{"id":97667,"date":"2020-10-20T08:42:25","date_gmt":"2020-10-20T06:42:25","guid":{"rendered":"https:\/\/prohoster.info\/blog\/administrirovanie\/shifrovanie-v-mysql-ispolzovanie-master-key"},"modified":"2020-10-20T08:42:25","modified_gmt":"2020-10-20T06:42:25","slug":"shifrovanie-v-mysql-ispolzovanie-master-key","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/shifrovanie-v-mysql-ispolzovanie-master-key","title":{"rendered":"Kriptimi n\u00eb MySQL: p\u00ebrdorimi i \u00c7el\u00ebsit Kryesor","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<h2><\/h2>\n<p><strong><em>N\u00eb prag t\u00eb fillimit t\u00eb nj\u00eb grupi t\u00eb ri p\u00ebr kursin&nbsp;<\/em><\/strong><noindex><a rel=\"nofollow\" href=\"https:\/\/otus.pw\/wMyj\/\"><strong><em>\u00abBaza t\u00eb dh\u00ebnash\u00bb<\/em><\/strong><\/a><\/noindex><strong><em>&nbsp;vazhdojm\u00eb t\u00eb publikojm\u00eb nj\u00eb seri artikujsh mbi enkriptimin n\u00eb MySQL.<\/em><\/strong><\/p>\n<p><img decoding=\"async\" alt=\"Kriptimi n\u00eb MySQL: p\u00ebrdorimi i \u00c7el\u00ebsit Kryesor\" src=\"\/wp-content\/uploads\/2020\/10\/762866d2c321acd726e30606c9108122.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>N\u00eb artikullin e kaluar t\u00eb k\u00ebsaj serie (<noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/otus\/blog\/522092\/\"><u>Kriptimi n\u00eb MySQL: depoja e \u00e7el\u00ebsave<\/u><\/a><\/noindex>) fol\u00ebm p\u00ebr magazinat e \u00e7el\u00ebsave. N\u00eb k\u00ebt\u00eb artikull do t\u00eb shqyrtojm\u00eb se si p\u00ebrdoret \u00e7el\u00ebsi kryesor (master key), si dhe do t\u00eb diskutojm\u00eb p\u00ebr avantazhet dhe disavantazhet e enkriptimit me metod\u00ebn e en\u00ebve (envelope encryption).&nbsp;<\/p>\n<p>Ideja e enkriptimit me en\u00eb \u00ebsht\u00eb q\u00eb \u00e7el\u00ebsat e p\u00ebrdorur p\u00ebr enkriptim (\u00e7el\u00ebsa t\u00eb tabelave) enkriptohen me nj\u00eb \u00e7el\u00ebs tjet\u00ebr (\u00e7el\u00ebsi kryesor, master key). P\u00ebr enkriptimin e t\u00eb dh\u00ebnave, n\u00eb fakt, p\u00ebrdoren \u00e7el\u00ebsat e tabelave. Kjo mund t\u00eb paraqitet grafikisht si:<\/p>\n<p><img decoding=\"async\" alt=\"Kriptimi n\u00eb MySQL: p\u00ebrdorimi i \u00c7el\u00ebsit Kryesor\" src=\"\/wp-content\/uploads\/2020\/10\/385afda0eff739f4720f59799c35b51f.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>\u00c7el\u00ebsi kryesor (master key) ndodhet n\u00eb depozitimin e \u00e7el\u00ebsave (keyring), nd\u00ebrsa \u00e7el\u00ebsat e hap\u00ebsirave tabelore jan\u00eb n\u00eb titujt e hap\u00ebsirave tabelore t\u00eb koduara (n\u00eb faqen 0 t\u00eb hap\u00ebsir\u00ebs tabelore).&nbsp;<\/p>\n<p>N\u00eb figur\u00ebn m\u00eb sip\u00ebr:<\/p>\n<ul>\n<li>\n<p>Tabeli A \u00ebsht\u00eb enkriptuar me \u00e7el\u00ebsin 1 (Key 1). \u00c7el\u00ebsi 1 \u00ebsht\u00eb enkriptuar me \u00e7el\u00ebsin kryesor (master key) dhe ruhet n\u00eb form\u00eb t\u00eb enkriptuar n\u00eb titullin e tabelit A.<\/p>\n<\/li>\n<li>\n<p>Tabeli B \u00ebsht\u00eb enkriptuar me \u00e7el\u00ebsin 2 (Key 2). \u00c7el\u00ebsi 2 \u00ebsht\u00eb enkriptuar me \u00e7el\u00ebsin kryesor (master key) dhe ruhet n\u00eb form\u00eb t\u00eb enkriptuar n\u00eb titullin e tabelit B.