pki-tks-9.0.7-1.fc16$>Tz-6c= e2Zn>>H?Hd   >`d  8  p4 @4  4 4 4 4 4444("8,9l:! >=?=@=G=4H>4I?T4X?Y?\?4]@|4^C0bDdDlDtD4uE4vFwG,4xG4HeHfHCpki-tks9.0.71.fc16Certificate System - Token Key ServiceCertificate System (CS) is an enterprise software system designed to manage enterprise Public Key Infrastructure (PKI) deployments. The Token Key Service (TKS) is an optional PKI subsystem that manages the master key(s) and the transport key(s) required to generate and distribute keys for hardware tokens. TKS provides the security between tokens and an instance of Token Processing System (TPS), where the security relies upon the relationship between the master key and the token keys. A TPS communicates with a TKS over SSL using client authentication. TKS helps establish a secure channel (signed and encrypted) between the token and the TPS, provides proof of presence of the security token during enrollment, and supports key changeover when the master key changes on the TKS. Tokens with older keys will get new token keys. Because of the sensitivity of the data that TKS manages, TKS should be set up behind the firewall with restricted access. For deployment purposes, a TKS requires the following components from the PKI Core package: * pki-setup * pki-native-tools * pki-util * pki-java-tools * pki-common * pki-selinux and can also make use of the following optional components from the PKI Core package: * pki-util-javadoc * pki-java-tools-javadoc * pki-common-javadoc * pki-silent Additionally, Certificate System requires ONE AND ONLY ONE of the following "Mutually-Exclusive" PKI Theme packages: * dogtag-pki-theme (Dogtag Certificate System deployments) * redhat-pki-theme (Red Hat Certificate System deployments)Nx86-17.phx2.fedoraproject.orgFedora ProjectFedora ProjectGPLv2Fedora ProjectSystem Environment/Daemonshttp://pki.fedoraproject.org/linuxnoarch# Attempt to update ALL old "TKS" instances to "systemd" for inst in `ls /etc/sysconfig/pki/tks`; do if [ ! -e "/etc/systemd/system/pki-tksd.target.wants/pki-tksd@${inst}.service" ]; then ln -s "/lib/systemd/system/pki-tksd@.service" \ "/etc/systemd/system/pki-tksd.target.wants/pki-tksd@${inst}.service" [ -L /var/lib/${inst}/${inst} ] && unlink /var/lib/${inst}/${inst} ln -s /usr/sbin/tomcat6-sysd /var/lib/${inst}/${inst} if [ -e /var/run/${inst}.pid ]; then kill -9 `cat /var/run/${inst}.pid` || : rm -f /var/run/${inst}.pid echo "pkicreate.systemd.servicename=pki-tksd@${inst}.service" >> \ /var/lib/${inst}/conf/CS.cfg || : /bin/systemctl daemon-reload >/dev/null 2>&1 || : /bin/systemctl restart pki-tksd@${inst}.service || : else echo "pkicreate.systemd.servicename=pki-tksd@${inst}.service" >> \ /var/lib/${inst}/conf/CS.cfg || : fi fi done /bin/systemctl daemon-reload >/dev/null 2>&1 || :if [ $1 = 0 ] ; then /bin/systemctl --no-reload disable pki-tksd.target > /dev/null 2>&1 || : /bin/systemctl stop pki-tksd.target > /dev/null 2>&1 || : fi/bin/systemctl daemon-reload >/dev/null 2>&1 || : if [ "$1" -ge "1" ] ; then /bin/systemctl try-restart pki-tksd.target >/dev/null 2>&1 || : fit=mKR."