| Tuesday 07 February 2012 |
|
![]() |
| news | meetings | document store | registration services | database | policies | training | mailing lists | tools | statistics |
| ::: Database - Protecting your data in the AfriNIC Database | |||||||||||||||||||
|
This document provides recommendations on how to use the various methods
available to AfriNIC To protect data in the AfriNIC Database, users will need a mntner object. These are created, like When using a maintainer to protect your data, you will have to choose one or more of the available Four authentication methods are currently available: * CRYPT-PW: This method takes an argument consisting of a Unix style encrypted password. When requesting a mntner object, the user must include an "auth:" auth: CRYPT-PW <crypted password> When submitting an update by e-mail to create, modify or delete an object
protected by a maintainer This pseudo attribute must be in the body of the e-mail message. If it is a
multipart mime message If this password, when encrypted, matches the one stored in the mntner
object the update will There is a cgi script here to generate a crypt-pw password for you. https://www.afrinic.net/tools/whois_crypt.htm Note: This method may be subject to two types of attacks: o Password cracking. This is the same kind of attack to which normal
computer passwords can * MD5-PW: This method takes an argument consisting of an MD5 encrypted password. When requesting a auth: MD5-PW <MD5 crypted password> Creating, modifying or deleting an object protected by a maintainer using
this method follows There is a cgi script here to generate an MD5 password for you. Please note that this method may be subject to the same types of attacks
as previously mentioned * PGPKEY: This is one of the strongest protection methods available. The user
specifies a PGP key-id pointing When sending updates to the database, the user must sign the message using
his/her PGP private key. Note: This type of usage of PGP is considered as commercial use by PGP
Inc. A commercial software Note: AfriNIC makes no claims about the identity of the owner of
the PGP key used. It just checks that http://www.Afrinic.net/supporting/db/afsup-pgp200502.htm This metho too is one of the strongest protection methods available. The user
specifies an X.509 When sending updates to the database, the user must sign the message using
his/her X.509 certificate Note1: AfriNIC makes no claims about the trust path of the certificate
or of the revocation status of Simultaneous Use of Several Authentication Schemes It is enough to match only one of the "auth:" attributes in the mntner object in order to update an object. We recommend using only one type of authentication method in one mntner object.
It should be the The best possible protection method is to have either PGPKEY or X.509 authentication. If, for whatever More information For a complete description of how to interact with the AfriNIC Database,
including data protection, * AfriNIC Database Reference Manual An empty template can be obtained using a whois client pointed to whois.afrinic.net as follows: http://www.afrinic.net/docs/db/afsup-obj200502.htm#29
|
|
| Copyright ©
2005-2010 AfriNIC. All rights reserved. For website comments/feedback, click here . For general inquiries, email contact@afrinic.net |