<\/p>\n<\/li>\n<li>\n<p>Dhe k\u00ebshtu me radh\u00eb.<\/p>\n<\/li>\n<\/ul>\n<p>Kur serveri ka nevoj\u00eb t\u00eb dekriptoj\u00eb tabel\u00ebn A, ai merr \u00e7el\u00ebsin kryesor nga depoja, lexon \u00e7el\u00ebsin e enkriptuar 1 nga titulli i tabel\u00ebs A dhe dekripton \u00e7el\u00ebsin 1. \u00c7el\u00ebsi i dekriptuar 1 ruhet n\u00eb memorien e serverit dhe p\u00ebrdoret p\u00ebr dekriptimin e tabel\u00ebs A.<\/p>\n<h3>InnoDB<\/h3>\n<p>N\u00eb InnoDB, enkriptimi dhe dekriptimi realizohen n\u00eb nivelin e hyrjes-daljes. Kjo do t\u00eb thot\u00eb se faqja enkriptohet menj\u00ebher\u00eb para se t\u00eb shkarkohet n\u00eb disk dhe dekriptohet menj\u00ebher\u00eb pas leximit nga disku.<\/p>\n<p>N\u00eb InnoDB, enkriptimi funksionon vet\u00ebm n\u00eb nivelin e hap\u00ebsirave t\u00eb tabelave. Dhe si rregull, t\u00eb gjitha tabelat krijohen n\u00eb hap\u00ebsira t\u00eb ve\u00e7anta tabelash (<noindex><a rel=\"nofollow\" href=\"https:\/\/dev.mysql.com\/doc\/refman\/8.0\/en\/innodb-file-per-table-tablespaces.html\"><u>file-per-table tablespace<\/u><\/a><\/noindex>). Duke folur ndryshe, krijohet nj\u00eb hap\u00ebsir\u00eb tabelash q\u00eb mund t\u00eb p\u00ebrmbaj\u00eb vet\u00ebm nj\u00eb tabel\u00eb. Megjithat\u00eb, ju gjithashtu mund t\u00eb krijoni tabela n\u00eb hap\u00ebsir\u00ebn e p\u00ebrgjithshme t\u00eb tabelave (<noindex><a rel=\"nofollow\" href=\"https:\/\/dev.mysql.com\/doc\/refman\/8.0\/en\/general-tablespaces.html\"><u>general tablespace<\/u><\/a><\/noindex>). Por \u00e7do rast, tabela gjithmon\u00eb ndodhet n\u00eb ndonj\u00eb hap\u00ebsir\u00eb tabelash. Dhe p\u00ebr shkak se enkriptingu kryhet n\u00eb nivelin e hap\u00ebsir\u00ebs tabelore, ajo \u00ebsht\u00eb ose e gjith\u00eb e enkriptuar, ose jo. Do t\u00eb thot\u00eb se n\u00eb hap\u00ebsir\u00ebn kryesore tabelore nuk mund t\u00eb enkriptohet vet\u00ebm nj\u00eb pjes\u00eb e tabelave.&nbsp;<\/p>\n<p>N\u00ebse p\u00ebr ndonj\u00eb arsye keni \u00e7aktivizuar file-per-table, t\u00eb gjitha tabelat krijohen brenda hap\u00ebsir\u00ebs tabelore sistematike (system tablespace). N\u00eb <noindex><a rel=\"nofollow\" href=\"https:\/\/www.percona.com\/software\/mysql-database\/percona-server\"><u>Percona Server p\u00ebr MySQL<\/u><\/a><\/noindex> hap\u00ebsir\u00ebn tabelore sistematike mund t\u00eb enkriptohet me an\u00eb t\u00eb variabl\u00ebs innodb<em>sys<\/em>tablespace<em>encrypt ose duke p\u00ebrdorur rrjedha enkriptimi (encryption threads), por kjo \u00ebsht\u00eb ende nj\u00eb funksion eksperimental. Kjo nuk ndodhet n\u00eb MySQL.<\/em><\/p>\n<p><em>Para se t\u00eb vazhdojm\u00eb, na nevojitet t\u00eb shqyrtojm\u00eb struktur\u00ebn e identifikuesit t\u00eb \u00e7el\u00ebsit kryesor (master key ID). Ai p\u00ebrb\u00ebhet nga UUID, KEY<\/em>ID dhe prefiksi \u00abINNODBKey\u00bb. Kjo duket k\u00ebshtu: INNODBKey-UUID-KEY<em>ID.<\/em><\/p>\n<p><em>UUID \u00ebsht\u00eb uuid i serverit me hap\u00ebsir\u00ebn tabelore t\u00eb koduar. KEY<\/em>ID \u00ebsht\u00eb thjesht nj\u00eb vler\u00eb q\u00eb rritet vazhdimisht. Kur krijohet fillimisht \u00e7el\u00ebsi kryesor KEY<em>ID \u00ebsht\u00eb e barabart\u00eb me 1. N\u00eb rrotullimin e \u00e7el\u00ebsit, kur krijohet nj\u00eb \u00e7el\u00ebs i ri kryesor, KEY<\/em>ID = 2 dhe k\u00ebshtu me radh\u00eb. N\u00eb vazhdim do t\u00eb flasim m\u00eb n\u00eb detaje p\u00ebr rotacionin e \u00e7el\u00ebsave kryesor\u00eb n\u00eb artikujt e tjer\u00eb t\u00eb k\u00ebsaj serie.