An online certificate-validation authority is often referred to as an OCSP responder.
•
Token Key Service. The Token Key Service (TKS) manages the master and transport keys required to generate and dis-
tribute keys for smart cards. The TKS provides security between tokens and the TPS because it protects the integrity of
the master key and token keys.
•
Token Processing System. The Token Processing System (TPS) acts as a registration authority for authenticating and
processing smart card enrollment requests, PIN reset requests, and formatting requests from the Enterprise Security
Client.
Three kinds of users can access Certificate System subsystems: administrators, agents, and end entities. Administrators are
responsible for the initial setup and ongoing maintenance of the subsystems. Administrators can designate users with spe-
cial privileges, agents, for each subsystem. Agents manage day-to-day interactions with end entities, which can be users or
servers and clients, and other aspects of the PKI. End entities must access a Certificate Manager subsystem to enroll for
certificates in a PKI deployment and for certificate maintenance, such as renewal or revocation.
Figure 1.1, “The Certificate System and Users” shows the ports used by administrators, agents, and end entities. All agent
and administrator interactions with Certificate System subsystems occur over HTTPS. End-entity interactions can take
place over HTTP or HTTPS.
Figure 1.1. The Certificate System and Users
2. Agent Tasks
2
Chapter 1. Agent Services
Summary of Contents for CERTIFICATE SYSTEM 7.2 - AGENT GUIDE
Page 1: ...Red Hat Certificate System Agent Guide 7 2 ...
Page 3: ......