Chapter 5. Using and Configuring the Token Management System: TPS, TKS, and Enterprise Security Client
134
Parameter
Description
op.renewal.
tokenType
.signing.certAttrId
Identifies which key on the token is used for the signing certificate.
op.renewal.
tokenType
.signing.certId
Identifies which key on the token is used for the signing certificate.
op.renewal.
tokenType
.signing.ca.profileId
The CA profile that should be used for renewing the signing certificate. The default is
caTokenUserSigningKeyRenewal
.
op.renewal.
tokenType
.signing.ca.conn
The CA connection to use. The default value is
ca1
.
op.renewal.
tokenType
.encryption.enable
Sets whether the encryption certificate renewal profile is enabled.
op.renewal.
tokenType
.encryption.certAttrId
Identifies which key on the token is used for the encryption certificate.
op.renewal.
tokenType
.encryption.certId
Identifies which key on the token is used for the encryption certificate.
op.renewal.
tokenType
.encryption.ca.profileId
The CA profile to use for renewing encryption certificates. The default value is
caTokenUserEncryptionKeyRenewal
.
op.renewal.
tokenType
.encryption.ca.conn
The CA connection to use to generate encryption certs. The default value is
ca1
.
Table 5.4. Renewal Operation Parameters
5.1.4. Configuring the PIN Reset Operation
The PIN is the password which protects the certificates and keys on the smart card. The TPS can
place two restrictions on the PIN: the maximum length and the minimum length. For example, to
require PINs to be between 6 and 12 characters, the following parameters are set:
op.pinReset.userKey.pinReset.pin.maxLen=12
op.pinReset.userKey.pinReset.pin.minLen=6
Like the formatting operation, the TPS can be configured to upload or update the applet version on
the smart card, update the symmetric key, and required LDAP authentication, as well as setting which
subsystem instances will process the operation. The
CS.cfg
file parameters for resetting the PIN are
listed in
Table 5.5, “PIN Reset Operation Parameters”
.
Parameter
Description
op.pinReset.
tokenType
.update.applet.emptyToken.enable
Specifies whether TPS should upload an applet to the token when it does not have one. The valid values are
true|false
.
op.pinReset.
tokenType
.update.applet.enable
Specifies if applet upgrade is turned on. The valid values are
true|false
.
op.pinReset.
tokenType
.update.applet.requiredVersion
The required key version.
op.pinReset.
tokenType
.update.applet.directory The local filesystem directory where the applets are located.
op.pinReset.
tokenType
.update.symmetricKeys.enable
Specifies if the key changeover feature should be enabled. The valid values are
true|false
. When enabled, TPS checks to see the key version
sent by the token matches
symmetricKeys.requiredVersion
.
op.pinReset.
tokenType
.update.symmetricKeys.requiredVersion
The required key version.
op.pinReset.
tokenType
.loginRequest.enable
Specifies if the login request should be sent to the token. This parameter enables authentication. The valid values are
true|false
.
op.pinReset.
tokenType
.pinReset.pin.minLen
The minimum number of characters for the PIN.
op.pinReset.
tokenType
.pinReset.pin.maxRetries The maximum number of times PIN authentication can be attempted on the token before the key is locked. This value is set on the token when the
PIN is set or reset.
op.pinReset.
tokenType
.pinReset.pin.maxLen
The maximum number of characters for the PIN.
op.pinReset.
tokenType
.tks.conn
The TKS connection to use.
op.pinReset.
tokenType
.auth.id
The LDAP authentication instance to use. The default value is
ldap1
.
op.pinReset.
tokenType
.auth.enable
Specifies whether to authenticate the user information. The valid values are
true|false
.
Table 5.5. PIN Reset Operation Parameters
Содержание CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Страница 1: ...Red Hat Certificate System 8 0 Admin Guide Publication date July 22 2009 updated on March 25 2010 ...
Страница 42: ...20 ...
Страница 43: ...Part I Setting up Certificate Services ...
Страница 44: ......
Страница 190: ...168 ...
Страница 208: ...186 ...
Страница 223: ...Part II Additional Configuration to Manage CA Services ...
Страница 224: ......
Страница 256: ...234 ...
Страница 270: ...248 ...
Страница 280: ...258 ...
Страница 292: ...270 ...
Страница 293: ...Part III Managing the Subsystem Instances ...
Страница 294: ......
Страница 363: ...Managing RA Users 341 5 The user details page shows the person s UID full name email address and user SSL certificate ...
Страница 408: ...386 ...
Страница 438: ...416 ...
Страница 439: ...Part IV References ...
Страница 440: ......
Страница 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Страница 504: ...482 ...
Страница 556: ...534 ...
Страница 564: ...542 ...