System Overview
Chapter
1
Introduction to Certificate Management System
53
4.
The Data Recovery Manager signs a proof-of-archival token with its private
transport key and sends the token to the Registration Manager.
5.
The Registration Manager verifies the token and sends the certificate requests
on to the Certificate Manager.
6.
The Certificate Manager issues the signing and encryption certificates and
sends them back to the Registration Manager.
7.
The Registration Manager delivers the certificates to the end entity.
Figure 1-2
Key storage process during end-entity enrollment
Data encrypted with the storage key can be retrieved only if m of n “split keys” are
provided at the same time by m of n authorized recovery agents. By default, m and
n are 2 and 3, respectively. Both values can be changed, as long as m is less than or
equal to n.
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 4.5
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version4 5 October 2001...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 162: ...162 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 796: ...796 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 827: ...827 Part 5 Appendix Appendix A Certificate Download Specification...
Page 828: ...828 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 850: ...850 Netscape Certificate Management System Installation and Setup Guide October 2001...