242
Novell eDirectory 8.8 Administration Guide
n
ov
do
cx (e
n)
22
Ju
n
e 20
09
The data in eDirectory can be stored in any of the following ways:
In the Data Information Base (DIB) or database
As backup data
LDIF file
You can encrypt attributes by creating and applying encrypted attributes policies to the servers.
To encrypt the attributes, do the following using iManager:
1
Create and define an encrypted attribute policy.
1a
Select the attributes for encryption.
1b
Select the
encryption scheme
for the attributes.
Refer to
“Creating and Defining Encrypted Attributes Policies” on page 244
for more
information.
2
Apply the encrypted attributes policy to a server.
Refer to
“Applying Encrypted Attributes Policies” on page 244
for more information.
You can also encrypt attributes through LDAP.
Refer to
“Managing Encrypted Attributes Policies Through LDAP” on page 245
for more
information.
NOTE:
Encrypted Attributes Policy assignment takes effect when Limber runs.
As a best practice, we recommend you to do the following:
Mark only sensitive attributes for encryption. Do not mark all attributes for encryption (for
example, public or server readable attributes).
Use AES while marking an attribute for encryption as it is the strong encryption algorithm.
The rest of this section provides the following information:
Section 11.1.1, “Using Encryption Schemes,” on page 242
Section 11.1.3, “Accessing the Encrypted Attributes,” on page 247
Section 11.1.4, “Viewing the Encrypted Attributes,” on page 248
Section 11.1.2, “Managing Encrypted Attributes Policies,” on page 243
Section 11.1.9, “Migrating to Encrypted Attributes,” on page 250
11.1.1 Using Encryption Schemes
eDirectory 8.8 provides the highest level of security for an attribute by supporting the following
encryption schemes:
Advanced Encryption Standard (AES)
Triple DES
Data Encryption Standard (DES)
Summary of Contents for EDIRECTORY 8.8 SP5
Page 4: ...4 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 72: ...72 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 118: ...118 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 130: ...130 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 188: ...188 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 222: ...222 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 240: ...240 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 264: ...264 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 290: ...290 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 322: ...322 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 540: ...540 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 548: ...548 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...
Page 616: ...616 Novell eDirectory 8 8 Administration Guide novdocx en 22 June 2009...