Chapter 7. Data Recovery Manager
180
Key recovery agents need an appropriate page to initiate the key recovery process. By default, the
DRM's agent services page includes the appropriate HTML form to allow key recovery agents to
initiate key recovery, authorize key recovery requests, and retrieve the encryption keys.
If this form is customized, do not to delete any of the information that is vital to the functioning of
the form; it is recommended that changes be restricted to the content in and appearance of the
form.
7.6.3. Testing the Key Archival and Recovery Setup
To test whether a key can be successfully archived a key, do the following:
1. Enroll for dual certificates using the CA's
Manual User Signing & Encryption Certificates
Enrollment
form.
2. Submit the request. Log in to the agent services page, and approve the request.
3. Log into the end-entities page, and check to see if the certificates have been issued. In the list of
certificates, there should be two new certificates with consecutive serial numbers.
4. Import the certificates into the web browser.
5. Confirm that the key has been archived. In the DRM's agent services page, select
Show
completed requests
. If the key has been archived successfully, there will be information about
that key. If the key is not shown, check the logs, and correct the problem. If the key has been
successfully archived, close the browser window.
6. Verify the key. Send a signed and encrypted email. When the email is received, open it, and check
the message to see if it is signed and encrypted. There should be a security icon at the top-right
corner of the message window that indicates that the message is signed and encrypted.
7. Delete the certificate. Check the encrypted email again; the mail client should not be able to
decrypt the message.
8. Test whether an archived key can be recovered successfully:
a. Open the DRM's agent services page, and click the
Recover Keys
link. Search for the key by
the key owner, serial number, or public key. If the key has been archived successfully, the key
information will be shown.
b. Click
Recover
.
c. In the form that appears, enter the the PKCS #12 password which encrypts the PKCS #12
package and the base-64 encoded certificate that corresponds to the private key to recover;
use the CA to get this information. If the archived key was searched for by providing the
base-64 encoded certificate, then the certificate does not have to be supplied here.
d. The next screen returns a key recovery authorization number and a link to verify the status of
this key recovery initiation request. This page keeps refreshing until all agents have completed
authorizing the recovery request. It is important not to close this browser window.
Depending on the agent scheme, a specified number of agents must authorize this key
recovery. Send this key recovery request authorization number to each of those agents. Once
Summary of Contents for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Page 15: ...xv Index 525 ...
Page 16: ...xvi ...
Page 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Page 154: ...132 ...
Page 194: ...172 ...
Page 238: ...216 ...
Page 244: ...222 ...
Page 246: ...224 ...
Page 286: ...264 ...
Page 292: ...270 ...
Page 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Page 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Page 398: ...376 ...
Page 412: ...390 ...
Page 472: ...450 ...
Page 506: ...484 ...
Page 528: ...506 ...
Page 546: ...524 ...