Chapter 8. Token Processing System
208
Parameter
Description
• 1 - Key compromised.
• 2 - CA key compromised.
• 3 - Affiliation changed.
• 4 - Certificate superseded.
• 5 - Cessation of operation.
• 6 - Certificate is on hold.
op.enroll.
tokenType
.keyGen.encryption.recovery.onHold.scheme
The recovery scheme for encryption certificates
for tokens that are to be put on hold. The
valid values are
GenerateNewKey
and
RecoverLast
.
op.enroll.
tokenType
.keyGen.encryption.recovery.onHold.revokeCert
Specifies if the encryption certificate should be
revoked if the token's key has been comprised.
The valid values are
true|false
.
op.enroll.
tokenType
.keyGen.encryption.recovery.onHold.revokeCert.reason
Specifies what the signing certificate revocation
reason should be. The default value is
0
. The
valid values are as follows:
• 0 - Unspecified.
• 1 - Key compromised.
• 2 - CA key compromised.
• 3 - Affiliation changed.
• 4 - Certificate superseded.
• 5 - Cessation of operation.
• 6 - Certificate is on hold.
op.enroll.
tokenType
.keyGen.tokenName
The name of the token to use. The TPS can
substitute some special strings. For example,
if using
cuid
, the
tokenName
is substituted
with the CUID of the token; if using
uid
, the
tokenName
is substituted with the UID of the
authenticating user.
op.enroll.
tokenType
.keyGen.keyType.num
The number of keys/certificates to be generated
for the profile. The values are integers. The
default is
2
.
op.enroll.
tokenType
.keyGen.keyType.value.
n
Specifies
keyType
. The default values are
signing|encryption
.
op.enroll.
tokenType
.keyGen.signing.keySize
Specifies the key size to use for key generation.
The default is
1024
.
Do not alter these values.
• op.enroll.
tokenType
.keyGen.signing.public.keyCapabilities.encrypt
Summary of Contents for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Page 15: ...xv Index 525 ...
Page 16: ...xvi ...
Page 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Page 154: ...132 ...
Page 194: ...172 ...
Page 238: ...216 ...
Page 244: ...222 ...
Page 246: ...224 ...
Page 286: ...264 ...
Page 292: ...270 ...
Page 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Page 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Page 398: ...376 ...
Page 412: ...390 ...
Page 472: ...450 ...
Page 506: ...484 ...
Page 528: ...506 ...
Page 546: ...524 ...