Keys and Certificates for the Main Subsystems
428
Netscape Certificate Management System Installation and Setup Guide • May 2002
Transport Key Pair and Certificate
Every Data Recovery Manager you have installed has a Data Recovery Manager
transport certificate. The public key of the key pair that is used to generate the
transport certificate is used by the client software to encrypt an end user’s
encryption private key before it is sent to the Data Recovery Manager for archival;
only those clients capable of generating dual-key pairs (one for signing and one for
encryption) use the transport certificate. For more information on how this
certificate is used, see “Key Archival Process” on page 717.
The first time you generated this certificate is when you installed the Data
Recovery Manager. The default nickname for the certificate is
kraTransportCert cert-<instance_id>
, where
<instance_id>
identifies the
CMS instance in which the Data Recovery Manager is installed.
The transport certificate was issued by the CA to which you submitted the
certificate signing request. You might have submitted the request to the Certificate
Manager that is installed in the same instance, internally deployed another CA, or a
public CA. To find out the issuer name, follow the instructions in “Viewing the
Certificate Database Content” on page 482.
Storage Key Pair
Every Data Recovery Manager you have installed has a Data Recovery Manager
storage key pair. The first time you generated this key pair is when you installed the
Data Recovery Manager.
The Data Recovery Manager uses the public component of this key pair to encrypt
(or wrap) end users’ encryption private keys during the key archival operation; it
uses the private component to decrypt (or unwrap) the archived key during the
recovery operation. That is, the public key is used to encrypt the key repository the
server uses to store end users’ encryption private keys. For more information on
how this key pair is used, see Chapter 22, “Setting Up Key Archival and Recovery.”
Note that the public component of the storage key pair is not certified; there is no
certificate that corresponds to the public key.
Keys encrypted with the storage key can be retrieved only by authorized key
recovery agents. For details, see “Key Recovery Agents and Their Passwords” on
page 721.
Summary of Contents for NETSCAPE DIRECTORY SERVER 6.01
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 01 May 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide May 2002...