Chapter 1. Overview
12
When an OCSP responder is set up with a Certificate Manager, and publishing is set up to the OCSP
responder, CRLs are published to the OCSP responder when they are issued or updated.
1.2.5. Token Key Service
The Token Key Service (TKS) provides secure channels for communication between smart card
tokens and a TPS instance. It creates these channels by using a pre-generated master key to derive
secret keys that are specific for each individual token enrolled through the TPS. These secure
channels allow the commands and keys sent to the smart card to be encrypted, and the shared
secrets between tokens and the TKS help the smart card validate that the privileged commands
sent to it are from the appropriate TPS. During server-side key generation, the TKS also generates
transport keys which wrap, or encrypt, the user's private keys to secure them during transit.
1.2.6. Token Processing System
The Token Processing System (TPS) is the conduit between the Enterprise Security Client, the user
interface for end users to manage their smart cards, and the other subsystems in the Certificate
System. It automatically initiates certificate enrollments with the CA and key recovery through the
DRM. It uses the TKS to generate and store master keys used to derive token-specific secret keys.
1.3. Deployment Scenarios
1.3.1. Single Certificate Manager
Some deployments require a single Certificate Manager to handle all end-entity interactions. No DRM
is necessary to provide key archival or recovery capabilities, and no OCSP is required for certificate
verification. This Certificate Manager can use a signing certificate issued by a public certificate
authority or its self-signed CA signing certificate to sign all the certificates it issues.
Содержание CERTIFICATE SYSTEM 7.3 - ADMINISTRATION
Страница 1: ...Red Hat Certificate System 7 3 Administration Guide Publication date May 2007 updated March 25 2010 ...
Страница 15: ...xv Index 525 ...
Страница 16: ...xvi ...
Страница 38: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Страница 82: ...Chapter 2 Installation and Configuration 60 rpm ev rhpki manage ...
Страница 154: ...132 ...
Страница 194: ...172 ...
Страница 238: ...216 ...
Страница 244: ...222 ...
Страница 246: ...224 ...
Страница 286: ...264 ...
Страница 292: ...270 ...
Страница 318: ...Chapter 13 Certificate Profiles 296 Parameter IssuerType_n IssuerName_n ...
Страница 321: ...Freshest CRL Extension Default 299 Parameter PointName_n PointIssuerName_n ...
Страница 371: ...Configuring Mappers 349 Figure 15 9 Selecting a New Mapper Type 6 Edit the mapper instance and click OK ...
Страница 398: ...376 ...
Страница 412: ...390 ...
Страница 472: ...450 ...
Страница 500: ...Appendix A Certificate and CRL Extensions 478 Parameter namen Table A 8 IssuerAlternativeName Configuration Parameters ...
Страница 506: ...484 ...
Страница 528: ...506 ...
Страница 546: ...524 ...