<\/p>\n<p>Tani q\u00eb dim\u00eb se si duket identifikuesi i \u00e7el\u00ebsit kryesor, le t\u00eb shikojm\u00eb titullin e hap\u00ebsir\u00ebs s\u00eb tabelave t\u00eb enkriptuara. Kur hap\u00ebsira e tabelave \u00ebsht\u00eb e enkriptuar, informacioni mbi enkriptimin i shtohet titullit. Kjo duket si m\u00eb posht\u00eb:<\/p>\n<p><img decoding=\"async\" alt=\"Kriptimi n\u00eb MySQL: p\u00ebrdorimi i \u00c7el\u00ebsit Kryesor\" src=\"\/wp-content\/uploads\/2020\/10\/0703933a85f0a106c07c0dbd6b7f4186.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<p>KEY ID \u00ebsht\u00eb KEY<em>ID nga identifikuesi i \u00e7el\u00ebsit kryesor, t\u00eb cilin e kemi diskutuar tashm\u00eb. UUID \u00ebsht\u00eb uuid i serverit, i cili p\u00ebrdoret gjithashtu n\u00eb identifikuesin e \u00e7el\u00ebsit kryesor. TABLESPACE KEY \u00ebsht\u00eb \u00e7el\u00ebsi i hap\u00ebsir\u00ebs tabelore, i cili p\u00ebrb\u00ebhet nga 256 bit, t\u00eb gjeneruar rast\u00ebsisht nga serveri. Vektori i inicializimit (IV, initialization vector) gjithashtu p\u00ebrb\u00ebhet nga 256 bit t\u00eb gjeneruar rast\u00ebsisht (pavar\u00ebsisht se duhet t\u00eb jet\u00eb 128 bit). IV p\u00ebrdoret p\u00ebr t\u00eb inicializuar enkriptimin dhe dekriptimin AES (nga 256 bit p\u00ebrdoren vet\u00ebm 128). N\u00eb fund ndodhet nj\u00eb kontrollues CRC32 p\u00ebr TABLESPACE KEY dhe IV.<\/em><\/p>\n<p><em>Gjat\u00eb gjith\u00eb k\u00ebtij koh\u00eb kam th\u00ebn\u00eb pak m\u00eb thjesht q\u00eb n\u00eb titull ka nj\u00eb \u00e7el\u00ebs t\u00eb koduar t\u00eb hap\u00ebsir\u00ebs s\u00eb tabel\u00ebs. N\u00eb t\u00eb v\u00ebrtet\u00eb, \u00e7el\u00ebsi i hap\u00ebsir\u00ebs s\u00eb tabel\u00ebs dhe vektori i inicializimit ruhen dhe kodohen s\u00eb bashku me \u00e7el\u00ebsin kryesor. Kini parasysh se para se t\u00eb kodohen \u00e7el\u00ebsi i hap\u00ebsir\u00ebs s\u00eb tabel\u00ebs dhe vektori i inicializimit, p\u00ebr to llogaritet CRC32.<\/em><\/p>\n<h3>Pse \u00ebsht\u00eb e nevojshme CRC32?<\/h3>\n<p><em>N\u00ebse e shprehim n\u00eb dy fjal\u00eb, q\u00eb t\u00eb sigurohemi p\u00ebr vlefshm\u00ebrin\u00eb e \u00e7el\u00ebsit kryesor. Pas \u00e7kodimit t\u00eb \u00e7el\u00ebsit t\u00eb hap\u00ebsir\u00ebs s\u00eb tabel\u00ebs dhe vektorit t\u00eb inicializimit, llogaritet nj\u00eb shum\u00eb kontrolli dhe krahasohet me CRC32-n\u00eb e ruajtur n\u00eb titull. N\u00ebse shumat e kontrollit p\u00ebrputhen, at\u00ebher\u00eb kemi \u00e7el\u00ebsin kryesor t\u00eb duhur dhe \u00e7el\u00ebsin e hap\u00ebsir\u00ebs s\u00eb tabel\u00ebs. N\u00eb t\u00eb kund\u00ebrt, hap\u00ebsira e tabel\u00ebs sh\u00ebnohet si e munguar (ndon\u00ebse ende nuk do t\u00eb mund ta \u00e7kodojm\u00eb).