Chapter 8. Token Processing System
206
Parameter
Description
• 3 - Affiliation changed.
• 4 - Certificate superseded.
• 5 - Cessation of operation.
• 6 - Certificate is on hold.
op.enroll.
tokenType
.keyGen.encryption.recovery.destroyed.scheme
Specifies the encryption certificate recovery
scheme for destroyed tokens. The default value
is
RecoverLast
. The other possible value is
GenerateNewKey
.
op.enroll.
tokenType
.keyGen.encryption.recovery.destroyed.revokeCert
Specifies if the encryption certificate should be
revoked. The valid values are
true|false
. The
default value is
true
.
op.enroll.
tokenType
.keyGen.encryption.recovery.destroyed.revokeCert.reason
op.enroll.
tokenType
.keyGen.encryption.recovery.destroyed.revokeCert.reason
Specifies what the encryption certificate
revocation reason should be. The default value is
0
. The valid values are as follows:
• 0 - Unspecified.
• 1 - Key compromised.
• 2 - CA key compromised.
• 3 - Affiliation changed.
• 4 - Certificate superseded.
• 5 - Cessation of operation.
• 6 - Certificate is on hold.
op.enroll.
tokenType
.keyGen.recovery.keyCompromise.keyType.num
The number of key types for recovery for the
tokens whose keys are compromised.
op.enroll.
tokenType
.keyGen.recovery.keyCompromise.keyType.value.
n
Specifies
keyType
. The default values are
signing|encryption
.
op.enroll.
tokenType
.keyGen.signing.recovery.keyCompromise.scheme
Specifies the signing certificate recovery scheme
for tokens whose keys are compromised. The
default value is
GenerateNewKey
. The other
possible value is
RecoverLast
.
op.enroll.
tokenType
.keyGen.signing.recovery.keyCompromise.revokeCert
Specifies if the signing certificate should be
revoked if the original token's key has been
comprised. The valid values are
true|false
.
op.enroll.
tokenType
.keyGen.signing.recovery.keyCompromise.revokeCert.reason
Specifies what the signing certificate revocation
reason should be. The default value is
0
. The
valid values are as follows:
• 0 - Unspecified.
• 1 - Key compromised.
Summary of Contents for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Page 15: ...xv Index 525 ...
Page 16: ...xvi ...
Page 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Page 154: ...132 ...
Page 194: ...172 ...
Page 238: ...216 ...
Page 244: ...222 ...
Page 246: ...224 ...
Page 286: ...264 ...
Page 292: ...270 ...
Page 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Page 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Page 398: ...376 ...
Page 412: ...390 ...
Page 472: ...450 ...
Page 506: ...484 ...
Page 528: ...506 ...
Page 546: ...524 ...