199
Chapter
6
Data Recovery Manager
When data is stored in encrypted form, you must have the private key that
corresponds to the public key that was used to encrypt the data in order to decrypt
and read it. If the private key is lost, the data cannot be retrieved. A private key can
be lost because of a hardware failure, for example, or because the key’s owner
forgets the password or loses the hardware token in which the key is stored.
Similarly, encrypted data cannot be retrieved if the owner of the key is unavailable
to supply it—for example, has left the organization that owns the data.
This chapter explains how to use the Data Recovery Manager to archive
end-entity’s encryption private keys and how to use the archived keys later, in
place of missing encryption keys, to recover encrypted data.
This chapter contains the following sections:
•
Data Recovery Manager’s Key Pairs and Certificates
•
PKI Setup for Key Archival and Recovery
•
Key Archival Process
•
Key Recovery Process
•
Installing a Standalone Data Recovery Manager
•
Configuring Key Archival and Recovery Process
PKI Setup for Key Archival and Recovery
To be able to archive end-entity’s’ encryption private keys and recover them later,
you need a PKI setup that includes the following elements:
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...