<\/em><\/p>\n<p><em>Mund t\u00eb pyesni: n\u00eb cilin moment realizohet kontrolli i \u00e7el\u00ebsave? P\u00ebrgjigjja \u00ebsht\u00eb - gjat\u00eb aktivizimit t\u00eb serverit. Serveri me tabela t\u00eb koduara \/ hap\u00ebsira tabelore lexon UUID, KEY<\/em>ID nga titulli dhe gjeneron identifikuesin e \u00e7el\u00ebsit kryesor. Pastaj merr \u00e7el\u00ebsin kryesor t\u00eb nevojsh\u00ebm nga depozitimi (keyring), dekripton \u00e7el\u00ebsin e hap\u00ebsir\u00ebs tabelore dhe kontrollon kontrolluesin. P\u00ebrs\u00ebri, n\u00ebse kontrolluesi p\u00ebrputhet, at\u00ebher\u00eb gjith\u00e7ka \u00ebsht\u00eb n\u00eb rregull, n\u00ebse jo - hap\u00ebsira tabelore sh\u00ebnohet si e munguar.<\/p>\n<p>N\u00ebse keni lexuar artikullin e kaluar t\u00eb k\u00ebsaj serie (<noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/otus\/blog\/522092\/\"><u>Kriptimi n\u00eb MySQL: depoja e \u00e7el\u00ebsave<\/u><\/a><\/noindex>), mund t\u00eb mbani mend se kur p\u00ebrdoret depoja e \u00e7el\u00ebsave n\u00eb server, serveri, n\u00eb fillim, merr vet\u00ebm list\u00ebn e identifikuesve t\u00eb \u00e7el\u00ebsave, m\u00eb sakt\u00ebsisht, key id dhe user id, pasi kjo \u00e7ift e identifikon qart\u00eb \u00e7el\u00ebsin. Dhe tani po them, se serveri, n\u00eb fillim, merr t\u00eb gjith\u00eb \u00e7el\u00ebsat e nevojsh\u00ebm p\u00ebr verifikimin e mund\u00ebsis\u00eb p\u00ebr t\u00eb \u00e7el\u00ebsuar \u00e7el\u00ebsat e hap\u00ebsirave t\u00eb tabelave. Pra, pse gjat\u00eb inicializimit, n\u00eb rastin e depojes s\u00eb \u00e7el\u00ebsit n\u00eb server, ngarkohen vet\u00ebm key<em>id dhe user<\/em>id, dhe jo t\u00eb gjitha \u00e7el\u00ebsat? Sepse ndoshta nuk keni nevoj\u00eb p\u00ebr t\u00eb gjith\u00eb \u00e7el\u00ebsat. Kjo kryesisht lidhet me rotacionin e \u00e7el\u00ebsit kryesor. Kur \u00e7el\u00ebsi kryesor rotullohet n\u00eb magazin\u00eb, krijohet nj\u00eb \u00e7el\u00ebs i ri kryesor, por \u00e7el\u00ebsat e vjet\u00ebr nuk fshihen. Prandaj, n\u00eb magazin\u00ebn e serverit t\u00eb \u00e7el\u00ebsave mund t\u00eb keni shum\u00eb \u00e7el\u00ebsa q\u00eb nuk i nevojiten serverit dhe, si pasoj\u00eb, nuk nxirren gjat\u00eb aktivizimit t\u00eb serverit.<\/p>\n<p>Ka ardhur koha p\u00ebr t\u00eb biseduar pak p\u00ebr avantazhet dhe disavantazhet e enkriptimit duke p\u00ebrdorur \u00e7el\u00ebsin kryesor. Avantazhi m\u00eb i madh \u00ebsht\u00eb se ju nevojitet vet\u00ebm nj\u00eb \u00e7el\u00ebs enkriptimi (\u00e7el\u00ebsi kryesor), q\u00eb do t\u00eb ruhet ve\u00e7mas nga t\u00eb dh\u00ebnat tuaja t\u00eb enkriptuara. Kjo e b\u00ebn aktivizimin e serverit t\u00eb shpejt\u00eb, dhe magazin\u00ebn t\u00eb vog\u00ebl, gj\u00eb q\u00eb e leht\u00ebson menaxhimin. Dhe gjithashtu \u00e7el\u00ebsi kryesor i vet\u00ebm \u00ebsht\u00eb leht\u00ebsisht i riparuesh\u00ebm.<\/p>\n<p>Megjithat\u00eb, enkriptimi me \u00e7el\u00ebsin kryesor ka nj\u00eb t\u00eb met\u00eb t\u00eb madhe: nj\u00eb her\u00eb q\u00eb hap\u00ebsira e tabelave \u00ebsht\u00eb enkriptuar me tablespace_key, ajo mbetet gjithmon\u00eb e enkriptuar me t\u00eb nj\u00ebjtin \u00e7el\u00ebs. Rrotullimi i \u00e7el\u00ebsit kryesor k\u00ebtu nuk ndihmon. Pse \u00ebsht\u00eb kjo nj\u00eb e met\u00eb? Ne e dim\u00eb se n\u00eb MySQL ka bugs q\u00eb mund t\u00eb \u00e7ojn\u00eb n\u00eb d\u00ebshtim t\u00eb papritur dhe krijimin e nj\u00eb skedari core. Duke qen\u00eb se skedari core p\u00ebrmban nj\u00eb dump t\u00eb memories s\u00eb serverit, mund t\u00eb ndodh\u00eb q\u00eb n\u00eb dump t\u00eb ket\u00eb \u00e7el\u00ebsin