{"id":670,"date":"2016-08-24T11:09:13","date_gmt":"2016-08-24T20:09:13","guid":{"rendered":"\/blog\/?p=670"},"modified":"2023-09-21T09:37:57","modified_gmt":"2023-09-21T00:37:57","slug":"safenet-datasecure-protectdb-properties-sample","status":"publish","type":"post","link":"https:\/\/hasu0707.duckdns.org\/blog\/?p=670","title":{"rendered":"SafeNet DataSecure ProtectDB.properties sample"},"content":{"rendered":"\n<!-- HTML generated using hilite.me --><div style=\"background: #ffffff; overflow:auto;width:auto;border:solid gray;border-width:.1em .1em .1em .8em;padding:.2em .6em;\"><pre style=\"margin: 0; line-height: 125%\"><span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># ProtectDB.properties  09\/07\/21 16:30:15 SafeNet, Inc.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># SafeNet Network-Attached Encryption (NAE) properties file<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># Release Version: 5.4.0.000008<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># NOTE: Do not use quotes when specifying values in this file.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n\r\n\r\n<span style=\"color: #888888\">#[Version]<\/span>\r\n<span style=\"color: #888888\"># Version of the properties file for the SafeNet PKCS#11\/ICAPI\/MSCAPI\/.NET<\/span>\r\n<span style=\"color: #888888\"># providers.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># Do not modify this property.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #996633\">Version<\/span><span style=\"color: #333333\">=<\/span>2.5\r\n\r\n\r\n<span style=\"color: #888888\">#[Network Configuration]<\/span>\r\n<span style=\"color: #888888\"># [NAE Server IP]<\/span>\r\n<span style=\"color: #888888\"># The IP address and port of the NAE server.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># Multiple IPs can be specified when load balancing is used. The port must<\/span>\r\n<span style=\"color: #888888\"># be the same on all NAE servers.  You can configure up to three tiers of<\/span>\r\n<span style=\"color: #888888\"># NAE servers.  Tiers are numbered 1-3.  If all servers in the primary tier 1<\/span>\r\n<span style=\"color: #888888\"># become unreachable, the client will switch to tier 2.   If all servers<\/span>\r\n<span style=\"color: #888888\"># in tier 2 become unrechable, the client will switch to tier 3.  When<\/span>\r\n<span style=\"color: #888888\"># using an alternatate tier, the client will periodically try to switch<\/span>\r\n<span style=\"color: #888888\"># back to tier 1 (after Connection_Retry_Interval has expired).<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># For all tier-aware parameters, the tier is indicated with a trailing<\/span>\r\n<span style=\"color: #888888\"># .n after the parameter name, i.e. NAE_IP.1=127.0.0.1<\/span>\r\n<span style=\"color: #888888\"># Setting the parameter with no tier sets the default value for all tiers.<\/span>\r\n<span style=\"color: #888888\"># i.e. Connection_Timeout=600000 sets Connection_Timeout for all tiers while<\/span>\r\n<span style=\"color: #888888\"># Connection_Timeout.1=700000 sets Connection_Timeout for tier 1.<\/span>\r\n<span style=\"color: #888888\"># A tier-specic setting will override<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># For NAE_IP, IPs are separated by colons, e.g.,<\/span>\r\n<span style=\"color: #888888\"># 192.168.1.10:192.168.1.11:192.168.1.12<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #996633\">NAE_IP<\/span><span style=\"color: #333333\">=<\/span>10.10.10.86\r\n\r\n<span style=\"color: #888888\"># #[Network Configuration]<\/span>\r\n<span style=\"color: #888888\"># [NAE Server Port]<\/span>\r\n<span style=\"color: #888888\"># NAE_Port is tier-aware<\/span>\r\n<span style=\"color: #888888\"># Do not set the port value to 9443 because this is the port typically used<\/span>\r\n<span style=\"color: #888888\"># to connect to the management console.<\/span>\r\n<span style=\"color: #996633\">NAE_Port<\/span><span style=\"color: #333333\">=<\/span>9000\r\n\r\n<span style=\"color: #888888\">#[Network Configuration]<\/span>\r\n<span style=\"color: #888888\"># [Protocol]<\/span>\r\n<span style=\"color: #888888\"># The protocol used between the client and the NAE server.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># If you are load balancing across multiple NAE servers, the protocol must<\/span>\r\n<span style=\"color: #888888\"># be the same for each server.