
Creating Data Recovery Manager Agents and Administrators
149
d. The next screen returns a key recovery authorization number and a link to verify the status of
this key recovery initiation request. This page keeps refreshing until all agents have completed
authorizing the recovery request. It is important not to close this browser window.
Depending on the agent scheme, a specified number of agents must authorize this key
recovery. Send this key recovery request authorization number to each of those agents. Once
the agents receive this key recovery authorization number, they can authorize this request by
going to the DRM agent services page and clicking the
Authorize Recovery
link.
e. Once all the agents have authorized the recovery, the next screen returns a link to download a
PKCS #12 blob containing the recovered key pair. Follow the link, and save the blob to file.
9. Restore the key to the browser's database. Import the
.p12
file into the browser and mail client.
10. Open the test email. The message should be shown again.
6.7. Creating Data Recovery Manager Agents and
Administrators
When the subsystem is configured, there is a default user created with both administrator and agent
privileges.This user can perform both administrator and agent operations and access the Console and
the agent services page.
To create an additional administrator, agent, or auditor, create a user in the Certificate System instance
where the user will have privileges and assign the user to the appropriate group. An agent or auditor
must have a certificate stored in the subsystem's internal database. If the Console is configured for
SSL client authentication, all administrators must also a certificate.
To create a new user entry, do the following:
1. Log into the administrative console.
pkiconsole https://server.example.com:10443/kra
2. In the
Configuration
tab, select
Users and Groups
. Click
Add
.
3. Fill in the information in the
Edit User Information
dialog.
Содержание CERTIFICATE SYSTEM 7.2 - MIGRATION GUIDE
Страница 36: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Страница 144: ...124 ...
Страница 160: ...140 ...
Страница 208: ...188 ...
Страница 210: ...190 ...
Страница 256: ...236 ...
Страница 282: ...Chapter 12 Certificate Profiles 262 Parameter IssuerName_n IssuerType_n ...
Страница 285: ...Freshest CRL Extension Default 265 Parameter PointName_n PointIssuerName_n ...
Страница 335: ...Configuring Mappers 315 Figure 14 9 Selecting a New Mapper Type 6 Edit the mapper instance and click OK ...
Страница 362: ...342 ...
Страница 376: ...356 ...
Страница 436: ...416 ...
Страница 490: ...470 ...
Страница 504: ...484 ...