Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Anchor
Overview
Overview
Overview

Back to Top

The AES Encryption Provider provides strong, FIPS-compliant encryption for passwords stored in the AMS database.

Anchor
Create
Create
Creating an AES Encryption Provider

Back to Top

To use the AES Encryption Provider you must create an instance (or import one) and then set it as the default encryption provider.

...

  1. Open the Configuration tab in the Arellia Security Manager console.
  2. In the Configuration tree navigate to Settings > Configuration > Service Providers > Encryption Providers.
  3. Right-click on Encryption Providers and select New > AES Encryption Provider.
  4. Name your provider and click OK to create it.

Image Removed Image Added

Anchor
Config
Config
Configuring the Default Encryption Provider 

Back to Top

Warning

Once your encryption provider has been used to store passwords you should not delete or change the provider. Doing so will prevent AMS from recovering anything encrypted by the provider.  Instead of deleting or changing you should create a new provider and configure it as default.

...

  1. Open the Configuration tab in the Arellia Security Manager console.
  2. In the Configuration tree navigate to Settings > Configuration > Infrastructure > Configuration Settings.
  3. On the right under Product select Arellia Management Server.
    Image Added 
  4. Click Select... next to Encryption Provider and choose your provider.
  5. Click the Save button to save your settings.

...

Anchor
Custom
Custom
Using a Custom Key

Back to Top

You can use a custom password or passphrase to generate a key that your AES encryption provider will use to encrypt stored passwords.

...

Anchor
Expect
Expect
What to Expect

Back to Top

Whenever new passwords are stored in the AMS database (LSS User Passwords, configured User Credentials, etc.) they will encrypted using the selected encryption provider.