You can subscribe to this list here.
| 2001 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
(1) |
Dec
(3) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2002 |
Jan
(3) |
Feb
(2) |
Mar
(8) |
Apr
(3) |
May
(6) |
Jun
(1) |
Jul
(15) |
Aug
(6) |
Sep
|
Oct
(10) |
Nov
(2) |
Dec
(4) |
| 2003 |
Jan
(1) |
Feb
(7) |
Mar
(3) |
Apr
(6) |
May
(7) |
Jun
(5) |
Jul
(5) |
Aug
(25) |
Sep
(14) |
Oct
(2) |
Nov
|
Dec
(2) |
| 2004 |
Jan
(7) |
Feb
(4) |
Mar
(12) |
Apr
(16) |
May
(43) |
Jun
(56) |
Jul
(43) |
Aug
(40) |
Sep
(66) |
Oct
(12) |
Nov
(26) |
Dec
(10) |
| 2005 |
Jan
(13) |
Feb
(33) |
Mar
(16) |
Apr
(7) |
May
(10) |
Jun
(34) |
Jul
(41) |
Aug
(8) |
Sep
(4) |
Oct
(32) |
Nov
(20) |
Dec
(25) |
| 2006 |
Jan
(30) |
Feb
(101) |
Mar
(5) |
Apr
(75) |
May
(74) |
Jun
(22) |
Jul
(6) |
Aug
(70) |
Sep
(19) |
Oct
(21) |
Nov
(31) |
Dec
(50) |
| 2007 |
Jan
(15) |
Feb
(20) |
Mar
(24) |
Apr
(33) |
May
(13) |
Jun
(18) |
Jul
(13) |
Aug
(7) |
Sep
(63) |
Oct
(68) |
Nov
(29) |
Dec
(68) |
| 2008 |
Jan
(30) |
Feb
(33) |
Mar
(30) |
Apr
(103) |
May
(78) |
Jun
(48) |
Jul
(72) |
Aug
(24) |
Sep
(62) |
Oct
(63) |
Nov
(70) |
Dec
(37) |
| 2009 |
Jan
(34) |
Feb
(35) |
Mar
(64) |
Apr
(34) |
May
(34) |
Jun
(58) |
Jul
(30) |
Aug
(30) |
Sep
(46) |
Oct
(52) |
Nov
(12) |
Dec
(23) |
| 2010 |
Jan
(121) |
Feb
(18) |
Mar
(53) |
Apr
(62) |
May
(62) |
Jun
(20) |
Jul
(33) |
Aug
(20) |
Sep
(36) |
Oct
(35) |
Nov
(44) |
Dec
(63) |
| 2011 |
Jan
(19) |
Feb
(32) |
Mar
(94) |
Apr
(41) |
May
(47) |
Jun
(25) |
Jul
(34) |
Aug
(20) |
Sep
(9) |
Oct
(41) |
Nov
(33) |
Dec
(24) |
| 2012 |
Jan
(12) |
Feb
(36) |
Mar
(48) |
Apr
(32) |
May
(20) |
Jun
(15) |
Jul
(32) |
Aug
(13) |
Sep
(33) |
Oct
(54) |
Nov
(25) |
Dec
(16) |
| 2013 |
Jan
(45) |
Feb
(39) |
Mar
(38) |
Apr
(50) |
May
(29) |
Jun
(30) |
Jul
(33) |
Aug
(12) |
Sep
(9) |
Oct
(25) |
Nov
(29) |
Dec
(20) |
| 2014 |
Jan
(25) |
Feb
(19) |
Mar
(16) |
Apr
(33) |
May
(27) |
Jun
(37) |
Jul
(29) |
Aug
(27) |
Sep
(37) |
Oct
(58) |
Nov
(109) |
Dec
(26) |
| 2015 |
Jan
(4) |
Feb
(35) |
Mar
(22) |
Apr
(35) |
May
(28) |
Jun
(20) |
Jul
(4) |
Aug
(16) |
Sep
(37) |
Oct
(13) |
Nov
(13) |
Dec
(14) |
| 2016 |
Jan
(22) |
Feb
(7) |
Mar
(23) |
Apr
(30) |
May
(10) |
Jun
(10) |
Jul
(15) |
Aug
(12) |
Sep
(22) |
Oct
(31) |
Nov
(5) |
Dec
(5) |
| 2017 |
Jan
(30) |
Feb
(25) |
Mar
(28) |
Apr
(4) |
May
(19) |
Jun
(13) |
Jul
(7) |
Aug
(1) |
Sep
(2) |
Oct
(5) |
Nov
(12) |
Dec
(2) |
| 2018 |
Jan
(7) |
Feb
|
Mar
(7) |
Apr
(2) |
May
(8) |
Jun
(18) |
Jul
(6) |
Aug
(3) |
Sep
(15) |
Oct
(33) |
Nov
(13) |
Dec
(7) |
| 2019 |
Jan
(5) |
Feb
(7) |
Mar
(30) |
Apr
(5) |
May
(4) |
Jun
(69) |
Jul
(86) |
Aug
(22) |
Sep
(6) |
Oct
(7) |
Nov
(5) |
Dec
(3) |
| 2020 |
Jan
(10) |
Feb
(12) |
Mar
(22) |
Apr
(5) |
May
(1) |
Jun
(4) |
Jul
(6) |
Aug
|
Sep
(9) |
Oct
|
Nov
|
Dec
(1) |
| 2021 |
Jan
(4) |
Feb
(11) |
Mar
(7) |
Apr
(7) |
May
|
Jun
(3) |
Jul
(10) |
Aug
(6) |
Sep
|
Oct
|
Nov
(18) |
Dec
(2) |
| 2022 |
Jan
(1) |
Feb
(1) |
Mar
|
Apr
|
May
|
Jun
(2) |
Jul
|
Aug
(4) |
Sep
|
Oct
|
Nov
|
Dec
|
| 2023 |
Jan
|
Feb
|
Mar
|
Apr
(1) |
May
(1) |
Jun
|
Jul
|
Aug
(5) |
Sep
|
Oct
|
Nov
|
Dec
|
|
From: Tomas G. <to...@ta...> - 2002-03-18 12:44:40
|
