Use > Hardening > Confidential Manager > Confidential Manager Overview

Confidential Manager Overview

The Confidential Manager framework solves the problem of managing and distributing sensitive data for Universal CMDB and other products.

Confidential Manager consists of two main components: the client and the server. These two components are responsible for transferring data in a secured manner.

  • The Confidential Manager client is a library used by applications to access sensitive data.
  • The Confidential Manager server receives requests from Confidential Manager clients, or from third party clients, and performs the required tasks. The Confidential Manager server is responsible for saving the data in a secure manner.

Confidential Manager encrypts credentials in transport, in the client cache, in persistency, and in memory. Confidential Manager uses symmetric cryptography for transporting credentials between the Confidential Manager client and the Confidential Manager server by using a shared secret. Confidential Manager uses various secrets for encryption of cache, persistency, and transport according to the configuration.

For detailed guidelines for managing credential encryption on the Data Flow Probe, see Data Flow Credentials Management.