Escrow Users
Prerequisites
Access Level:
Super-Admin
Permission Requirements
- . Basic Key Escrow
- Escrow own key
- Check if own key is escrowed
- . Key Escrow Administration
- View all escrowed keys in the system
- List escrow recovery keys
- Delete escrowed keys
- View Escrow groups
- View Escrow users
- Escrow public key
- View history of all Sitekey-authorized Escrow actions
View Escrow Users
- Go to the Management icon in the top left taskbar.
- Navigate to the Escrow section.
- Click the Escrow Users in the left panel.
- View a list of all escrow users in the system.
Only users with Admin or Super-Admin roles can view escrow users.
Create a New Escrow User Account
The escrow user registers their own account through the Connect Application, selecting the Escrow category and the escrow group you assigned them. See Get Started for the full procedure.
Tell them which escrow group they belong to before they start. It is the first thing the wizard asks, and they cannot proceed without it.
Once they have registered, activate the account as described below.
Delegate Escrow Permissions
Escrow permissions are granted through a user's permission profile, and are separate from the escrow accounts themselves. This is how an administrator gets visibility into escrow without becoming an escrow user.
- Log in with an Admin or Super-Admin role.
- Go to Management in the top toolbar.
- Select the Users section.
- Select Users.
- Find and select the admin user you are delegating to.
- Click the Open Full Menu three-dot button in the top right panel.
- Select Open Overlay.
- In the overlay, select the Profile & Permissions card in the left panel.
- Go to the Basic Key Escrow and Key Escrow Administration sections.
- Set the permissions. The recommended set is:
- Escrow own key
- Check if own key is escrowed
- View all escrowed keys in the system
- List escrow recovery key
- Delete escrowed keys — leave unchecked
- View escrowed keys
- View Escrow groups
- View Escrow users
- Escrow public key
- View history of all site-key-authorized escrow actions
- Click Save in the top right panel.
Delete escrowed keys is the one permission to withhold. Deleting an escrowed key removes the only recovery path for that user's data. Reserve it for Super-Admins.
Only Admins and Super-Admins should manage escrow permissions at all.
Activate a New Escrow User
- Upon escrow account registration, each escrow user receives a private-public key pair.
- Users may download keys with the default name or give each key a custom name.
To Escrow User
- Send your escrow public key to the Site-key Admin.
- Optionally, ask about your escrow group.
- Wait to receive your signed escrow key request from a Super-Admin.
To Site-key Admin
- Open Connect Application.
- Select your deployment card.
- In the login window, select Site-key category.
- Click Load key in the login page.
- In the pop-up, select your site-key file from your local machine.
- Click Open to import.
- Enter your account password.
- Click Login.
- In the new window, in the top left corner card, click Import Certificates.
- In the pop-up, drag-and-drop the escrow user's public key.
- Tick the Sign box.
- Enter your account password.
- Click Download to download the signed request locally.
- Send the signed request to a Super-Admin.
To Super-Admin
- Download the signed escrow key request from the Site-key Admin.
- Go to the Management icon in the top left taskbar.
- Navigate to the Escrow section.
- Click the Escrow Certificates in the left panel.
- Click the Execute signed certificates button in the top right panel.
- In the pop-up, click Browse Files.
- Select the signed escrow key request file from your local machine and click Open.
- To execute, click Apply.
- Send the signed escrow key request file back to the escrow user.
To Escrow User
- Open Connect Application.
- Select your deployment card.
- In the login window, select Escrow category.
- Click Load key in the login page.
- Open the signed escrow key file from the Super-Admin locally.
- Enter your account password.
- Click Login.
Edit an Existing Escrow User
To Escrow User
- Send your escrow public key to the Site-key Admin.
- Optionally, ask about your escrow group.
- Wait for your signed escrow key request from a Super-Admin.
To Site-key Admin
- Open Connect Application.
- Select your deployment card.
- In the login window, select Site-key category.
- Click Load key in the login page.
- In the pop-up, select your site-key file from your local machine.
- Click Open to import.
- Enter your account password.
- Click Login.
- In the new window, in the top left corner card, click Import Certificates.
- In the pop-up, drag-and-drop the escrow user's public key.
- Click the Edit button in the top left card.
- In the pop-up, update the escrow user metadata.
- Click Save.
- Tick the Sign box in the top left card.
- Enter your account password.
- Click Download to download the signed request locally.
- Send the signed request to a Super-Admin.
To Super-Admin
- Download the signed escrow key request from the Site-key Admin.
- Go to the Management icon in the top left taskbar.
- Navigate to the Escrow section.
- Click the Escrow Certificates in the left panel.
- Click the Execute signed certificates button in the top right panel.
- In the pop-up, click Browse Files.
- Select the signed escrow key request file from your local machine and click Open.
- To execute, click Apply.
- Send the signed escrow key request file back to the escrow user.
To Escrow User
- Open Connect Application.
- Select your deployment card.
