NOTE: It is recommended that you create a backup before encrypting the database information in a database. Then you can restore the previous state if necessary.
In certain circumstances, it is necessary to store encrypted information in the One Identity Manager database: If you did not encrypt the database when you installed with the Configuration Wizard, use the Crypto Configuration program to encrypt. With this program an encryption file is created and the contents of the database columns that are affected are converted.
To change the encryption method
-
In the Designer, set the Common | EncryptionScheme configuration parameter and select one of the options:
-
RSA: RSA encryption with AES for large data (default).
-
FIPSCompliantRSA: FIPS certified RSA with AES for large data. This method is used if encryption must match the FIPS 104-2 standard. The local security policy Use FIPS compliant algorithms for encryption, hashing, and signing must be enabled.
-
NOTE: If the Common | EncryptionScheme configuration parameter is not set, RSA encryption is used as the method.