Clients That Can Generate Dual Key Pairs; Data Recovery Manager - Netscape MANAGEMENT SYSTEM 4.5 Installation And Setup Manual

Hide thumbs Also See for NETSCAPE MANAGEMENT SYSTEM 4.5:
Table of Contents

Advertisement

PKI Setup for Key Archival and Recovery
HTML forms with which your users can request dual certificates (based on
dual keys) and key recovery agents can request key recovery
The sections that follow explain these elements in detail. For step-by-step
instructions on setting up your PKI environment for key archival and recovery, see
"Configuring Key Archival and Recovery Process" on page 751.

Clients That Can Generate Dual Key Pairs

Only keys that are used exclusively for encrypting data should be archived; signing
keys in particular should never be archived. Having two copies of a signing key
would defeat the certainty with which the key identifies its owner; a second copy
could be used to impersonate the digital identity of the original key owner.
Clients that generate single key pairs use the same private key for both signing and
encrypting data, so you cannot archive and recover a private key deriving from a
single key pair. By contrast, clients that can generate dual key pairs use one private
key for encrypting data and the other for signing data. Because the encryption
private key is separate, you can archive it.
In addition to generating dual key pairs, your users' clients must also support the
encryption key archival option in certificate requests. This option triggers the key
archival process at the time encryption private keys are generated as a part of
certificate issuance.
Netscape 6 and Netscape Communicator versions 4.7x (when used in conjunction
with Netscape Personal Security Manager) support generation of dual key-pairs.
For a brief introduction to Personal Security Manager, see page 39.

Data Recovery Manager

With the Data Recovery Manager, you can archive data encryption keys when they
are created during dual key-pair generation. You can then recover the keys if they
are lost or the key owner is unavailable.
The Data Recovery Manager can archive and recover keys only from clients that
support dual key-pair generation and the key archival option in certificate
requests.
736
Netscape Certificate Management System Installation and Setup Guide • October 2001

Advertisement

Table of Contents
loading

Table of Contents