Key Recovery Process
726
Netscape Certificate Management System Installation and Setup Guide • March 2002
3.
If the request passes all the policy rules, the Data Recovery Manager sends a
confirmation HTML page to the web browser the agent used. If the request
fails any of the policy checks, the server logs an appropriate error message.
The confirmation page contains information and input sections:
❍
The information section includes the user’s information.
❍
The input section includes fields for entering the user’s certificate
corresponding to the key that needs to be recovered, the password for the
PKCS #12 package, and key recovery agents’ passwords.
The Data Recovery Manager uses the certificate to construct the
PKCS #12 package (which includes the user’s encryption private key and
corresponding certificate), the PKCS #12 password to encrypt the PKCS
#12 package, and key recovery agents’ passwords to construct the PIN
required to unlock its key repository.
4.
The key recovery agents verify the information in the confirmation page and
enter the certificate in MIME-64 format, the password for the PKCS #12
package, and their individual identifiers and passwords. The Data Recovery
Manager agent submits the page to the Data Recovery Manager.
5.
The Data Recovery Manager matches the key recovery agent information with
its m of n scheme (see “Key Recovery Agent Scheme” on page 727). After
verifying that the required number of recovery agents entered their passwords,
the server uses the agents’ passwords to construct the PIN required to access
the private key repository.
6.
The Data Recovery Manager then retrieves the user's private key from its key
repository and decrypts it by using the private component of the storage key
pair.
7.
The Data Recovery Manager packages the user's certificate and the
corresponding private key as a PKCS #12 package and encrypts it with the
PKCS #12 password provided by the recovery agent. It then delivers the
package to the client the recovery agent used to initiate the key recovery
process, and prompts the agent to store the encrypted package. The agent may
choose to store the package in the local file system of the client machine (only if
it has restricted access) or on a floppy diskette.
The recovery agent can then send the encrypted PKCS #12 package and the
corresponding password to an individual by any secure, out-of-band means.
Summary of Contents for NETSCAPE MANAGEMENT SYSTEM 6.0
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 0 March 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide March 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide March 2002...