A first enterprise official desires to recover an encryption certificate of a
user.
The user may be a current member of an enterprise or a former member of the enterprise.
The first enterprise official convinces a second enterprise official to designate
the encryption certificate of the user as approved for recovery, where the second
enterprise official has authorization to designate the encryption certificate as
approved for recovery. The encryption certificate is designated as approved for
recovery. The first enterprise official convinces a third enterprise official to
execute recovery of the encryption certificate. The third enterprise official has
authorization to execute recovery of the encryption certificate. The encryption
certificate is recovered by the third enterprise official and provided to the first
enterprise official.