pki-tks - Certificate System - Token Key Service

Property Value
Distribution Ubuntu 18.04 LTS (Bionic Beaver)
Repository Ubuntu Universe i386
Package filename pki-tks_10.6.0-1ubuntu2_all.deb
Package name pki-tks
Package version 10.6.0
Package release 1ubuntu2
Package architecture all
Package type deb
Category universe/java
License -
Maintainer Ubuntu Developers <>
Download size 68.69 KB
Installed size 305.00 KB
Certificate System (CS) is an enterprise software system designed
to manage enterprise Public Key Infrastructure (PKI) deployments.
The Token Key Service (TKS) is an optional PKI subsystem that manages the
master key(s) and the transport key(s) required to generate and distribute
keys for hardware tokens.  TKS provides the security between tokens and an
instance of Token Processing System (TPS), where the security relies upon the
relationship between the master key and the token keys.  A TPS communicates
with a TKS over SSL using client authentication.
TKS helps establish a secure channel (signed and encrypted) between the token
and the TPS, provides proof of presence of the security token during
enrollment, and supports key changeover when the master key changes on the
TKS.  Tokens with older keys will get new token keys.
Because of the sensitivity of the data that TKS manages, TKS should be set up
behind the firewall with restricted access.


Package Version Architecture Repository
pki-tks_10.6.0-1ubuntu2_all.deb 10.6.0 all Ubuntu Universe
pki-tks - - -


Name Value
libsymkey-java >= 10.6.0-1ubuntu2
pki-server >= 10.6.0-1ubuntu2


Type URL
Binary Package pki-tks_10.6.0-1ubuntu2_all.deb
Source Package dogtag-pki

Install Howto

  1. Update the package index:
    # sudo apt-get update
  2. Install pki-tks deb package:
    # sudo apt-get install pki-tks




2018-04-25 - Timo Aaltonen <>
dogtag-pki (10.6.0-1ubuntu2) bionic; urgency=medium
* control: Add conflicts on libtomcat7-java to pki-server.
2018-04-18 - Timo Aaltonen <>
dogtag-pki (10.6.0-1ubuntu1) bionic; urgency=medium
* rules: Build everything in one pass.
* Fix ACL evaluation in allow,deny mode. (Closes: #893690)
- CVE-2018-1080
2018-04-18 - Timo Aaltonen <>
dogtag-pki (10.6.0-1) experimental; urgency=medium
* New upstream release.
* control: Update VCS urls.
2018-04-10 - Timo Aaltonen <>
dogtag-pki (10.6.0~beta2-3) experimental; urgency=medium
* rules: Fix JAVA_HOME, create a symlink to the native jvm dir and
ship it with pki-server.
* pki-base.postinst: Modify JAVA_HOME for installed instances on
* debian-support.diff: Revert start delay to 5s, use systemctl
2018-04-06 - Timo Aaltonen <>
dogtag-pki (10.6.0~beta2-2) experimental; urgency=medium
* pki-tools: Add new manpages.
* debian-support.diff: Fix keystore permissions.
* debian-support.diff: Skip systemctl enable/disable.
* control: Add openjdk-8-jre-headless to pki-base-java depends.
2018-03-30 - Timo Aaltonen <>
dogtag-pki (10.6.0~beta2-1) experimental; urgency=medium
* New upstream prerelease.
* patches: Refreshed.
* control, rules: Build using tomcat 8.5, adjust dependencies to
* fix-jar-search.diff: Dropped, upstream
* rules: Use sql nssdb's by default.
* debian-support.diff: Bump the delay after starting the instance to 10s.
* fix-symkey-path.diff: Move symkey.jar handling here from fix-jar-
* fix-tomcat-paths.diff: Use tomcat paths provided by Debian,
merge fix-cli-migrate.diff here.
* tools: DRMTool links are handled by cmake now, drop .links.
* rules: Don't clean usr/share/pki/server/lib before dh_install, it's
jar symlinks now.
* base.install: Updated.
* control, rules: Build using JDK8.
* control: Add python3-distutils to build-depends.
* rename-logging-config.diff: Dropped, upstream.
* use-bindsto.diff: Dropped, upstream.
* fix-cve-2016-1240.diff: Dropped, upstream.
* debian-support.diff: Tomcat setup upstreamed.
2018-02-09 - Timo Aaltonen <>
dogtag-pki (10.5.5-1) unstable; urgency=medium
* New upstream release.
* tests: Add some debugging info, and force the hostname if it isn't
* patches: Refreshed.
* tools.install: Updated.
* tests: Remove installed instances.
2018-01-05 - Timo Aaltonen <>
dogtag-pki (10.5.3-4) unstable; urgency=medium
* rules: Remove resteasy-jandex-jaxrs.jar symlink, it looks unused
anyway. (Closes: #857150)
* tests: Sleep for 10 seconds between spawning instances, it seems
racy otherwise.
2017-12-22 - Timo Aaltonen <>
dogtag-pki (10.5.3-3) unstable; urgency=medium
* control: Add libhttpclient-java, libhttpcore-java, libjaxrs-api-java to
pki-base-java Depends.
* rename-logging-config.diff: Rename LOGGING_CONFIG to
PKI_LOGGING_CONFIG, otherwise catalina startup would fail.
* fix-jar-search.diff: Fix search for commons-collections3.jar and
* rules: Link jboss-logging.jar under server/common/lib too.
2017-12-22 - Timo Aaltonen <>
dogtag-pki (10.5.3-2) unstable; urgency=medium
* control: Add python{,3}-cryptography to pki-base, pki-server and
python3-pki-base Depends.

See Also

Package Description
pki-tools_10.6.0-1ubuntu2_i386.deb Certificate System - PKI Tools
pki-tps-client_10.6.0-1ubuntu2_i386.deb Certificate System - Token Processing System client
pki-tps_10.6.0-1ubuntu2_all.deb Certificate System - Token Processing System
pktanon_2~git20160407.0.2bde4f2+dfsg-3build1_i386.deb profile-based traffic anonymizer
pktools-dev_2.6.7.3+ds-1_i386.deb GDAL add-on tools to perform useful raster processing - development files
pktools_2.6.7.3+ds-1_i386.deb GDAL add-on tools to perform useful raster processing
pktstat_1.8.5-5_i386.deb top-like utility for network connections usage
pkwalify_1.22.99~git3d3f0ea-1_all.deb perl kwalify validator
placnet_1.03-2_all.deb Plasmid Constellation Network project
plainbox-insecure-policy_0.25-1_all.deb policykit policy required to use plainbox (insecure version)
plainbox-provider-checkbox_0.25-2_i386.deb CheckBox provider for PlainBox
plainbox-provider-resource-generic_0.23-1.1_i386.deb CheckBox generic resource jobs provider
plainbox_0.25-1_all.deb toolkit for software and hardware integration testing
plait_1.6.2-1ubuntu1_all.deb command-line jukebox
plan_1.10.1-5build1_i386.deb X/Motif day planner