Configuring TPS Enrollment Operations
131
Parameter
Description
op.enroll.
tokenType
.keyGen.encryption.recovery.keyCompromise.scheme
Specifies encryption certificate recovery scheme for tokens whose key is compromised. The valid values include
GenerateNewKey
and
RecoverLast
.
op.enroll.
tokenType
.keyGen.encryption.recovery.keyCompromise.revokeCert
Specifies if the encryption certificate should be revoked if the token's key has been comprised. The valid values are
true|false
.
op.enroll.
tokenType
.keyGen.encryption.recovery.keyCompromise.revokeCert.reason
Specifies what the signing certificate revocation reason should be. The default value is
0
. The valid values are as follows:
• 0 - Unspecified.
• 1 - Key compromised.
• 2 - CA key compromised.
• 3 - Affiliation changed.
• 4 - Certificate superseded.
• 5 - Cessation of operation.
• 6 - Certificate is on hold.
op.enroll.
tokenType
.keyGen.recovery.onHold.keyType.num
The number of key types for the tokens to put on hold for temporary loss reasons. The valid values are integers. The default is
2
.
op.enroll.
tokenType
.keyGen.recovery.onHold.keyType.value.
#
Specifies
keyType
. The default values are
signing|encryption
.
op.enroll.
tokenType
.keyGen.signing.recovery.onHold.scheme
The recovery scheme for signing certificates for tokens that are to be put on hold. The valid values are
GenerateNewKey
and
RecoverLast
.
op.enroll.
tokenType
.keyGen.signing.recovery.onHold.revokeCert
Specifies if the signing certificate should be revoked if the token's key has been comprised. The valid values are
true|false
.
op.enroll.
tokenType
.keyGen.signing.recovery.onHold.revokeCert.reason
Specifies what the signing certificate revocation reason should be. The default value is
0
. The valid values are as follows:
• 0 - Unspecified.
• 1 - Key compromised.
• 2 - CA key compromised.
• 3 - Affiliation changed.
• 4 - Certificate superseded.
• 5 - Cessation of operation.
• 6 - Certificate is on hold.
op.enroll.
tokenType
.keyGen.encryption.recovery.onHold.scheme
The recovery scheme for encryption certificates for tokens that are to be put on hold. The valid values are
GenerateNewKey
and
RecoverLast
.
op.enroll.
tokenType
.keyGen.encryption.recovery.onHold.revokeCert
Specifies if the encryption certificate should be revoked if the token's key has been comprised. The valid values are
true|false
.
op.enroll.
tokenType
.keyGen.encryption.recovery.onHold.revokeCert.reason
Specifies what the signing certificate revocation reason should be. The default value is
0
. The valid values are as follows:
• 0 - Unspecified.
• 1 - Key compromised.
• 2 - CA key compromised.
• 3 - Affiliation changed.
• 4 - Certificate superseded.
Summary of Contents for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Page 42: ...20 ...
Page 43: ...Part I Setting up Certificate Services ...
Page 44: ......
Page 190: ...168 ...
Page 208: ...186 ...
Page 223: ...Part II Additional Configuration to Manage CA Services ...
Page 224: ......
Page 256: ...234 ...
Page 270: ...248 ...
Page 280: ...258 ...
Page 292: ...270 ...
Page 293: ...Part III Managing the Subsystem Instances ...
Page 294: ......
Page 408: ...386 ...
Page 438: ...416 ...
Page 439: ...Part IV References ...
Page 440: ......
Page 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Page 504: ...482 ...
Page 556: ...534 ...
Page 564: ...542 ...