dogtag-pki 10.6.0-1ubuntu2 source package in Ubuntu
Changelog
dogtag-pki (10.6.0-1ubuntu2) bionic; urgency=medium * control: Add conflicts on libtomcat7-java to pki-server. -- Timo Aaltonen <email address hidden> Wed, 25 Apr 2018 10:00:08 +0300
Upload details
- Uploaded by:
- Timo Aaltonen
- Uploaded to:
- Bionic
- Original maintainer:
- Debian FreeIPA Team
- Architectures:
- any all
- Section:
- misc
- Urgency:
- Medium Urgency
See full publishing history Publishing
Series | Published | Component | Section | |
---|---|---|---|---|
Bionic | release | universe | misc |
Downloads
File | Size | SHA-256 Checksum |
---|---|---|
dogtag-pki_10.6.0.orig.tar.xz | 3.7 MiB | 360c5c42e96a3813476da52f1585bd3a66f2f1e72f9f3e3a0a7cd89ff6ad255f |
dogtag-pki_10.6.0-1ubuntu2.debian.tar.xz | 31.9 KiB | 3a6d96be5672b7ca74c4c25a755029b488d1ea2328653f95df11bf709f457ac7 |
dogtag-pki_10.6.0-1ubuntu2.dsc | 3.6 KiB | 993ce223d8bf438c56eb5a0e6270af2bd5076ade2963b7a1a0376249e6cb5e5f |
Available diffs
- diff from 10.6.0-1ubuntu1 to 10.6.0-1ubuntu2 (502 bytes)
Binary packages built by this source
- dogtag-pki: Dogtag Public Key Infrastructure (PKI) Suite
The Dogtag Public Key Infrastructure (PKI) Suite is comprised of the following
five subsystems and a client (for use by a Token Management System):
.
* Certificate Authority (CA)
* Data Recovery Manager (DRM)
* Online Certificate Status Protocol (OCSP) Manager
* Token Key Service (TKS)
* Token Processing System (TPS)
* Enterprise Security Client (ESC)
.
Additionally, it provides a console GUI application used for server and
user/group administration of CA, DRM, OCSP, and TKS, javadocs on portions
of the Dogtag API, as well as various command-line tools used to assist with
a PKI deployment.
- dogtag-pki-console-theme: No summary available for dogtag-pki-console-theme in ubuntu cosmic.
No description available for dogtag-
pki-console- theme in ubuntu cosmic.
- dogtag-pki-server-theme: Certificate System - PKI Server User Interface
This PKI Common Framework User Interface contains the Dogtag
textual and graphical user interface for the PKI Common Framework.
.
This package is used by the Dogtag Certificate System.
- libsymkey-java: Symmetric Key Java library
The Symmetric Key Java library supplies various symmetric key operations
to Java programs.
.
This package is a part of the PKI Core used by the Certificate System.
- libsymkey-jni: Symmetric Key JNI Library
The Symmetric Key Java Native Interface (JNI) package supplies various native
symmetric key operations to Java programs.
.
This package is a part of the PKI Core used by the Certificate System.
- libsymkey-jni-dbgsym: debug symbols for libsymkey-jni
- pki-base: Certificate System - PKI Framework
The PKI Framework contains the common and client libraries and utilities.
.
This package is a part of the PKI Core used by the Certificate System.
- pki-base-java: No summary available for pki-base-java in ubuntu cosmic.
No description available for pki-base-java in ubuntu cosmic.
- pki-ca: No summary available for pki-ca in ubuntu cosmic.
No description available for pki-ca in ubuntu cosmic.
- pki-console: No summary available for pki-console in ubuntu cosmic.
No description available for pki-console in ubuntu cosmic.
- pki-javadoc: No summary available for pki-javadoc in ubuntu cosmic.
No description available for pki-javadoc in ubuntu cosmic.
- pki-kra: Certificate System - Data Recovery Manager
Certificate System (CS) is an enterprise software system designed
to manage enterprise Public Key Infrastructure (PKI) deployments.
.
The Data Recovery Manager (DRM) is an optional PKI subsystem that can act
as a Key Recovery Authority (KRA). When configured in conjunction with the
Certificate Authority (CA), the DRM stores private encryption keys as part of
the certificate enrollment process. The key archival mechanism is triggered
when a user enrolls in the PKI and creates the certificate request. Using the
Certificate Request Message Format (CRMF) request format, a request is
generated for the user's private encryption key. This key is then stored in
the DRM which is configured to store keys in an encrypted format that can only
be decrypted by several agents requesting the key at one time, providing for
protection of the public encryption keys for the users in the PKI deployment.
.
Note that the DRM archives encryption keys; it does NOT archive signing keys,
since such archival would undermine non-repudiation properties of signing keys.
