Encrypted attributes
Local Administrative group members who are assigned DirDataAdmin and SchemaAdmin roles
can specify attributes that are to be encrypted in the directory database.
For encryption, a subset of the encryption schemes that are supported
for password information is used.
The attributes can be encrypted by using either 2-way or 1-way encryption schemes. The supported encryption schemes include AES-256, AES-192, AES-128, SSHA, SHA-224, SHA-256, SHA-384, SHA-512, SSHA-224, SSHA-256, SSHA-384 and SSHA-512 and the supported attribute syntaxes include directory string, IA5 string, distinguished name, and telephone number.
DirDataAdmin and SchemaAdmin roles to specify access to encrypted
attributes that is limited to clients that use secure connections. Furthermore, the policy allows
group members to define specific attributes as being non-matchable. Such attributes can only be used
in presence filters. Additionally, the policy also allows group members to specify whether the
values to be returned on a search must be encrypted or only the attribute names must be returned.
After you specify the attributes that are to be encrypted, the existing server data is encrypted only after the next server startup. The time that is taken for this operation depends on the number of entries that are to be encrypted. The encrypted attribute policy can be managed by using the web administration tool.