<\/span>\r\n<span style=\"color: #888888\"># Protocol is tier-aware.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># Valid values: tcp, ssl.<\/span>\r\n<span style=\"color: #888888\"># Default: tcp<\/span>\r\n<span style=\"color: #888888\"># Recommended: ssl<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #996633\">Protocol<\/span><span style=\"color: #333333\">=<\/span>tcp\r\n\r\n\r\n<span style=\"color: #888888\">#[Connection Configuration]<\/span>\r\n<span style=\"color: #888888\"># [Persistent Connections]<\/span>\r\n<span style=\"color: #888888\"># Enable or disable persistent connections.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># If enabled, the client will use a pool of persistent connections to the<\/span>\r\n<span style=\"color: #888888\"># NAE server. If disabled, a new connection will be created and then<\/span>\r\n<span style=\"color: #888888\"># closed for each request.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># Valid values: yes, no.<\/span>\r\n<span style=\"color: #888888\"># Default: yes<\/span>\r\n<span style=\"color: #888888\"># Recommended: yes<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #996633\">Use_Persistent_Connections<\/span><span style=\"color: #333333\">=<\/span>yes\r\n\r\n\r\n<span style=\"color: #888888\">#[Connection Configuration]<\/span>\r\n<span style=\"color: #888888\"># [Connection Pooling]<\/span>\r\n<span style=\"color: #888888\"># The maximum number of connections in the persistent connection pool.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># This value is used only when persistent connections are enabled.<\/span>\r\n<span style=\"color: #888888\"># Size_of_Connection_Pool is tier-aware.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># Default: 300<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #996633\">Size_of_Connection_Pool<\/span><span style=\"color: #333333\">=<\/span>300\r\n\r\n\r\n<span style=\"color: #888888\">#[Connection Configuration]<\/span>\r\n<span style=\"color: #888888\"># [Connection Timeout]<\/span>\r\n<span style=\"color: #888888\"># The timeout when connecting to the NAE server.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># The timeout is specified in milliseconds. The client will wait for the<\/span>\r\n<span style=\"color: #888888\"># specified number of milliseconds when trying to connect to each NAE<\/span>\r\n<span style=\"color: #888888\"># server.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># Setting this value to 0 uses the system connect() timeout.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># Caution: Setting this value too low may cause connections to fail when<\/span>\r\n<span style=\"color: #888888\"># the NAE servers and\/or network are under load. Do not change it unless<\/span>\r\n<span style=\"color: #888888\"># you really need to.<\/span>\r\n<span style=\"color: #888888\"># Connection_Timeout is tier-aware.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># Default: 60000<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #996633\">Connection_Timeout<\/span><span style=\"color: #333333\">=<\/span>60000\r\n\r\n\r\n<span style=\"color: #888888\">#[Connection Configuration]<\/span>\r\n<span style=\"color: #888888\"># [Connection Idle Timeout]<\/span>\r\n<span style=\"color: #888888\"># The time a connection is allowed to be idle in the connection pool<\/span>\r\n<span style=\"color: #888888\"># before it gets closed automatically by the client.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># The timeout is specified in milliseconds. The client will check how long<\/span>\r\n<span style=\"color: #888888\"># each connection has been idle for. If the time has passed the value<\/span>\r\n<span style=\"color: #888888\"># specified here, the client will close the connection and remove it from<\/span>\r\n<span style=\"color: #888888\"># the connection pool. To be effective, this setting must be less than the<\/span>\r\n<span style=\"color: #888888\"># Connection Timeout setting in the NAE Server Settings section in the<\/span>\r\n<span style=\"color: #888888\"># Management Console of the NAE server.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># Setting this value to 0 is equivalent to an infinite timeout.<\/span>\r\n<span style=\"color: #888888\"># Connection_Idle_Timeout is tier-aware.