:24am UTC](https://discuss.elastic.co/t/encryption-at-rest-support/113537/1 "2017-12-29T06:24:58Z")

</div>

In X-Pack platinum, "Encryption at rest support" was introduced in 5.3.0 Released. As there's no documentation about it and I understand it is about filesystem encryption on the actual host running Elasticsearch.

I would like to clarify if this feature is to  
option 1: **provide** filesystem encryption service with dm-crypt; or  
option 2: **support** running Elasticsearch on encrypted filesystem (which means we need to do dm-crypt ourselves on the filesystem) ?

If is option1, could you share

- Is the encryption done on per node basis or?
- Will this affect search performance?

---

<div class="post-metadata">

**Author:** ![Magnus\_Kessler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnus_kessler/32/42001_2.png) [@Magnus\_Kessler](https://discuss.elastic.co/u/Magnus_Kessler)\
**Post date:** [December 29, 2017, 6:51am UTC](https://discuss.elastic.co/t/encryption-at-rest-support/113537/2 "2017-12-29T06:51:00Z")

</div>

Jiali,

This question was previously answered [here](https://discuss.elastic.co/t/encryption-at-rest-support-in-x-pack-platinum/100111). It's option 2 on your list.

An encrypted file system has to be set up on each node. The overhead of encryption depends on how well your CPUs support the additional mathematical operations required to encrypt the data, and any overhead incurred by the FS stack. Maximum throughput and duration of individual queries are generally influenced by latencies in the FS.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 26, 2018, 6:51am UTC](https://discuss.elastic.co/t/encryption-at-rest-support/113537/3 "2018-01-26T06:51:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
