Table of Migrated PKI Settings

When you use first run Reflection PKI Services Manager on a system with a Reflection for Secure IT 6.x or F-Secure server, settings are migrated from your configuration file (sshd2_config) and map files to the pki_config and pki_map files used by Reflection PKI Services Manager.

The following table summarizes how these prior versions settings are migrated.

Prior version keyword

Migrated?

Equivalent PKI Services Manager keyword

HostCA

Yes

TrustAnchor

HostCANoCRLs

Yes

TrustAnchor RevocationCheckOrder = none

HostCertificateFile

No

--

DynamicMapFile

Yes

DynamicFile

(This keyword is configured in pki_mapfile.)

ExternalMapper

Yes

Supported in map file rules by using the Extern option in the conditional expression.

ExternalMapperTimeout

Yes

ExternTimeout

(This keyword is configured in pki_mapfile.)

LDAPServers

Yes

CertServers

CRLServers

(All servers are migrated to both keywords)

LocalPKI

Yes

LocalStore

OCSPResponder

Yes

OCSPResponders

PkiOcspMode

Yes

RevocationCheckOrder

RevocationChecks

Yes

RevocationCheckOrder

RevocationCA

Yes

OcspCertificate

MapFile

Yes

MapFile

OcspMode

Yes

RevocationCheckOrder

PKI

Yes

TrustAnchor

PkiDisableCrls

Yes

RevocationCheckOrder =none

PkiIgnoreBasicConstraints

Yes

StrictMode

SocksServer

No

--