Hi, I will try to give answers to your questions. 1. EJBCA can in theory be used for any kind of certificates implementing the Java Certificate interface. If the CV certificates are very special, you would implement a special subclass of the interface se.anatom.ejbca.ca.sign.ISignSession. If the CV certificates on the other hand is only a specially limited form of a regular X509 certificate, changes to se.anatom.ejbca.ca.sign.RSASignSession is the only thing needed. Possibly even configuration changes ni src/ca/META-INF/ejb-jar.xml is sufficient, since you can disable use of any v3 extensions etc through configuration. Is there any specification available of the CV certificates? 2. There is no OCSP module to date. The application server works with http or rmi-iiop calls, so there is no standard way of adding a custom protocol, such as OCSP, if it is not used over http. The database however is available in the backend, so it is completely possible to have an OCSP service besides the app.server who reads the database and answers queries. In that case nothing in EJBCA would have to be changed, but off-course the OCSP service must be created. There is no OCSP-work in progress for the time being in EJBCA. I would welcome any initiative, or market requirement, though... 3. The complete issuance of a certificate consists of two steps, reistering the user and issuing the certificate (in response to a request). None of these tasks are very demanding, creating the certificate typically takes less than 1 second on a PIII 800 MHz (actually less than .5 secs with 1024 bit CA key). With these figures in mind, I would say the possible number of certificates generated in one day would be in the 10-thousands. 4. Yes, in the current version in CVS there is a sample configuration for using Oracle. It is available on the EJBCA homepage (http://ejbca.sourceforge.net/) under Documentation->HOWTO-Database. 5. No. Since Resin is not a full J2EE server (last time I checked) it cannot be used to run EJB Session Beans, which is used in EJBCA. The Caontainer used must fully implement the EJB 1.1 spec. Hope the answers are helpful. Regards, Tomas ------------------- > Dear Mr. Sirs, > > I would be very grateful, if you would answer the following questions > related to EJBCA: > > 1.) Which files are to be changed in order to issue CV certificate ? > 2.) Can OCSP be used with EJBCA and what should be changed for this > application? > 3.) Can you indicate approximate amount of certificate, which can be > issued this software in day (1000 .... 3000 certificates) ? > 4.) Is it possible to use Oracle as data base? What should be changed for > this application ? > 5.) Is it possible to use Resin as application server? What should be > changed for this application ? > > I would be grateful for any information. > I thank you in advance for your co-operation > > Sincerely yours > > Slava Sklarewski |
|
From: <Sla...@de...> - 2002-03-18 10:05:50
|
Dear Mr. Sirs, I would be very grateful, if you would answer the following questions related to EJBCA: 1.) Which files are to be changed in order to issue CV certificate ? 2.) Can OCSP be used with EJBCA and what should be changed for this application? 3.) Can you indicate approximate amount of certificate, which can be issued this software in day (1000 .... 3000 certificates) ? 4.) Is it possible to use Oracle as data base? What should be changed for this application ? 5.) Is it possible to use Resin as application server? What should be changed for this application ? I would be grateful for any information. I thank you in advance for your co-operation Sincerely yours Slava Sklarewski |
|
From: Timothy F. <trf...@ya...> - 2002-03-14 14:03:42
|
