Server-side Encryption for Amazon Redshift Targets
Server-side Encryption for Amazon Redshift Targets
If you want Amazon Redshift to encrypt data while uploading the .csv files to Amazon Redshift, you must enable server-side encryption. To enable server-side encryption, select
Server Side Encryption
as the encryption type in the target session properties.
You can configure the customer master key ID generated by AWS Key Management Service (AWS KMS) in the connection properties for server-side encryption. You must add IAM EC2 role and IAM Redshift role to the customer master key when you use IAM authentication and server-side encryption using customer master key. If you select the server-side encryption in the target session properties and do not specify the customer master key ID in the connection properties, Amazon S3-managed encryption keys are used to encrypt data.