MS SQL Server :: Español: Transparent Data Encryption (TDE)

Опубликовано: 22 Июль 2026
на канале: Wally Pons
153
11

Nota: Esta es la versión en Español

Archivos de Github: https://github.com/WallyPons/YouTube
Nombre: TDE.sql

Ventajas del TDE
• Cifrado transparente: no requiere cambios en la aplicación ni en procedimientos SQL.
• Protege datos en reposo (data, logs, backups).
• Cumple regulaciones y estándares de seguridad (PCI DSS, HIPAA, GDPR, etc.).
• Sencillo de implementar en comparación con column-level o Always Encrypted.

Desventajas / Limitaciones del TDE
• No cifra datos en memoria ni en tránsito (para eso se usa TLS/SSL o Always Encrypted).
• Dependencia del certificado: si se pierde y no hay backup, la base de datos queda irrecuperable.
• Impacto en rendimiento: normalmente 3%–10% de overhead en I/O (depende de CPU, disco y carga).
• Limitaciones de funcionalidades:
a. No soporta FileStream ni In-Memory OLTP.
b. TempDB siempre se cifra si hay alguna BD con TDE, lo que puede afectar escenarios de temp-heavy workloads.
• Migración y restauración requieren mover/instalar también el certificado asociado.


Chapters:
00:00 Intro
00:55 Verificar TDE-DMK (Encryption)
02:21 Crear DMK
02:47 Crear Certificado
03:35 Asignar Certificado
04:57 Habilitar Cifrado (Encryption)
05:21 Backup del Certificado / Base de Datos
06:54 Probar Certificado / Restore
11:08 Eliminar DMK / TDE
14:20 Outro

Would you like to hire me for your SQL questions and solutions?: https://www.fiverr.com/s/e6ALv5E

I've worked across SQL Server, MySQL, and PostgreSQL, supporting both small businesses and
enterprise-level environments. Whether it's a one-time fix or ongoing support, I'll bring
clarity, reliability, and efficiency to your data.

Your database problems don't have to slow you down, let's solve them together!