System Overview
Chapter
1
Introduction to Certificate Management System
53
4.
The Data Recovery Manager signs a proof-of-archival token with its private
transport key and sends the token to the Registration Manager.
5.
The Registration Manager verifies the token and sends the certificate requests
on to the Certificate Manager.
6.
The Certificate Manager issues the signing and encryption certificates and
sends them back to the Registration Manager.
7.
The Registration Manager delivers the certificates to the end entity.
Figure 1-2
Key storage process during end-entity enrollment
Data encrypted with the storage key can be retrieved only if m of n “split keys” are
provided at the same time by m of n authorized recovery agents. By default, m and
n are 2 and 3, respectively. Both values can be changed, as long as m is less than or
equal to n.
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 6.0
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 0 March 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide March 2002...