Details
-
Type:
Epic
-
Status: Closed
-
Priority:
Blocker
-
Resolution: Fixed
-
Affects Version/s: None
-
Fix Version/s: None
-
Component/s: None
-
Labels:None
-
Epic Name:Support for delegated key pair generation
-
Issue discovered during:Another issue
-
Sprint:6.9.0 Sprint 3
Description
Delegated key pair generation
- offloads the CA service provider
- allows peer RA machines to keep escrowed keys "in house" while connected to an external CA service provider
The goal would be to allow a key pair generation (and optional escrow) to take place where this is authorized.
The RA in this case should not blindly trust the CA, so the CA could fool the RA into sending private keys upstream unless this is desired.
Attachments
Issue Links
- is blocked by
-
ECA-5286 Make CA based Key recovery possible on RA
-
- Closed
-
-
ECA-5817 RaMasterApi with outgoing upstream connection from RA
-
- Closed
-
-
ECA-5987 Make it possible to mark certificate for recovery using local key generation
-
- Closed
-
-
ECA-5954 Add system config option for local key generation
-
- Closed
-
-
ECA-5956 Encrypt keypair for key recovery using a selectable crypto token, for local key generation
-
- Closed
-
-
ECA-5957 Ability to request key recovery from RA Web
-
- Closed
-
-
ECA-5983 Document delegated key recovery
-
- Closed
-
-
ECA-6028 System test for delegated key generation
-
- Closed
-
- is related to
-
ECA-5978 RA enrollment with requestid doesn't authenticate password with reusecert = true
-
- Closed
-
-
ECA-6012 Key recovery flag not reset on rejected approval using local key generation
-
- Closed
-
-
ECA-4895 RA users will be able to request server side generated keystores
-
- Closed
-
-
ECA-6019 Add EjbcaWS support for key recovery with local key pair generation
-
- Closed
-
- relates
-
ECA-5171 EE self service: Public RA user must be able to request renewal of its certificate
-
- Open
-
-
ECA-4213 Option to explicitly set keystore password during enrollment
-
- Closed
-
-
ECA-5170 Public RA user must be able to finalize legacy enrollment with username and enrollment code
-
- Closed
-