Server-side encryption for Amazon Redshift sources
Server-side encryption for Amazon Redshift sources
If you want Amazon Redshift to encrypt data while fetching the file from Amazon Redshift and staging the file to Amazon S3, you must enable server-side encryption.
You can configure the customer master key ID generated by AWS Key Management Service (AWS KMS) in the connection properties for server-side encryption. You must add IAM EC2 role and IAM Redshift role to the customer master key when you use IAM authentication and server-side encryption using customer master key.
If you select the server-side encryption in the advanced target properties, you must specify the customer master key ID in the connection properties.
The staging files in the Amazon S3 are deleted after the task is complete.