How are the keys assigned to the folder or file when using FSM?
Originally Published: 2008-07-30
Last Modified: 2023-09-24
Article Number
000066733
Applies To
RSA File Security Manager (FSM)
Issue

How are the keys assigned to the folder or file when using FSM?


Resolution

Each folder is uniquely mapped to its encryption key. FSM is the only system that has access to the encryption keys. When a user logs into the system, FSM probes for the User SID or Group GID. This is in turn mapped to a Role Key. A role key is in turn mapped to the actual encryption key. As you can see there are several layers of indirection before FSM encrypts/decrypts the files on behalf of the user.

Note that the encryption keys are never physically presented to the end user.