Key Archival Process
Chapter
6
Data Recovery Manager
201
CMS does not provide any policy plug-in modules for the Data Recovery Manager.
However, you can write custom policy plug-in modules (that is, write Java classes
that implement these rules), register them in the Data Recovery Manager’s policy
framework, and create policy rules using these plug-in implementations. For
details about writing custom plug-ins see the CMS SDK.
Forms for Users and Key Recovery Agents
End-entity’s encryption private keys are archived by the Data Recovery Manager
when they are generated. So, for key archival to occur, the enrollment form that
users fill out to request dual certificates must have the JavaScript code for
activating the key archival option embedded in it, along with a valid copy of the
Data Recovery Manager’s transport certificate. Then, when a Certificate Manager
or Registration Manager that is processing the end-entity’s certificate issuance
request detects the key archival option, it automatically requests the service of the
Data Recovery Manager. For information on customizing this form, see “Step C.
Customize the Certificate Enrollment Form” on page 231.
Initiating the key recovery process also requires its own HTML form. By default,
the Data Recovery Manager Agent Services interface provides a form for initiating
the process and retrieving keys. For information on customizing this form, see
“Step D. Customize the Key Recovery Form” on page 237.
Key Archival Process
If your certificate infrastructure has been set up for key archival, the Data Recovery
Manager automatically archives end-entity’s encryption private keys. For general
information on the type of PKI setup needed for archiving keys, see “PKI Setup for
Key Archival and Recovery” on page 199. For specific instructions on setting up a
key archival and recovery infrastructure, see “Installing a Standalone Data
Recovery Manager” on page 215.
Why You Should Archive Keys
If a end-entity’s loses a private data-encryption key or is unavailable to use his or
her private key, the key must be recovered before any data that was encrypted with
the corresponding public key can be read. You can recover the private key if an
archival copy of it was created when the key was generated.
Summary of Contents for Certificate Management System 6.1
Page 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Page 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Page 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Page 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Page 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Page 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Page 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...