Topology Decisions
166
Netscape Certificate Management System Installation and Setup Guide • May 2002
Figure 4-3
Certificate Manager and Data Recovery Manager in different instances
The Data Recovery Manager is intended for archival and recovery of private
encryption keys only. Therefore end entities must be using either a browser that
supports dual-key generation or a browser that is using Netscape Personal Security
Manager, which supports dual keys. When determining the location of a Data
Recovery Manager, be sure to look into firewall considerations, the physical
security required for each subsystem, and the physical location of the Certificate
Manager agent, Data Recovery Manager agent, and other persons responsible for
administering the Certificate Manager and recovering keys.
Like a Certificate Manager, a Data Recovery Manager has special physical security
requirements, since a compromised Data Recovery Manager would have
devastating security consequences for your entire PKI. You may therefore want to
keep the Data Recovery Manager in a special locked room or building, a choice that
can affect your deployment strategy.
Summary of Contents for NETSCAPE DIRECTORY SERVER 6.01
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 01 May 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide May 2002...