Chapter 3. Plug-in Implemented Server Functionality Reference
192
dn:cn=userPassword, cn=encrypted attributes,o=UserRoot, cn=ldbm database,
cn=plugins, cn=config
objectclass:top
objectclass:nsAttributeEncryption
cn:userPassword
nsEncryptionAlgorithm:AES
To configure database encryption, see the "Database Encryption" section of the "Configuring Directory
Databases" chapter in the
Directory Server Administrator's Guide
. For more information about
indexes, refer to the "Managing Indexes" chapter in the
Directory Server Administrator's Guide
.
3.4.8.1. nsAttributeEncryption (Object Class)
This object class is used for core configuration entries which identify and encrypt selected attributes
within a Directory Server database.
This object class is defined in Directory Server.
Superior Class
top
OID
2.16.840.1.113730.3.2.316
Required Attributes
objectClass
Defines the object classes for the entry.
cn
Specifies the attribute being encrypted using its
common name.
nsEncryptionAlgorithm
18
The encryption cipher used.
3.4.8.2. nsEncryptionAlgorithm
nsEncryptionAlgorithm
selects the cipher used by
nsAttributeEncryption
. The algorithm
can be set per encrypted attribute.
Parameter
Description
Entry DN
cn=attributeName, cn=encrypted attributes,
cn=databaseName, cn=ldbm database,
cn=plugins, cn=config
Valid Values
The following are supported ciphers:
• Advanced Encryption Standard Block Cipher
(AES)
• Triple Data Encryption Standard Block Cipher
(3DES)
Default Value
Syntax
DirectoryString
Summary of Contents for 8.1
Page 8: ...viii ...
Page 14: ...xiv ...
Page 16: ...2 ...
Page 250: ...236 ...
Page 334: ...320 ...
Page 372: ...358 ...