
Encrypting Data In eDirectory
245
n
ov
do
cx (e
n)
11
Ju
ly 20
08
Recommendation:
eDirectory stores several attributes for its own operations which should not be
marked for encryption. If these attributes are marked for encryption, some of the eDirectory
functionality will possibly be broken or it will not perform as expected.
The attributes that should not marked for encryption are:
federationBoundaryType
Volume
ACL
federationBoundary
member
federationControl
federationSearchPath
encryptionPolicyDN
indexDefinition
dgIdentity
dgAllowUnknown
agTimeout
Host Server
hostResourcePath
ndsPredicateState
ndsStatusExternalReference
ndsStausLimber
ndsStatusSchema
Though the list is not exhaustive, similar kind of attributes should not be marked for encryption.
10.1.3 Accessing the Encrypted Attributes
When you encrypt the attributes, you also protect the access to the encrypted attributes. This is
because eDirectory 8.8 and later can restrict the access to the encrypted attributes over secure
channel (LDAP secure channel or NCP secure channel.)
By default, the encrypted attributes can be accessed only through a secure channel.
However, if you want the clients to be able to access the encrypted attributes over clear text, then
disable the Always Require Secure Channel option. For more information, refer to
“Enabling and
Disabling Access to Encrypted Attributes Over Clear Text Channels” on page 245
.
Enabling and Disabling Access to Encrypted Attributes Over Clear Text Channels
You can enable or disable the access to encrypted attributes over clear text channels by enabling or
disabling Always Require Secure Channel option (that is, the attrEncryptionRequireSecure
attribute) using either iManager or LDAP.
Summary of Contents for EDIRECTORY 8.8 SP3
Page 4: ...novdocx en 11 July 2008...
Page 72: ...72 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 120: ...120 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 132: ...132 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 190: ...190 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 238: ...238 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 262: ...262 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 288: ...288 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 320: ...320 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 348: ...348 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 388: ...388 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 492: ...492 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 586: ...586 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 599: ...The eDirectory Management Toolbox 599 novdocx en 11 July 2008 Click Help for details...
Page 600: ...600 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 614: ...614 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...