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># Default: 600000<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #996633\">Connection_Idle_Timeout<\/span><span style=\"color: #333333\">=<\/span>600000\r\n\r\n\r\n<span style=\"color: #888888\">#[Connection Configuration]<\/span>\r\n<span style=\"color: #888888\"># [Connection Retry]<\/span>\r\n<span style=\"color: #888888\"># The amount of time to wait before trying to reconnect to a disabled<\/span>\r\n<span style=\"color: #888888\"># server.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># The retry interval is specified in milliseconds. If one of the NAE<\/span>\r\n<span style=\"color: #888888\"># servers in a load balanced configuration is not reachable, the client<\/span>\r\n<span style=\"color: #888888\"># will disable this server, and then wait for the specified number of<\/span>\r\n<span style=\"color: #888888\"># milliseconds before trying to connect to it again.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># Setting this value to 0 is equivalent to an infinite retry interval<\/span>\r\n<span style=\"color: #888888\"># (meaning the disabled server will never be brought back into use).<\/span>\r\n<span style=\"color: #888888\"># Connection_Retry_Interval is tier-aware.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># Default: 600000<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #996633\">Connection_Retry_Interval<\/span><span style=\"color: #333333\">=<\/span>600000\r\n\r\n\r\n<span style=\"color: #888888\">#[Connection Configuration]<\/span>\r\n<span style=\"color: #888888\"># [Cluster_Synchronization_Delay]<\/span>\r\n<span style=\"color: #888888\"># The total amount of time to spend trying to make requests on keys<\/span>\r\n<span style=\"color: #888888\"># go to the same device the key create or latest key modify went to.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># A device tries to replicate key information to other devices in the<\/span>\r\n<span style=\"color: #888888\"># cluster after it completes a key create or modify request.  Until<\/span>\r\n<span style=\"color: #888888\"># that replication completes, requests on the key need to go to the<\/span>\r\n<span style=\"color: #888888\"># device pushing the replication.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># If replication fails, the device waits for 30 seconds, then<\/span>\r\n<span style=\"color: #888888\"># tries again.  If three replications fail, the device stops trying<\/span>\r\n<span style=\"color: #888888\"># to replicate data.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># The default is 100 seconds: 3 times 30 seconds plus a few extra<\/span>\r\n<span style=\"color: #888888\"># seconds per try for network latency.  For larger clusters additional<\/span>\r\n<span style=\"color: #888888\"># time may be needed.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># Disable the function: 0 seconds<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># Default: 100 seconds<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #996633\">Cluster_Synchronization_Delay<\/span><span style=\"color: #333333\">=<\/span>100\r\n\r\n<span style=\"color: #888888\">#[Connection Configuration]<\/span>\r\n<span style=\"color: #888888\"># [EdgeSecure Name]<\/span>\r\n<span style=\"color: #888888\"># Name of device or file containing the name of an EdgeSecure device.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># The name of an EdgeSecure device is a unique value assigned<\/span>\r\n<span style=\"color: #888888\"># by the administrator to define a single device.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># If the name refers to a readable file, then the first line in the file<\/span>\r\n<span style=\"color: #888888\"># defines the name of an EdgeSecure device.  This allows all properties<\/span>\r\n<span style=\"color: #888888\"># files stored on different platforms to be the same and still allow<\/span>\r\n<span style=\"color: #888888\"># each platform to refer to a different EdgeSecure device.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># EdgeSecure_Name is tier-aware.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># Default: none<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\">#EdgeSecure_Name=<\/span>\r\n\r\n\r\n\r\n<span style=\"color: #888888\">#[SSL\/TLS Configuration]<\/span>\r\n<span style=\"color: #888888\"># [Cipherspec]<\/span>\r\n<span style=\"color: #888888\"># The SSL\/TLS protocol and encryption algorithms to use.