Setting Token Types for Specified Smart Cards
139
5.4. Setting Token Types for Specified Smart Cards
The TPS can be configured to use specific token profiles to format a new smart card, based on some
attribute of the smart card, such as its answer-to-reset (ATR) message or a range of serial numbers for
the smart cards.
This is useful to manage multiple types of smart card profiles in a single deployment to determine and
assign the smart card profile automatically based on physical distribution of those cards, rather than
some software process change.
There are three steps to configuring type-specific formatting operations:
1. Configure the type-specific TPS profile, as in
Section 5.1, “Configuring TPS Smart Card
Operations”
.
2. Configure the type-specific authentication profile, as in
Section 5.7.3, “Configuring or Disabling
LDAP Authentication”
.
3. Configure the mapping filter and target, as in
Section 5.4.2, “Mapping Token Types to Smart Card
Operation Profiles”
.
5.4.1. Default Token Types
There are several default token types already configured for smart card operations, as listed in
Table 5.6, “Default Token Types”
. There are several profiles available for security officers, regular
users, and devices.
Token Type
Description
cleanToken
For operations for any blank token, without any
other applied token types.
soKey
For operations for generating keys for security
officer stations.
soCleanSOToken
For operations for blank tokens for security
officer stations.
soKeyTemporary
For operations for temporary security officer
tokens.
soCleanUserToken
For operations for blank user tokens for security
officers.
soUserKey
For operations for security officer user tokens.
tokenKey
For operations for generating keys for uses with
servers or devices.
userKey
For operations for regular user tokens.
userKeyTemporary
For operations for temporary user tokens.
Table 5.6. Default Token Types
5.4.2. Mapping Token Types to Smart Card Operation Profiles
Each type of operation contains a parameter
mapping.
#
. containing mapping IDs.
Содержание CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Страница 1: ...Red Hat Certificate System 8 0 Admin Guide Publication date July 22 2009 updated on March 25 2010 ...
Страница 42: ...20 ...
Страница 43: ...Part I Setting up Certificate Services ...
Страница 44: ......
Страница 190: ...168 ...
Страница 208: ...186 ...
Страница 223: ...Part II Additional Configuration to Manage CA Services ...
Страница 224: ......
Страница 256: ...234 ...
Страница 270: ...248 ...
Страница 280: ...258 ...
Страница 292: ...270 ...
Страница 293: ...Part III Managing the Subsystem Instances ...
Страница 294: ......
Страница 363: ...Managing RA Users 341 5 The user details page shows the person s UID full name email address and user SSL certificate ...
Страница 408: ...386 ...
Страница 438: ...416 ...
Страница 439: ...Part IV References ...
Страница 440: ......
Страница 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Страница 504: ...482 ...
Страница 556: ...534 ...
Страница 564: ...542 ...