Potential Token Operation Errors
167
The CA parameters not only specify the type of token (
userKey
) but also the type of certificate
(
encryption
). It would be possible in this case to use different CAs for signing and encryption
certificate enrollments.
The DRM parameters also specify the types of keys being generated and archived:
op.enroll.userKey.keyGen.encryption.serverKeygen.drm.conn=drm1
op.enroll.tokenKey.keyGen.encryption.serverKeygen.drm.conn=drm2
The
format
operation parameters are listed in
Table 5.1, “Format Operation Parameters”
; the
reset
operation parameters are listed in
Table 5.5, “PIN Reset Operation Parameters”
; and the
enroll
operation parameters are listed in
Table 5.2, “Enrollment Operation Parameters”
.
4. Set the mapping parameters for the different
tokenType
operations. The mapping parameters
help the TPS distinguish between the different types of tokens, assign the correct
tokenType
to
the token, and direct their requests to appropriate operation handling parameters. For example:
op.enroll.mapping.0.filter.appletMajorVersion=1
op.enroll.mapping.0.filter.appletMinorVersion=5
op.enroll.mapping.0.filter.tokenATR=
op.enroll.mapping.0.filter.tokenCUID.end=1000
op.enroll.mapping.0.filter.tokenCUID.start=4000
op.enroll.mapping.0.filter.tokenType=userKey
op.enroll.mapping.0.target.tokenType=userKey
The mapping and filter parameters are listed in
Table 5.7, “Mapping and Filters”
.
5.9. Potential Token Operation Errors
Errors that are returned by smart cards are listed in
Section 15.7, “Smart Card Error Codes”
.
These errors are specifically related to the function or behavior of the smart cards themselves, not
necessarily the TPS or token management system in Certificate System.
When managing the TPS itself, it is important to know that token operations can cause a large
number of unindexed searches to be returned in the instance's internal Directory Server logs. (An
unindexed search shows up in Red Hat Directory Server access logs as
notes=U
.) Unindexed
searches are resource-intensive and can affect performance for the Directory Server. However,
many of the unindexed searches returned for Certificate System token operations are improperly
labeled index searches when they are really indexed VLV searches. The remainder of the unindexed
searches still had very low etimes for the searches and should not significantly affect Certificate
System performance.
Summary of Contents for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Page 42: ...20 ...
Page 43: ...Part I Setting up Certificate Services ...
Page 44: ......
Page 190: ...168 ...
Page 208: ...186 ...
Page 223: ...Part II Additional Configuration to Manage CA Services ...
Page 224: ......
Page 256: ...234 ...
Page 270: ...248 ...
Page 280: ...258 ...
Page 292: ...270 ...
Page 293: ...Part III Managing the Subsystem Instances ...
Page 294: ......
Page 408: ...386 ...
Page 438: ...416 ...
Page 439: ...Part IV References ...
Page 440: ......
Page 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Page 504: ...482 ...
Page 556: ...534 ...
Page 564: ...542 ...