Data Recovery Manager - Netscape MANAGEMENT SYSTEM 6.2 - ADMINISTRATOR Administrator's Manual

Table of Contents

Advertisement

How Certificate Management System Works
An agent can also revoke a certificate. They might do this if someone leaves the
company.
When the certificate is revoked, it is marked revoked in the internal database, and
is marked revoked in the publishing system. The certificate is also added to the
Certificate Revocation List (CRL) produced by the Certificate Manager. See
Chapter 14, "Revocation and CRLs" for complete details.

Data Recovery Manager

The Data Recovery Manager is an optional subsystem of CMS that can act as a Key
Recovery Authority. When configured in conjuncture with a Certificate Manager
or Registration Manager, the Data Recover Manager stores private encryption keys
as part of the certificate enrollment process. The key archival mechanism is
triggered when a user enrolls in the PKI and creates the certificate request. Using
the CRMF request format, the request generates a request for the users private
encryption key. The key is then stored in the Data Recovery Manager. The Data
Recovery Manager is configured to store keys in an encrypted format that can only
be decrypted by several agents requesting the key at one time, providing for
protection of the public encryption keys for the users in your deployment.
Note that the Data Recovery Manager archives encryption keys. It does not archive
signing keys, since such archival would undermine nonrepudiation properties of
signing keys.
Key Archival
If you have set up a Data Recovery Manager as part of your PKI, the private
encryption key for an end-entity is requested and stored when the enrollment
request is made.
Key Retrieval
If you have set up a Data Recovery Manager up as part of your PKI, you can
retrieve the private encryption keys of your users to decrypt messages or other
documents that have been encrypted with the private encryption key. CMS
provides a key retrieval system that can only be activated by several agents
approving the key retrieval at the same time to offer maximum security of the
stored keys.
See Chapter 6, "Data Recovery Manager" for complete details.
Chapter 1
Overview
51

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate management system 6.2

Table of Contents