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># Default is \"HIGH:!ADH:!DH:!DSA:!EXPORT:RSA+RC4:RSA+DES:RSA+AES\"<\/span>\r\n<span style=\"color: #888888\"># which translates to high-strength RSA key exchange and RC4, triple DES,<\/span>\r\n<span style=\"color: #888888\"># or AES.<\/span>\r\n<span style=\"color: #888888\"># Cipher_Spec is tier-aware.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># Default: HIGH:!ADH:!DH:!DSA:!EXPORT:RSA+RC4:RSA+DES:RSA+AES<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\">#Cipher_Spec=HIGH:!ADH:!DH:!DSA:!EXPORT:RSA+RC4:RSA+DES:RSA+AES<\/span>\r\n\r\n\r\n<span style=\"color: #888888\">#[SSL\/TLS Configuration]<\/span>\r\n<span style=\"color: #888888\"># [CA Certificate for Server Authentication]<\/span>\r\n<span style=\"color: #888888\"># The CA certificate that signed the NAE server certificate presented to<\/span>\r\n<span style=\"color: #888888\"># clients to establish SSL connections.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># If you are using SSL between the client and server, you must specify a<\/span>\r\n<span style=\"color: #888888\"># path to the CA certificate that signed the NAE server certificate. If<\/span>\r\n<span style=\"color: #888888\"># the client cannot validate the certificate presented by the NAE server,<\/span>\r\n<span style=\"color: #888888\"># the client will not be able to establish an SSL connection with the NAE<\/span>\r\n<span style=\"color: #888888\"># server.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># You should provide the path and file name of the CA certificate. The<\/span>\r\n<span style=\"color: #888888\"># path can be absolute or relative to the application. Do not use quotes<\/span>\r\n<span style=\"color: #888888\"># when specifying the path, even if it contains spaces.<\/span>\r\n<span style=\"color: #888888\"># CA_File is tier-aware.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># No default.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #996633\">CA_File<\/span><span style=\"color: #333333\">=<\/span>\r\n\r\n\r\n<span style=\"color: #888888\">#[SSL\/TLS Configuration]<\/span>\r\n<span style=\"color: #888888\"># [Client Certificate]<\/span>\r\n<span style=\"color: #888888\"># The client certificate to present to the NAE server.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># This value is required when client certificate authentication is enabled<\/span>\r\n<span style=\"color: #888888\"># on the NAE server. The certificate must be in PEM format. If this value<\/span>\r\n<span style=\"color: #888888\"># is set, the certificate and private key must be present even if the NAE<\/span>\r\n<span style=\"color: #888888\"># server is not configured to request a client certificate.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># You should provide the path and file name of the client certificate. The<\/span>\r\n<span style=\"color: #888888\"># path can be absolute or relative to the application. Do not use quotes<\/span>\r\n<span style=\"color: #888888\"># when specifying the path, even if it contains spaces.<\/span>\r\n<span style=\"color: #888888\"># Cert_File is tier-aware.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># No default.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #996633\">Cert_File<\/span><span style=\"color: #333333\">=<\/span>\r\n\r\n\r\n<span style=\"color: #888888\">#[SSL\/TLS Configuration]<\/span>\r\n<span style=\"color: #888888\"># [Client Private Key]<\/span>\r\n<span style=\"color: #888888\"># The private key associated with the client certificate specified in<\/span>\r\n<span style=\"color: #888888\"># Cert_File.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># This value is required when client certificate authentication is enabled<\/span>\r\n<span style=\"color: #888888\"># on the NAE server. The client private key must be in PEM-encoded PKCS#12<\/span>\r\n<span style=\"color: #888888\"># format. If this value is set, a correctly formatted key and certificate<\/span>\r\n<span style=\"color: #888888\"># must be present.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># You should provide the path and file name of the private key. The path<\/span>\r\n<span style=\"color: #888888\"># can be absolute or relative to the application. Do not use quotes when<\/span>\r\n<span style=\"color: #888888\"># specifying the path, even if it contains spaces.