Figure 6-1 illustrates how the key archival process occurs when an end-entity's requests a
certificate. The deployment scenario shown in this figure has a Registration Manager acting
as the trusted enrollment authority to a Certificate Manager and Data Recovery Manager.
Figure 6-1
How the key archival process works
These are the steps shown in Figure 6-1:
A end entity uses a client capable of generating dual key pairs to access the certificate
1.
enrollment form served by the Registration Manager, fills in all the information, and
submits the request.
The client detects the JavaScript option and exports only the end-entity's encryption
private key, not the signing private key.
The Registration Manager detects the key archival option in the end-entity's request
and asks the client for the end-entity's encryption private key.
The client encrypts the end-entity's encryption private key with the public key from the
Data Recovery Manager's transport certificate; a copy of the transport certificate is
embedded in the enrollment form.
Key Archival Process
Chapter 6
Data Recovery Manager
191
Need help?
Do you have a question about the CERTIFICATE SYSTEM 7.1 - ADMINISTRATOR and is the answer not in the manual?