Encrypted attributes

Local Administrative group members who are assigned DirDataAdmin and SchemaAdmin roles can specify attributes that are to be encrypted in the directory database. For encryption, a subset of the encryption schemes that are supported for password information is used.

The attributes can be encrypted by using either 2-way or 1-way encryption schemes. The supported encryption schemes include AES-256, AES-192, AES-128, SSHA, SHA-224, SHA-256, SHA-384, SHA-512, SSHA-224, SSHA-256, SSHA-384 and SSHA-512 and the supported attribute syntaxes include directory string, IA5 string, distinguished name, and telephone number.

Note: You cannot use the PBKDF2 algorithm for encrypted attributes.
The encrypted attribute policy allows local admin group members who are assigned DirDataAdmin and SchemaAdmin roles to specify access to encrypted attributes that is limited to clients that use secure connections. Furthermore, the policy allows group members to define specific attributes as being non-matchable. Such attributes can only be used in presence filters. Additionally, the policy also allows group members to specify whether the values to be returned on a search must be encrypted or only the attribute names must be returned.
Note: The search filters that can be used with one-way encryption and two-way encryption are as follows.

1-way encrypted attributes can be used only in 'present' filters, for example (attr=*)

2-way encrypted attributes can be used in 'present' or 'equality' (exact match) filters.

After you specify the attributes that are to be encrypted, the existing server data is encrypted only after the next server startup. The time that is taken for this operation depends on the number of entries that are to be encrypted. The encrypted attribute policy can be managed by using the web administration tool.