- pki-ocsp: Certificate System - Online Certificate Status Protocol Manager
Certificate System (CS) is an enterprise software system designed
to manage enterprise Public Key Infrastructure (PKI) deployments.
.
The Online Certificate Status Protocol (OCSP) Manager is an optional PKI
subsystem that can act as a stand-alone OCSP service. The OCSP Manager
performs the task of an online certificate validation authority by enabling
OCSP-compliant clients to do real-time verification of certificates. Note
that an online certificate-validation authority is often referred to as an
OCSP Responder.
.
Although the Certificate Authority (CA) is already configured with an
internal OCSP service. An external OCSP Responder is offered as a separate
subsystem in case the user wants the OCSP service provided outside of a
firewall while the CA resides inside of a firewall, or to take the load of
requests off of the CA.
.
The OCSP Manager can receive Certificate Revocation Lists (CRLs) from
multiple CA servers, and clients can query the OCSP Manager for the
revocation status of certificates issued by all of these CA servers.
.
When an instance of OCSP Manager is set up with an instance of CA, and
publishing is set up to this OCSP Manager, CRLs are published to it
whenever they are issued or updated.
- pki-server: Certificate System - PKI Server Framework
The PKI Server Framework is required by the following four PKI subsystems:
.
the Certificate Authority (CA),
the Data Recovery Manager (DRM),
the Online Certificate Status Protocol (OCSP) Manager, and
the Token Key Service (TKS).
.
This package is a part of the PKI Core used by the Certificate System.
The package contains scripts to create and remove PKI subsystems.
- pki-tks: Certificate System - Token Key Service
Certificate System (CS) is an enterprise software system designed
to manage enterprise Public Key Infrastructure (PKI) deployments.
.
The Token Key Service (TKS) is an optional PKI subsystem that manages the
master key(s) and the transport key(s) required to generate and distribute
keys for hardware tokens. TKS provides the security between tokens and an
instance of Token Processing System (TPS), where the security relies upon the
relationship between the master key and the token keys. A TPS communicates
with a TKS over SSL using client authentication.
.
TKS helps establish a secure channel (signed and encrypted) between the token
and the TPS, provides proof of presence of the security token during
enrollment, and supports key changeover when the master key changes on the
TKS. Tokens with older keys will get new token keys.
.
Because of the sensitivity of the data that TKS manages, TKS should be set up
behind the firewall with restricted access.
- pki-tools: Certificate System - PKI Tools
This package contains PKI executables that can be used to help make
Certificate System into a more complete and robust PKI solution.
.
This package is a part of the PKI Core used by the Certificate System.
- pki-tools-dbgsym: No summary available for pki-tools-dbgsym in ubuntu cosmic.
No description available for pki-tools-dbgsym in ubuntu cosmic.
- pki-tps: Certificate System - Token Processing System
Certificate System (CS) is an enterprise software system designed
to manage enterprise Public Key Infrastructure (PKI) deployments.
.
The Token Processing System (TPS) is an optional PKI subsystem that acts
as a Registration Authority (RA) for authenticating and processing
enrollment requests, PIN reset requests, and formatting requests from
the Enterprise Security Client (ESC).
.
TPS is designed to communicate with tokens that conform to
Global Platform's Open Platform Specification.
.
TPS communicates over SSL with various PKI backend subsystems (including
the Certificate Authority (CA), the Data Recovery Manager (DRM), and the
Token Key Service (TKS)) to fulfill the user's requests.
.
TPS also interacts with the token database, an LDAP server that stores
information about individual tokens.
- pki-tps-client: Certificate System - Token Processing System client
Certificate System (CS) is an enterprise software system designed
to manage enterprise Public Key Infrastructure (PKI) deployments.
.
The Token Processing System (TPS) is an optional PKI subsystem that acts
as a Registration Authority (RA) for authenticating and processing
enrollment requests, PIN reset requests, and formatting requests from
the Enterprise Security Client (ESC).
.
TPS is designed to communicate with tokens that conform to
Global Platform's Open Platform Specification.
.
TPS communicates over SSL with various PKI backend subsystems (including
the Certificate Authority (CA), the Data Recovery Manager (DRM), and the
Token Key Service (TKS)) to fulfill the user's requests.
.
TPS also interacts with the token database, an LDAP server that stores
information about individual tokens.
.
This client is a test tool that interacts with TPS. It is useful to test
TPS server configs without risking an actual smart card.
- pki-tps-client-dbgsym: debug symbols for pki-tps-client
- python3-pki-base: No summary available for python3-pki-base in ubuntu cosmic.
No description available for python3-pki-base in ubuntu cosmic.