This feature involves having TPS request a private key from the server and have said key escrowed by the KRA. This also involves injecting this key onto the token using APDU commands.
This key will be used optionally for the encryption cert to go onto the token.
The actual serverSideKeygen feature is provided in #888, and the key injection part should be covered in #887. The same two tickets will also take care of keyRecovery feature. I think this ticket is not needed.
mark and close as "duplicate" per previous comment.
This ticket it NOT covered by #888, and #887.
The remote authority part is covered, but there turned out to be a bunch of code needed to perform an enrollment with server side key gen from the TPS side. A). Request the data from the DRM, B). Inject the private key onto the token, which as not covered by #887.
Have this feature working locally, patch is out for review.
Patch pushed tomaster.
Metadata Update from @jmagne: - Issue set to the milestone: 10.2 - 05/14 (May)
Dogtag PKI is moving from Pagure issues to GitHub issues. This means that existing or new issues will be reported and tracked through Dogtag PKI's GitHub Issue tracker.
This issue has been cloned to GitHub and is available here: https://github.com/dogtagpki/pki/issues/1453
If you want to receive further updates on the issue, please navigate to the GitHub issue and click on Subscribe button.
Subscribe
Thank you for understanding, and we apologize for any inconvenience.