![Netscape Certificate Management System 6.2 Скачать руководство пользователя страница 230](http://html1.mh-extra.com/html/netscape/certificate-management-system-6-2/certificate-management-system-6-2_administrators-manual_1674697230.webp)
Configuring Key Archival and Recovery Process
230
Netscape Certificate Management System Administrator’s Guide • June 2003
•
The key archival option—this must be included in the certificate enrollment
form that your users use to request certificates.
•
The Data Recovery Manager’s transport certificate—this must also be included
in the certificate enrollment form (ProfileSelect.template). The Data Recovery
Manager uses it to encrypt the end-entity’s encryption private key with the
public key in the transport certificate before sending the end-entity’s key to its
key repository. For information about the key repository, see “Where the Keys
are Stored” on page 200.
Make sure that the transport certificate, in its base-64 encoded format, is
embedded in the form. Otherwise, the Data Recovery Manager will fail to
archive end-entity’s keys.
Note that the JavaScript method includes parameters for specifying various things.
You are required to update the following information only:
•
The Data Recovery Manager’s transport certificate.
•
The algorithm, length, type, and usage for end-entity’s key pairs. When you
update this information, the key archival option is automatically set. For
information on specifying the key type, length, and algorithm, see
generateCRMFRequest()
in Javascript API for Client Certificate Management.
This document is located where you extracted Personal Security Manager files
after downloading it from the web site.
The steps that follow explain how to do this.
1.
Copy the transport certificate in its base-64 encoded format.
The transport certificate is stored in the Data Recovery Manager’s certificate
database. If the transport certificate is signed by a Certificate Manager, then a
copy of the certificate is also available with the Certificate Manager. Follow the
instructions as appropriate.
To copy the transport certificate information from a Certificate Manager’s
database:
a.
Open a web browser window.
b.
Go to the end-entity page hosted by the Certificate Manager.
c.
Click the Retrieval tab.
d.
List or search for the transport certificate.
Содержание Certificate Management System 6.2
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Страница 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 70: ...Support for Open Standards 70 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 164: ...How a Registration Manager Works 164 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 322: ...Configuring the Server s Security Preferences 322 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 564: ...Managing Policy Plug in Modules 564 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 744: ...1 3 Organization Security Policies 744 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 796: ...DNs in Certificate Management System 796 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...