7.2. Finding and Recovering Keys

7.2. Finding and Recovering Keys

If an end user loses a private encryption key or if a key's owner is unavailable, data encrypted with that key cannot be read unless a copy of the private key was archived when the key was created. The archived key can then be recovered and used to read the data.

A DRM agent manages key recovery through the DRM agent services page. Archived keys can be searched to view the details or to initiate a key recovery. Once a key recovery is initiated, a minimum number of designated DRM agents are required to authorize the recovery.

NOTE

This section describes how to recover keys that are not stored on a smart card. For smart card key recovery, see chapter 7, "Token Processing System," in the Certificate System Administration Guide and Section 9.6, “Administrator Operations”.