Pre- O-- wrote:
Maybe you are missing one of those property values in the

CA declaration? Yes, that was the problem. Thanks.


# There is an option in the NewPKI system to generate the certificate on a "Hardware key". How can I set the PIN code for this smartcard?

This is independant from the PKI, you need to see with the utilities provided whith your SmartCard.


# What happens if someone has an active certificate and in
the CA (Admin) I revoke it? It won't send anything to the RA…
Actually, it kind of will; when the next CRL will be generated on the CA, it will include the revoked certificate.
Let's say that you request, on the RA, a new certificate from this CA, when the response comes back to the RA, it will include the CRL, and the previously revoked certificate will be marked as revoked in the RA.


And what happens if I revoke someone in the RA, I can't get
the certificate back from him.
Is there a way to stop a user from using his/her certificate?

That's the role of CRLs.

# Is there an option to manually allow each certification
request in the CA admin. So if the RA requests a certificate
it won't be automatically accepted just when the CA says so.
And in an option it could be blocked as well.

No, the RA Operators must be trusted, they're the most important people on the PKI...


# Can you name some (free, open-source) programs that I can
use this PKI certificate with. I know this PKI is a standard
and the certificate can be used in any PKI based
application, but I couldn’t find free software for it (There
are a bunch of expensive, although).
I would like to find programs that I can sign and encrypt
files in the Windows Explorer with this certificate.

You can use outlook or firefox to sign or encrypt emails.

--
Frédéric Giudicelli
http://www.newpki.org
_____________________________________________________________________
NewPKI                                          http://www.newpki.org
User Support Mailing List                     [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to