Key Archival Process
200
Netscape Certificate Management System Administrator’s Guide • June 2003
Here are a few situations in which you might need to recover a end-entity’s
encryption private key:
•
An employee loses the encryption private key (for example, after a disk crash
or by forgetting the password to the key file) and cannot read encrypted mail
messages.
•
An employee is on an extended leave, and you need access to an encrypted
document in his or her files.
•
An employee leaves the company, and company officials need to perform an
audit that requires gaining access to the employee's encrypted mail.
Where the Keys are Stored
If configured properly, the Data Recovery Manager, stores your end-entity’s
encryption private keys automatically whenever the associated or connected
Registration Manager or Certificate Manager issues certificates to your users. The
Data Recovery Manager stores encryption private keys in a secure key repository
in its internal database; each key is stored as a key record.
The archived copy of the key remains encrypted (or wrapped) with the Data
Recovery Manager’s storage key; see “Data Recovery Manager’s Key Pairs and
Certificates” on page 213. It can be decrypted (or unwrapped) only by using the
corresponding private key, to which no individual has direct access. A
combination of one or more key recovery agents’ passwords enables the Data
Recovery Manager to retrieve its private storage key and use it to decrypt and
recover an archived key. For details on how this process works, see “Key Recovery
Agents and Their Passwords” on page 203.
The Data Recovery Manager indexes stored keys by key number (or ID), owner
name, and a hash of the public key, allowing for highly efficient searching by name
or by public key. The key recovery agents have the privilege to insert, delete, and
search for key records. The search feature works like this:
•
When the key recovery agents search by the key ID, only the key that
corresponds to that ID is returned.
•
When the agents search by user name, all stored keys belonging to that owner
are returned.
•
When the agents search by the public key in a certificate, only the
corresponding private key is returned.
Содержание Certificate Management System 6.2
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Страница 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 70: ...Support for Open Standards 70 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 164: ...How a Registration Manager Works 164 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 322: ...Configuring the Server s Security Preferences 322 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 564: ...Managing Policy Plug in Modules 564 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 744: ...1 3 Organization Security Policies 744 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 796: ...DNs in Certificate Management System 796 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...