
Encrypting Data In eDirectory
251
n
ov
do
cx (e
n)
11
Ju
ly 20
08
To encrypt replication, you need to use the attribute dsEncryptedReplicationConfig. The syntax is:
enable/disable flag#destination replica number#source replica number
Replace with either of these flags:
0: Encrypted replication is disabled
1: Encrypted replication is enabled
Source replica number and destination replica number represents source and destination replica
numbers of a partition. These numbers can be specified in any order because if the replication from
A to B is encrypted, then replication from B to A is also encrypted.
NOTE:
If the source and destination replica number at the partition level is 0 and if the flag is set to
1, all the replicas are considered to be enabled for encrypted replication.
To enable encrypted replication at the partition level, the value of the dsEncryptedReplicationConfig
attribute should be set to 1#0#0.
Following is a sample LDIF file for enabling encrypted replication at the partition level:
dn: o=ou
changetype:modify
replace: dsEncryptedReplicationConfig
dsEncryptedReplicationConfig:1#0#0
These configurations at the partition level are overridden by the configurations at the replica level.
Refer to
“Enabling Encrypted Replication at the Replica Level using LDAP” on page 252
for more
information.
Enabling Encrypted Replication at the Replica Level
When you enable encrypted replication at the replica level, replication between specific replicas is
encrypted. Both outbound and inbound replication between the replicas are encrypted.
For example, consider partition P1 has replicas R1, R2, R3, and R4. You can encrypt the replication
between replicas R1 and R2 or between R2 and R4.
To enable encrypted replication between replicas of a partition, you need to define an encryption
link between the replicas. Refer to
“Enabling Encrypted Replication at the Replica Level Using
iManager” on page 252
for more information.
If you have enabled encrypted replication for one replica, it means that:
the inbound synchronization from a server to this replica
outbound synchronization from this replica to any other server is encrypted.
The replicas you have enabled for encrypted replication must be on eDirectory 8.8 servers. The
remaining replicas in the replica ring, that are not enabled for encrypted replication, can be on
servers with earlier versions of eDirectory.
If you have enabled only specific replicas for encrypted replication, you can add an eDirectory 8.8
server or a pre-eDirectory 8.8 server to the replica ring.
Содержание EDIRECTORY 8.8 SP3
Страница 4: ...novdocx en 11 July 2008...
Страница 72: ...72 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 120: ...120 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 132: ...132 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 190: ...190 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 238: ...238 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 262: ...262 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 288: ...288 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 320: ...320 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 348: ...348 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 388: ...388 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 492: ...492 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 586: ...586 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 599: ...The eDirectory Management Toolbox 599 novdocx en 11 July 2008 Click Help for details...
Страница 600: ...600 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 614: ...614 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...