Chapter 5. Using and Configuring the Token Management System: TPS, TKS, and Enterprise Security Client
134
Parameter
Description
op.renewal.
tokenType
.signing.certAttrId
Identifies which key on the token is used for the signing certificate.
op.renewal.
tokenType
.signing.certId
Identifies which key on the token is used for the signing certificate.
op.renewal.
tokenType
.signing.ca.profileId
The CA profile that should be used for renewing the signing certificate. The default is
caTokenUserSigningKeyRenewal
.
op.renewal.
tokenType
.signing.ca.conn
The CA connection to use. The default value is
ca1
.
op.renewal.
tokenType
.encryption.enable
Sets whether the encryption certificate renewal profile is enabled.
op.renewal.
tokenType
.encryption.certAttrId
Identifies which key on the token is used for the encryption certificate.
op.renewal.
tokenType
.encryption.certId
Identifies which key on the token is used for the encryption certificate.
op.renewal.
tokenType
.encryption.ca.profileId
The CA profile to use for renewing encryption certificates. The default value is
caTokenUserEncryptionKeyRenewal
.
op.renewal.
tokenType
.encryption.ca.conn
The CA connection to use to generate encryption certs. The default value is
ca1
.
Table 5.4. Renewal Operation Parameters
5.1.4. Configuring the PIN Reset Operation
The PIN is the password which protects the certificates and keys on the smart card. The TPS can
place two restrictions on the PIN: the maximum length and the minimum length. For example, to
require PINs to be between 6 and 12 characters, the following parameters are set:
op.pinReset.userKey.pinReset.pin.maxLen=12
op.pinReset.userKey.pinReset.pin.minLen=6
Like the formatting operation, the TPS can be configured to upload or update the applet version on
the smart card, update the symmetric key, and required LDAP authentication, as well as setting which
subsystem instances will process the operation. The
CS.cfg
file parameters for resetting the PIN are
listed in
Table 5.5, “PIN Reset Operation Parameters”
.
Parameter
Description
op.pinReset.
tokenType
.update.applet.emptyToken.enable
Specifies whether TPS should upload an applet to the token when it does not have one. The valid values are
true|false
.
op.pinReset.
tokenType
.update.applet.enable
Specifies if applet upgrade is turned on. The valid values are
true|false
.
op.pinReset.
tokenType
.update.applet.requiredVersion
The required key version.
op.pinReset.
tokenType
.update.applet.directory The local filesystem directory where the applets are located.
op.pinReset.
tokenType
.update.symmetricKeys.enable
Specifies if the key changeover feature should be enabled. The valid values are
true|false
. When enabled, TPS checks to see the key version
sent by the token matches
symmetricKeys.requiredVersion
.
op.pinReset.
tokenType
.update.symmetricKeys.requiredVersion
The required key version.
op.pinReset.
tokenType
.loginRequest.enable
Specifies if the login request should be sent to the token. This parameter enables authentication. The valid values are
true|false
.
op.pinReset.
tokenType
.pinReset.pin.minLen
The minimum number of characters for the PIN.
op.pinReset.
tokenType
.pinReset.pin.maxRetries The maximum number of times PIN authentication can be attempted on the token before the key is locked. This value is set on the token when the
PIN is set or reset.
op.pinReset.
tokenType
.pinReset.pin.maxLen
The maximum number of characters for the PIN.
op.pinReset.
tokenType
.tks.conn
The TKS connection to use.
op.pinReset.
tokenType
.auth.id
The LDAP authentication instance to use. The default value is
ldap1
.
op.pinReset.
tokenType
.auth.enable
Specifies whether to authenticate the user information. The valid values are
true|false
.
Table 5.5. PIN Reset Operation Parameters
Summary of Contents for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Page 42: ...20 ...
Page 43: ...Part I Setting up Certificate Services ...
Page 44: ......
Page 190: ...168 ...
Page 208: ...186 ...
Page 223: ...Part II Additional Configuration to Manage CA Services ...
Page 224: ......
Page 256: ...234 ...
Page 270: ...248 ...
Page 280: ...258 ...
Page 292: ...270 ...
Page 293: ...Part III Managing the Subsystem Instances ...
Page 294: ......
Page 408: ...386 ...
Page 438: ...416 ...
Page 439: ...Part IV References ...
Page 440: ......
Page 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Page 504: ...482 ...
Page 556: ...534 ...
Page 564: ...542 ...