Netscape MANAGEMENT SYSTEM 6.1 - ADMINISTRATOR Administrator's Manual page 817

Table of Contents

Advertisement

Cryptographic Message Syntax (CMS) The syntax used to digitally sign, digest,
authenticate, or encrypt arbitrary messages, such as CMMF.
cryptographic module See PKCS #11 module.
cryptographic service provider (CSP)
A cryptographic module that performs
cryptographic services, such as key generation, key storage, and encryption, on
behalf of software that uses a standard interface such as that defined by PKCS #11
to request such services.
CSP See cryptographic service provider (CSP).
Data Recovery Manager An optional, independent CMS subsystem that
manages the long-term archival and recovery of RSA encryption keys for end
entities. A Certificate Manager or Registration Manager can be configured to
archive end entities' encryption keys with a Data Recovery Manager before issuing
new certificates. The Data Recovery Manager is useful only if end entities are
encrypting data (such as sensitive email) that the organization may need to recover
someday. It can be used only with end entities that support dual key pairs—that is,
two separate key pairs, one for encryption and one for digital signatures.
Data Recovery Manager agent A user who belongs to a group authorized to
manage agent services for a Data Recovery Manager, including managing the
request queue and authorizing recovery operation using HTML-based
administration pages.
Data Recovery Manager recovery agent One of the m of n people who own
portions of the storage key for the Data Recovery Manager.
Data Recovery Manager storage key Special key used by the Data Recovery
Manager to encrypt the end entity's encryption key (after it has been decrypted
with the Data Recovery Manager's private transport key). The storage key never
leaves the Data Recovery Manager.
Data Recovery Manager transport certificate Certifies the public key used by an
end entity to encrypt the entity's encryption key for transport to the Data Recovery
Manager. The Data Recovery Manager uses the private key corresponding to the
certified public key to decrypt the end entity's key before encrypting it with the
Data Recovery Manager storage key. The Data Recovery Manager also uses the
same private key to sign the proof of archival token it sends to the Registration
Manager after storing an end entity's encryption key.
decryption The unscrambling of data that has been encrypted. See encryption.
Glossary
817

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.1

Table of Contents