The PGP Encryption Server (Symantec Encryption Management Server) at the core is a keyserver and will manage all the public and private keys for an organization. The Organization Key is used to sign all user keys and to encrypt server backups. As such, keys that reside on the server can be exported, including the Organization Key Pair.
This article details how to backup the Organization Key for the PGP Encryption Server.
As all backups are encrypted with the Organization Key, it is extremely important to back up the Organization Key. If the Organization Key is not backed it up, it is not possible to restore from backups encrypted to the Organization Key.
Important Note: Make special care to protect the organization key when exporting. Do not allow the Org Key to be exported without a passphrase unless absolutely necessary, and if this is done, protect it so that it does not end up in unauthorized hands.
Ignition Keys are also linked to the Org Key, so if the Ignition Key password cannot be entered, the passphrase and Org Key can unlock the system.
For more information on Ignition Keys in case a server is rebooted, see the following article:
153393 - The Ignition Key Passphrase must be entered after a PGP Encryption Server is rebooted (Symantec Encryption Management Server)
Each PGP Encryption Server is pre-configured with a unique Organization Key generated by the Setup Assistant. If different settings for this key is needed, the Organization Key can be re-generated based on new settings, however this should only be done prior to live deployment of the server or creation of user keys by the server.
The Organization Key automatically renews itself one day before its expiration date including all of the same settings.
The Organization Key can be backed up during the initial installation of the server or by exporting the key from the PGP Encryption Server interface.
To backup your Organization Key:
157080 - Pictured Installation Guide for Symantec Encryption Management Server (PGP Server)
153588 - Restore Backup files to the PGP Encryption Server (Symantec Encryption Management Server)
180749 - Upgrading PGP Encryption Server using a *.pup file (Symantec Encryption Management Server)
153318 - Restoring Encryption Management Server Backups larger than 2GB
197045 - Custom scripts are moved when upgrading to Encryption Management Server 10.5
ISFR-1907
ISFR-1906