Enrolling Smart Cards Through The Enterprise Security Client - Red Hat CERTIFICATE SYSTEM 7.3 - ADMINISTRATION Administration Manual

Hide thumbs Also See for CERTIFICATE SYSTEM 7.3 - ADMINISTRATION:
Table of Contents

Advertisement

card. Similarly, an old applet can be replaced with a new applet. Any keys or certificates created or
managed with the old applet are destroyed.
To upgrade the applet in the TPS, put the new applet in the applet directory, and set the
update.applet.enable parameter in the CS.cfg file to true. For example, to update the applet
when enrolling a smart card of the type userKey, the parameters would be the following:
op.enroll.userKey.update.applet.enable=true
op.enroll.userKey.update.applet.emptyToken.enable=false
op.enroll.userKey.update.applet.requiredVersion=1.3.4255CC01
op.enroll.userKey.update.applet.directory=/usr/share/rhpki/tps/applets
op.enroll.userKey.update.applet.encryption=true
If a smart card only has the card manager, then the card manager capability must be enabled by
editing the following parameter:
op.operation.key_type.update.applet.emptyToken.enable=true
NOTE
If the filename set in the update.applet.requiredVersion parameter contains
any alphabetic characters, then all of these alphabetic characters must always
be uppercase letters; this applies to the actual name of the file, as well as the
update.applet.requiredVersion parameter.
The TPS queries the applet version on the smart card before trying to execute any operations.
If the update feature is enabled and the applet version from the client is different from the one
specified by the update.applet.requiredVersion parameter, the TPS updates the applet
automatically.
NOTE
The TPS audit log shows whether the applet update worked successfully.
The parameters to enable upgrading the applets are set in the TPS operation configurations. The
parameters for upgrading the applet during a formatting operation are in
Preferences"; the parameters for upgrading the applet when resetting the PIN are listed in
"PIN Reset Operation
Preferences"; and the parameters for upgrading the applet during an enrollment
Table 8.8, "Enrollment Operation
operation are in
8.5. Enrolling Smart Cards through the Enterprise Security
Client
There are several parameters relating to smart card certificate enrollment — such as enabling SSL
and configuring symmetric key changes — which are not configured during when the TPS is first set
up. The TPS is fully operational without any further customization, but setting these extra parameters
allows more flexibility to using the TPS with the Enterprise Security Client.

Enrolling Smart Cards through the Enterprise Security Client

Preferences".
Table 8.10, "Format Operation
Table 8.9,
187

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the CERTIFICATE SYSTEM 7.3 - ADMINISTRATION and is the answer not in the manual?

Questions and answers

Table of Contents