pki-tps - Certificate System - Token Processing Service

Property Value
Distribution Fedora 27
Repository Fedora Updates x86_64
Package filename pki-tps-10.5.12-1.fc27.x86_64.rpm
Package name pki-tps
Package version 10.5.12
Package release 1.fc27
Package architecture x86_64
Package type rpm
Homepage -
License -
Maintainer -
Download size 744.21 KB
Installed size 1.79 MB
The Token Processing System (TPS) is an optional PKI subsystem that acts
as a Registration Authority (RA) for authenticating and processing
enrollment requests, PIN reset requests, and formatting requests from
the Enterprise Security Client (ESC).
TPS is designed to communicate with tokens that conform to
Global Platform's Open Platform Specification.
TPS communicates over SSL with various PKI backend subsystems (including
the Certificate Authority (CA), the Key Recovery Authority (KRA), and the
Token Key Service (TKS)) to fulfill the user's requests.
TPS also interacts with the token database, an LDAP server that stores
information about individual tokens.
The utility "tpsclient" is a test tool that interacts with TPS.  This
tool is useful to test TPS server configs without risking an actual
smart card.
Certificate System (CS) is an enterprise software system designed
to manage enterprise Public Key Infrastructure (PKI) deployments.
PKI Core contains ALL top-level java-based Tomcat PKI components:
* pki-symkey
* pki-base
* pki-base-python2 (alias for pki-base)
* pki-base-python3
* pki-base-java
* pki-tools
* pki-server
* pki-ca
* pki-kra
* pki-ocsp
* pki-tks
* pki-tps
* pki-javadoc
which comprise the following corresponding PKI subsystems:
* Certificate Authority (CA)
* Key Recovery Authority (KRA)
* Online Certificate Status Protocol (OCSP) Manager
* Token Key Service (TKS)
* Token Processing Service (TPS)
Python clients need only install the pki-base package.  This
package contains the python REST client packages and the client
upgrade framework.
Java clients should install the pki-base-java package.  This package
contains the legacy and REST Java client packages.  These clients
should also consider installing the pki-tools package, which contain
native and Java-based PKI tools and utilities.
Certificate Server instances require the fundamental classes and
modules in pki-base and pki-base-java, as well as the utilities in
pki-tools.  The main server classes are in pki-server, with subsystem
specific Java classes and resources in pki-ca, pki-kra, pki-ocsp etc.
Finally, if Certificate System is being deployed as an individual or
set of standalone rather than embedded server(s)/service(s), it is
strongly recommended (though not explicitly required) to include at
least one PKI Theme package:
* dogtag-pki-theme (Dogtag Certificate System deployments)
* dogtag-pki-server-theme
* redhat-pki-server-theme (Red Hat Certificate System deployments)
* redhat-pki-server-theme
* customized pki theme (Customized Certificate System deployments)
* <customized>-pki-server-theme
NOTE:  As a convenience for standalone deployments, top-level meta
packages may be provided which bind a particular theme to
these certificate server packages.


Package Version Architecture Repository
pki-tps-10.5.12-1.fc27.i686.rpm 10.5.12 i686 Fedora Updates
pki-tps-10.4.8-5.fc27.x86_64.rpm 10.4.8 x86_64 Fedora
pki-tps-10.4.8-5.fc27.i686.rpm 10.4.8 i686 Fedora
pki-tps - - -


Name Value
java-1.8.0-openjdk-headless - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
nss-tools >= 3.28.3
openldap-clients -
pki-server = 10.5.12-1.fc27
pki-symkey = 10.5.12-1.fc27
rtld(GNU_HASH) -
systemd-units -


Name Value - -
pki-tps = 10.5.12-1.fc27
pki-tps(x86-64) = 10.5.12-1.fc27
pki-tps-client -
pki-tps-tomcat -


Name Value
pki-tps-client -
pki-tps-tomcat -


Type URL
Binary Package pki-tps-10.5.12-1.fc27.x86_64.rpm
Source Package pki-core-10.5.12-1.fc27.src.rpm

Install Howto

Install pki-tps rpm package:

