Tests for Data-at-Rest Encryption over NFS

NFS shares are an example from the many protocols Bloombase StoreSafe supports for encryption. A share from a Windows Server 2025 system that is accessible by configure clients is created to act as backend storage. Bloombase StoreSafe creates a virtual encrypted share on its own hostname path that is accessed from a client software system.


tmpivz8zhde.jpg


tmpkrmyujqp.jpg


Microsoft Windows 11 clients can use the included map network drive option to add the NFS share presented by

Bloombase StoreSafe Intelligent Storage Firewall with a drive letter. Data owners can alternatively use the mount command to specify additional mounting options.

tmpwxcy7g_4.jpg

On the demo virtual encrypted NFS share, a sample plaintext file is created by the client and saved. The file is transparently encrypted by the Bloombase StoreSafe encryption engine and stored on the Microsoft Windows Server 2025 backend share.

tmpbudonek8.jpg

If the application data is attempted to be accessed directly on the backend without going through the Bloombase StoreSafe encryption engine, only ciphertext can be read as expected.


tmpzyqw_jxf.jpg