Installing a Standalone Data Recovery ManagerChapter 6 Data Recovery Manager 217By default, the Data Recovery Manager uses a single SSL server certificate forauthentication purposes. However, you can request and install additional SSLserver certificates for the Data Recovery Manager. For example, you can configurethe Data Recovery Manager to use separate server certificates for authenticating toNetscape Console, the end entity services interface, and the Data RecoveryManager Agent Services interface. For instructions, see “Configuring the Server toUse Separate SSL Server Certificates” on page 321.TokensYou choose either the internal token (if you plan to use the internal/softwaretoken) or an external token to store the signing certificate and key pair and the SSLsigning certificate and key pair.If you are using an external token, you will need to install it before you run theInstallation Wizard. In the wizard, you can select from a list of already installedand available tokens. For example, SmartCard. For installation instructions, see“External Token” on page 316.Internal DatabaseEach subsystem uses an internal database to store information (such as certificatesand certificate requests) used by the subsystem you will be installing in this CMSinstance. By default, a separate internal database is created for each subsystem youconfigure. You can choose to use the same internal database for more than onesubsystem by specifying this when running the installation wizard to configurethat subsystem. You should carefully consider whether you want to store thisinformation in a separate internal database for each subsystem or use one internaldatabase for all subsystems installed on the host.It’s recommended that you do not use this Directory Server instance for any otherpurposes; the directory schema will be configured for storing CMS data.Key Type and LengthIf you wish, you can import the signing key and certificate used in a previousversion of CMS installation rather than generating a new signing key pair. Forinformation on how to do this, check the migration information.