Free Trial

Safari Books Online is a digital library providing on-demand subscription access to thousands of learning resources.


  • Create BookmarkCreate Bookmark
  • Create Note or TagCreate Note or Tag
  • DownloadDownload
  • PrintPrint

Chapter 18. Archiving Encryption Keys

You can archive the private keys for encryption certificates at either a Windows Server 2003 or Windows Server 2008 enterprise certification authority (CA) to allow recovery of the private key if a user’s private key is lost or corrupted. This functionality is available at a Windows Server 2003 or Windows Server 2008 enterprise CA running on the Enterprise or Datacenter edition.

An organization should specify key archival and recovery in its security policy. If an organization does not specify that it allows key archival and recovery, it is almost impossible for the organization to implement key archival and recovery, because there are no guidelines for the implementation. If the security policy allows key archival, the policy must state when it is permissible for a certificate’s private key to be recovered from the CA database.


  

You are currently reading a PREVIEW of this book.

                                                                                        

Get instant access to over
$1 million worth of books and videos.

  

Start a Free Trial