
106 Novell eDirectory 8.8 SP7 Troubleshooting Guide
20.5 Viewing or Modifying Encrypted Attributes through
iManager
If an attribute of an object is encrypted, you cannot view or modify the object by using iManager 2.5.
To work around this issue, you can view or modify the encrypted attribute over a secure channel,
using any of the following methods:
LDAP: The LDAP request must be send over a secure channel, which means that the trusted root
certificate of the server must be used.
ICE: LDIF scripts can be used to modify the object. If you do this, ICE must use a secure channel.
Use iManager 2.5 FP2, iManager 2.6, or later.
NOTE: We recommend using iManager 2.6 or later for viewing or modifying encrypted attributes.
Alternatively, you can turn off the secure channel required option for viewing or modifying the
encrypted attributes by disabling the
requireSecure
attribute in the EA policy. This makes the object
and the encrypted attributes accessible by any client over clear text channel. After this, iManager will
be able to access the object.
20.6 Merging Trees With Encrypted Replication Enabled Fails
When encrypted replication is enabled, merging trees fails. Disable secure replication on each tree
before doing a merge.
20.7 Limber Displays -603 Error
Limber displays the -603 error if the server has only sub-ref replica of the encrypted attribute policy
partition.
To work around this issue, do any one of the following:
Give read access to the NCP server object. You can do this through iManager by adding a trustee
at the tree root and giving read access to NCP server object. In the attributes, specify
attrEncryptionDefinition
and
attrEncryptionRequiresSecure
.
Give Public Read access to the following attributes through LDAP or ndssch:
attrEncryptionDefinition
attrEncryptionRequiresSecure
Kommentare zu diesen Handbüchern