Using the advanced settings you can specify the following:
- Encryption algorithm - use this setting to select the encryption algorithm that is used to encrypt users’ answers to secret questions and other security sensitive information. You can select from two options: Triple DES and AES. By default, Password Manager uses Triple DES algorithm to encrypt data. Note, that users’ answers will be encrypted if the “Store answers using reversible encryption” option is selected in the Q&A Profile settings. Otherwise, the answers will be hashed.
- Encryption key length - use this setting to select whether a 192-bit or 256-bit encryption key will be used.
- Attribute for storing Q&A profiles - use this setting to enter the attribute name that will be used for storing Q&A profile data. By default, Password Manager stores Q&A profile data in the comment attribute of each user's account and the configuration data in the comment attribute of a configuration storage account, which is automatically created when installing Password Manager.
- Hashing algorithm - use this setting to select the hashing algorithm that will be used to hash users’ answers to secret questions. The following algorithms are available: MD5 and SHA-256. By default, Password Manager uses SHA-256 hashing algorithm. Password Manager will hash users’ answers if “Store answers using reversible encryption” option is not selected in the Q&A Profile settings.
IMPORTANT: If you change the hashing algorithm, the selected algorithm will be applied to newly created Q&A profiles only. Existing Q&A profiles will be hashed with the previously selected algorithm.
To modify the advanced settings
- On the home page of the Administration site, click General Settings|Reinitialization, and expand the Advanced settings section.
- From the Encryption algorithm drop-down list, select the encryption algorithm for encrypting users’ answers to secret questions and other security sensitive data.
- From the Encryption key length drop-down list, select whether a 192-bit or 256-bit encryption key will be used to encrypt data.
-
From the Hashing algorithm drop-down list, select the algorithm that will be used to hash users’ authentication answers.
- In the Select the attribute of user’s account in Active Directory in which user’s Questions and Answers profile and Corporate phone will be stored section, provide the following data.
- Click Save.
Once you click Save, Reinitialize Instance dialog box appears.
- In the Reinitialize Instance dialog box, a password is generated for the configuration file that you should export to update users’ Q&A profiles and click Export.
- Click Save.
Use one of the following methods to clear old hives from AD user objects.
To update users’ Q&A profiles with new instance settings and clear old Q&A data for user objects in Active Directory
- Run the Migration wizard from the Password Manager CD autorun window.
- On the Welcome page, select the Update users’ Q&A profiles with new instance settings and clear old Q&A data for user objects in Active Directory task.
- On the next page, upload the configuration file you exported. Click Browse to select the file, enter the password generated while exporting the configuration file, and click Next.
- On the Select users page, do one of the following and click Next:
- If you want to convert the Q&A profiles of users from the user scope of a Management Policy, select the required policy in the Select Management Policy drop-down box and click Next.
- If you want to convert the Q&A profiles of a user in a user group, select The following groups. To select groups, click Add and do the following:
- If you want to convert the Q&A profiles of a user in an OU, select The following OUs. To select OUs, click Add and do the following:
- In the Add OUs dialog box, enter the OU name, select the domain from the list and click Search.
- Select the required OUs in the list and click Save.
- On the next page, do one of the following and click Next:
|
NOTE: For production mode, select Clear old Q&A data for user objects in Active Directory checkbox to clear old user Q&A data. |
- On the status page, click View the report for detailed information to view a detailed account of updating profiles. If you updated Q&A profiles in test mode, click Update Q&A profiles in production mode.
Once you have updated the Q&A profiles with new instance settings, join other instances to this realm by exporting the configuration from the current instance and importing it to other instances. For more information on how to import and export configuration settings, see Import/Export Configuration Settings .
Clear old Q&A data for user objects in Active Directory
- Run the Migration wizard from the Password Manager CD autorun window.
- On the Welcome page, select the Clear old Q&A data for user objects in Active Directory task.
- On the Select users page, do one of the following and click Next:
-
If you want to clear the old Q&A profiles of users from the user scope of a Management Policy, select the required policy in the Select Management Policy drop-down box and click Next.
-
If you want to clear the old Q&A profiles of a user in a user group, select The following groups. To select groups, click Add and do the following:
-
In the Add Groups dialog box, enter the group name, select the domain from the list and click Search.
-
Select the required groups in the list and click Save.
-
-
If you want to clear the old Q&A profiles of a user in an OU, select The following OUs. To select OUs, click Add and do the following:
-
In the Add OUs dialog box, enter the OU name, select the domain from the list and click Search.
-
Select the required OUs in the list and click Save.
-
-
-
On the status page, click View the report for detailed information to view a detailed account of updating profiles. Click Finish.
|
NOTE: The latest version of Q&A, which is currently in use will not be deleted. |