How Key Archival Works - Netscape MANAGEMENT SYSTEM 6.2 - ADMINISTRATOR Administrator's Manual

Table of Contents

Advertisement

How Key Archival Works

When a Certificate Manager or Registration Manager receives a certificate request
that contains the key archival option, it automatically forwards the request to the
Data Recovery Manager to archive the end-entity's encryption private key. The
Data Recovery Manager receives an encrypted copy of the end-entity's private key
and stores the key in its key repository. To archive the key, the Data Recovery
Manager uses two special key pairs:
A transport key pair and corresponding certificate
A storage key pair
Figure 6-1 illustrates how the key archival process occurs when an end-entity's
requests a certificate. The deployment scenario shown in this figure has a
Registration Manager acting as the trusted enrollment authority to a Certificate
Manager and Data Recovery Manager.
Figure 6-1
How the key archival process works
These are the steps shown in Figure 6-1:
A end entity uses a client capable of generating dual key pairs to access the
1.
certificate enrollment form served by the Registration Manager, fills in all the
information, and submits the request.
Key Archival Process
Chapter 6
Data Recovery Manager
201

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.2

Table of Contents