Chapter 5. Using and Configuring the Token Management System: TPS, TKS, and Enterprise Security Client
Figure 5.1. Editing the Token Policy
The supported token policies accept values of either YES or NO. To set two policies, separate them
with a semi-colon. For example:
RE_ENROLL=NO;PIN_RESET=YES
RENEW=NO;PIN_RESET=NO
If both RE_ENROLL and RENEW are set to YES, then the renewal setting takes precedence, the token
certificates are renewed when they expire.
The default values for all three parameters can be set in the TPS's CS.cfg file in the
tokendb.defaultPolicy parameter. For example:
tokendb.defaultPolicy=RE_ENROLL=YES
NOTE
If the PIN_RESET policy is not set, then user-initiated PIN resets are allowed by default. If
the policy is present and is changed from NO to YES, then a PIN reset can be initiated by
the user once; after the PIN is reset, the policy value automatically changes back to NO.
138
Need help?
Do you have a question about the CERTIFICATE SYSTEM 8.0 - ADMINISTRATION and is the answer not in the manual?
Questions and answers