Key Archival Process
Chapter
6
Data Recovery Manager
199
CMS does not provide any policy plug-in modules for the Data Recovery Manager.
However, you can write custom policy plug-in modules (that is, write Java classes
that implement these rules), register them in the Data Recovery Manager’s policy
framework, and create policy rules using these plug-in implementations. For
details about writing custom plug-ins see the CMS SDK.
Forms for Users and Key Recovery Agents
End-entity’s encryption private keys are archived by the Data Recovery Manager
when they are generated. So, for key archival to occur, the enrollment form that
users fill out to request dual certificates must have the JavaScript code for
activating the key archival option embedded in it, along with a valid copy of the
Data Recovery Manager’s transport certificate. Then, when a Certificate Manager
or Registration Manager that is processing the end-entity’s certificate issuance
request detects the key archival option, it automatically requests the service of the
Data Recovery Manager. For information on customizing this form, see “Step C.
Customize the Certificate Enrollment Form” on page 229.
Initiating the key recovery process also requires its own HTML form. By default,
the Data Recovery Manager Agent Services interface provides a form for initiating
the process and retrieving keys. For information on customizing this form, see
“Step D. Customize the Key Recovery Form” on page 235.
Key Archival Process
If your certificate infrastructure has been set up for key archival, the Data Recovery
Manager automatically archives end-entity’s encryption private keys. For general
information on the type of PKI setup needed for archiving keys, see “PKI Setup for
Key Archival and Recovery” on page 197. For specific instructions on setting up a
key archival and recovery infrastructure, see “Installing a Standalone Data
Recovery Manager” on page 213.
Why You Should Archive Keys
If a end-entity’s loses a private data-encryption key or is unavailable to use his or
her private key, the key must be recovered before any data that was encrypted with
the corresponding public key can be read. You can recover the private key if an
archival copy of it was created when the key was generated.
Содержание Certificate Management System 6.2
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Страница 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 70: ...Support for Open Standards 70 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 164: ...How a Registration Manager Works 164 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 322: ...Configuring the Server s Security Preferences 322 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 564: ...Managing Policy Plug in Modules 564 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 744: ...1 3 Organization Security Policies 744 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 796: ...DNs in Certificate Management System 796 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...