Searching Certificates - Red Hat CERTIFICATE SYSTEM 8 - AGENTS GUIDE Agents Manual

Using web-based agent services
Table of Contents

Advertisement

Chapter 9. TPS: Managing Token and Smart Card Operations
Changing the status of the token to anything other than active has two possible actions. If the
token is permanently taken offline (permanently lost, damaged, or terminated), then the certificates
on the token are revoked and the token is inactivated. However, if the token is temporarily lost or
inaccessible, then the token is essentially suspended, the certificates on it are inactivated, and a new
token with temporary certificates is issued.
NOTE
If a token is terminated, the physical token can be reused with new certificates.
Temporary certificates, by default, are only valid for one week. Within that time, the status on the
original token has to be finalized, in one of two ways:
• The token could be found. If the user locates the original token, the TPS agent can reactivate the
original token by changing the status to This temporarily lost token has been found. Changing
the status of the original token to active also takes the certificates off hold; when this is done, the
status of the temporary token is automatically updated and its certificates revoked.
• If the user cannot locate the original token, the TPS agent must change the status of the original
token to This temporarily lost token cannot be found. The certificates on the original token are
revoked. The status of the temporary token is updated to inactive and its certificates revoked. The
user is then permitted to enroll for a permanent token.

9.3.4. Searching Certificates

NOTE
It is possible to list the certificates for a single token by opening the token information
page and then clicking the Show Certificates button.
Certificates are recorded as attributes of the token, so the search is for the token rather than the
certificate alone.
To find all tokens, a subset of tokens, or a specific token, click the List/Search Certificates link in
the Agent Operations tab, and fill in the name of the user or the whole or partial token identification
number (CUID). The certificates search form, then, appears identical to the regular token search form.
As with searching for tokens, asterisks (*) can be used in the search fields as wildcards and leaving a
field blank returns all tokens.
There is a maximum allowed number of search results configured for the TPS Directory Server
database, so the number of entries returned is constrained by the search limit. Each results page
shows 25 records.
120

Advertisement

Table of Contents
loading

This manual is also suitable for:

Certificate system 8.0 - administration

Table of Contents