<\/span>\r\n<span style=\"color: #888888\"># Key_File is tier-aware.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># No default.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #996633\">Key_File<\/span><span style=\"color: #333333\">=<\/span>\r\n\r\n\r\n<span style=\"color: #888888\">#[SSL\/TLS Configuration]<\/span>\r\n<span style=\"color: #888888\"># [Client Private Key Passphrase]<\/span>\r\n<span style=\"color: #888888\"># The passphrase to unlock the client private key specified in Key_File.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># This value is required when client certificate authentication is enabled<\/span>\r\n<span style=\"color: #888888\"># on the NAE server. Since the value is in the clear, this properties file<\/span>\r\n<span style=\"color: #888888\"># must have its permission restricted so that it can be read only by the<\/span>\r\n<span style=\"color: #888888\"># applications that are to have legitimate access to it.<\/span>\r\n<span style=\"color: #888888\"># Passphrase is tier-aware.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># No default.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #996633\">Passphrase<\/span><span style=\"color: #333333\">=<\/span>\r\n\r\n\r\n<span style=\"color: #888888\">#[Local Encryption Configuration]<\/span>\r\n<span style=\"color: #888888\"># [Symmetric Key Caching]<\/span>\r\n<span style=\"color: #888888\"># Enables key caching.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># If enabled, the client will be able to use symmetric keys to encrypt<\/span>\r\n<span style=\"color: #888888\"># data locally.  If disabled, only remote encryption will be supported.<\/span>\r\n<span style=\"color: #888888\"># Should only be enabled with Protocol set to ssl.  To allow key caching<\/span>\r\n<span style=\"color: #888888\"># over unsecured communication, set the this variable to tcp_ok<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># Valid values: yes, no, tcp_ok<\/span>\r\n<span style=\"color: #888888\"># Default: no<\/span>\r\n<span style=\"color: #888888\"># Recommended: no<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #996633\">Symmetric_Key_Cache_Enabled<\/span><span style=\"color: #333333\">=<\/span>no\r\n\r\n\r\n<span style=\"color: #888888\">#[Local Encryption Configuration]<\/span>\r\n<span style=\"color: #888888\"># [Symmetric Key Cache Expiry]<\/span>\r\n<span style=\"color: #888888\"># Seconds after which a key may be removed from cache.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># The expiration interval is specified in seconds. If the time expires<\/span>\r\n<span style=\"color: #888888\"># and the key is referenced, it will be erased from the cache and<\/span>\r\n<span style=\"color: #888888\"># imported from the NAE server.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># This value has to be greater than or equal to 0 for key caching to work.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># Setting this value to 0 is equivalent to an infinite timeout.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># Default: 43200 (12 hours)<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #996633\">Symmetric_Key_Cache_Expiry<\/span><span style=\"color: #333333\">=<\/span>43200\r\n\r\n\r\n<span style=\"color: #888888\"># [Persistent Key Caching]<\/span>\r\n<span style=\"color: #888888\"># [Persistent_Cache_Enabled]<\/span>\r\n<span style=\"color: #888888\"># Enables persistent key caching during local encryption.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># To persist symmetric keys Symmetric_Key_Cache_Enabled must be set to<\/span>\r\n<span style=\"color: #888888\"># \"yes\" or \"tcp_ok\", Persistent_Cache_Enabled must be set to \"yes\",<\/span>\r\n<span style=\"color: #888888\"># Persistent_Cache_Expiry set to a zero or positive value, and<\/span>\r\n<span style=\"color: #888888\"># Persistent_Cache_Directory set to an existing directory.<\/span>\r\n<span style=\"color: #888888\"># If Symmetric_Key_Cache_Enabled or Public_Key_Cache_Enabled is set<\/span>\r\n<span style=\"color: #888888\"># to \"no\", all Persistent_Cache_* properties will be ignored.