Avoid single point of failure with PKIAAS

The “Add Token” adds a HSM to the Trust Center, e.g. to store trust center keys. This has nothing to do with the personal token used to authenticate in the portal.

Personal token for authentication must be either added in self-registration or by enrolling a person in the trust center (“CA / Enroll Person”). Once you enroll additional people under the same trust center, you can assign them the required role, so that they can see the trust center and act accordingly.

Please remember, that the first person (in this case you) has ultimate rights initially. Any further enrolled person will have no specific rights. You will first need to open the subject view and give them the required roles with “Manage Role”.

The error message is a bit misleading (and already corrected). It should report, that the token is already assigned to a non-person subject, i.e. your trust center.

You can fix this by removing the token from the trust center in the service request where you added the token.