
Database Encryption
55
WARNING
There is no mechanism for recovering a lost key. Therefore, it is especially important
to back up the server's certificate database safely. If the server's certificate were lost, it
would not be possible to decrypt any encrypted data stored in its database.
WARNING
If the SSL certificate is expiring and needs to be renewed, export the encrypted backend
instance before the renewal. Update the certificate, then re-import the exported LDIF file.
3.2.3.2. Encryption Ciphers
The encryption cipher is configurable on a per-attribute basis and must be selected by the
administrator at the time encryption is enabled for an attribute. Configuration can be done through the
Console or through the command line.
The following ciphers are supported:
• Advanced Encryption Standard (AES)
• Triple Data Encryption Standard (3DES)
All ciphers are used in Cipher Block Chaining mode.
Once the encryption cipher is set, it should not be changed without exporting and re-importing the
data.
3.2.3.3. Configuring Database Encryption from the Console
1. In the Console, open the
Directory Server
.
2. Open the
Configuration
tab, and select the
Data
node.
3. In the
Data
node, select the backend to edit, such as
dc=example,dc=com
.
4. Next, select the root to edit, such as
o=userRoot
.
5. Select the
Attribute Encryption
tab.
6. Hit the
Add Attribute
button, and a list of attributes will appear. Select the attribute to encrypt.
NOTE
For existing attribute entries to be encrypted, the information must be exported, then
re-imported. See
Section 3.2.3.5, “Exporting and Importing an Encrypted Database”
.
7. Select which encryption cipher to use.
8. Repeat steps
6
and
7
for every attribute to encrypt. Then hit
Save
.
Summary of Contents for DIRECTORY SERVER 8.0
Page 18: ...xviii ...
Page 29: ...Configuring the Directory Manager 11 6 Enter the new password and confirm it 7 Click Save ...
Page 30: ...12 ...
Page 112: ...94 ...
Page 128: ...110 ...
Page 190: ...Chapter 6 Managing Access Control 172 4 Click New to open the Access Control Editor ...
Page 224: ...206 ...
Page 324: ...306 ...
Page 334: ...316 ...
Page 358: ...340 ...
Page 410: ...392 ...
Page 420: ...402 ...
Page 444: ...426 ...
Page 454: ...436 ...
Page 464: ...446 ...
Page 484: ...466 ...
Page 512: ...494 ...
Page 522: ...504 ...