
Chapter 6. Data Recovery Manager
142
•
Section 6.2.1, “Transport Key Pair and Certificate”
•
Section 6.2.2, “Storage Key Pair”
•
Section 6.2.3, “SSL Server Certificate”
6.2.1. Transport Key Pair and Certificate
Every DRM has a transport certificate. The public key of the key pair that is used to generate the
transport certificate is used by the client software to encrypt an end entity's private encryption key
before it is sent to the DRM for archival; only those clients capable of generating dual-key pairs
use the transport certificate. For more information on how this certificate is used, see
Section 6.4,
“Overview of Archiving Keys”
.
6.2.2. Storage Key Pair
Every DRM has a storage key pair.
The DRM uses the public component of this key pair to encrypt (or wrap) private encryption keys
when archiving the keys. It uses the private component to decrypt (or unwrap) the archived key during
recovery. For more information on how this key pair is used, see
Chapter 6, Data Recovery Manager
.
NOTE
The public component of the storage key pair is not certified; there is no certificate that
corresponds to the public key. It is a self-signed certificate.
Keys encrypted with the storage key can be retrieved only by authorized key recovery agents. For
details, see
Section 6.5.1, “Key Recovery Agents and Their Passwords”
.
6.2.3. SSL Server Certificate
Every Certificate System DRM has at least one SSL server certificate. The first SSL server certificate
is generated when the DRM is configured. The default nickname for the certificate is
Server-Cert
cert-
instance_id
, where
instance_id
identifies the DRM instance is installed.
The DRM's SSL server certificate was issued by the CA to which the certificate request was submitted,
which can be a Certificate System CA or a third-party CA. To view the issuer name, open the
certificate details in the
System Keys and Certificates
option in the DRM Console.
The DRM uses its SSL server certificate for server-side authentication to the DRM agent services
interface. By default, the Data Recovery Manager uses a single SSL server certificate for
authentication. However, additional SSL server certificates can be requested and installed for the
DRM.
6.3. Forms for Users and Key Recovery Agents
End entity private encryption keys are archived by the DRM when they are generated. When
a Certificate Manager processing a certificate request detects the request for key archival, it
automatically requests the service of the DRM. Because the DRM transport certificate is stored within
the CA's
CS.cfg
file, the CA enrollment form can automatically trigger the key archival.
Содержание CERTIFICATE SYSTEM 7.2 - MIGRATION GUIDE
Страница 36: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Страница 144: ...124 ...
Страница 160: ...140 ...
Страница 208: ...188 ...
Страница 210: ...190 ...
Страница 256: ...236 ...
Страница 282: ...Chapter 12 Certificate Profiles 262 Parameter IssuerName_n IssuerType_n ...
Страница 285: ...Freshest CRL Extension Default 265 Parameter PointName_n PointIssuerName_n ...
Страница 335: ...Configuring Mappers 315 Figure 14 9 Selecting a New Mapper Type 6 Edit the mapper instance and click OK ...
Страница 362: ...342 ...
Страница 376: ...356 ...
Страница 436: ...416 ...
Страница 490: ...470 ...
Страница 504: ...484 ...