Key Archival Process
Chapter
22
Setting Up Key Archival and Recovery
719
How Key Archival Works
When a Certificate Manager or Registration Manager receives a certificate request
that contains the key archival option, it automatically requests the service of the
Data Recovery Manager to archive the user’s encryption private key. The Data
Recovery Manager receives an encrypted copy of the user’s private key and stores
the key in its key repository. To archive the key, the Data Recovery Manager uses
two special key pairs:
•
A transport key pair and corresponding certificate
•
A storage key pair
Figure 22-1 illustrates how the key archival process occurs when a user requests a
certificate. The deployment scenario shown in this figure has a Registration
Manager acting as the trusted enrollment authority to a Certificate Manager and
Data Recovery Manager.
Figure 22-1
How the key archival process works
Summary of Contents for NETSCAPE DIRECTORY SERVER 6.01
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 01 May 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide May 2002...