Configuring the Applet Update Operation
135
5.1.5. Configuring the Applet Update Operation
The TPS communicates with an applet on the smart card. The smart cards can be manufactured with
both a card manager applet and a vendor applet or with only the card manager applet. If the cards
only have the card manager applet, the TPS can install the Certificate System applet onto the smart
card. Similarly, an old applet can be replaced with a new applet. Any keys or certificates created or
managed with the old applet are destroyed.
NOTE
The only supported card manager applet is the CoolKey applet which ships with Red Hat
Enterprise Linux 5.3.
To upgrade the applet in the TPS, put the new applet in the applet directory, and set the
update.applet.enable
parameter in the
CS.cfg
file to
true
. For example, to update the applet
when enrolling a smart card of the type
userKey
, the parameters would be the following:
op.enroll.userKey.update.applet.enable=true
op.enroll.userKey.update.applet.emptyToken.enable=false
op.enroll.userKey.update.applet.requiredVersion=1.3.44724DDE
op.enroll.userKey.update.applet.directory=/usr/share/pki/tps/applets
op.enroll.userKey.update.applet.encryption=true
If a smart card only has the card manager, then the card manager capability must be enabled by
editing the following parameter:
op.
operation.key_type
.update.applet.emptyToken.enable=true
NOTE
If the filename set in the
update.applet.requiredVersion
parameter contains
any
alphabetic characters, then all of these alphabetic characters must always
be uppercase letters; this applies to the actual name of the file, as well as the
update.applet.requiredVersion
parameter.
The TPS queries the applet version on the smart card before trying to execute any operations.
If the update feature is enabled and the applet version from the client is different from the one
specified by the
update.applet.requiredVersion
parameter, the TPS updates the applet
automatically.
NOTE
The TPS audit log shows whether the applet update worked successfully.
The parameters to enable upgrading the applets are set in the TPS operation configurations. The
parameters for upgrading the applet during a formatting operation are in
Table 5.1, “Format Operation
Parameters”
; the parameters for upgrading the applet when resetting the PIN are listed in
Table 5.5,
“PIN Reset Operation Parameters”
; and the parameters for upgrading the applet during an enrollment
operation are in
Table 5.2, “Enrollment Operation Parameters”
.
Summary of Contents for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Page 42: ...20 ...
Page 43: ...Part I Setting up Certificate Services ...
Page 44: ......
Page 190: ...168 ...
Page 208: ...186 ...
Page 223: ...Part II Additional Configuration to Manage CA Services ...
Page 224: ......
Page 256: ...234 ...
Page 270: ...248 ...
Page 280: ...258 ...
Page 292: ...270 ...
Page 293: ...Part III Managing the Subsystem Instances ...
Page 294: ......
Page 408: ...386 ...
Page 438: ...416 ...
Page 439: ...Part IV References ...
Page 440: ......
Page 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Page 504: ...482 ...
Page 556: ...534 ...
Page 564: ...542 ...