Encrypting Data In eDirectory
241
no
vd
ocx
(e
n)
6 Ap
ril 20
07
Viewing Encrypted Attributes Using DSBrowse
If you have enabled the Always Require Secure Channel option, that is, if a secure channel is always
required to access the encrypted attributes, you cannot view those attributes of the entry that are
marked for encryption. However, you can view the other attributes of the entry that are not
encrypted.
SNMP Traps
NDS
®
Value Events are blocked if you have specified that you always need a secure channel to
access the encrypted attributes. Traps that are related to value events have value data as NULL and
the result will be set to -6089, which indicates that you need a secure channel to get the encrypted
attribute value. The following traps have the value data as NULL:
ndsAddValue
ndsDeleteValue
ndsDeleteAttribute
10.1.5 Encrypting and Decrypting Backup Data
While backing up data on a server that has attributes marked for encryption, you are prompted to
provide a password to encrypt or decrypt backup data. The -E option in the ndsbackup utility
facilitates this. For more information, refer to the ndsbackup manpage.
For more information on backing up your data, refer to
Chapter 16, “Backing Up and Restoring
Novell eDirectory,” on page 409
.
10.1.6 Cloning the DIB Fileset Containing Encrypted Attributes
While cloning, if the eDirectory database contains encrypted attributes in it, then the cloned DIB
fileset will also have these attribute values encrypted. You need to set a password to secure the key
used by eDirectory to encrypt the values in the cloned DIB fileset. When you place the cloned DIB
fileset on another server, you will be asked to provide this password.
For more information, refer to
“Clone DIB Set” on page 210
.
10.1.7 Adding eDirectory 8.8 Servers to Replica Rings
You can add eDirectory 8.8 servers to replica rings irrespective of whether the attributes are marked
for encryption on one or all the servers hosting the replica or whether Always Require Secure
Channel is enabled or disabled.
For more information on adding eDirectory 8.8 server to the replica ring, refer to
“Adding a
Replica” on page 133
.
10.1.8 Backward Compatibility
You need to change all eDirectory utilities like iManager, SNMP, DirXML
®
and NSureAudit to
secure NCP
TM
to access encrypted attributes. Otherwise, you need to specify that a secure channel is
not necessary to access the encrypted attributes. Refer to
“Enabling and Disabling Access to
Encrypted Attributes Over Clear Text Channels” on page 239
for more information.
Summary of Contents for EDIRECTORY 8.8 SP2
Page 4: ...novdocx en 6 April 2007...
Page 116: ...116 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 128: ...128 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 255: ...256 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 406: ...408 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 563: ...566 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 573: ...576 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...
Page 601: ...604 Novell eDirectory 8 8 Administration Guide novdocx en 6 April 2007...