Key Archival Process
720
Netscape Certificate Management System Installation and Setup Guide • May 2002
These are the steps shown in Figure 22-1:
1.
A user uses a client capable of generating dual key pairs to access the certificate
enrollment form served by the Registration Manager, fills in all the
information, and submits the request.
The Registration Manager detects the key archival option in the user’s request
and asks the client for the user’s encryption private key.
The client encrypts the user’s encryption private key with the public key from
the Data Recovery Manager’s transport certificate; a copy of the transport
certificate is embedded in the enrollment form.
2.
Upon receiving the encrypted key from the client, the Registration Manager
sends it to the Data Recovery Manager for storage, along with some other
information (including the user’s public key). Then, the Registration Manager
waits for verification from the Data Recovery Manager that the private key has
been received and stored and that it corresponds to the user's public
encryption key.
3.
Upon receiving the encrypted key from the Registration Manager, the Data
Recovery Manager decrypts it with the private key that corresponds to the
public key in its transport certificate. After confirming that the private
encryption key corresponds to the user’s public encryption key, the Data
Recovery Manager encrypts it again with its storage key before storing it in its
internal database. (The storage key either resides in a software or a hardware
token and is never exposed to any other entity.)
4.
Once the user’s private encryption key has been successfully stored, the Data
Recovery Manager uses the private key of its transport key pair to sign a token
confirming that the key has been successfully stored; the Data Recovery
Manager then sends the token to the Registration Manager.
5.
After the Registration Manager receives and verifies the signed token, it sends
the certificate request to the Certificate Manager for issuance.
6.
The Certificate Manager formulates two certificates, one each for signing and
encryption key pairs, and returns them to the Registration Manager.
7.
The Registration Manager forwards the certificates to the client (the user).
Note that all three subsystems subject the request to configured policy rules at
appropriate stages. If the request fails to meet any of the policy rules, the
subsystem rejects the request.
Summary of Contents for NETSCAPE DIRECTORY SERVER 6.01
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 01 May 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide May 2002...