PKI Setup for Key Archival and Recovery
716
Netscape Certificate Management System Installation and Setup Guide • March 2002
•
HTML forms with which your users can request dual certificates (based on
dual keys) and key recovery agents can request key recovery
The sections that follow explain these elements in detail. For step-by-step
instructions on setting up your PKI environment for key archival and recovery, see
“Configuring Key Archival and Recovery Process” on page 731.
Clients That Can Generate Dual Key Pairs
Only keys that are used exclusively for encrypting data should be archived; signing
keys in particular should never be archived. Having two copies of a signing key
would defeat the certainty with which the key identifies its owner; a second copy
could be used to impersonate the digital identity of the original key owner.
Clients that generate single key pairs use the same private key for both signing and
encrypting data, so you cannot archive and recover a private key deriving from a
single key pair. By contrast, clients that can generate dual key pairs use one private
key for encrypting data and the other for signing data. Because the encryption
private key is separate, you can archive it.
In addition to generating dual key pairs, your users’ clients must also support the
encryption key archival option in certificate requests. This option triggers the key
archival process at the time encryption private keys are generated as a part of
certificate issuance.
Netscape 6 and Netscape Communicator versions 4.7x (when used in conjunction
with Netscape Personal Security Manager) support generation of dual key-pairs.
For a brief introduction to Personal Security Manager, see page 39.
Data Recovery Manager
With the Data Recovery Manager, you can archive data encryption keys when they
are created during dual key-pair generation. You can then recover the keys if they
are lost or the key owner is unavailable.
The Data Recovery Manager can archive and recover keys only from clients that
support dual key-pair generation and the key archival option in certificate
requests.
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 6.0
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 0 March 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide March 2002...