In an environment with pretty tough security requirements an idea has come up to use local encryption on servers for many if not all databases.
If this requirement turns out to be real, what kind of CPU impact can we expect on the server. Let’s assume an even mix of simple, medium and strong encryption is used over all databases.
For 4.000 users we were thinking about a Windows based 2-box-cluster, 2-4 Xeons, 4 GB RAM. These would be for databases/applications only, mail would be served by two clusters based on similar hardware. This is Notes clients only, no browser access. Fast is good, they have a special deal enterprise license, processors are cheap, so probably make that 4 Xeons per box.
I know that Windows sounds funny for a system with actual security requirements, but that should be ok when the server is reachable on nothing but port 1352 and an angry pit bull is guarding the safe containing the smartcard-reader in the server rack.
I also know that the proposed hardware would easily handle the load without local encryption, and would remain usable even if one server in a cluster died.
What I don’t know is what locally encrypting everything on a server will do to the CPUs.
Has anybody done this before? What is your experience regarding CPU requirements?