Red Hat CERTIFICATE SYSTEM 8.0 - ADMINISTRATION Admin Manual page 151

Hide thumbs Also See for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION:
Table of Contents

Advertisement

... card issuer information ...
op.enroll.soKey.cardmgr_instance=A0000000030000
op.enroll.soKey.issuerinfo.enable=true
op.enroll.soKey.issuerinfo.value=http://server.example.coml:7888/cgi-bin/so/index.cgi
... CA connection and profile ...
op.enroll.soKey.keyGen.encryption.ca.conn=ca1
op.enroll.soKey.keyGen.encryption.ca.profileId=caTokenUserEncryptionKeyEnrollment
op.enroll.soKey.keyGen.encryption.certAttrId=c2
op.enroll.soKey.keyGen.encryption.certId=C2
... key generation information ...
op.enroll.soKey.keyGen.encryption.cuid_label=$cuid$
op.enroll.soKey.keyGen.encryption.keySize=1024
op.enroll.soKey.keyGen.encryption.keyUsage=0
op.enroll.soKey.keyGen.encryption.keyUser=0
op.enroll.soKey.keyGen.encryption.label=encryption key for $userid$
op.enroll.soKey.keyGen.encryption.overwrite=true
... recovering lost tokens ...
op.enroll.soKey.keyGen.encryption.recovery.destroyed.revokeCert=false
op.enroll.soKey.keyGen.encryption.recovery.destroyed.revokeCert.reason=0
op.enroll.soKey.keyGen.encryption.recovery.destroyed.scheme=RecoverLast
op.enroll.soKey.keyGen.encryption.recovery.keyCompromise.revokeCert=true
op.enroll.soKey.keyGen.encryption.recovery.keyCompromise.revokeCert.reason=1
op.enroll.soKey.keyGen.encryption.recovery.keyCompromise.scheme=GenerateNewKey
op.enroll.soKey.keyGen.encryption.recovery.onHold.revokeCert=true
op.enroll.soKey.keyGen.encryption.recovery.onHold.revokeCert.reason=6
op.enroll.soKey.keyGen.encryption.recovery.onHold.scheme=GenerateNewKey
op.enroll.soKey.keyGen.encryption.revokeCert=true
... key archival information ...
op.enroll.soKey.keyGen.encryption.serverKeygen.archive=true
op.enroll.soKey.keyGen.encryption.serverKeygen.drm.conn=drm1
op.enroll.soKey.keyGen.encryption.serverKeygen.enable=true
NOTE
There are a number of other parameters which are used by the TPS and are included
in the configuration which are never to be altered from the default. For creating new
enrollment operation profiles, simply copy these parameters from an existing profile. The
list of verboten parameters is in
Never Be
Edited".
Parameter
op.enroll.tokenType.temporaryToken.tokenType The tokenType to use for temporary tokens. tokenType typically re
op.enroll.tokenType.keyGen.recovery.destroyed.keyType.num
op.enroll.tokenType.keyGen.recovery.destroyed.keyType.value.#
op.enroll.tokenType.keyGen.signing.recovery.destroyed.scheme
op.enroll.tokenType.keyGen.signing.recovery.destroyed.revokeCert
op.enroll.tokenType.keyGen.signing.recovery.destroyed.revokeCert.reason
Configuring TPS Enrollment Operations
Table 5.3, "Important Enrollment Parameters That Should
Description
should be recovered, and what format should be used.
Specifies number of keyTypes. The default value is 2.
Specifies keyType. The valid values are signing|encryption
Specifies the signing certificate recovery scheme for destroyed to
RecoverLast.
Sets whether signing certificates should be revoked. The valid va
Sets what the signing certificate revocation reason should be. The
• 0 - Unspecified.
129

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the CERTIFICATE SYSTEM 8.0 - ADMINISTRATION and is the answer not in the manual?

Questions and answers

Table of Contents