This article is valid for Smart ID Identity Manager 24.R1 or later.

Detailed Overview Of Descriptors

The engine’s descriptors are:

Here each descriptor is described in detail, including requirements how it shall be bootstrapped.

EncryptedFields

Descriptor included in default configuration.

Correct bootstrapping is required for productive use!

Only dev- and test systems may use placeholders (e.g. created with bootstrap.zip package or the corresponding Docker container).

ConfigZipEncrypter

Descriptor included in default configuration.

Correct bootstrapping may be required for productive use, depending on the use-case.

Dev- and test systems may use placeholders (e.g. created with bootstrap.zip package or the corresponding Docker container).

ConfigZipSigner

Descriptor included in default configuration.

Correct bootstrapping may be required for productive use, depending on the use-case.

Dev- and test systems may use placeholders (e.g. created with bootstrap.zip package or the corresponding Docker container).

ObjectHistorySigner

Descriptor included in default configuration.

Correct bootstrapping is required for productive use!

Only dev- and test systems may use placeholders (e.g. created with bootstrap.zip package or the corresponding Docker container).

SignEmailDescriptor

Descriptor included in default configuration.

Correct bootstrapping may be required for productive use, depending on the use-case.

Dev- and test systems may use placeholders (e.g. created with bootstrap.zip package or the corresponding Docker container).

hermodDeviceEnc

Descriptor included in default configuration.

Bootstrapping required for technical reasons, but with relaxed security requirements compared to other use-cases.

SelfServiceJWTSigner

Descriptor included in default configuration.

Correct bootstrapping is required for productive use!

Only dev- and test systems may use placeholders (e.g. created with bootstrap.zip package or the corresponding Docker container).

ContentProviderJWSSigner

Descriptor included in default configuration.

Correct bootstrapping may be required for productive use, depending on the use-case.

Dev- and test systems may use placeholders (e.g. created with bootstrap.zip package or the corresponding Docker container).

Misc Attestation Key Descriptors (att_…)

Descriptors included in default configuration.

Replacement of the default certificates is optional.

idopteAuthentication

Descriptor not present by default, can be ignored unless the Idopte middleware is used for PKI card production.

insideClientAuth

Descriptor not present by default, can be ignored unless the Idopte middleware is used for PKI card production.

Pin-Blob Decryption Descriptors

Descriptors not present by default, can be ignored unless pin-blobs from pre-personalized cards (using Personal Desktop Client / KGS) have to be decrypted.