![Netscape Certificate Management System 6.2 Administrator'S Manual Download Page 234](http://html1.mh-extra.com/html/netscape/certificate-management-system-6-2/certificate-management-system-6-2_administrators-manual_1674697234.webp)
Configuring Key Archival and Recovery Process
234
Netscape Certificate Management System Administrator’s Guide • June 2003
The method triggers the client to generate two RSA key pairs—one key of
length 512 for encrypting data and another key of length 1024 for signing
data.
i.
Save your changes.
Step D. Configure Key Archival Policies
This step is optional.
Unlike Certificate Manager and Registration Manager, no policy plug-in modules
are provided for the Data Recovery Manager. If you have implemented any custom
policy modules for the Data Recovery Manager’s key archival process, you should
make sure that they are configured properly. For details on configuring policies for
a subsystem, see “Configuring Policy Rules for a Subsystem” on page 489.
Step 2. Set Up the Key Recovery Process
Before proceeding with this section, you should have read “Key Recovery Process”
on page 203. In particular, you should be familiar with how the key archival
process works. If you are not, see “How Agent-Initiated Key Recovery Works” on
page 206.
The Data Recovery Manager supports agent-initiated key recovery process, in
which end-entity’s encryption private keys are recovered by designated key
recovery agents. This section explains how to set up the key recovery process.
To set up agent-initiated key recovery process, follow these steps:
•
Step A. Verify the m of n Scheme
•
Step B. Facilitate the Key Recovery Agents to Change the Passwords
•
Step C. Determine the Authorization Mode for Key Recovery
•
Step D. Customize the Key Recovery Form
•
Step E. Configure Key Recovery Policies
Step A. Verify the m of n Scheme
During the installation of the Data Recovery Manager, you were asked to specify
the total number of key recovery agents (a minimum of one) and the number of
agents (of this total) required to authorize a key recovery operation. This
combination is called m of n scheme. For more information about this, see “Key
Recovery Agent Scheme” on page 209.
Summary of Contents for Certificate Management System 6.2
Page 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Page 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Page 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Page 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Page 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Page 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Page 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Page 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...