Encrypting Data In eDirectory
247
no
vd
ocx (
E
NU)
01
F
ebr
ua
ry
200
6
9.3.1 Encrypting Data in an All New Setup
In case of a new setup, you would have just installed the operating system and then eDirectory. It is
assured that there is no clear text data present in the hard disk where the DIB resides.
Complete the following steps to ensure that the encrypted data in eDirectory is truly secure:
1
Plan in advance which attributes you want to encrypt and with what scheme.
That is, you must decide in advance which attributes you want to encrypt before uploading the
data in clear text into the eDirectory.
WARNING:
Once you have loaded any data into the eDirectory in the clear, you should not
mark an attribute for encryption. Though you can do it, this leads to security problems.
2
Configure eDirectory and
set the encryption schemes
that you want on an attribute.
3
Load your existing data into the new server.
Bulkloading from an LDIF
file or
replicating with another server
are the two most likely
scenarios. Make sure that if you bulk load, you don’t copy the clear text LDIF file onto the
same hard disk where the DIB resides. (Remember the Rule mentioned: No clear text data can
ever be written to the disk.)
4
Destroy any existing clear text data
Any disks (or on other media) with the clear text data on it should be securely wiped. This
includes things like the clear text LDIF file used to bulk load the server, any other server that
was used for replication, or tapes with old backups on them.
9.3.2 Encrypting Data in an Existing Setup
This scenario includes the following:
•
“Existing Clear Text Data to Encrypted Data” on page 247
•
“Changing the Scheme of the Encrypted Data” on page 248
Existing Clear Text Data to Encrypted Data
You can mark clear text data for encryption and ensure that the data is secure through the following
methods:
•
“Through Replication” on page 247
•
“Through Backup and Restore” on page 248
Through Replication
1
Setup encryption on a new server as follows:
1a
Plan in advance which attributes you want to encrypt and with what scheme.
That is, you must decide in advance which attributes you want to encrypt before uploading
the data in clear text into the eDirectory.
WARNING:
Once you have loaded any data into the eDirectory in the clear, you should
not mark an attribute for encryption. Though you can do it, this leads to security problems.
Summary of Contents for EDIRECTORY 8.8 - GUIDE
Page 4: ...novdocx ENU 01 February 2006...
Page 16: ...16 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 68: ...68 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 90: ...90 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 116: ...116 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 128: ...128 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 184: ...184 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 249: ...250 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 307: ...308 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 333: ...334 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 371: ...372 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 439: ...440 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 519: ...520 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 529: ...530 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Page 555: ...556 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...