Key Archival Process
718
Netscape Certificate Management System Installation and Setup Guide • May 2002
Here are a few situations in which you might need to recover a user’s encryption
private key:
•
An employee loses the encryption private key (for example, after a disk crash
or by forgetting the password to the key file) and cannot read encrypted mail
messages.
•
An employee is on an extended leave, and you need access to an encrypted
document in his or her files.
•
An employee leaves the company, and company officials need to perform an
audit that requires gaining access to the employee's encrypted mail.
Where the Keys are Stored
If configured properly, the Data Recovery Manager, stores your users’ encryption
private keys automatically whenever the associated or connected Registration
Manager or Certificate Manager issues certificates to your users. The Data
Recovery Manager stores encryption private keys in a secure key repository in its
internal database; each key is stored as a key record.
The archived copy of the key remains encrypted (or wrapped) with the Data
Recovery Manager’s storage key; see “Storage Key Pair” on page 428. It can be
decrypted (or unwrapped) only by using the corresponding private key, to which
no individual has direct access. A combination of one or more key recovery agents’
passwords enables the Data Recovery Manager to retrieve its private storage key
and use it to decrypt and recover an archived key. For details on how this process
works, see “Key Recovery Agents and Their Passwords” on page 721.
The Data Recovery Manager indexes stored keys by key number (or ID), owner
name, and a hash of the public key, allowing for highly efficient searching by name
or by public key. The key recovery agents have the privilege to insert, delete, and
search for key records. The search feature works like this:
•
When the key recovery agents search by the key ID, only the key that
corresponds to that ID is returned.
•
When the agents search by user name, all stored keys belonging to that owner
are returned.
•
When the agents search by the public key in a certificate, only the
corresponding private key is returned.
Summary of Contents for NETSCAPE DIRECTORY SERVER 6.01
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 01 May 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide May 2002...