~F65 aN0}F cH(`/A큤A큤AA큤A큤AAA큤AAA큤AANNNn Nn NNnNNNNNNn Nn Nn Nn Nn Nn Nn Nn Nn Nn Nn Nn Nn Nn Nn Nn Nn Nn Nn Nn Nn Nn Nn Nn Nn Nn NNNn NNNNn Nn NNNNn Nn NNae8568cfa68c76ec91e753ca260a87976ab46b45851213eba8d89065d46593b6ff97fc6ace1b449bca45f067c9f993b2e40dc8a9d3bb13796d1af6a5d9a83b4e58bce92064223220ec1cc84242f536200a756c6a4be6c5d3e9347bf0cdbb86a2d6bf5823021651d1cb53350adcf4bb818ac77768f5cbc43898ad06af1036b00ef653abffcaf3f11cc10a8851e25792bc535fdfd2c11d700fc58e0616cb560817f08ab44ab3d23f63d1b6af48abaf492cc536b31b226b4848a83a8d82dcab973f0333a933be909484f7a111a163122d6c9fa30ef569971ad8fcb634b036159bbe727f0cd8f7005410d9a2299c1e5dd0c0d39ffce9150f36e29ffc0ab596e0fa37e5007779fca32384e3d66b229c7e3f57257c0d44489543a11c69ebf559806c8c7d143f224693e217d6d85ccd03ab86b2a7ef0833d94303b66f3084d9bc24a92a117b76f4a6e9d910fbb8baeec4ea016fbeaf2684b65e1323ff42509022594b21ec31bf26a2a67c926d91931e98a619c5e4ed8f913b4031759451d363397e0e4f804a511f3520fa95e054fe99d641cee447bccf318971a9092066411882a5873727ed767345475519c0b68cc96bd20f23cb2045c3829dcc72c67a4f1a133a7d15d459ca80eaa2644d0759807787208d887117cb5cc0ad635af8906d9ffbd6a7bf39981643da29bc41f6fd22f8c37d539c573195608a8dc6fd47f75341539b6ddbb760a2dee6aef9a244f84690b0e80d22f419f277d615a90b129483aa669128f68c20c6a9881beb5076c205b18c5872880ba55b11e3d30337994d569a1505cd9763194d865777ccfadbb81f25da44489ea9ec2c20ee8298d1874110df171da7933352c48fd0a0ed2926fbfcdca513c4ee373e590b330f00556e7b8331af3f6401db87dc2740d5e7a76227055cd0d021ce051e86d87db16a59e3606f13607dae99682e543963e4d6e9a6590caf41c1c759670c1ea70e3b6cf8c12019485db8765d448b089c45226bb2cf6dad3cdf581c3af18a90d6b911ccb66c7b2179a7a75fd1bca75eac7d894fd5cd1ea75a0ed89170c0d4d1580016ef8436ecf4e619543752303a3f673928e2839845976001deaec22af953bacd3b72fe5c49443a185a898cb6cbf062b7553903273f6089afa9f3d9192bbfb97aca8fb372af8a4d2c87ece78c5473e295a5e093e13dd43a12274d05cbab31707239f6313913a810d10ecfce642683fcb28b555c7e96759a5c921e066fa630ff7d51850e34bfb4d5c7a07736f62f4ad52e28f52632878ebd2d30964c671d9b94013309a6e10a2ff61845cfbea5f5c51f5cd387c3207a755d356e2af0279e2dd31186b49781e5b9bb2f1f11c52aebf15935dacb0949469fc495527e7a3fbce59fbe103d84323b76057e95470ac65e34d5a14c7a7fa61f14e630fee7d7f68b6c037b0c84ebf899bc63dcb6d63171e2afc11e695ab35bebc65d018b53cdf1049c02ea814bf30cc2b7fbce0da4c8b14b4c230a7bbf75f75f7b8383bff05b43bebc00c35f224b5364958dec3705b81c72ac7bfb2fdf5fe07e1b4adf2588e54720f1198b0f84ae4a186f348a40da3ebdc94d667eb164fe14473fddcf73e6d94a900625a8b34413c3644876fa6cde88138f7acfe065fef5ddd0c9c621f25a3332a7cced28b1856210547f2f8fbe0bd101388b005fdd3ebe269e5ea97d71ef514e4698e26e10c9163b08c0db1b79ce65pki-tks-9.0.7.jarrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootpki-tks-9.0.7-1.fc16.src.rpmconfig(pki-tks)pki-tks      /bin/sh/bin/sh/bin/shconfig(pki-tks)javapki-commonpki-selinuxpki-tks-themerpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)systemd-unitssystemd-unitssystemd-unitsrpmlib(PayloadIsXz)9.0.7-1.fc161:1.6.09.0.159.0.159.0.03.0.4-14.6.0-14.0-15.2-14.9.1.1N{#@Nm@Nf @NS@N@MML8LYV@KՀ@KzKoKPXKG@K&(J`@Jack Magne 9.0.7-1Matthew Harmsen 9.0.6-1Ade Lee 9.0.5-1Ade Lee 9.0.4-1Matthew Harmsen 9.0.3-1Matthew Harmsen 9.0.2-1Matthew Harmsen 9.0.1-1Matthew Harmsen 9.0.0-1Matthew Harmsen 