NOTE: It is recommended that you create a backup before encrypting the database information in a database. Then you can restore the previous state if necessary.
In certain circumstances, it is necessary to store encrypted information in the One Identity Manager database: If you did not encrypt the database when you installed with the Configuration Wizard, use the Crypto Configuration program to encrypt. With this program an encryption file is created and the contents of the database columns that are affected are converted.
To change the encryption method
NOTE: If the Common | EncryptionScheme configuration parameter is not set, RSA encryption is used as the method.
Detailed information about this topic
NOTE: It is recommended that you create a backup before encrypting the database information in a database. Then you can restore the previous state if necessary.
To create a new database key and encrypt the One Identity Manager database
-
Start the Launchpad and log in to the One Identity Manager database.
-
In the Installation overview > Installation Checklist section, select the Encrypt the database entry and click Run.
This starts the Crypto Configuration program.
-
Click Next on the home page.
-
On the New database connection page, enter the valid connection credentials for the One Identity Manager database.
-
On the Select action page, select Create or change database key.
-
On the Private key page, select There was no encryption yet.
-
On the New private key page, create a new key.
-
Click Create key.
-
Select the directory path for saving the file using the file browser and enter a name for the key file.
-
Click Save.
The (*.key) key file is generated. This closes the file browser and displays the path and file name under Private key.
-
Click Next.
This establishes which data to encrypt.
-
The date to be encrypted is displayed on the Convert database page.
-
Click Convert.
-
Confirm the following two security questions with Yes.
This starts data encryption and displays the conversion progress.
-
Click Next.
-
Click Finish on the last page to end the program.
NOTE:
-
To change a database key, you need the key file with the old database key. The key is change and saved in a new key file.
-
It is recommended that you create a backup before encrypting the database information in a database. Then you can restore the previous state if necessary.
To change a database key and encrypt the One Identity Manager database
-
Start the Launchpad and log in to the One Identity Manager database.
-
In the Installation overview > Installation Checklist section, select the Encrypt the database entry and click Run.
This starts the Crypto Configuration program.
-
Click Next on the home page.
-
On the New database connection page, enter the valid connection credentials for the One Identity Manager database.
-
On the Select action page, select Create or change database key.
-
Load the existing key on Private key.
-
Select Encryption was enabled.
-
Click Load key.
-
Using the file browser, select the (*.key) file with the old database key.
-
Click Open.
This closes the file browser and displays the path and file name.
-
Click Next.
-
On the New private key page, create a new key.
-
Click Create key.
-
Select the directory path for saving the file using the file browser and enter a name for the key file.
-
Click Save.
The (*.key) key file is generated. This closes the file browser and displays the path and file name under Private key.
-
Click Next.
This establishes which data to encrypt.
-
The date to be encrypted is displayed on the Convert database page.
-
Click Convert.
-
Confirm the following two security questions with Yes.
This starts data encryption and displays the conversion progress.
-
Click Next.
-
Click Finish on the last page to end the program.
Use this method if the database already has encryption but you want to encrypt more columns.
NOTE: It is recommended that you create a backup before encrypting the database information in a database. Then you can restore the previous state if necessary.
To repeat One Identity Manager database encryption using an existing database key
-
Start the Launchpad and log in to the One Identity Manager database.
-
In the Installation overview > Installation Checklist section, select the Encrypt the database entry and click Run.
This starts the Crypto Configuration program.
-
Click Next on the home page.
-
On the New database connection page, enter the valid connection credentials for the One Identity Manager database.
-
On the Select action page, select Encrypt using existing key.
This establishes which data to encrypt.
-
The date to be encrypted is displayed on the Convert database page.
-
Click Convert.
-
Confirm the following two security questions with Yes.
This starts data encryption and displays the conversion progress.
-
Click Next.
-
Click Finish on the last page to end the program.