-
Notifications
You must be signed in to change notification settings - Fork 146
Installing KRA with Random Serial Numbers
Endi S. Dewata edited this page Feb 10, 2022
·
10 revisions
This page describes the process to install a KRA subsystem with random serial numbers.
To install KRA with random serial numbers, follow the normal KRA installation procedure, then specify the following parameter:
To use random key IDs, add the following parameters in the [KRA]
section:
pki_key_id_generator=random
The key ID length (in bits) can be specified in pki_key_id_length
parameter. By default it will be 160 bits.
To use random key request IDs, add the following parameters in the [KRA]
section:
pki_key_request_id_generator=random
The key request ID length (in bits) can be specified in pki_key_request_id_length
parameter. By default it will be 160 bits.
The keys will have random IDs, for example:
$ pki -n admin kra-key-find
The key requests will also have random IDs, for example:
$ pki -n admin kra-key-request-find
Tip
|
To find a page in the Wiki, enter the keywords in search field, press Enter, then click Wikis. |