Attribute Encryption Compatibility for Passwords with Database User Stores
search cancel

Attribute Encryption Compatibility for Passwords with Database User Stores

book

Article ID: 39074

calendar_today

Updated On:

Products

CA Identity Manager CA Identity Suite

Issue/Introduction

This article explains the compatibility and best practices for attribute-level encryption when utilizing a database as a user store in Identity Manager.

Environment

Identity Manager 14.5 & 15

Resolution

Using attribute level encryption for passwords is not advised when other applications require access to the password (such as SiteMinder).

LDAP user stores hash password automatically. So encryption on the application level is not needed. So when the LDAP server needs to authenticate it does a has compare which works for IM and any other application using the information, like SiteMinder.

Adding attribute level encryption on top of this breaks this as the private key is with Identity Manager only.

 

With databases as user stores, this is roughly the same. Originally the ability to hash the password field was not present in databases, and it was up to the application level to apply the encryption. This means that only Identity Manager application can digest the password and no other application can use the password attribute.

Today database vendor have added the level of encryption similar to the one used in LDAP servers. So the applications read and write in clear text and the database is handling the encryption. So again, in this scenario it is not advised to use attribute level encryption if other applications need to use the password data.

Additional Information

To speak with a customer representative or a Support Engineer see Contact Support. Scroll to the bottom of the page and click on your respective region