Installing and Configuring iFolder Services
85
no
vd
ocx
(e
n)
13
Ma
y 20
09
6.6.6 Using KeyRecovery to Recover the Data
Each iFolder has a unique data encryption key which is auto-generated during iFolder creation. The
key is encrypted by using a passphrase provided by individual user and also by using the public key
with the Recovery agent. If the user forget the secret passphrase, he or she cannot access either the
iFolder data or the encrypted key used for recovering it unless the passphrase is saved locally
(enabling Remember passphrase). To avoid this problem, user export the keys using the
Security >
Export Keys
option in the client and send it manually to the Recovery agent using the e-mail address
provided in the Export dialog box in the client GUI. The Recovery agent retrieves the keys and
sends back to the user through e-mail or any other communication channel. User can then import the
keys and use them to reset the passphrase.
NOTE:
The keys are exported to a file in XML format. It is recommended to save the file as
<
filename
>.xml
This section help you understand the process followed by a Recovery agent to retrieve the key.
1
Go to the location where iFolder is installed.
2
Run
KeyRecovery
or
KeyReovery.exe
based on the platform you use and follow the on-
screen instructions.
The following table summarizes the decisions you make.
3
Send the decrypted key usually by replying to the mail attached with the encrypted keys and the
one-time passphrase (if the key is encrypted using the one-time passphrase) to the user.
4
Send the one-time passphrase (if the key is encrypted using the one-time passphrase) to the user
through any other communication channel other than the one you used to exchange the key
files.
Platform
Default Location of the Utility
Linux
/opt/novell/ifolder3/bin/KeyRecovery
Windows
C:/Program Files/iFolder/KeyRecovery.exe
Macintosh
/opt/novell/ifolder3/KeyRecovery
Parameters
Description
Encrypted Key file path
Specify the path (including the file name of the encrypted key) for
reading the encrypted keys.
Private Key
Specify the path to the private key file (PKCS12 file format, *.p12).
Decrypted Key file path
Specify the path to store the decrypted key file. Ensure that the
filename also included in the path you specify.
Private Key password
Specify the password to decrypt the private key.
Encrypt Result key
Specify whether you want to encrypt the decrypted key with one time
passphrase. Default value: Yes
One time passphrase
Specify a one time passphrase to encrypt the decrypted keys.
Summary of Contents for IFOLDER 3.7 - SECURITY ADMINISTRATION
Page 12: ...12 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Page 24: ...24 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Page 38: ...38 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Page 98: ...98 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Page 100: ...100 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Page 102: ...102 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Page 162: ...162 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Page 168: ...168 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Page 172: ...172 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Page 182: ...182 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Page 184: ...184 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Page 196: ...196 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Page 202: ...202 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...
Page 216: ...216 OES 2 SP1 Novell iFolder 3 7 Administration Guide novdocx en 13 May 2009...