Symantec Access Management

Tech Tip : CA Single Sign-On : Password Data blob when migrating User Directory data to a new store 

Jun 25, 2018 11:35 AM

Question:

We are planning to migrate users from our current User Directory to a new one, and we are currently using this User Directory for Password Services. As part of the migration, the user password attributes (including disabled flag, password blob) will be migrated to the new store. Then, we will change the User Directory on the AdminUI settings to use the new one.

When we do this, could the password data attribute be lost? Could this cause any impact on losing the encrypted data from the password attributes?

Environment:

Policy Server R12.52 SP1LDAP User Directory

Answer:

As there are not going to be any other changes rather than the User Directory itself, and the user structure and content will be maintained, there will not be any problem, as the password blob is still stored (and moved) so the Policy Server it is the same one using the same session key to decrypt the password blob. So as long as the password data attribute containing the blob is maintained in the new User Directory, the Policy Server will be able to decrypt it when needed again.

Additional Information:

 

KD : kb000016191

Statistics
0 Favorited
0 Views
0 Files
0 Shares
0 Downloads

Related Entries and Links

No Related Resource entered.