# dnf install pki-tps




2018-08-13 - Dogtag Team <> 10.5.12-1
- dogtagpki Pagure Issue #2481 - ECC keys not supported for signing
audit logs (cfu)
- dogtagpki Pagure Issue #3041 -Enable all config audit events (cfu)
- dogtagpki Pagure Issue #3043 - consumer initialization failed.
Error (0) Total update succeeded (abokovoy)
- Fixed pki console configurations that involves ldap passwords leave the
plain text password in signed audit logs (cfu)
- Fixed Certificate generation happens with partial attributes in CMCRequest
file (cfu)
- Fixed Better understanding of NSS_USE_DECODED_CKA_EC_POINT for ECC (cfu)
- Fixed CMC Revocations throws exception with same reqIssuer & certissuer (cfu)
2018-08-09 - Dogtag Team <> 10.5.11-2
- freeipa Pagure Issue #7627 - ipa-replica-install --setup-kra broken
on DL0 with latest version (abokovoy)
2018-07-31 - Dogtag Team <> 10.5.11-1
- dogtagpki Pagure Issue #2915 - keyGen fails when only Identity
certificate exists (jmagne)
2018-07-02 - Dogtag Team <> 10.5.10-1
- Updated "jss" build and runtime requirements (mharmsen)
- Updated "tomcatjss" build and runtime requirements (mharmsen)
- dogtagpki Pagure Issue #2865 X500Name.directoryStringEncodingOrder
overridden by CSR encoding (cfu)
- dogtagpki Pagure Issue #2920 Part2 of SharedToken Audit (cfu)
- dogtagpki Pagure Issue #2922 IPAddressName: fix construction from
String (ftweedal)
- dogtagpki Pagure Issue #2959 Address pkispawn ECC profile overrides (cfu)
- dogtagpki Pagure Issue #2992 CMC Simple request profiles and CMCResponse
to support simple response (cfu)
- dogtagpki Pagure Issue #3003 AuditVerify failure due to line breaks (cfu)
- dogtagpki Pagure Issue #3037 CMC SharedToken SubjectDN default (cfu)
2018-06-08 - Dogtag Team <> 10.5.9-1
- dogtagpki Pagure Issue #2922 - Name Constraints: Using a Netmask
produces an odd entry in a certifcate (ftweedal)
- dogtagpki Pagure Issue #2941 - ExternalCA: Installation failed during
csr generation with ecc (rrelyea, gkapoor)
- dogtagpki Pagure Issue #2999 - Cert validation for installation with
external CA cert (edewata)
- dogtagpki Pagure Issue #3028 - CMC CRMF request results in
InvalidKeyFormatException when signing algorithm is ECC (cfu)
- dogtagpki Pagure Issue #3033 - CRMFPopClient tool - should allow
option to do no key archival (cfu)
2018-05-23 - Dogtag Team <> 10.5.8-1
- Updated "jss" build and runtime requirements (mharmsen)
- dogtagpki Pagure Issue #1576 - subsystem -> subsystem SSL handshake
issue with TLS_ECDHE_RSA_* on Thales HSM (cfu)
- dogtagpki Pagure Issue #1741 - ECDSA Certificates Generated by
Certificate System fail NIST validation test with parameter field. (cfu)
- dogtagpki Pagure Issue #2940 - [MAN] Missing Man pages for tools
CMCRequest, CMCResponse, CMCSharedToken (cfu)
- dogtagpki Pagure Issue #2992 - servlet profileSubmitCMCSimple throws
NPE (cfu)
- dogtagpki Pagure Issue #2995 - SAN in internal SSL server certificate in
pkispawn configuration step (cfu)
- dogtagpki Pagure Issue #2996 - ECC installation for non CA subsystems
needs improvement (jmagne)
- dogtagpki Pagure Issue #2997 - Token name normalization problem in
pki-server subsystem-cert-validate (edewata)
- dogtagpki Pagure Issue #3018 - CMC profiles: Some CMC profiles have
wrong input class_id (cfu)
2018-04-10 - Dogtag Team <> 10.5.7-2
- dogtagpki Pagure Issue #2940 -[MAN] Missing Man pages for tools
CMCRequest, CMCResponse, CMCSharedToken (cfu)
- dogtagpki Pagure Issue #2946 - libtps does not directly depend on libz
(build failure with nss-3.35) (ftweedal, cfu)
- dogtagpki Pagure Issue #2950 - Need ECC-specific Enrollment Profiles
for standard conformance (cfu)

See Also

Package Description
pl-7.4.2-4.fc27.i686.rpm SWI-Prolog - Edinburgh compatible Prolog compiler
pl-7.4.2-4.fc27.x86_64.rpm SWI-Prolog - Edinburgh compatible Prolog compiler
pl-compat-yap-devel-7.4.2-4.fc27.i686.rpm Development files building YAP application against SWI Prolog
pl-compat-yap-devel-7.4.2-4.fc27.x86_64.rpm Development files building YAP application against SWI Prolog
pl-devel-7.4.2-4.fc27.i686.rpm Development files for SWI Prolog
pl-devel-7.4.2-4.fc27.x86_64.rpm Development files for SWI Prolog
pl-doc-7.4.2-4.fc27.x86_64.rpm Documentation for SWI Prolog
pl-jpl-7.4.2-4.fc27.x86_64.rpm A bidirectional Prolog/Java interface for SWI Prolog
pl-odbc-7.4.2-4.fc27.x86_64.rpm SWI-Prolog ODBC interface
pl-static-7.4.2-4.fc27.i686.rpm Static library for SWI Prolog
pl-static-7.4.2-4.fc27.x86_64.rpm Static library for SWI Prolog
pl-xpce-7.4.2-4.fc27.x86_64.rpm A toolkit for developing graphical applications in Prolog
plasma-breeze-5.12.7-1.fc27.i686.rpm Artwork, styles and assets for the Breeze visual style for the Plasma Desktop
plasma-breeze-5.12.7-1.fc27.x86_64.rpm Artwork, styles and assets for the Breeze visual style for the Plasma Desktop
plasma-breeze-common-5.12.7-1.fc27.noarch.rpm Common files shared between KDE 4 and Plasma 5 versions of the Breeze style