e enkriptuar t\u00eb hap\u00ebsir\u00ebs s\u00eb tabelave. Ajo q\u00eb \u00ebsht\u00eb edhe m\u00eb e keqe, \u00e7el\u00ebsat e enkriptuar t\u00eb hap\u00ebsir\u00ebs s\u00eb tabelave ruhen n\u00eb memory, e cila mund t\u00eb swap n\u00eb disk. Mund t\u00eb thoni se kjo nuk \u00ebsht\u00eb nj\u00eb e met\u00eb, pasi ju nevojiten t\u00eb drejtat root p\u00ebr t\u00eb aksesuar k\u00ebto skedar\u00eb dhe seksionin e swap. Po, por root \u00ebsht\u00eb i nevojsh\u00ebm vet\u00ebm p\u00ebr nj\u00eb koh\u00eb t\u00eb shkurt\u00ebr. Sa her\u00eb q\u00eb dikush t\u00eb ket\u00eb akses n\u00eb \u00e7el\u00ebsin e enkriptuar t\u00eb hap\u00ebsir\u00ebs s\u00eb tabelave, ai\/ajo do t\u00eb jet\u00eb n\u00eb gjendje ta p\u00ebrdor\u00eb at\u00eb p\u00ebr t\u00eb dekoduar t\u00eb dh\u00ebnat, madje pa pasur nevoj\u00eb p\u00ebr t\u00eb drejtat root. P\u00ebr m\u00eb tep\u00ebr, disku mund t\u00eb vidhet, dhe skedar\u00ebt e swapit\/core mund t\u00eb lexohen me ndihm\u00ebn e mjeteve t\u00eb jashtme. Q\u00ebllimi i TDE \u00ebsht\u00eb ta b\u00ebj\u00eb at\u00eb t\u00eb paduksh\u00ebm, edhe n\u00ebse disku vidhet. <noindex><a rel=\"nofollow\" href=\"https:\/\/www.percona.com\/software\/mysql-database\/percona-server\"><u>Percona Server p\u00ebr MySQL<\/u><\/a><\/noindex> ka mund\u00ebsi p\u00ebr rishifrimin e hap\u00ebsir\u00ebs tablike me \u00e7el\u00ebsa t\u00eb rinj t\u00eb gjeneruar. Kjo funksion quhet rrjedha e enkriptimit (encryption threads) dhe n\u00eb momentin e shkruajtjes s\u00eb k\u00ebtij artikulli ende p\u00ebrfundimisht \u00ebsht\u00eb eksperimentale.<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/otus.pw\/wMyj\/\"><strong>M\u00ebso m\u00eb shum\u00eb p\u00ebr kursin<\/strong><\/a><\/noindex><\/p>\n<h3>Lexoni m\u00eb shum\u00eb:<\/h3>\n<ul>\n<li>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/otus\/blog\/522092\/\">Kriptimi n\u00eb MySQL: depoja e \u00e7el\u00ebsave<\/a><\/noindex><\/p>\n<\/li>\n<\/ul>\n<p>Burimi: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/otus\/blog\/524050\/\">habr.com<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u043f\u0440\u0435\u0434\u0434\u0432\u0435\u0440\u0438\u0438 \u0441\u0442\u0430\u0440\u0442\u0430 \u043d\u043e\u0432\u043e\u0433\u043e \u043d\u0430\u0431\u043e\u0440\u0430 \u043d\u0430 \u043a\u0443\u0440\u0441&nbsp;\u00ab\u0411\u0430\u0437\u044b \u0434\u0430\u043d\u043d\u044b\u0445\u00bb&nbsp;\u043f\u0440\u043e\u0434\u043e\u043b\u0436\u0430\u0435\u043c \u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u0442\u044c \u0441\u0435\u0440\u0438\u044e \u0441\u0442\u0430\u0442\u0435\u0439 \u043f\u0440\u043e \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u0435 \u0432 MySQL. \u0412 \u043f\u0440\u0435\u0434\u044b\u0434\u0443\u0449\u0435\u0439 \u0441\u0442\u0430\u0442\u044c\u0435 \u044d\u0442\u043e\u0439 \u0441\u0435\u0440\u0438\u0438 (\u0428\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u0435 \u0432 MySQL: \u0445\u0440\u0430\u043d\u0438\u043b\u0438\u0449\u0435 \u043a\u043b\u044e\u0447\u0435\u0439) \u043c\u044b \u0433\u043e\u0432\u043e\u0440\u0438\u043b\u0438 \u043e \u0445\u0440\u0430\u043d\u0438\u043b\u0438\u0449\u0430\u0445 \u043a\u043b\u044e\u0447\u0435\u0439. \u0412 \u044d\u0442\u043e\u0439 \u0441\u0442\u0430\u0442\u044c\u0435 \u043c\u044b \u0440\u0430\u0441\u0441\u043c\u043e\u0442\u0440\u0438\u043c, \u043a\u0430\u043a \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f \u0433\u043b\u0430\u0432\u043d\u044b\u0439 \u043a\u043b\u044e\u0447 (master key), \u0430 \u0442\u0430\u043a\u0436\u0435 \u043e\u0431\u0441\u0443\u0434\u0438\u043c \u0434\u043e\u0441\u0442\u043e\u0438\u043d\u0441\u0442\u0432\u0430 \u0438 \u043d\u0435\u0434\u043e\u0441\u0442\u0430\u0442\u043a\u0438 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u043c\u0435\u0442\u043e\u0434\u043e\u043c \u043a\u043e\u043d\u0432\u0435\u0440\u0442\u043e\u0432 (envelope encryption).&nbsp; \u0418\u0434\u0435\u044f \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u043a\u043e\u043d\u0432\u0435\u0440\u0442\u043e\u0432 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":97668,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-97667","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.10 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u043f\u0440\u0435\u0434\u0434\u0432\u0435\u0440\u0438\u0438 \u0441\u0442\u0430\u0440\u0442\u0430 \u043d\u043e\u0432\u043e\u0433\u043e \u043d\u0430\u0431\u043e\u0440\u0430 \u043d\u0430 \u043a\u0443\u0440\u0441 \u00ab\u0411\u0430\u0437\u044b \u0434\u0430\u043d\u043d\u044b\u0445\u00bb \u043f\u0440\u043e\u0434\u043e\u043b\u0436\u0430\u0435\u043c \u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u0442\u044c \u0441\u0435\u0440\u0438\u044e \u0441\u0442\u0430\u0442\u0435\u0439 \u043f\u0440\u043e \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u0435 \u0432 MySQL.\u0412 \u043f\u0440\u0435\u0434\u044b\u0434\u0443\u0449\u0435\u0439 \u0441\u0442\u0430\u0442\u044c\u0435 \u044d\u0442\u043e\u0439 \u0441\u0435\u0440\u0438\u0438 (\u0428\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u0435 \u0432 MySQL: \u0445\u0440\u0430\u043d\u0438\u043b\u0438\u0449\u0435 \u043a\u043b\u044e\u0447\u0435\u0439) \u043c\u044b \u0433\u043e\u0432\u043e\u0440\u0438\u043b\u0438 \u043e \u0445\u0440\u0430\u043d\u0438\u043b\u0438\u0449\u0430\u0445 \u043a\u043b\u044e\u0447\u0435\u0439. \u0412 \u044d\u0442\u043e\u0439 \u0441\u0442\u0430\u0442\u044c\u0435 \u043c\u044b \u0440\u0430\u0441\u0441\u043c\u043e\u0442\u0440\u0438\u043c, \u043a\u0430\u043a \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f \u0433\u043b\u0430\u0432\u043d\u044b\u0439 \u043a\u043b\u044e\u0447 (master key), \u0430 \u0442\u0430\u043a\u0436\u0435 \u043e\u0431\u0441\u0443\u0434\u0438\u043c \u0434\u043e\u0441\u0442\u043e\u0438\u043d\u0441\u0442\u0432\u0430 \u0438 \u043d\u0435\u0434\u043e\u0441\u0442\u0430\u0442\u043a\u0438 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u043c\u0435\u0442\u043e\u0434\u043e\u043c \u043a\u043e\u043d\u0432\u0435\u0440\u0442\u043e\u0432 (envelope encryption). \u0418\u0434\u0435\u044f \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u043a\u043e\u043d\u0432\u0435\u0440\u0442\u043e\u0432 \u0437\u0430\u043a\u043b\u044e\u0447\u0430\u0435\u0442\u0441\u044f \u0432\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/shifrovanie-v-mysql-ispolzovanie-master-key\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.10\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0428\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u0435 \u0432 MySQL: \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435 Master Key | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u043f\u0440\u0435\u0434\u0434\u0432\u0435\u0440\u0438\u0438 \u0441\u0442\u0430\u0440\u0442\u0430 \u043d\u043e\u0432\u043e\u0433\u043e \u043d\u0430\u0431\u043e\u0440\u0430 \u043d\u0430 \u043a\u0443\u0440\u0441 \u00ab\u0411\u0430\u0437\u044b \u0434\u0430\u043d\u043d\u044b\u0445\u00bb \u043f\u0440\u043e\u0434\u043e\u043b\u0436\u0430\u0435\u043c \u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u0442\u044c \u0441\u0435\u0440\u0438\u044e \u0441\u0442\u0430\u0442\u0435\u0439 \u043f\u0440\u043e \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u0435 \u0432 MySQL.\u0412 \u043f\u0440\u0435\u0434\u044b\u0434\u0443\u0449\u0435\u0439 \u0441\u0442\u0430\u0442\u044c\u0435 \u044d\u0442\u043e\u0439 \u0441\u0435\u0440\u0438\u0438 (\u0428\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u0435 \u0432 MySQL: \u0445\u0440\u0430\u043d\u0438\u043b\u0438\u0449\u0435 \u043a\u043b\u044e\u0447\u0435\u0439) \u043c\u044b \u0433\u043e\u0432\u043e\u0440\u0438\u043b\u0438 \u043e \u0445\u0440\u0430\u043d\u0438\u043b\u0438\u0449\u0430\u0445 \u043a\u043b\u044e\u0447\u0435\u0439. \u0412 \u044d\u0442\u043e\u0439 \u0441\u0442\u0430\u0442\u044c\u0435 \u043c\u044b \u0440\u0430\u0441\u0441\u043c\u043e\u0442\u0440\u0438\u043c, \u043a\u0430\u043a \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f \u0433\u043b\u0430\u0432\u043d\u044b\u0439 \u043a\u043b\u044e\u0447 (master key), \u0430 \u0442\u0430\u043a\u0436\u0435 \u043e\u0431\u0441\u0443\u0434\u0438\u043c \u0434\u043e\u0441\u0442\u043e\u0438\u043d\u0441\u0442\u0432\u0430 \u0438 \u043d\u0435\u0434\u043e\u0441\u0442\u0430\u0442\u043a\u0438 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u043c\u0435\u0442\u043e\u0434\u043e\u043c \u043a\u043e\u043d\u0432\u0435\u0440\u0442\u043e\u0432 (envelope encryption). \u0418\u0434\u0435\u044f \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u043a\u043e\u043d\u0432\u0435\u0440\u0442\u043e\u0432 \u0437\u0430\u043a\u043b\u044e\u0447\u0430\u0435\u0442\u0441\u044f \u0432\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/shifrovanie-v-mysql-ispolzovanie-master-key\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-10-20T06:42:25+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-10-20T06:42:25+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Enkriptimi n\u00eb MySQL: p\u00ebrdorimi i Master Key | ProHoster","description":"N\u00eb prag t\u00eb fillimit t\u00eb nj\u00eb grupi t\u00eb ri p\u00ebr kursin \"Baza t\u00eb Dh\u00ebnash\", vazhdojm\u00eb t\u00eb publikojm\u00eb nj\u00eb seri artikujsh mbi enkriptimin n\u00eb MySQL. N\u00eb artikullin e m\u00ebparsh\u00ebm t\u00eb k\u00ebsaj serie (Enkriptimi n\u00eb MySQL: depoja e \u00e7el\u00ebsave), fol\u00ebm p\u00ebr depot e \u00e7el\u00ebsave. N\u00eb k\u00ebt\u00eb artikull do t\u00eb shqyrtojm\u00eb si p\u00ebrdoret \u00e7el\u00ebsi kryesor (master key), si dhe do t\u00eb diskutojm\u00eb p\u00ebrfitimet dhe disavantazhet e enkriptimit me metod\u00ebn e zarfit (envelope encryption). Ideja e enkriptimit me zarfa \u00ebsht\u00eb","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/shifrovanie-v-mysql-ispolzovanie-master-key","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0428\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u0435 \u0432 MySQL: \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435 Master Key | ProHoster","og:description":"\u0412 \u043f\u0440\u0435\u0434\u0434\u0432\u0435\u0440\u0438\u0438 \u0441\u0442\u0430\u0440\u0442\u0430 \u043d\u043e\u0432\u043e\u0433\u043e \u043d\u0430\u0431\u043e\u0440\u0430 \u043d\u0430 \u043a\u0443\u0440\u0441 \u00ab\u0411\u0430\u0437\u044b \u0434\u0430\u043d\u043d\u044b\u0445\u00bb \u043f\u0440\u043e\u0434\u043e\u043b\u0436\u0430\u0435\u043c \u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u0442\u044c \u0441\u0435\u0440\u0438\u044e \u0441\u0442\u0430\u0442\u0435\u0439 \u043f\u0440\u043e \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u0435 \u0432 MySQL.\u0412 \u043f\u0440\u0435\u0434\u044b\u0434\u0443\u0449\u0435\u0439 \u0441\u0442\u0430\u0442\u044c\u0435 \u044d\u0442\u043e\u0439 \u0441\u0435\u0440\u0438\u0438 (\u0428\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u0435 \u0432 MySQL: \u0445\u0440\u0430\u043d\u0438\u043b\u0438\u0449\u0435 \u043a\u043b\u044e\u0447\u0435\u0439) \u043c\u044b \u0433\u043e\u0432\u043e\u0440\u0438\u043b\u0438 \u043e \u0445\u0440\u0430\u043d\u0438\u043b\u0438\u0449\u0430\u0445 \u043a\u043b\u044e\u0447\u0435\u0439. \u0412 \u044d\u0442\u043e\u0439 \u0441\u0442\u0430\u0442\u044c\u0435 \u043c\u044b \u0440\u0430\u0441\u0441\u043c\u043e\u0442\u0440\u0438\u043c, \u043a\u0430\u043a \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f \u0433\u043b\u0430\u0432\u043d\u044b\u0439 \u043a\u043b\u044e\u0447 (master key), \u0430 \u0442\u0430\u043a\u0436\u0435 \u043e\u0431\u0441\u0443\u0434\u0438\u043c \u0434\u043e\u0441\u0442\u043e\u0438\u043d\u0441\u0442\u0432\u0430 \u0438 \u043d\u0435\u0434\u043e\u0441\u0442\u0430\u0442\u043a\u0438 \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u043c\u0435\u0442\u043e\u0434\u043e\u043c \u043a\u043e\u043d\u0432\u0435\u0440\u0442\u043e\u0432 (envelope encryption). \u0418\u0434\u0435\u044f \u0448\u0438\u0444\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u043a\u043e\u043d\u0432\u0435\u0440\u0442\u043e\u0432 \u0437\u0430\u043a\u043b\u044e\u0447\u0430\u0435\u0442\u0441\u044f \u0432","og:url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/shifrovanie-v-mysql-ispolzovanie-master-key","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-10-20T06:42:25+00:00","article:modified_time":"2020-10-20T06:42:25+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"97667","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 10:15:28","updated":"2022-10-03 07:13:51"},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/97667","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=97667"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/97667\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media\/97668"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=97667"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=97667"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=97667"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}