
234
Novell eDirectory 8.8 Administration Guide
no
vd
ocx (
E
NU)
01
F
ebr
ua
ry
200
6
Viewing Encrypted Attributes Using iManager
If Always Require Secure Channel is enabled, you cannot view the encrypted attributes. You get the
error -6089, indicating that you need a secure channel to access the encrypted attributes.
If Always Require Secure Channel is disabled, you can see the encrypted attributes values in
iManager.
For more information, refer to
“Browsing Objects in Your Tree” on page 200
.
Viewing Encrypted Attributes Using DSBrowse
If you have enabled the Always Require Secure Channel option, that is, if a secure channel is always
required to access the encrypted attributes, you cannot view those attributes of the entry that are
marked for encryption. However, you can view the other attributes of the entry that are not
encrypted.
SNMP Traps
NDS
®
Value Events are blocked if you have specified that you always need a secure channel to
access the encrypted attributes. Traps that are related to value events have value data as NULL and
the result will be set to -6089, which indicates that you need a secure channel to get the encrypted
attribute value. The following traps have the value data as NULL:
• ndsAddValue
• ndsDeleteValue
• ndsDeleteAttribute
9.1.5 Encrypting and Decrypting Backup Data
While backing up data on a server that has attributes marked for encryption, you are prompted to
provide a password to encrypt or decrypt backup data. The -E option in the ndsbackup utility
facilitates this. For more information, refer to the ndsbackup manpage.
For more information on backing up your data, refer to
Chapter 14, “Backing Up and Restoring
Novell eDirectory,” on page 373
.
9.1.6 Cloning the DIB Fileset Containing Encrypted Attributes
While cloning, if the eDirectory database contains encrypted attributes in it, then the cloned DIB
fileset will also have these attribute values encrypted. You need to set a password to secure the key
used by eDirectory to encrypt the values in the cloned DIB fileset. When you place the cloned DIB
fileset on another server, you will be asked to provide this password.
For more information, refer to
“Clone DIB Set” on page 204
.
9.1.7 Adding eDirectory 8.8 Servers to Replica Rings
You can add eDirectory 8.8 servers to replica rings irrespective of whether the attributes are marked
for encryption on one or all the servers hosting the replica or whether Always Require Secure
Channel is enabled or disabled.
Содержание EDIRECTORY 8.8 - GUIDE
Страница 4: ...novdocx ENU 01 February 2006...
Страница 16: ...16 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 68: ...68 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 90: ...90 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 116: ...116 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 128: ...128 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 184: ...184 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 249: ...250 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 307: ...308 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 333: ...334 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 371: ...372 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 439: ...440 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 519: ...520 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 529: ...530 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 555: ...556 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...