- In the login window, select Escrow category.
- Click Load key in the login page.
- Open the signed escrow key file from the Super-Admin locally.
- Enter your account password.
- Click Login.
The escrow user must log in using the updated public key file containing the edits. No other public key is accepted.
Delete an Existing Escrow User
To Super-Admin
- Go to the Management icon in the top left taskbar.
- Navigate to the Escrow section.
- Click the Escrow Users in the left panel.
- Select the escrow user for whom you want to create a deletion request.
- Click the Create deletion request button in the top right panel.
- Select the destination folder for the deletion request on your local machine.
- Click Save.
- Send the deletion request to the Site-key Admin.
To Site-key Admin
- Download the escrow user deletion request from the Super-Admin.
- Open Connect Application.
- Select your deployment card.
- In the login window, select Site-key category.
- Click Load key in the login page.
- Open your site-key file from your local machine.
- Enter your account password.
- Click Login.
- In the new window, in the top left corner card, click Import Certificates.
- In the pop-up, drag-and-drop the escrow user's deletion request file.
- Click the Delete button in the top left card.
- In the pop-up, click Delete to proceed.
- Tick the Sign box.
- Enter your account password.
- Click Download to download the signed escrow user deletion request locally.
- Send the signed escrow user deletion request back to the Super-Admin.
To Super-Admin
- Download the signed escrow user deletion request from the Site-key Admin.
- Go to the Management icon in the top left taskbar.
- Navigate to the Escrow section.
- Click the Escrow Certificates in the left panel.
- Click the Execute signed certificates button in the top right panel.
- In the pop-up, click Browse Files.
- Select the signed escrow user deletion request file from your local machine and click Open.
- To execute, click Apply.
The deletion request includes the Request Type, User ID, Name, and Email. In the backend, the signed certificate serves as an order to remove an escrow user. The Site-key Admin must coordinate with the Super-Admin to add or remove escrow users. Only signed orders from the Site-key Admin can create, edit, or delete escrow users.
Recover a User's Private Key
Key recovery, also called de-escrowing, is the reason escrow users exist. It reverses enrollment: each escrow group contributes the key part it holds, the key parts are combined to reconstruct the Recovery Key, and the Recovery Key decrypts the user's stored private key.
Before you begin
- The user's key was enrolled in escrow. A key that was never escrowed cannot be recovered by any means, and no procedure here changes that.
- Every escrow group can produce a participating member. Any one member of a group can act for it, because all members of a group hold the same key part. A group that can field nobody stops recovery outright.
- An escrow user is available to receive the key parts and perform the reconstruction. It can be any escrow user, including one who is not a member of any contributing group.
- Your institution has a way to hand the recovered key and a new password to the user securely, outside tiCrypt.
Who does what
| Participant | Contribution |
|---|---|
| One escrow user per group | Supplies their group's key part. It does not matter which member, only that every group is represented. |
| A receiving escrow user | Collects the key parts from every group and reconstructs the Recovery Key. Any escrow user can do this once they hold every key part; they do not need to belong to a contributing group. |
| Administrator | Nothing cryptographic. Administrators can require escrow on an account, but they do not take part in recovery and cannot decrypt the result. |
How recovery proceeds
- One escrow user from each group logs in through the Escrow category of the Connect Application and shares their group's key part with the escrow user who will perform the recovery.
- Once that escrow user holds a key part from every group, the key parts combine to reconstruct the Recovery Key.
- The Recovery Key decrypts the user's stored private key.
- The recovered key is passed to the user together with a randomly generated password, through a channel outside tiCrypt. Each institution decides what channel is acceptable for this.
- The user signs in with the recovered key and that password, then sets a new password. Doing so generates a new private key and invalidates the recovered one.
Recovery needs breadth, not depth. Three members of one group cannot substitute for one member each from three groups, because those three people all hold the same key part. If a group has lost every member, the keys enrolled against that group cannot be recovered.
The step-by-step interface actions for sharing a key part are not yet documented here. If you are an escrow user being asked to take part in a recovery, your Site Key Admin will tell you what to provide. See Get Started.
Bulk Email Escrow Users
bulk-action
- Go to the Management icon in the top left taskbar.
- Navigate to the Escrow section.
- Click the Escrow Users in the left panel.
- Select the escrow user(s) you want to send a bulk email to.
- Click the Bulk Email button in the top right panel.
- In the pop-up, click Copy to copy the emails or click Download to download the emails.
- Once done, click Close.
Change the Password of an Escrow User
To Escrow User
- Open Connect Application.
- Select your deployment card.
- In the login window, select Escrow category.
- Click Load key on the login page.
- Open your escrow key file.
- Enter your password.
- Click Login.
- In the new window, select the Change password button in the top right corner.
- In the pop-up, enter the current password.
- Enter the new password and confirm it.
- Click Update.
You are prompted to log out, and your new key is downloaded. Use this new key to log in next time.