This page contains features we’d like to see in the project. Can you help? Please check our Roadmap also.
General Requests#
Misc Features#
Better Active Directory integration
issuing certificates to servers running in Windows via Auto Enrollment Proxy
Better integration between Fortitude (mod_nss) and CS
automated certificate issuance and renewal
OS integration
automatic CA discovery
centralized policy management
Make subsystem smaller and faster
Implement a new subsystem to management CRLs, CA certificates (Trust Management Server)
Implement document signing subsystem
Implement time stamping subsystem
Provide user interface to the security domain where subsystem infomation is stored
Implement service discovery for the CA service
Provide backup and restore capability so that certificates and requests can be migrated easily
Integrate log4j into the server
Individual Server-Side PKI Subsystem Enhancement Requests#
Data Recovery Manager Features#
Need cleaner interface between CA and DRM. Potentially use XML-based protocol.
Online Certificate Status Protocol Manager Features#
Improve performance
Support SCVP
Intergrate path validation service
Token Key Service Features#
Provide management UI to manage master keys
Token Processing System Features#
Build a small TPS that has CA/TKS/TPS functionalities all in one
Implement TPS in Java
Support TPS cloning
Consolidate the token management UI and the security officer UI
Clean up the protocol between TPS and ESC
PKI Subsystem Tools Enhancement Requests#
Java Tools#
Improve startup time
Consider to provide user interfaces to some of the tools
Native Tools#
Create man pages for the native tools
Provide a set of command line utilities, that can be bundled in the base OS, that will enroll, renew certificate in Apache web servers, Machines
Individual Client-Side PKI Subsystem Enhancement Requests#
Enterprise Security Features#
Need ways to enroll a token without the backend (TPS, CA, TKS…etc)
Build end-user applications around ESC
Sign files, encrypt files
ssh to web sites