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># Valid values: yes, no<\/span>\r\n<span style=\"color: #888888\"># Default: no<\/span>\r\n<span style=\"color: #888888\"># Recommended: no<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #996633\">Persistent_Cache_Enabled<\/span><span style=\"color: #333333\">=<\/span>no\r\n\r\n<span style=\"color: #888888\"># [Persistent Key Caching]<\/span>\r\n<span style=\"color: #888888\"># [Persistent Cache Directory]<\/span>\r\n<span style=\"color: #888888\"># The location of the directory which will contain the persistent key caches.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># Provide just the path to a directory where the provider will create the<\/span>\r\n<span style=\"color: #888888\"># persistent cache file.  The value can be absolute or relative to the<\/span>\r\n<span style=\"color: #888888\"># application.  Do not use quotes when specifying the path, even if it contains spaces.<\/span>\r\n<span style=\"color: #888888\"># On Windows platforms, the value must not equal just a backslash (\\) or end<\/span>\r\n<span style=\"color: #888888\"># with a backslash if not a root directory (e.g., C:\\ is okay, however C:\\TEMP\\<\/span>\r\n<span style=\"color: #888888\"># is not).<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># default: none<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #996633\">Persistent_Cache_Directory<\/span><span style=\"color: #333333\">=<\/span>\r\n\r\n<span style=\"color: #888888\"># [Persistent Key Caching]<\/span>\r\n<span style=\"color: #888888\"># [Persistent Key Cache Expiry Keys]<\/span>\r\n<span style=\"color: #888888\"># Seconds after which a key may be removed from cache.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># The expiration interval is specified in seconds. If the time expires<\/span>\r\n<span style=\"color: #888888\"># and the key is referenced, it will be erased from the cache and<\/span>\r\n<span style=\"color: #888888\"># imported from the NAE server.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># This value has to be greater than or equal to 0 for key caching to work.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># Setting this value to 0 is equivalent to an infinite timeout.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># Default: 43200 (12 hours)<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #996633\">Persistent_Cache_Expiry_Keys<\/span><span style=\"color: #333333\">=<\/span>43200\r\n\r\n<span style=\"color: #888888\"># [Persistent Key Caching]<\/span>\r\n<span style=\"color: #888888\"># [Persistent Cache Maximum Size]<\/span>\r\n<span style=\"color: #888888\"># Maximum number of elements in the Persistent Cache.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># This value has to be greater than 0 for key caching to work.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># Default: 100<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #996633\">Persistent_Cache_Max_Size<\/span><span style=\"color: #333333\">=<\/span>100\r\n\r\n\r\n\r\n<span style=\"color: #888888\">#[Logging Configuration]<\/span>\r\n<span style=\"color: #888888\"># [Log Level]<\/span>\r\n<span style=\"color: #888888\"># The level of logging that will be performed by the client.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># The log level determines how verbose your client logs are. You can<\/span>\r\n<span style=\"color: #888888\"># disable logging by selecting NONE; however, it is recommended that you<\/span>\r\n<span style=\"color: #888888\"># set the log level to MEDIUM. A log level of HIGH can create a very large<\/span>\r\n<span style=\"color: #888888\"># log file. Set the log level to HIGH to troubleshoot configuration<\/span>\r\n<span style=\"color: #888888\"># problems.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># Valid values:<\/span>\r\n<span style=\"color: #888888\">#     NONE      - nothing is logged<\/span>\r\n<span style=\"color: #888888\">#     LOW       - only essential events are logged<\/span>\r\n<span style=\"color: #888888\">#     MEDIUM    - some events are logged<\/span>\r\n<span style=\"color: #888888\">#     HIGH      - many events are logged<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># Default: MEDIUM<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #996633\">Log_Level<\/span><span style=\"color: #333333\">=<\/span>MEDIUM\r\n\r\n\r\n<span style=\"color: #888888\">#[logging configuration]<\/span>\r\n<span style=\"color: #888888\"># [log file]<\/span>\r\n<span style=\"color: #888888\"># the location of the log file the client will create.