1.3.3-1Ade Lee 1.3.2-1Matthew Harmsen 1.3.1-2Matthew Harmsen 1.3.1-1Kevin Wright 1.3.0-4Matthew Harmsen 1.3.0-3Kevin Wright 1.3.0-2Ade Lee 1.3.0-1- Bugzilla Bug #730146 - SSL handshake picks non-FIPS ciphers in FIPS mode (cfu) - Bugzilla Bug #730162 - TPS/TKS token enrollment failure in FIPS mode (hsm+NSS). (jmagne) - Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . (mharmsen) - Bugzilla Bug #699809 - Convert CS to use systemd (alee)- Bugzilla Bug #734590 - Refactor JNI libraries for Fedora 16+ . . . - Bugzilla Bug #699809 - Convert CS to use systemd (alee)- Bugzilla Bug #699809 - Convert CS to use systemd- Bugzilla Bug #712931 - CS requires too many ports to be open in the FW- Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser (jdennis) - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems (mharmsen) - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. (jmagne) - Bugzilla Bug #669226 - Remove Legacy Build System (mharmsen) - Updated release of 'jss'- Bugzilla Bug #693815 - /var/log/tomcat6/catalina.out owned by pkiuser - Bugzilla Bug #699837 - service command is not fully backwards compatible with Dogtag pki subsystems- Bugzilla Bug #690950 - Update Dogtag Packages for Fedora 15 (beta) - Bugzilla Bug #683581 - CA configuration with ECC(Default EC curve-nistp521) CA fails with 'signing operation failed' - Bugzilla Bug #684381 - CS.cfg specifies incorrect type of comments - Require "jss >= 4.2.6-15" as a build and runtime requirement- Updated Dogtag 1.3.x --> Dogtag 2.0.0 --> Dogtag 9.0.0 - Bugzilla Bug #620925 - CC: auditor needs to be able to download audit logs in the java subsystems - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of CC interface review - Bugzilla Bug #583823 - CC: Auditing issues found as result of CC - interface review - Bugzilla Bug #558100 - host challenge of the Secure Channel needs to be generated on TKS instead of TPS. - Bugzilla Bug #630121 - OCSP responder lacking option to delete or disable a CA that it serves - Bugzilla Bug #504061 - ECC: unable to install subsystems - phase 1 - Bugzilla Bug #637330 - CC feature: Key Management - provide signature verification functions (JAVA subsystems) - Bugzilla Bug #555927 - rhcs80 - AgentRequestFilter servlet and port fowarding for agent services - Bugzilla Bug #631179 - Administrator is not allowed to remove ocsp signing certificate using console - Bugzilla Bug #638242 - Installation Wizard: at SizePanel, fix selection of signature algorithm; and for ECC curves - Bugzilla Bug #529945 - (Instructions and sample only) CS 8.0 GA release -- DRM and TKS do not seem to have CRL checking enabled - Bugzilla Bug #609641 - CC: need procedure (and possibly tools) to help correctly set up CC environment - Bugzilla Bug #651916 - kra and ocsp are using incorrect ports to talk to CA and complete configuration in DonePanel - Bugzilla Bug #651977 - turn off ssl2 for java servers (server.xml) - Bugzilla Bug #489385 - references to rhpki - Bugzilla Bug #649910 - Console: an auditor or agent can be added to an administrator group. - Bugzilla Bug #632425 - Port to tomcat6 - Bugzilla Bug #638377 - Generate PKI UI components which exclude a GUI interface - Bugzilla Bug #653576 - tomcat5 does not always run filters on servlets as expected - Bugzilla Bug #642357 - CC Feature- Self-Test plugins only check for validity - Bugzilla Bug #643206 - New CMake based build system for Dogtag - Bugzilla Bug #499494 - change CA defaults to SHA2 - Bugzilla Bug #649343 - Publishing queue should recover from CA crash. - Bugzilla Bug #491183 - rhcs rfe - add rfc 4523 support for pkiUser and pkiCA, obsolete 2252 and 2256 - Bugzilla Bug #223346 - Two conflicting ACL list definitions in source repository - Bugzilla Bug #663546 - Disable the functionalities that are not exposed in the console - Bugzilla Bug #656733 - Standardize jar install location and jar names - Bugzilla Bug #661142 - Verification should fail when a revoked certificate is added - Bugzilla Bug #662127 - CC doc Error: SignedAuditLog expiration time interface is no longer available through console - Bugzilla Bug #531137 - RHCS 7.1 - Running out of Java Heap Memory During CRL Generation - Bugzilla Bug #672111 - CC doc: certServer.usrgrp.administration missing information - Bugzilla Bug #583825 - CC: Obsolete servlets to be removed from web.xml as part of the CC interface review - Bugzilla Bug #656665 - Please Update Spec File to use 'ghost' on files in /var/run and /var/lock - Bugzilla Bug #674917 - Restore identification of Tomcat-based PKI subsystem instances- Bugzilla Bug #606556 - Add known session key test to TKS self test set - Bugzilla Bug #608086 - CC: CA, OCSP, and DRM need to add more audit calls - Bugzilla Bug #527593 - More robust signature digest alg, like SHA256 instead of SHA1 for ECC - Bugzilla Bug #528236 - rhcs80 web conf wizard - cannot specify CA signing algorithm - Bugzilla Bug #533510 - tps exception, cannot start when signed audit true - Bugzilla Bug #529280 - TPS returns HTTP data without ending in 0rn per RFC 2616 - Bugzilla Bug #498299 - Should not be able to change the status manually on a token marked as permanently lost or destroyed - Bugzilla Bug #554892 - configurable frequency signed audit - Bugzilla Bug #500700 - tps log rotation - Bugzilla Bug #562893 - tps shutdown if audit logs full - Bugzilla Bug #557346 - Name Constraints Extension cant be marked critical - Bugzilla Bug #556152 - ACL changes to CA and OCSP - Bugzilla Bug #556167 - ACL changes to CA and OCSP - Bugzilla Bug #581004 - add more audit logging to the TPS - Bugzilla Bug #566517 - CC: Add client auth to OCSP publishing, and move to a client-auth port - Bugzilla Bug #565842 - Clone config throws errors - fix key_algorithm - Bugzilla Bug #581017 - enabling log signing from tps ui pages causes tps crash - Bugzilla Bug #581004 - add more audit logs - Bugzilla Bug #595871 - CC: TKS needed audit message changes - Bugzilla Bug #598752 - Common Criteria: TKS ACL analysis result. - Bugzilla Bug #598666 - Common Criteria: incorrect ACLs for signedAudit - Bugzilla Bug #504905 - Smart card renewal should load old encryption cert on the token. - Bugzilla Bug #499292 - TPS - Enrollments where keys are recovered need to do both GenerateNewKey