Key Archival Process
Chapter
22
Setting Up Key Archival and Recovery
739
How Key Archival Works
When a Certificate Manager or Registration Manager receives a certificate request
that contains the key archival option, it automatically requests the service of the
Data Recovery Manager to archive the user’s encryption private key. The Data
Recovery Manager receives an encrypted copy of the user’s private key and stores
the key in its key repository. To archive the key, the Data Recovery Manager uses
two special key pairs:
•
A transport key pair and corresponding certificate
•
A storage key pair
Figure 22-1 illustrates how the key archival process occurs when a user requests a
certificate. The deployment scenario shown in this figure has a Registration
Manager acting as the trusted enrollment authority to a Certificate Manager and
Data Recovery Manager.
Figure 22-1
How the key archival process works
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 4.5
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version4 5 October 2001...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 162: ...162 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 796: ...796 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 827: ...827 Part 5 Appendix Appendix A Certificate Download Specification...
Page 828: ...828 Netscape Certificate Management System Installation and Setup Guide October 2001...
Page 850: ...850 Netscape Certificate Management System Installation and Setup Guide October 2001...