
488
Novell eDirectory 8.8 Administration Guide
n
ov
do
cx (e
n)
11
Ju
ly 20
08
16.11 Backing Up and Restoring NICI
Novell International Cryptography Infrastructure (NICI) stores keys and user data in the file system
and in system and user specific directories and files. These directories and files are protected by
setting the proper permissions on them using the mechanism provided by the operating system. This
is done by the NICI installation program.
Uninstalling NICI from the system does not remove the system or user directories and files.
Therefore, the only reason to restore these files to a previous state is to recover from a catastrophic
system failure or a human error. It is important to understand that overwriting an existing set of NICI
user directories and files might break an existing application.
Backing up and restoring NICI requires two things:
1. Backing up and restoring directories and files.
2. Backing up and restoring specific user rights on those directories and files.
The exact sequence of events required is depends on the platform you are using.
The critical issue with backup and restore is to maintain the exact permissions on the directories and
files. NICI’s operation and the security it provides depend on these permissions being set properly.
Typical commercial backup software should preserve permissions on the NICI system and user
directories and files. Check your backup software to see if it does the job before doing a custom
backup of NICI.
Care should be taken to back up the existing NICI directory structure and its contents, if any, before
doing a restore. Losing the machine key is unrecoverable. Because the user data and keys could be
encrypted using the machine key, losing it would result in a permanent loss of user data.
Doing a restore of just NICI will require knowledge on your part to determine which files must be
restored. During restoration, it is important that the correct access rights be restored for the correct
owner. On UNIX and Windows systems, the name of the user specific directory reflects the ID of the
owner, but on both systems, the owner ID might change between the time of the backup and the time
of the restore. For security reasons, the operator must know which account is being restored and
determine that the directory name and access rights are assigned accordingly. The mere existence of
a user account on the system with the same ID as the one that was backed up does not mean that the
current account is the actual owner of the information being restored.
For more information, see
TID10098087, How to Backup NICI 2.7.x and 2.6.x (http://
support.novell.com/cgi-bin/search/searchtid.cgi?/10098087.htm)
and
TID10096647, How to
Backup the eDirectory Database and Associated Security Services Files (http://support.novell.com/
cgi-bin/search/searchtid.cgi?/10096647.htm)
in the Novell Knowledgebase.
16.11.1 UNIX
In NICI 2.6.5 and earlier, the
/var/novell/nici
directory contains all the system and user
directories and files. In NICI 2.7.0 and later,
/var/novell/nici
is a symbolic link to the
/
var/opt/novell/nici
directory that contains the files.
To determine the version of NICI you are using, see the
/etc/nici.cfg
file.
Summary of Contents for EDIRECTORY 8.8 SP3
Page 4: ...novdocx en 11 July 2008...
Page 72: ...72 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 120: ...120 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 132: ...132 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 190: ...190 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 238: ...238 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 262: ...262 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 288: ...288 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 320: ...320 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 348: ...348 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 388: ...388 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 492: ...492 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 586: ...586 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 599: ...The eDirectory Management Toolbox 599 novdocx en 11 July 2008 Click Help for details...
Page 600: ...600 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Page 614: ...614 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...