
Encrypting Data In eDirectory
10
239
n
ov
do
cx (e
n)
11
Ju
ly 20
08
10
Encrypting Data In eDirectory
In Novell
®
eDirectory
TM
8.8 and later, you can encrypt specific data when they are stored on the disk
and when they are transmitted between two or more eDirectory 8.8 servers. This provides greater
security for the confidential data.
Refer to the
Novell eDirectory 8.8 What's New Guide
(http://www.novell.com/documentation/
edir88/index.html)
for more information on the need for encryption of data and the scenarios in
which you can encrypt data.
You can protect data by encrypting the following:
Attributes: For protecting confidential data stored on the disk.
See
Section 10.1, “Encrypted Attributes,” on page 239
.
Replication: For protecting confidential data during replication between eDirectory 8.8 servers.
Section 10.2, “Encrypted Replication,” on page 248
.
10.1 Encrypted Attributes
In eDirectory 8.8 and later, you can encrypt the attributes to protect data while they are stored on the
disk. Encrypted attributes is a server-specific feature.
When you encrypt an attribute, the value of the attribute is encoded. For example, you can encrypt
an attribute empno stored in DIB. If empno=1000, then the value of the attribute (1000), is not
stored as clear text on the disk. You can read this encrypted value only when you access the
directory over a secure channel.
All attributes in a schema can be enabled for encryption. However, we recommend you not to enable
Common Name (CN) attribute for encryption and enable only the sensitive data for encryption.
Refer to
Section 10.3, “Achieving Complete Security While Encrypting Data,” on page 259
before
you decide on marking any attributes for encryption.
There is no limitation in accessing Public and Server readable encrypted attributes, this means that a
client can access these attributes over clear text but you can mark these attributes for encryption at
the DIB level. Enabling encryption on an attribute which is flagged [Public Read] in schema, does
not prevent it from being accessed via non-secure methods.
Figure 10-1
Encrypted Attributes
eDirectory Server
(earlier versions)
eDirectory 8.8
Server
Attributes cannot
be encrypted
Encryption enabled
for attribute 'empno'
1) Paul
empno ='1000'
2) Jack
empno ='2000'
1) Paul
empno =****
2) Jack
empno =****
Содержание EDIRECTORY 8.8 SP3
Страница 4: ...novdocx en 11 July 2008...
Страница 72: ...72 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 120: ...120 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 132: ...132 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 190: ...190 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 238: ...238 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 262: ...262 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 288: ...288 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 320: ...320 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 348: ...348 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 388: ...388 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 492: ...492 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 586: ...586 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 599: ...The eDirectory Management Toolbox 599 novdocx en 11 July 2008 Click Help for details...
Страница 600: ...600 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 614: ...614 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...