How Agent-Initiated Key Recovery Works - Netscape MANAGEMENT SYSTEM 4.5 Installation And Setup Manual

Hide thumbs Also See for NETSCAPE MANAGEMENT SYSTEM 4.5:
Table of Contents

Advertisement

Key Recovery Process
The Data Recovery Manager informs the agent who initiated the key recovery
process of the status of the authorizations. When all of the authorizations are
entered, the Data Recovery Manager checks the information. If the information
presented is correct, it retrieves the requested key and returns it along with the
corresponding certificate in the form of a PKCS #12 package to the agent who
initiated the key recovery process.
Key recovery agents can switch to remote authorization by deselecting the local
authorization option in the Key Recovery form.

How Agent-Initiated Key Recovery Works

In an agent-initiated key recovery, the key is recovered by the collective efforts of a
Data Recovery Manager agent and authorized key recovery agents. You may need
to resort to this type of key recovery if the owner of a key cannot be reached and
the authorities in the organization need to access that user's encrypted data (for
example, S/MIME mail messages).
Upon retrieving the private encryption key (in the form of a PKCS #12 package),
the agents may forward the key to the original user, the manager of the original
owner, or some other authorities.
Figure 22-2 illustrates how agent-initiated key recovery works.
744
Netscape Certificate Management System Installation and Setup Guide • October 2001

Advertisement

Table of Contents
loading

Table of Contents