Encrypting Data In eDirectory
231
no
vd
ocx (
E
NU)
01
F
ebr
ua
ry
200
6
4
Follow the instructions in the Encrypted Attributes Policies Management Wizard to delete the
policy.
Help is available throughout the wizard.
Managing Encrypted Attributes Policies Through LDAP
IMPORTANT:
We strongly recommend you to use iManager for managing encrypted attributes
and not LDAP.
This section contains the following procedures:
•
“Creating and Defining Encrypted Attributes Policies” on page 231
•
“Editing Encrypted Attributes Policies” on page 232
•
“Applying Encrypted Attributes Policy” on page 232
•
“Deleting Encrypted Attributes Policy” on page 232
NOTE:
You should specify the attribute and scheme pair while marking any attribute through LDIF
for encryption and not the list of attributes and scheme. This is the current limitation with encrypted
attributes.
Creating and Defining Encrypted Attributes Policies
1
Create an attribute encryption policy.
For example, the encrypted attributes policy is AE Policy- test-server, then
dn: cn=AE Policy - test-server, o=novell
changetype: add
objectClass: encryptionPolicy
2
Add the attrEncryptionDefinition attribute to the Policy object you created and mark the
attributes for encryption.
For example, if the attribute name you want to encrypt is CRID then specify the encryption
scheme and attribute name as mentioned below:
dn: cn=AE Policy - test-server, o=novell
changetype: modify
add: attrEncryptionDefinition
attrEncryptionDefinition: aes$CRID
NOTE:
Attribute name specifies the NDS name for the attribute. Many attributes in eDirectory
have both an LDAP name and an NDS name. Here, specify the attribute name requires the
NDS name.
3
Add the attrEncryptionRequiresSecure attribute to the policy.
The value of this attribute specifies whether a secure channel is always necessary to access the
encrypted attributes. The value 0 means that it is not always necessary. The value 1 means that
it is always necessary.
For example:
dn: cn=AE Policy - test-server, o=novell
changetype: modify
Содержание EDIRECTORY 8.8 - GUIDE
Страница 4: ...novdocx ENU 01 February 2006...
Страница 16: ...16 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 68: ...68 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 90: ...90 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 116: ...116 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 128: ...128 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 184: ...184 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 249: ...250 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 307: ...308 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 333: ...334 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 371: ...372 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 439: ...440 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 519: ...520 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 529: ...530 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 555: ...556 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...