Key Archival Process
202
Netscape Certificate Management System Administrator’s Guide • February 2003
Here are a few situations in which you might need to recover a end-entity’s
encryption private key:
•
An employee loses the encryption private key (for example, after a disk crash
or by forgetting the password to the key file) and cannot read encrypted mail
messages.
•
An employee is on an extended leave, and you need access to an encrypted
document in his or her files.
•
An employee leaves the company, and company officials need to perform an
audit that requires gaining access to the employee's encrypted mail.
Where the Keys are Stored
If configured properly, the Data Recovery Manager, stores your end-entity’s
encryption private keys automatically whenever the associated or connected
Registration Manager or Certificate Manager issues certificates to your users. The
Data Recovery Manager stores encryption private keys in a secure key repository
in its internal database; each key is stored as a key record.
The archived copy of the key remains encrypted (or wrapped) with the Data
Recovery Manager’s storage key; see “Data Recovery Manager’s Key Pairs and
Certificates” on page 215. It can be decrypted (or unwrapped) only by using the
corresponding private key, to which no individual has direct access. A
combination of one or more key recovery agents’ passwords enables the Data
Recovery Manager to retrieve its private storage key and use it to decrypt and
recover an archived key. For details on how this process works, see “Key Recovery
Agents and Their Passwords” on page 205.
The Data Recovery Manager indexes stored keys by key number (or ID), owner
name, and a hash of the public key, allowing for highly efficient searching by name
or by public key. The key recovery agents have the privilege to insert, delete, and
search for key records. The search feature works like this:
•
When the key recovery agents search by the key ID, only the key that
corresponds to that ID is returned.
•
When the agents search by user name, all stored keys belonging to that owner
are returned.
•
When the agents search by the public key in a certificate, only the
corresponding private key is returned.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...