PKI Setup for Key Archival and Recovery
200
Netscape Certificate Management System Administrator’s Guide • February 2003
•
Clients that can generate dual keys and that support the key archival option
(using the CRMF/CMMF protocol). These include Netscape 6.2 and Netscape
7.0 and higher.
•
An installed and configured Data Recovery Manager
•
HTML forms with which end-entity’s can request dual certificates (based on
dual keys) and key recovery agents can request key recovery
The sections that follow explain these elements in detail. For step-by-step
instructions on setting up your PKI environment for key archival and recovery, see
“Installing a Standalone Data Recovery Manager” on page 215.
Clients That Can Generate Dual Key Pairs
Only keys that are used exclusively for encrypting data should be archived; signing
keys in particular should never be archived. Having two copies of a signing key
would defeat the certainty with which the key identifies its owner; a second
archived copy could be used to impersonate the digital identity of the original key
owner.
Clients that generate single key pairs use the same private key for both signing and
encrypting data, so you cannot archive and recover a private key deriving from a
single key pair. By contrast, clients that can generate dual key pairs use one private
key for encrypting data and the other for signing data. Because the encryption
private key is separate, you can archive it.
In addition to generating dual key pairs, your end-entity’s clients must also
support the encryption key archival option in certificate requests. This option
triggers the key archival process at the time encryption private keys are generated
as a part of certificate issuance.
Netscape 6.2 and Netscape 7.0 or higher support generation of dual key-pairs.
Data Recovery Manager
With the Data Recovery Manager, you can archive end-entity encryption keys
when they are created during dual key-pair generation. You can then recover the
keys if they are lost or the key owner is unavailable.
The Data Recovery Manager can archive and recover keys only from clients that
support dual key-pair generation and the key archival option in certificate
requests.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...