and RecoverLast operation for encryption key. - Bugzilla Bug #498299 - fix case where no transitions available - Bugzilla Bug #595391 - session domain table to be moved to ldap - Bugzilla Bug #598643 - Common Criteria: incorrect ACLs (non-existing groups) - Bugzilla Bug #504359 - pkiconsole - Administrator Group's Description References Fedora- Bugzilla Bug 584917- Can not access CA Configuration Web UI after CA installation- Bugzilla Bug #566059 - Add 'pki-console' as a runtime dependency for CA, KRA, OCSP, and TKS . . .- Bugzilla Bug #562986 - Supply convenience symlink(s) for backwards compatibility (rename jar files as appropriate)- Removed BuildRequires: dogtag-pki-tks-ui- Corrected "|| :" scriptlet logic (see Bugzilla Bug #475895) - Bugzilla Bug #553075 - Apply "registry" logic to pki-tks . . . - Bugzilla Bug #553847 - New Package for Dogtag PKI: pki-tks- Removed 'with exceptions' from License- Bugzilla Bug #X - Packaging for Fedora Dogtag/bin/sh/bin/sh/bin/sh                                                      *                                        9.0.7-1.fc169.0.7-1.fc16  pki-tksd.target.wantspki-tks.confpki-tksd.targetpki-tksd@.servicepki-tks-9.0.7LICENSEpki-tks-9.0.7.jarpki-tks.jartksconfCS.cfgacl.ldifcatalina.policycatalina.propertiescontext.xmldatabase.ldifdb.ldifindex.ldifjk2.manifestjk2.propertiesjkconf.ant.xmljkconfig.manifestlogging.propertiesschema.ldifserver-minimal.xmlserver.xmlserverCertNick.confshm.manifesttomcat-jk2.manifesttomcat-users.xmltomcat6.confuriworkermap.propertiesweb.xmlworkers.propertiesworkers.properties.minimalworkers2.propertiesworkers2.properties.minimalsetupconfig.desktopregistry_instancewebappsROOTWEB-INFweb.xmlindex.jsptksWEB-INFclassesvelocity.propertiesweb.xmltkstks/etc/systemd/system//etc/tmpfiles.d//lib/systemd/system//usr/share/doc//usr/share/doc/pki-tks-9.0.7//usr/share/java/pki//usr/share/pki//usr/share/pki/tks//usr/share/pki/tks/conf//usr/share/pki/tks/setup//usr/share/pki/tks/webapps//usr/share/pki/tks/webapps/ROOT//usr/share/pki/tks/webapps/ROOT/WEB-INF//usr/share/pki/tks/webapps/tks//usr/share/pki/tks/webapps/tks/WEB-INF//var/lock/pki//var/run/pki/-O2drpmnoarch-redhat-linux-gnuASCII textASCII text, with very long linesXML document textXML document textdirectoryempty (Zip archive data)exported SGML document, ASCII textxz2? 7zXZ !#,v]"k%]z1.ٔL흷zKtw(w@g5RUbR0e~W+yk7t<~hړ!!$pM|c5% iFqXdq>c ! bqMvaMYzeԥrwtJ;#Q7?I,Z?0W bixL/Dgkz}{^͠<`!OdqaRzڞbc% x 'k0Fb1Ep@c=ahdrF~IT9Yyw3l + 9.*xMt<ҊZ=췫\)<)!iFB ] x)G%Yncjlr)$8r|5׌(|WM^K?Kjb>6c~h Lwxpwc*ME.Yܲ+B)od= _1#8ʱzK?asR15MfyJo> d?gD)|ME-HXW͹:OQF]0.3CRNHLTU3jh}Iإe1İjbzw;/xQ"#|Ԛ 豉 %&#TVVd#= t!}"lXV`0-I̲kG'm|Ld0=>O~Qo^RG A/EPp7GE|6 Xg쎝E5_ѿV&GmK5MKYG:֐P2dM?X{,ܴE|j~wbH3>2# Vm26Np}1QcO ]f%Bp-yxBz֚¥V]Xg#ovݝ t0>fq8% Cccҝa&S n<趔Z*1 Xt$rj`^.@w(& ne㵂=w{)2@lsY DʜLږ!$ jٯ-! QY - >cÚ4]p??d`+jdm{|'_qõ ԃ(zqڇc&7;S7?%FuHpN;p{1|e=׶LxL~Qœ?*elS7A- Ӧ{:=O O24N. (pSiulK `m@ZJߊDz[~]22T h6b1SF@ l {k4u{huRSIUf0-Vx^Iy+ȱp9P˕zn֓1= Mu7?LgkSEYٷ2DA C0&^?)m70VЏ*c|='J y/P%_:Z@?|~ٮ6mX .Y[&U1–h?Ra4ҹdZ~i"@܆5: }"*hV-\JֆlT$WC0æmEZ"Cnb@ } is/]pRN`5ZrݪD,M4Hː,_oUHejqk n]1R M $ERA?ǗLbX@2rhe 0.t.YUt-q,}$jf׍x,b4 2wVZAs&z4@O@$ژޠ< YZ