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># you should provide the path and file name of the log file. the path can<\/span>\r\n<span style=\"color: #888888\"># be absolute or relative to the application. do not use quotes when<\/span>\r\n<span style=\"color: #888888\"># specifying the path, even if it contains spaces.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># default: logfile (created in the current directory)<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #996633\">Log_File<\/span><span style=\"color: #333333\">=<\/span>\/opt\/oracle\/11g\/lib\/safenet\/protectdb.log\r\n\r\n\r\n<span style=\"color: #888888\">#[Logging Configuration]<\/span>\r\n<span style=\"color: #888888\"># [Log Rotation]<\/span>\r\n<span style=\"color: #888888\"># The log rotation method.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># This value specifies how frequently the log file is rotated.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># Valid values:<\/span>\r\n<span style=\"color: #888888\">#     Daily     - log file is rotated once a day<\/span>\r\n<span style=\"color: #888888\">#     Size      - log file is rotated when it exceeds Log_Size_Limit<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># Default: Daily<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #996633\">Log_Rotation<\/span><span style=\"color: #333333\">=<\/span>Daily\r\n\r\n\r\n<span style=\"color: #888888\">#[Logging Configuration]<\/span>\r\n<span style=\"color: #888888\"># [Log Size]<\/span>\r\n<span style=\"color: #888888\"># The maximum log file size.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># If Log_Rotation=Size, the log will be rotated after it reaches the<\/span>\r\n<span style=\"color: #888888\"># specified size. This value is only used when Log_Rotation=Size.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># The size may be specified in bytes, kilobytes (using 'k' or 'K'), or<\/span>\r\n<span style=\"color: #888888\"># megabytes (using 'm' or 'M'). One kilobyte is 1024 bytes, and one<\/span>\r\n<span style=\"color: #888888\"># megabyte is 1048576 bytes.<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #888888\"># Default: 100k<\/span>\r\n<span style=\"color: #888888\">#<\/span>\r\n<span style=\"color: #996633\">Log_Size_Limit<\/span><span style=\"color: #333333\">=<\/span>100k\r\n<\/pre><\/div>\r\n<div id=\"gtx-trans\" style=\"position: absolute; left: 136px; top: -8.60938px;\"><div class=\"gtx-trans-icon\"><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p># # ProtectDB.properties 09\/07\/21 16:30:15 SafeNet, Inc. # # SafeNet Network-Attached Encryption (NAE) properties file # # Release Version: 5.4.0.000008 # # NOTE: Do not use quotes when specifying values in this file. # #[Version] # Version of the properties file for the SafeNet PKCS#11\/ICAPI\/MSCAPI\/.NET # providers. # # Do not modify this property. # [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_import_markdown_pro_load_document_selector":0,"_import_markdown_pro_submit_text_textarea":"","site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[10],"tags":[],"class_list":["post-670","post","type-post","status-publish","format-standard","hentry","category-computing_database"],"_links":{"self":[{"href":"https:\/\/hasu0707.duckdns.org\/blog\/index.php?rest_route=\/wp\/v2\/posts\/670","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hasu0707.duckdns.org\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hasu0707.duckdns.org\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hasu0707.duckdns.org\/blog\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/hasu0707.duckdns.org\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=670"}],"version-history":[{"count":0,"href":"https:\/\/hasu0707.duckdns.org\/blog\/index.php?rest_route=\/wp\/v2\/posts\/670\/revisions"}],"wp:attachment":[{"href":"https:\/\/hasu0707.duckdns.org\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=670"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hasu0707.duckdns.org\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=670"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hasu0707.duckdns.org\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=670"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}