Synchronizing two-way cryptography between server instances
You must synchronize two-way cryptography between directory server instances to reduce the time that is required to encrypt and decrypt data during server communications.
Before you begin
To synchronize directory server instances by using two-way cryptography, you must have two or more instances.
You must synchronize the servers before you do any of the following operations:
- Starting the second server instance.
- Running the idsbulkload command from the second server instance.
- Running the idsldif2db command from the second server instance. When you import an LDIF data that is not cryptographically synchronized, AES encrypted entries in the file are not imported.
About this task
If you want to use replication, distributed directory, or import and export LDIF data between server instances, you must cryptographically synchronize the instances for better performance.
Although, in the procedure two server instances are used. You might need a group of server instances that are cryptographically synchronized.
Procedure
To cryptographically synchronize two server instances, assuming that you created the first server instance do the following steps.
Results
After the directory server instances are cryptographically synchronized, AES encrypted data gets loaded correctly.