Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: 5.0.1.

Comment: This article is new for Smart ID Identity Manager 24.R1.

Remember to update the release version number before publishing externally.

Info

This article is new for Smart ID Identity Manager 245.0.R11.

Descriptor overview

The engine’s descriptors are the following:

...

Each descriptor is described in detail in the sections below, including requirements how it shall be bootstrapped.

Certain descriptors are used for optional features. If a certain feature (for example email signing) is not used in a given deployment, then you may configure the descriptor in question with a placeholder. Any PKCS#12 file containing a self-signed keypair will be sufficient in this case.

EncryptedFields

Info

Descriptor included in default configuration.

Correct bootstrapping is required for productive use.

Only dev- and test systems may use placeholders (for example created with bootstrap.zip package or the corresponding docker container).

...

Info

Descriptor included in default configuration.

Correct bootstrapping may be required for productive use, depending on the use case.

Dev- and test systems may use placeholders (for example created with bootstrap.zip package or the corresponding docker container).

...

Info

Descriptor included in default configuration.

Correct bootstrapping may be required for productive use, depending on the use case.

Dev- and test systems may use placeholders (for example created with bootstrap.zip package or the corresponding docker container).

...

Info

Descriptor included in default configuration.

Correct bootstrapping may be required for productive use, depending on the use case.

Dev- and test systems may use placeholders (for example created with bootstrap.zip package or the corresponding docker container).

...

  • Placeholder allowed only if history verification is disabled (via activitiHistoryCleanerJobTrigger.cronExpression set to a date in the distant future. See List of Identity Manager system properties and Quartz CronTrigger tutorial for more information)

    • Integrity of history signature would be as risk

    • Re-signing requires use of the batch_re-sign_history tool once the first history entry is created

    • If you plan on enabling it at a later date, it is recommended not to use a placeholder

Key requirements

...

Info

Descriptor included in default configuration.

Correct bootstrapping may be required for productive use, depending on the use case.

Dev- and test systems may use placeholders (for example created with bootstrap.zip package or the corresponding docker container).

Use case

Send signed e-mails emails from IDM

Required

When e-mail email signing is configured

Configured in the following application

...

  • Placeholders allowed only if email signing is not used

    • Email verification will fail if not issued by a trusted S/MIME CA

    • Integrity of e-mails emails sent by IDM may be at risk if placeholder key is used

...

...

Info

Descriptor included in default configuration.

Correct bootstrapping is required for productive use.

Only dev- and test systems may use placeholders (for example created with bootstrap.zip package or the corresponding docker container).

...

Authentication of Smart ID Self-Service users to the Identity Manager babackend

Configured in the following applications

...

Info

Descriptor included in default configuration.

Correct bootstrapping may be required for productive use, depending on the use case.

Dev- and test systems may use placeholders (for example created with bootstrap.zip package or the corresponding docker container).

...

Storage

...

Info

Descriptors included in default configuration.

Correct bootstrapping may be required for productive use, depending on the use case.

Replacement of the default certificates is optional.

...

  • Verify Certification Signing Requests (CSR) from Smart ID Mobile/Smart ID Desktop App.

  • Optionally limit profile provisioning with Smart ID Mobile/Smart ID Desktop App to certain devices, for example company devices. This can be done by using Mobile/Desktop apps with custom private keys and configuring the corresponding public keys into in Identity Manager (by default Identity Manager includes certificates for the built-in keys of any Mobile and Desktop App installation)

...

Info

Descriptor not present by default, can be ignored unless the Idopte middleware is used for PKI card production.

Use case

Initial handshake with Idopte client-side middleware, see Encoding using Idopte middleware in Identity Manager

Configured in the following application

...

Info

Descriptor not present by default, can be ignored skipped unless the Idopte middleware is used for PKI card production.

Use case

Authenticate to the IN Groupe Inside Server, which performs certain cryptographic operations on behalf of IDM when using the Idopte middleware (see Encoding using Idopte middleware in Identity Manager)

Configured in the following applications

...

Info

Descriptors not present by default, can be ignored skipped unless pin-blobs from pre-personalized cards (using Personal Desktop Client/KGS) have to be decrypted.

Descriptor names

Can be any descriptor listed in the pinBlobDecryptor.keyDescriptorNames property of system.properties (or its docker counterpart)

...

Decrypting pin-blobs from pre-personalized cards to for example print pin letters for them (see Encodings using Personal Desktop Client middleware in Identity Manager (section "Read encrypted PINs")

...