![Red Hat CERTIFICATE SYSTEM 7.3 - ADMINISTRATION Скачать руководство пользователя страница 224](http://html.mh-extra.com/html/red-hat/certificate-system-7-3-administration/certificate-system-7-3-administration_administration-manual_1427433224.webp)
Chapter 8. Token Processing System
202
Parameter
Description
conn.ca
n
.SSLOn
Sets if SSL needs to be turned on to connect to
the CA. This value must be
true
.
conn.ca
n
.keepAlive
Sets whether to keep the connection to the CA
alive or terminate it after every operation. The
valid values are
true|false
.
Table 8.2. CA Connection Settings
Parameter
Description
conn.tks
n
.hostport
The TKS subsystem hostname and port number.
The format is
hostname:port
. This should be the
TKS's agent port.
conn.tks
n
.clientNickname
The client certificate nickname to use. This
certificate is used by the TPS when connecting to
the TKS. This client certificate should be trusted
by the TKS, and the client should be a configured
TKS agent.
conn.tks
n
.retryConnect
The number of times the TPS tries to reconnect
to the TKS after a connection attempt fails. The
valid values are integers. For example,
3
.
conn.tks
n
.SSLOn
Sets whether SSL needs to be turned on for the
connection to the TKS. This value must be
true
.
conn.tks
n
.keepAlive
Sets whether to keep the connection to the TKS
alive or terminate it after every operation. The
valid values are
true|false
.
conn.tks
n
.serverKeygen
Sets where key generation happens. When set
to
true
, key generation happens on the server.
When set to
false
, key generation happens on
the client, or token.
conn.tks1.servlet.computeSessionKey
The servlet to compute session key for the
secure channel; for example,
/tks/agent/
tks/computeSessionKey
.
conn.tks1.servlet.createKeySetData
The servlet to create key set data; for example,
/tks/agent/tks/createKeySetData
. This
servlet is used for key upgrade.
conn.tks1.servlet.encryptData
The servlet which encrypts data with token's
KEK key; for example,
/tks/agent/tks/
encryptData
.
Table 8.3. TKS Connection Settings
Parameter
Description
conn.drm
n
.hostport
The DRM subsystem hostname and port number.
The format is
hostname:port
This should be the
DRM agent port.
conn.drm
n
.clientNickname
The client certificate nickname to use. This
certificate is used by TPS when connecting to the
DRM. This client certificate should be trusted by
Содержание CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Страница 1: ...Red Hat Certificate System 7 3 Administration Guide Publication date May 2007 updated March 25 2010 ...
Страница 15: ...xv Index 525 ...
Страница 16: ...xvi ...
Страница 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Страница 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Страница 154: ...132 ...
Страница 194: ...172 ...
Страница 238: ...216 ...
Страница 244: ...222 ...
Страница 246: ...224 ...
Страница 286: ...264 ...
Страница 292: ...270 ...
Страница 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Страница 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Страница 371: ...Configuring Mappers 349 Figure 15 9 Selecting a New Mapper Type 6 Edit the mapper instance and click OK ...
Страница 398: ...376 ...
Страница 412: ...390 ...
Страница 472: ...450 ...
Страница 500: ...Appendix A Certificate and CRL Extensions 478 Parameter namen Table A 8 IssuerAlternativeName Configuration Parameters ...
Страница 506: ...484 ...
Страница 528: ...506 ...
Страница 546: ...524 ...