4. Once the private encryption key has been successfully stored, the DRM uses the private key of its
transport key pair to sign a token confirming that the key has been successfully stored; the DRM
then sends the token to the Certificate Manager.
5. The Certificate Manager issues two certificates for the signing and encryption key pairs and
returns them to the end entity.
Both subsystems subject the request to configured certificate profile constraints at appropriate stages.
If the request fails to meet any of the profile constraints, the subsystem rejects the request.
6.5. Overview of Key Recovery
The DRM supports agent-initiated key recovery. Agent-initiated recovery is when designated recovery
agents use the key recovery form on the DRM agent services page to process and approve key
recovery requests. With the approval of a specified number of agents, an organization can recover
keys when the key's owner is unavailable or when keys have been lost.
6.5.1. Key Recovery Agents and Their Passwords
NOTE
DRM agents are also known as key recovery agents.
Key recovery agents have the authority to retrieve private encryption keys. Any user can be
designated as a recovery agent. Recovery agents need to do the following:
• Be added to the Data Recovery Manager Agents group.
• Obtain a client certificate identifying themselves. The DRM administrator needs to add that user
certificate to the DRM's internal database.
• Be available to retrieve private encryption keys. It is not necessary for all key recovery agents to be
available for the key recovery operation; the required number to authorize the recovery of a key is
configured by the administrator. See
specified number of key recovery agents must all present their certificates to authorize the recovery
of the specific private key.
6.5.1.1. Interface for the Key Recovery Process
With the key recovery form provided in the DRM agent services page, key recovery agents can
collectively authorize and retrieve private encryption keys and associated certificates in a PKCS #12
package, which can then be imported into the client.
The DRM agent's certificate is required to access the key recovery form. For information on DRM
Section 16.1.2.3,
agents, see
6.5.1.2. Key Recovery Authorization and How it Works
DRM agents can authorize key recovery. This is explained in more detail in the Certificate System
Agent's Guide. To authorize key recovery, the required number of recovery agents access the DRM
agent services page and use the Authorize Recovery button to enter each authorization separately.
Section 6.5.2, "Key Recovery Agent
"Agents".
Overview of Key Recovery
Scheme". However, the
145
Need help?
Do you have a question about the CERTIFICATE SYSTEM 7.2 - ADMINISTRATION and is the answer not in the manual?
Questions and answers