Chapter 5.
127
Using and Configuring the Token
Management System: TPS, TKS, and
Enterprise Security Client
This chapter gives an overview of using hardware security modules, also called
HSMs
or
tokens
, to
generate and store Certificate System instance certificates and keys. This chapter includes installation
and usage considerations for supported HSMs, describes different tasks for managing tokens, and
contains other information for using hardware tokens with Certificate System.
5.1. Configuring TPS Smart Card Operations
The way that the TPS is configured affects how smart card operations are handled, both coming in
from the Enterprise Security Client and going between the CA and TPS, depending on the nature of
the operation.
There are four operations that are performed through the TPS:
• Formatting the smart card
• Enrolling the smart card (requesting and installing certificates on the card) and renewing certificates
on the card
• Changing the password (PIN) on the smart card
• Upgrading the applet version on the smart card
Each of these operations is configured in the TPS instance's
CS.cfg
file, similar to a CA enrollment
profile.
5.1.1. Configuring Format Operations
When the TPS is contacted by a smart card for a format operation, there are several different
operations the TPS can perform, depending on the status of the smart card.
• Whether an empty token should be rejected or have the required applet (card format) uploaded, so it
is made usable.
• Whether a smart card with an outdated applet should be upgraded and, if so, which version of
applet to upload.
• Whether a smart card with outdated keys should be updated with new symmetric keys. Keys can
become outdated if the TKS had a master key changeover.
• Whether to revoke the certificates associated with the token.
For example, to configure the TPS to reject a smart card without an applet, to update a smart card
with new symmetric keys, and to revoke certificates associated with the smart card, the following
parameters are set:
op.format.tokenKey.update.applet.emptyToken.enable=true
op.format.tokenKey.update.symmetricKeys.enable=true
Содержание CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Страница 1: ...Red Hat Certificate System 8 0 Admin Guide Publication date July 22 2009 updated on March 25 2010 ...
Страница 42: ...20 ...
Страница 43: ...Part I Setting up Certificate Services ...
Страница 44: ......
Страница 190: ...168 ...
Страница 208: ...186 ...
Страница 223: ...Part II Additional Configuration to Manage CA Services ...
Страница 224: ......
Страница 256: ...234 ...
Страница 270: ...248 ...
Страница 280: ...258 ...
Страница 292: ...270 ...
Страница 293: ...Part III Managing the Subsystem Instances ...
Страница 294: ......
Страница 363: ...Managing RA Users 341 5 The user details page shows the person s UID full name email address and user SSL certificate ...
Страница 408: ...386 ...
Страница 438: ...416 ...
Страница 439: ...Part IV References ...
Страница 440: ......
Страница 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Страница 504: ...482 ...
Страница 556: ...534 ...
Страница 564: ...542 ...