Configuring Server-Side Key Generation and Archival of Encryption Keys
189
</VirtualHost>
3. Restart the TPS instance.
/etc/init.d/rhpki-tps restart
4. The Enterprise Security Client needs to be configured to communicate with the TPS over SSL; this
is done by setting the
Phone Home URL
, which is the default URL the Enterprise Security Client
uses to connect to the TPS.
Resetting the Enterprise Security Client's Phone Home URL is described in more detail in
Managing Smart Cards with the Enterprise Security Client
.
a. Open the Enterprise Security Client.
/usr/lib/esc-1.0.1/esc
b. Insert a new, blank token into the machine.
Blank tokens are unformatted, so they do not have an existing Phone Home URL, and
the URL must be set manually. Formatted tokens (and tokens can be formatted by the
manufacturer or by your IT department) already have the URL set, and thus do not prompt to
set the Phone Home URL.
c. Fill in the new TPS URL with the SSL port information. For example:
http
s
://server.example.com:
7890
/cgi-bin/home/index.cgi
8.5.2. Configuring Server-Side Key Generation and Archival of
Encryption Keys
The global platform environment prevents removing private keys from the smart card. For encryption
keys, it is often necessary to back up the key material for later recovery, which means the keys
should be generated outside the smart card and then imported. The keys are generated in the DRM
subsystem, where the keys can also be archived. The TPS, TKS, and DRM must all be configured to
support server-side generation and archival for encryption keys.
To configure server-side key generation for tokens enrolled through the token management system:
1. Add the TPS to the DRM as a key recovery agent.
2. Import the DRM transport key into the TKS.
3. Configure the TPS to generate and archive keys.
8.5.2.1. Step 1: Adding the TPS as a DRM Recovery Agent
1. Open the DRM Console.
2. In the
Configuration
tab, select
Users and Groups
.
3. In the
Users
tab, click
Add
, and create the new user; give this user a name such as
TPS
Recovery Agent
. Add this user to the
Data Recovery Manager Agents
group.
Summary of Contents for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Page 15: ...xv Index 525 ...
Page 16: ...xvi ...
Page 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Page 154: ...132 ...
Page 194: ...172 ...
Page 238: ...216 ...
Page 244: ...222 ...
Page 246: ...224 ...
Page 286: ...264 ...
Page 292: ...270 ...
Page 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Page 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Page 398: ...376 ...
Page 412: ...390 ...
Page 472: ...450 ...
Page 506: ...484 ...
Page 528: ...506 ...
Page 546: ...524 ...