Clients That Can Generate Dual Key Pairs; Data Recovery Manager - Netscape MANAGEMENT SYSTEM 6.1 - ADMINISTRATOR Administrator's Manual

Table of Contents

Advertisement

PKI Setup for Key Archival and Recovery
Clients that can generate dual keys and that support the key archival option
(using the CRMF/CMMF protocol). These include Netscape 6.2 and Netscape
7.0 and higher.
An installed and configured Data Recovery Manager
HTML forms with which end-entity's can request dual certificates (based on
dual keys) and key recovery agents can request key recovery
The sections that follow explain these elements in detail. For step-by-step
instructions on setting up your PKI environment for key archival and recovery, see
"Installing a Standalone Data Recovery Manager" on page 215.

Clients That Can Generate Dual Key Pairs

Only keys that are used exclusively for encrypting data should be archived; signing
keys in particular should never be archived. Having two copies of a signing key
would defeat the certainty with which the key identifies its owner; a second
archived copy could be used to impersonate the digital identity of the original key
owner.
Clients that generate single key pairs use the same private key for both signing and
encrypting data, so you cannot archive and recover a private key deriving from a
single key pair. By contrast, clients that can generate dual key pairs use one private
key for encrypting data and the other for signing data. Because the encryption
private key is separate, you can archive it.
In addition to generating dual key pairs, your end-entity's clients must also
support the encryption key archival option in certificate requests. This option
triggers the key archival process at the time encryption private keys are generated
as a part of certificate issuance.
Netscape 6.2 and Netscape 7.0 or higher support generation of dual key-pairs.

Data Recovery Manager

With the Data Recovery Manager, you can archive end-entity encryption keys
when they are created during dual key-pair generation. You can then recover the
keys if they are lost or the key owner is unavailable.
The Data Recovery Manager can archive and recover keys only from clients that
support dual key-pair generation and the key archival option in certificate
requests.
200
Netscape Certificate Management System Administrator's Guide • February 2003

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.1

Table of Contents