Configuring Multiple Instances for Different Functions
185
conn.ca2.keepAlive=true
conn.ca2.retryConnect=3
conn.ca2.servlet.enrollment=/ca/ee/ca/profileSubmitSSLClient
conn.ca2.servlet.revoke=/ca/subsystem/ca/doRevoke
conn.ca2.servlet.unrevoke=/ca/subsystem/ca/doUnrevoke
conn.ca2.timeout=100
3. Set up the operation parameters to use the different instances to perform the different TPS
functions.
The parameters for the different operations set the type of operation, the type of token profile, the
subsystem type, and other parameters specific to the operation and the subsystem type.
For example, the TKS subsystem connection to use for regular enrollment operations would be as
follows:
op.enroll.userKey.tks.conn=tks1
The CA configuration parameters to enroll and format that kind of token are as follows:
op.enroll.userKey.keyGen.encryption.ca.conn=ca1
op.enroll.userKey.keyGen.signing.ca.conn=ca2
op.enroll.userKeyTemporary.keyGen.auth.ca.conn=ca2
op.format.tokenKey.ca.conn=ca11
The CA parameters not only specify the type of token (
userKey
) but also the type of certificate
(
encryption
). It would be possible in this case to use different CAs for signing and encryption
certificate enrollments.
The DRM parameters also specify the types of keys being generated and archived:
op.enroll.userKey.keyGen.encryption.serverKeygen.drm.conn=drm1
op.enroll.tokenKey.keyGen.encryption.serverKeygen.drm.conn=drm2
The
format
operation parameters are listed in
Table 8.10, “Format Operation Preferences”
; the
reset
operation parameters are listed in
Table 8.9, “PIN Reset Operation Preferences”
; and the
enroll
operation parameters are listed in
Table 8.8, “Enrollment Operation Preferences”
.
4. Set the mapping parameters for the different
tokenType
operations. The mapping parameters
help the TPS distinguish between the different types of tokens, assign the correct
tokenType
to
the token, and direct their requests to appropriate operation handling parameters. For example:
op.enroll.mapping.0.filter.appletMajorVersion=1
op.enroll.mapping.0.filter.appletMinorVersion=5
op.enroll.mapping.0.filter.tokenATR=
op.enroll.mapping.0.filter.tokenCUID.end=1000
op.enroll.mapping.0.filter.tokenCUID.start=4000
op.enroll.mapping.0.filter.tokenType=userKey
op.enroll.mapping.0.target.tokenType=userKey
Содержание CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Страница 1: ...Red Hat Certificate System 7 3 Administration Guide Publication date May 2007 updated March 25 2010 ...
Страница 15: ...xv Index 525 ...
Страница 16: ...xvi ...
Страница 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Страница 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Страница 154: ...132 ...
Страница 194: ...172 ...
Страница 238: ...216 ...
Страница 244: ...222 ...
Страница 246: ...224 ...
Страница 286: ...264 ...
Страница 292: ...270 ...
Страница 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Страница 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Страница 371: ...Configuring Mappers 349 Figure 15 9 Selecting a New Mapper Type 6 Edit the mapper instance and click OK ...
Страница 398: ...376 ...
Страница 412: ...390 ...
Страница 472: ...450 ...
Страница 500: ...Appendix A Certificate and CRL Extensions 478 Parameter namen Table A 8 IssuerAlternativeName Configuration Parameters ...
Страница 506: ...484 ...
Страница 528: ...506 ...
Страница 546: ...524 ...