2. Agent Tasks
The designated agents for each subsystem are responsible for the everyday management of end-entity requests and other
aspects of the PKI:
•
Certificate Manager agents manage certificate requests received by the Certificate Manager subsystem, maintain and
revoke certificates as necessary, and maintain global information about certificates.
•
DRM agents initiate the recovery of lost keys and can obtain information about key service requests and archived keys.
NOTE
Recovering lost or archived key information is done automatically in smart card deployments because the TPS
server is a DRM agent. Smart cards are marked as lost in the TPS agent page, and then another smart card is later
used to recover the old encryption keys automatically during certificate enrollment.
•
Online Certificate Status Manager agents can perform tasks such as checking which CAs are currently configured to
publish their CRLs to the Online Certificate Status Manager, identifying a Certificate Manager to the Online Certific-
ate Status Manager, adding CRLs directly to the Online Certificate Status Manager, and viewing the status of OCSP
service requests submitted by OCSP-compliant clients.
•
TPS agents can view smart card enrollment and formatting activities, list tokens from the token database, edit token in-
formation, delete tokens from the token database, and mark tokens as permanently lost, temporarily lost, or damaged.
•
There is no direct TKS agent interface for TKS agents to interact with the system. However, configured TKS agents
are capable of providing the secure communications channel through the TPS server required for smart card operations
through the token management system. The allowed smart card operations are similar to those for TPS agents.
The privileged operations of an agent are performed through the Certificate System agent services pages. For a user to ac-
cess these pages, the user must have a personal SSL client certificate and have been identified as a privileged user in the
user database by the Certificate System administrator. For more information on creating privileged users, see the Certific-
ate System Administration Guide.
•
Section 2.1, “Certificate Manager Agent Services”
•
Section 2.2, “Data Recovery Manager Agent Services”
•
Section 2.3, “Online Certificate Status Manager Agent Services”
•
Section 2.4, “TPS Agent Services”
2.1. Certificate Manager Agent Services
The default entry page for Certificate Manager agent services is shown in Figure 1.2, “Certificate Manager Agent Services
Page”. Only designated Certificate Manager agents, with a valid certificate in their client software, are allowed to access
these pages.
2.1. Certificate Manager Agent
Services
3
Chapter 1. Agent Services
Summary of Contents for CERTIFICATE SYSTEM 7.2 - AGENT GUIDE
Page 1: ...Red Hat Certificate System Agent Guide 7 2 ...
Page 3: ......