![Netscape Certificate Management System 6.2 Скачать руководство пользователя страница 209](http://html1.mh-extra.com/html/netscape/certificate-management-system-6-2/certificate-management-system-6-2_administrators-manual_1674697209.webp)
Key Recovery Process
Chapter
6
Data Recovery Manager
209
Key Recovery Agent Scheme
The key recovery agent scheme consists of configuring the Data Recovery Manager to
recognize a fixed number of key recovery agents (a minimum of one) and
specifying how many of these agents are required to authorize a key recovery
request before the archived key is restored. Each recovery agent provides the Data
Recovery Manager with a password, which it uses to generate a unique PIN; the
Data Recovery Manager uses the PIN to protect its storage key pair, which in turn
protects end-entity’s keys.
The Data Recovery Manager tracks the key recovery agent password for each agent
and allows you to facilitate changing agents’ passwords; you do not have direct
access to these passwords or the actual storage key password. Each password
retrieves only a part of the private storage key.
You first specified the key recovery agent scheme when you installed the Data
Recovery Manager.
Changing the Key Recovery Agent Scheme
You can change the total number of key recovery agents for a Data Recovery
Manager and the number of key recovery agents required to retrieve an
end-entity’s encryption private key from the Data Recovery Manager’s key
repository.
To change the key recovery agent scheme:
1.
Access the CMS window (see “Logging Into the CMS Console” on page 245).
2.
Click the Configuration tab.
CAUTION
The PKCS #12 package contains the private key. To minimize the
risk of key compromise, the recovery agent must use any secure,
out-of-band means to deliver the PKCS #12 package and password
to the key recipient. As an administrator, you should recommend
the recovery agent to use a good password for encrypting the PKCS
#12 package, and also consider setting up an appropriate delivery
mechanism.
Содержание Certificate Management System 6.2
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Страница 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 70: ...Support for Open Standards 70 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 164: ...How a Registration Manager Works 164 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 322: ...Configuring the Server s Security Preferences 322 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 564: ...Managing Policy Plug in Modules 564 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 744: ...1 3 Organization Security Policies 744 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 796: ...DNs in Certificate Management System 796 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...