13.04.2013 Views

Digipass Plug-In for SBR Administrator Reference - Vasco

Digipass Plug-In for SBR Administrator Reference - Vasco

Digipass Plug-In for SBR Administrator Reference - Vasco

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>Digipass</strong> <strong>Plug</strong>-<strong>In</strong> <strong>for</strong> <strong>SBR</strong> <strong>Administrator</strong> <strong>Reference</strong> Sensitive Data Encryption<br />

4 Sensitive Data Encryption<br />

Sensitive data is encrypted by <strong>Digipass</strong> <strong>Plug</strong>-<strong>In</strong> <strong>for</strong> <strong>SBR</strong> using an embedded key. If needed,<br />

this encryption may be strengthened by adding a custom key in the Configuration GUI. The<br />

embedded and custom keys are subjected to a logical XOR process to produce a new key<br />

derived from both.<br />

Note<br />

Encryption settings must be set be<strong>for</strong>e importing <strong>Digipass</strong>.<br />

4.1.1 Encrypted Data – Active Directory<br />

Table 28: Encrypted Data Attributes – Active Directory<br />

Attribute Class<br />

vasco-StaticPassword vasco-UserExt<br />

vasco-SharedSecret vasco-Component<br />

vasco-SharedSecret vasco-BackEndServer<br />

4.1.2 Encrypted Data – ODBC and Embedded Database<br />

Table 29: Encrypted Data Attributes – ODBC and Embedded Database<br />

Column Table<br />

vdsStaticPwd vdsUser<br />

vdsAdminPrivileges vdsUser<br />

vdsSharedSecret vdsComponent<br />

vdsSharedSecret vdsBackEnd<br />

4.1.3 Which Encryption Algorithms can be used?<br />

AES<br />

blowfish<br />

cast5<br />

3DES<br />

3DES with 3 keys<br />

4.1.4 Exporting Encryption Settings<br />

Encryption settings may be exported to a password-protected text file from the <strong>SBR</strong> <strong>Plug</strong>-<strong>In</strong><br />

Configuration GUI. This file must then be loaded to other <strong>SBR</strong> <strong>Plug</strong>-<strong>In</strong>s – see 11.1.9 Data<br />

Encryption <strong>for</strong> instructions.<br />

The same file must be loaded into the administration interfaces wherever they are installed:<br />

Administration MMC <strong>In</strong>terface<br />

1. Open the Administration MMC <strong>In</strong>terface.<br />

2. Right-click on the <strong>Digipass</strong> Administration node and select the Encryption Settings<br />

option.<br />

© 2006 VASCO Data Security <strong>In</strong>c. 60

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!