Configuring Key Archival and Recovery Process
738
Netscape Certificate Management System Installation and Setup Guide • May 2002
Unlike Certificate Manager and Registration Manager, no policy plug-in modules
are provided for the Data Recovery Manager. If you have implemented any custom
policy modules for the Data Recovery Manager’s key archival process, you should
make sure that they are configured properly. For details on configuring policies for
a subsystem, see “Configuring Policy Rules for a Subsystem” on page 569.
Step 2. Set Up the Key Recovery Process
Before proceeding with this section, you should have read “Key Recovery Process”
on page 721. In particular, you should be familiar with how the key archival
process works. If you are not, see “How Agent-Initiated Key Recovery Works” on
page 724.
The Data Recovery Manager supports agent-initiated key recovery process, in
which end users’ encryption private keys are recovered by designated key
recovery agents. This section explains how to set up the key recovery process.
To set up agent-initiated key recovery process, follow these steps:
•
Step A. Verify the m of n Scheme
•
Step B. Facilitate the Key Recovery Agents to Change the Passwords
•
Step C. Determine the Authorization Mode for Key Recovery
•
Step D. Customize the Key Recovery Form
•
Step E. Configure Key Recovery Policies
Step A. Verify the m of n Scheme
During the installation of the Data Recovery Manager, you were asked to specify
the total number of key recovery agents (a minimum of one) and the number of
agents (of this total) required to authorize a key recovery operation. This
combination is called m of n scheme. For more information about this, see “Key
Recovery Agent Scheme” on page 727.
Verify that the current m of n scheme is appropriate for your PKI setup. If it isn’t,
change the scheme following the instructions in “Changing the Key Recovery
Agent Scheme” on page 727.
Summary of Contents for NETSCAPE DIRECTORY SERVER 6.01
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 01 May 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide May 2002...