16.01.2013 Views

Microsoft Sharepoint Products and Technologies Resource Kit eBook

Microsoft Sharepoint Products and Technologies Resource Kit eBook

Microsoft Sharepoint Products and Technologies Resource Kit eBook

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

712 Part VIII: Securing SharePoint <strong>Products</strong> <strong>and</strong> <strong>Technologies</strong><br />

You cannot create the encryption key remotely. To re-generate the encryption<br />

key, go to the computer running as the job server, log on as the single sign-on<br />

administrator account, <strong>and</strong> do the following:<br />

1. On the SharePoint Portal Server Central Administration for server_name page,<br />

in the Component Configuration section, click Manage settings for single<br />

sign-on.<br />

Alternatively, click Start, point to All Programs, point to SharePoint<br />

Portal Server, <strong>and</strong> then click SharePoint Portal Server Single Sign-On<br />

Administration.<br />

2. On the Manage Settings for Single Sign-On for server_name page, in the<br />

Server Settings section, click Manage encryption key.<br />

3. On the Manage Encryption Key page, in the Encryption Key Creation section,<br />

click Create Encryption Key.<br />

4. On the Create Encryption Key page, to re-encrypt the credentials for the single<br />

sign-on database, select the Re-encrypt all credentials by using the new<br />

encryption key check box, <strong>and</strong> then click OK.<br />

Note If you do not re-encrypt the existing credentials with the new encryption<br />

key, users must retype their credentials for individual application definitions,<br />

<strong>and</strong> administrators for group application definitions must retype<br />

group credentials.<br />

Backing Up the Encryption Key<br />

After creating the encryption key, you should back it up. You must back up the key<br />

to a 3.5-inch floppy disk. You should lock up the backup disk for the encryption key<br />

in a safe place.<br />

Note Because the encryption key is the key that decrypts the encrypted<br />

credentials stored in the single sign-on database, the backup copy of the<br />

key should not be stored with the backup copy of the database. If a user<br />

obtains a copy of both the database <strong>and</strong> the key, the credentials stored in<br />

the database could be compromised.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!