Ce contenu n'est pas disponible dans la langue sélectionnée.
15.13. Configuring Changelog Encryption
			To increase security, Directory Server supports encrypting the changelog. This section explains how to enable this feature.
		
Prerequisites
			The server must have a certificate and key stored in the network security services (NSS) database. Therefor, enable TLS encryption on the server as described in Section 9.4.1, “Enabling TLS in Directory Server”.
		
Procedure
			To enable changelog encryption:
		
- Except for the server on which you want to enable changelog encryption, stop all instances in the replication topology by entering the following command:dsctl instance_name stop # dsctl instance_name stopCopy to Clipboard Copied! Toggle word wrap Toggle overflow 
- On the server where you want to enable changelog encryption:- Export the changelog, for example, to the/tmp/changelog.ldiffile:dsconf -D "cn=Directory Manager" ldap://server.example.com replication dump-changelog -o /tmp/changelog.ldif # dsconf -D "cn=Directory Manager" ldap://server.example.com replication dump-changelog -o /tmp/changelog.ldifCopy to Clipboard Copied! Toggle word wrap Toggle overflow 
- Stop the instance:dsctl instance_name stop # dsctl instance_name stopCopy to Clipboard Copied! Toggle word wrap Toggle overflow 
- Add the following setting to thedn: cn=changelog5,cn=configentry in the/etc/dirsrv/slapd-instance_name/dse.ldiffile:nsslapd-encryptionalgorithm: AES nsslapd-encryptionalgorithm: AESCopy to Clipboard Copied! Toggle word wrap Toggle overflow 
- Start the instance:dsctl instance_name start # dsctl instance_name startCopy to Clipboard Copied! Toggle word wrap Toggle overflow 
- Import the changelog from the/tmp/changelog.ldiffile:dsconf -D "cn=Directory Manager" ldap://server.example.com replication restore-changelog from-ldif /tmp/changelog.ldif # dsconf -D "cn=Directory Manager" ldap://server.example.com replication restore-changelog from-ldif /tmp/changelog.ldifCopy to Clipboard Copied! Toggle word wrap Toggle overflow 
 
- Start all instances on the other servers in the replication topology using the following command:dsctl instance_name start # dsctl instance_name startCopy to Clipboard Copied! Toggle word wrap Toggle overflow 
Verification
			To verify that the changelog is encrypted, run the following steps on the server with the encrypted changelog:
		
- Make a change in the LDAP directory, such as updating an entry.
- Stop the instance:dsctl stop instance_name # dsctl stop instance_nameCopy to Clipboard Copied! Toggle word wrap Toggle overflow 
- Enter the following command to display parts of the changelog:dbscan -f /var/lib/dirsrv/slapd-instance_name/changelogdb/replica_name_replGen.db | tail -50 # dbscan -f /var/lib/dirsrv/slapd-instance_name/changelogdb/replica_name_replGen.db | tail -50Copy to Clipboard Copied! Toggle word wrap Toggle overflow If the changelog is encrypted, you see only encrypted data.
- Start the instance:dsctl start instance_name # dsctl start instance_nameCopy to Clipboard Copied! Toggle word wrap Toggle overflow