
Encrypting Data In eDirectory
261
n
ov
do
cx (e
n)
11
Ju
ly 20
08
1b
Start with a clear install (probably including the operating system) on a freshly formatted
and partitioned disk.
This is to ensure that there is no clear text data on the disk. This means you cannot just
take an existing computer which has clear text data previous and re-install eDirectory. You
must have thoroughly erased all traces of data from the disk. Run some kind of secure
erase software, use a magnetic bulk eraser on the disk, or perform something equally
destructive to the data before installing eDirectory.
1c
Configure eDirectory and
set the encryption schemes
that you want on an attribute.
2
Restore the backed up DIB
(that contains the existing clear text data) on the new server. You
can backup the DIB using
DIB Clone
or
Hot Backup
.
3
Destroy any existing clear text data
Any disks (or on other media) with the clear text data on it should be securely wiped. This
includes things like the clear text LDIF file used to bulk load the server, any other server that
was used for replication, or tapes with old backups on them.
Changing the Scheme of the Encrypted Data
The steps require to do this using backup/restore are mentioned below:
1
Change the encryption algorithms
for an attribute.
2
Take a DIB backup. You can backup the DIB using
DIB Clone
or
Hot Backup
.
3
Restore the backed up DIB to a new fresh server, and delete the old server.
4
Destroy any existing clear text data on the old server. This avoids bits and pieces of data with
the old scheme still on the hard disk.
Any disks (or on other media) with the clear text data on it should be securely wiped.This
includes things like the clear text LDIF file used to bulk load the server, any other server that
were used for replication or tapes with old backups on them.
10.3.3 Conclusion
The scenarios listed here are not exhaustive and there might be more scenarios where this problem
occurs. As long as you follow the rule,
No information that would eventually be encrypted should
ever be written to the hard disk (or any other media) in the clear
, the encrypted data will be truly
secure.
Содержание EDIRECTORY 8.8 SP3
Страница 4: ...novdocx en 11 July 2008...
Страница 72: ...72 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 120: ...120 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 132: ...132 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 190: ...190 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 238: ...238 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 262: ...262 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 288: ...288 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 320: ...320 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 348: ...348 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 388: ...388 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 492: ...492 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 586: ...586 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 599: ...The eDirectory Management Toolbox 599 novdocx en 11 July 2008 Click Help for details...
Страница 600: ...600 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...
Страница 614: ...614 Novell eDirectory 8 8 Administration Guide novdocx en 11 July 2008...