Versions Compared
Key
- This line was added.
- This line was removed.
- Formatting was changed.
The The Smart ID Certificate Manager (CM) servers, indicated by the acronym CF (Certificate Factory) comprises several sub-components that may be loaded into the same computer or distributed to several computers in order to obtain higher performance.
The following sub-components are included when option CF is selected in the installation procedure:
- Certificate Factory (CF)
- CRL Factory (CRLF)
- Publication Factory (PF)
- Key Archiving and Recovery Factory (KARF)
- Expiry Check Service (ECS)
- PIN Protection Manager (PPM)
The configuration description in this chapter is Windows-oriented.
Configuration files
Expand | ||
---|---|---|
| ||
The configuration files of CF are found in <configuration_root>/config. The main configuration file is cm.conf. The operation of CF is controlled by parameters in this well commented file. |
Prerequisites
Expand | ||
---|---|---|
| ||
Date, time and time zone settings (in the Control Panel) must be the same on both the Certificate Issuing System (CIS) and CF. |
Step-by-step instructions
Expand | ||
---|---|---|
| ||
You can configure CF to:
Options for CIS
To manually change this after the installation, modify the value of Distributed configuration
|
Expand | |||||||
---|---|---|---|---|---|---|---|
| |||||||
The configuration file may contain sensitive information, for example, the pin code for tokens, which should be protected.
This feature is not limited to cm.conf . It can also be used in kar.conf, cis.conf or da.conf.
|
Expand | ||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ||||||||||||||
You can configure CF to process certificate requests that include transport certificates. A special modifier in CF needs to be configured in order to verify the transport certificate.
|
Expand | ||
---|---|---|
| ||
The mapping of individual labels to use custom keys is described in the Technical Description where the necessary configuration changes are shown in chapter “Certificate Formats”. |
Expand | ||
---|---|---|
| ||
The configuring of the Revocation Password function is described in detail in the Technical Description. |