Encrypting Data In eDirectory
9
no
vd
ocx (
E
NU)
01
F
ebr
ua
ry
200
6
227
9
Encrypting Data In eDirectory
In Novell
®
eDirectory
TM
8.8 and later, you can encrypt specific data when they are stored on the disk
and when they are transmitted between two or more eDirectory 8.8 servers. This provides greater
security for the confidential data.
Refer to the
Novell eDirectory 8.8 What's New Guide
(http://www.novell.com/documentation/
edir88/index.html)
for more information on the need for encryption of data and the scenarios in
which you can encrypt data.
You can protect data by encrypting the following:
• Attributes: For protecting confidential data stored on the disk.
See
Section 9.1, “Encrypted Attributes,” on page 227
.
• Replication: For protecting confidential data during replication between eDirectory 8.8 servers.
Section 9.2, “Encrypted Replication,” on page 235
.
9.1 Encrypted Attributes
In eDirectory 8.8 and later, you can encrypt the attributes to protect data while they are stored on the
disk. Encrypted attributes is a server-specific features.
When you encrypt an attribute, the value of the attribute is encoded. For example, you can encrypt
an attribute empno stored in DIB. If empno=1000, then the value of the attribute (1000), is not
stored as clear text on the disk. You can read this encrypted value only when you access the
directory over a secure channel.
All attributes in a schema can be enabled for encryption. However, we recommend you not to enable
Common Name (CN) attribute for encryption and enable only the sensitive data for encryption.
Refer to
Section 9.3, “Achieving Complete Security While Encrypting Data,” on page 246
before
you decide on marking any attributes for encryption.
There is no limitation in accessing Public and Server readable encrypted attributes, this means that a
client can access these attributes over clear text but you can mark these attributes for encryption at
the DIB level.
Figure 9-1
Encrypted Attributes
eDirectory Server
(earlier versions)
eDirectory 8.8
Server
Attributes cannot
be encrypted
Encryption enabled
for attribute 'empno'
1) Paul
empno ='1000'
2) Jack
empno ='2000'
1) Paul
empno =****
2) Jack
empno =****
Summary of Contents for EDIRECTORY 8.8 - GUIDE
Page 4: ...novdocx ENU 01 February 2006...
Page 16: ...16 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 68: ...68 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 90: ...90 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 116: ...116 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 128: ...128 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 184: ...184 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 249: ...250 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 307: ...308 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 333: ...334 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 371: ...372 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 439: ...440 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 519: ...520 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 529: ...530 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 555: ...556 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...