248
Novell eDirectory 8.8 Administration Guide
no
vd
ocx (
E
NU)
01
F
ebr
ua
ry
200
6
1b
Start with a clear install (probably including the OS) on a freshly formatted and
partitioned disk.
This is to ensure that there is no clear text data on the disk. This means you cannot just
take an existing computer which has clear text data previous and re-install eDirectory. You
must have thoroughly erased all traces of data from the disk. Run some kind of secure
erase software, use a magnetic bulk eraser on the disk, or perform something equally
destructive to the data before installing eDirectory.
1c
Configure eDirectory and
set the encryption schemes
that you want on an attribute.
2
Move this server into a replica ring
where you have the existing data that you want to encrypt,
let the replication happen then take the old server offline.
3
Destroy any existing clear text data
Any disks (or on other media) with the clear text data on it should be securely wiped. This
includes things like the clear text LDIF file used to bulk load the server, any other server that
was used for replication, or tapes with old backups on them.
Through Backup and Restore
1
Setup encrypting on a new server as follows:
1a
Plan in advance which attributes you want to encrypt and with what scheme.
That is, you must decide in advance which attributes you want to encrypt before uploading
the data in clear text into the eDirectory.
WARNING:
Once you have loaded any data into the eDirectory in the clear, you should
not mark an attribute for encryption. Though you can do it, this leads to security problems
listed in Note A.
1b
Start with a clear install (probably including the operating system) on a freshly formatted
and partitioned disk.
This is to ensure that there is no clear text data on the disk. This means you cannot just
take an existing computer which has clear text data previous and re-install eDirectory. You
must have thoroughly erased all traces of data from the disk. Run some kind of secure
erase software, use a magnetic bulk eraser on the disk, or perform something equally
destructive to the data before installing eDirectory.
1c
Configure eDirectory and
set the encryption schemes
that you want on an attribute.
2
Restore the backed up DIB
(that contains the existing clear text data) on the new server. You
can backup the DIB using
DIB Clone
or
Hot Backup
.
3
Destroy any existing clear text data
Any disks (or on other media) with the clear text data on it should be securely wiped. This
includes things like the clear text LDIF file used to bulk load the server, any other server that
was used for replication, or tapes with old backups on them.
Changing the Scheme of the Encrypted Data
The steps require to do this using backup/restore are mentioned below:
1
Change the encryption algorithms
for an attribute.
2
Take a DIB backup. You can backup the DIB using
DIB Clone
or
Hot Backup
.
3
Restore the backed up DIB to a new fresh server, and delete the old server.
Содержание EDIRECTORY 8.8 - GUIDE
Страница 4: ...novdocx ENU 01 February 2006...
Страница 16: ...16 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 68: ...68 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 90: ...90 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 116: ...116 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 128: ...128 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 184: ...184 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 249: ...250 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 307: ...308 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 333: ...334 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 371: ...372 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 439: ...440 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 519: ...520 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 529: ...530 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...
Страница 555: ...556 Novell eDirectory 8 8 Administration Guide novdocx ENU 01 February 2006...