Red-hat 8.1 Manual do Utilizador Página 140

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir
  • Página
    / 292
  • Índice
  • MARCADORES
  • Avaliado. / 5. Com base em avaliações de clientes
Vista de página 139
Example nsSubStrMiddle: 3
3.4 .8. Dat abase Attributes unde r cn=attribut eName, cn=encrypt ed att ributes,
cn=dat abase _name, cn=ldbm dat abase , cn=plugins, cn=config
The nsAttributeEncryption object class allows selective encryption of attributes within a database.
Extremely sensitive information such as credit card numbers and government identification numbers may
not be protected enough by routine access control measures. Normally, these attribute values are
stored in CLEAR within the database; encrypting them while they are stored adds another layer of
protection. T his object class has one attribute, nsEncryptionAlgorithm, which sets the encryption
cipher used per attribute. Each encrypted attribute represents a subentry under the above cn=config
information tree nodes, as shown in the following diagram:
Figure 3.3. Encrypte d Attribute s under t he cn=config Node
For example, the database encryption file for the userPassword attribute under o=UserRoot appears in
the Directory Server as follows:
dn:cn=userPassword, cn=encrypted attributes,o=UserRoot, cn=ldbm database,
cn=plugins, cn=config
objectclass:top
objectclass:nsAttributeEncryption
cn:userPassword
nsEncryptionAlgorithm :AES
To configure database encryption, see the "Database Encryption" section of the "Configuring Directory
Databases" chapter in the Directory Server Administrator's Guide. For more information about indexes,
refer to the "Managing Indexes" chapter in the Directory Server Administrator's Guide.
3.4 .8.1 . nsAt tribute Encryption (Object Class)
This object class is used for core configuration entries which identify and encrypt selected attributes
within a Directory Server database.
This object class is defined in Directory Server.
Superior Class
top
OID
2.16.840.1.113730.3.2.316
Required Attribute s
objectClass Defines the object classes for the entry.
cn Specifies the attribute being encrypted using its
common name.
nsEncryptionAlgorithm The encryption cipher used.
3.4 .8.2 . nsEncryptionAlgorit hm
nsEncryptionAlgorithm selects the cipher used by nsAttributeEncryption. T he algorithm can be
set per encrypted attribute.
Parameter Descript ion
Entry DN cn=attributeName, cn=encrypted attributes,
cn=databaseName, cn=ldbm database,
cn=plugins, cn=config
Valid Values The following are supported ciphers:
Advanced Encryption Standard Block Cipher
(AES)
14 0 Chapter 3. Plug-in Implemented Server Functionality Reference
Vista de página 139
1 2 ... 135 136 137 138 139 140 141 142 143 144 145 ... 291 292

Comentários a estes Manuais

Sem comentários