Previous Topic: Directory EncryptionNext Topic: VM Single System Image for CA VM:Secure


Password Encryption Facility

The Password Encryption Facility (PEF) is an optional feature of CA VM:Secure, and is available only if you have the Rules Facility installed. It allows your site to encrypt logon and minidisk passwords.

With PEF, all passwords are automatically encrypted. Encrypted passwords are maintained in the CP object directory and in the CA VM:Secure directory database. CA VM:Secure does not support partial encryption, where some passwords are encrypted and other passwords are clear text.

When a user issues a command that requires password checking and PEF is active, CA VM:Secure encrypts the password entered by the user, then compares the encrypted password with the password stored in the CA VM:Secure directory database or the CP object directory, as required.

PEF provides both forward encryption and reversible encryption for passwords. Forward encrypted passwords can never be decrypted. Reversible encrypted passwords allow you to back out of PEF and revert to clear text passwords.

Note: For more information about installing and using PEF, see the Rules Facility Guide.