
Chapter 7. Token Processing System
174
Parameter
Description
• 2 - CA key compromised.
• 3 - Affiliation changed.
• 4 - Certificate superseded.
• 5 - Cessation of operation.
• 6 - Certificate is on hold.
op.enroll.
tokenType
.keyGen.encryption.recovery.keyCompromise.scheme
Specifies encryption certificate recovery scheme
for tokens whose key is compromised. The
valid values include
GenerateNewKey
and
RecoverLast
.
op.enroll.
tokenType
.keyGen.encryption.recovery.keyCompromise.revokeCert
Specifies if the encryption certificate should be
revoked if the token's key has been comprised.
The valid values are
true|false
.
op.enroll.
tokenType
.keyGen.encryption.recovery.keyCompromise.revokeCert.reason
Specifies what the signing certificate revocation
reason should be. The default value is
0
. The
valid values are as follows:
• 0 - Unspecified.
• 1 - Key compromised.
• 2 - CA key compromised.
• 3 - Affiliation changed.
• 4 - Certificate superseded.
• 5 - Cessation of operation.
• 6 - Certificate is on hold.
op.enroll.
tokenType
.keyGen.recovery.onHold.keyType.num
The number of key types for the tokens to put on
hold for temporary loss reasons. The valid values
are integers. The default is
2
.
op.enroll.
tokenType
.keyGen.recovery.onHold.keyType.value.
n
Specifies
keyType
. The default values are
signing|encryption
.
op.enroll.
tokenType
.keyGen.signing.recovery.onHold.scheme
The recovery scheme for signing certificates
for tokens that are to be put on hold. The
valid values are
GenerateNewKey
and
RecoverLast
.
op.enroll.
tokenType
.keyGen.signing.recovery.onHold.revokeCert
Specifies if the signing certificate should be
revoked if the token's key has been comprised.
The valid values are
true|false
.
op.enroll.
tokenType
.keyGen.signing.recovery.onHold.revokeCert.reason
Specifies what the signing certificate revocation
reason should be. The default value is
0
. The
valid values are as follows:
• 0 - Unspecified.
Содержание CERTIFICATE SYSTEM 7.2 - MIGRATION GUIDE
Страница 36: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Страница 144: ...124 ...
Страница 160: ...140 ...
Страница 208: ...188 ...
Страница 210: ...190 ...
Страница 256: ...236 ...
Страница 282: ...Chapter 12 Certificate Profiles 262 Parameter IssuerName_n IssuerType_n ...
Страница 285: ...Freshest CRL Extension Default 265 Parameter PointName_n PointIssuerName_n ...
Страница 335: ...Configuring Mappers 315 Figure 14 9 Selecting a New Mapper Type 6 Edit the mapper instance and click OK ...
Страница 362: ...342 ...
Страница 376: ...356 ...
Страница 436: ...416 ...
Страница 490: ...470 ...
Страница 504: ...484 ...