Key Archival Process
Chapter
6
Data Recovery Manager
203
How Key Archival Works
When a Certificate Manager or Registration Manager receives a certificate request
that contains the key archival option, it automatically forwards the request to the
Data Recovery Manager to archive the end-entity’s encryption private key. The
Data Recovery Manager receives an encrypted copy of the end-entity’s private key
and stores the key in its key repository. To archive the key, the Data Recovery
Manager uses two special key pairs:
•
A transport key pair and corresponding certificate
•
A storage key pair
Figure 6-1 illustrates how the key archival process occurs when an end-entity’s
requests a certificate. The deployment scenario shown in this figure has a
Registration Manager acting as the trusted enrollment authority to a Certificate
Manager and Data Recovery Manager.
Figure 6-1
How the key archival process works
These are the steps shown in Figure 6-1:
1.
A end entity uses a client capable of generating dual key pairs to access the
certificate enrollment form served by the Registration Manager, fills in all the
information, and submits the request.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...