Configuring Symmetric Key Changeover
195
cd /var/lib/
instance_ID
/alias/
b. Generate the new master key. For example:
tksTool -M -n new_master -d /var/lib/rhpki-tks/alias -h token_name
Generating a new master key on the TKS is described in more detail in
Section 9.2, “Using Master
Keys”
.
3. Open the TKS's configuration file.
vi /etc/rhpki-tks/CS.cfg
4. Map the new master key's identifier,
02
, to its PKCS #11 object nickname in the TKS's
CS.cfg
file by adding the
tks.mk_mappings.#02#01
and
tks.defKeySet.mk_mappings.#02#01
parameters.
tks.mk_mappings.#02#01=
token_name:nickname
tks.defKeySet.mk_mappings.#02#01=
token_name:nickname
The values for the
token_name
and
nickname
follow the parameters outlined in
Table 8.13, “TKS
Configuration Parameters for Key Update”
.
Mapping master keys in the TKS configuration is described in more detail in
Section 9.3,
“Configuring the TKS to Associate the Master Key with Its Version”
.
5. Start the TKS instance.
/etc/init.d/rhpki-tks start
6. Stop the TPS instance to edit its configuration.
/etc/init.d/rhpki-tps stop
7. Edit the TPS's configuration file.
vi /etc/rhpki-tps/CS.cfg
8. Change the
symmetricKeys.enable
and
requiredVersion
parameters to use the newly-
generated master keys on the TKS. For example:
op.
operation_type
.update.
symmetricKeys.enable=true
op.
operation_type
.userKey.update.symmetricKeys.
requiredVersion=2
• For the enroll operation, the lines begin with
op.enroll
.
• For the format operation, the lines begin with
op.format
.
Summary of Contents for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Page 15: ...xv Index 525 ...
Page 16: ...xvi ...
Page 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Page 154: ...132 ...
Page 194: ...172 ...
Page 238: ...216 ...
Page 244: ...222 ...
Page 246: ...224 ...
Page 286: ...264 ...
Page 292: ...270 ...
Page 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Page 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Page 398: ...376 ...
Page 412: ...390 ...
Page 472: ...450 ...
Page 506: ...484 ...
Page 528: ...506 ...
Page 546: ...524 ...