
Encrypting Data In eDirectory
261
n
ov
do
cx (e
n)
11
Ju
ly 20
08
1b
Start with a clear install (probably including the operating system) on a freshly formatted
and partitioned disk.
This is to ensure that there is no clear text data on the disk. This means you cannot just
take an existing computer which has clear text data previous and re-install eDirectory. You
must have thoroughly erased all traces of data from the disk. Run some kind of secure
erase software, use a magnetic bulk eraser on the disk, or perform something equally
destructive to the data before installing eDirectory.
1c
Configure eDirectory and
set the encryption schemes
that you want on an attribute.
2
Restore the backed up DIB
(that contains the existing clear text data) on the new server. You
can backup the DIB using
DIB Clone
or
Hot Backup
.
3
Destroy any existing clear text data
Any disks (or on other media) with the clear text data on it should be securely wiped. This
includes things like the clear text LDIF file used to bulk load the server, any other server that
was used for replication, or tapes with old backups on them.
Changing the Scheme of the Encrypted Data
The steps require to do this using backup/restore are mentioned below:
1
Change the encryption algorithms
for an attribute.
2
Take a DIB backup. You can backup the DIB using
DIB Clone
or
Hot Backup
.
3
Restore the backed up DIB to a new fresh server, and delete the old server.
4
Destroy any existing clear text data on the old server. This avoids bits and pieces of data with
the old scheme still on the hard disk.
Any disks (or on other media) with the clear text data on it should be securely wiped.This
includes things like the clear text LDIF file used to bulk load the server, any other server that
were used for replication or tapes with old backups on them.
10.3.3 Conclusion
The scenarios listed here are not exhaustive and there might be more scenarios where this problem
occurs. As long as you follow the rule,
No information that would eventually be encrypted should
ever be written to the hard disk (or any other media) in the clear
, the encrypted data will be truly
secure.
Summary of Contents for EDIRECTORY 8.8 SP3
Page 4: ...novdocx en 11 July 2008...
Page 72: ...72 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 120: ...120 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 132: ...132 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 190: ...190 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 238: ...238 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 262: ...262 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 288: ...288 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 320: ...320 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 348: ...348 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 388: ...388 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 492: ...492 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 586: ...586 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 599: ...The eDirectory Management Toolbox 599 novdocx en 11 July 2008 Click Help for details...
Page 600: ...600 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 614: ...614 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...