
260
Novell eDirectory 8.8 Administration Guide
n
ov
do
cx (e
n)
11
Ju
ly 20
08
10.3.2 Encrypting Data in an Existing Setup
This scenario includes the following:
“Existing Clear Text Data to Encrypted Data” on page 260
“Changing the Scheme of the Encrypted Data” on page 261
Existing Clear Text Data to Encrypted Data
You can mark clear text data for encryption and ensure that the data is secure through the following
methods:
“Through Replication” on page 260
“Through Backup and Restore” on page 260
Through Replication
1
Setup encryption on a new server as follows:
1a
Plan in advance which attributes you want to encrypt and with what scheme.
That is, you must decide in advance which attributes you want to encrypt before uploading
the data in clear text into the eDirectory.
WARNING:
Once you have loaded any data into the eDirectory in the clear, you should
not mark an attribute for encryption. Though you can do it, this leads to security problems.
1b
Start with a clear install (probably including the OS) on a freshly formatted and
partitioned disk.
This is to ensure that there is no clear text data on the disk. This means you cannot just
take an existing computer which has clear text data previous and re-install eDirectory. You
must have thoroughly erased all traces of data from the disk. Run some kind of secure
erase software, use a magnetic bulk eraser on the disk, or perform something equally
destructive to the data before installing eDirectory.
1c
Configure eDirectory and
set the encryption schemes
that you want on an attribute.
2
Move this server into a replica ring
where you have the existing data that you want to encrypt,
let the replication happen then take the old server offline.
3
Destroy any existing clear text data
Any disks (or on other media) with the clear text data on it should be securely wiped. This
includes things like the clear text LDIF file used to bulk load the server, any other server that
was used for replication, or tapes with old backups on them.
Through Backup and Restore
1
Setup encrypting on a new server as follows:
1a
Plan in advance which attributes you want to encrypt and with what scheme.
That is, you must decide in advance which attributes you want to encrypt before uploading
the data in clear text into the eDirectory.
WARNING:
Once you have loaded any data into the eDirectory in the clear, you should
not mark an attribute for encryption. Though you can do it, this leads to security problems
listed in Note A.
Содержание EDIRECTORY 8.8 SP3
Страница 4: ...novdocx en 11 July 2008...
Страница 72: ...72 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 120: ...120 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 132: ...132 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 190: ...190 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 238: ...238 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 262: ...262 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 288: ...288 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 320: ...320 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 348: ...348 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 388: ...388 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 492: ...492 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 586: ...586 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 599: ...The eDirectory Management Toolbox 599 novdocx en 11 July 2008 Click Help for details...
Страница 600: ...600 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 614: ...614 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...