A Look at the Token Management System
11
1.4. A Look at the Token Management System
Certificate System creates, manages, renews, and revokes certificates, as well as archiving and
recovering keys. For organizations which use smart cards, the Certificate System has a token
management system — a collection of subsystems with established relationships — to generate keys
and requests and receive certificates to be used for smart cards. These relationships are shown in
Figure 1.5, “How Certificate System Manages Smart Cards”
.
Four Certificate System subsystems are involved with managing tokens:
• The Token Processing System (TPS) interacts with smart cards to help them generate and store
keys and certificates for a specific entity, such as a user or device. Smart card operations go
through the TPS and are forwarded to the appropriate subsystem for action, such as the Certificate
Authority to generate certificates or the Data Recovery Manager to archive and recover keys.
• The Token Key Service (TKS) generates, or derives, symmetric keys used for communication
between the TPS and smart card. Each set of keys generated by the TKS is unique because they
Summary of Contents for CERTIFICATE SYSTEM 8.0 - ADMINISTRATION
Page 42: ...20 ...
Page 43: ...Part I Setting up Certificate Services ...
Page 44: ......
Page 190: ...168 ...
Page 208: ...186 ...
Page 223: ...Part II Additional Configuration to Manage CA Services ...
Page 224: ......
Page 256: ...234 ...
Page 270: ...248 ...
Page 280: ...258 ...
Page 292: ...270 ...
Page 293: ...Part III Managing the Subsystem Instances ...
Page 294: ......
Page 408: ...386 ...
Page 438: ...416 ...
Page 439: ...Part IV References ...
Page 440: ......
Page 503: ...Netscape Defined Certificate Extensions Reference 481 OID 2 16 840 1 113730 13 ...
Page 504: ...482 ...
Page 556: ...534 ...
Page 564: ...542 ...