There is an excellent new book out covering the details of implementing PKI. Title: Introduction to the Public Key Infrastructure (PKI) for the Internet Author: Messaoud Benantar The book can serve as a valuable reference as it contains sections describing PKIX, X.509, ASN1 and other relevant standards. Tim __________________________________________________ Do You Yahoo!? Yahoo! Sports - live college hoops coverage http://sports.yahoo.com/ |
|
From: Tomas G. <to...@ta...> - 2002-03-14 13:40:38
|
I have updated the homepage with for example Timothys excelent architectural overview. /Tomas |
|
From: Timothy F. <trf...@ya...> - 2002-03-01 16:41:28
|
I certainly agree with your comment about a picture saying more than a thousand words. As I was looking at EJBCA, I found it very helpful to diagram its architecture in the way I did. After having completed the diagram, I realized that it might be very useful to others as well. It would probably be a good idea to include the diagram in the doc directory. As far as exploding down another level in the CA component. The only reason I didn't was for lack of space and to keep the diagram looking neat. I will see what I can do to create another version that does show the additional detail. I'll send you an update when I have something. Tim --- Tomas Gustavsson <to...@ta...> wrote: > > Nice, really nice! To make it complete, should we > explode the subcomponents in CA-component also? > > i.e. Store Component contains CertificateDataBean, > CRLDataBean, CertificateStoreSession and > PublisherSession. > > One picture really says more than a thousand words! > > /Tomas > > ------------------- > > Attached is a Word document that contains a > diagram > > which is a high level overview of EJBCA's tiers. > > > > Tim > > > > > > __________________________________________________ > > Do You Yahoo!? > > Yahoo! Greetings - Send FREE e-cards for every > occasion! > > http://greetings.yahoo.com > __________________________________________________ Do You Yahoo!? Yahoo! Greetings - Send FREE e-cards for every occasion! http://greetings.yahoo.com |
|
From: Tomas G. <to...@ta...> - 2002-03-01 14:01:43
|
> to others as well. It would probably be a good idea > to include the diagram in the doc directory. I will, and also put it on the webpage. /Tomas |
|
From: Tomas G. <to...@ta...> - 2002-03-01 10:21:08
|
Nice, really nice! To make it complete, should we explode the subcomponents in CA-component also? i.e. Store Component contains CertificateDataBean, CRLDataBean, CertificateStoreSession and PublisherSession. One picture really says more than a thousand words! /Tomas ------------------- > Attached is a Word document that contains a diagram > which is a high level overview of EJBCA's tiers. > > Tim > > > __________________________________________________ > Do You Yahoo!? > Yahoo! Greetings - Send FREE e-cards for every occasion! > http://greetings.yahoo.com |
|
From: Timothy F. <trf...@ya...> - 2002-02-28 20:40:38
|
Attached is a Word document that contains a diagram which is a high level overview of EJBCA's tiers. Tim __________________________________________________ Do You Yahoo!? Yahoo! Greetings - Send FREE e-cards for every occasion! http://greetings.yahoo.com |
|
From: Tomas G. <mp...@ch...> - 2002-02-21 09:31:19
|
I just checked in some work restructuring the LICENSE terms of EJBCA. The structure is simply as this: EJBCA it self is GPL. Interfaces are LGPL, i.e. using an interface to make a custom authentication module (not touching EJBCA code, only modifying deployment descriptors) falls under LGPL. I think this is the most logical model. /Tomas |
|
From: Tomas G. <to...@ta...> - 2002-01-10 08:18:54
|
I just made a release for version 1.1. I finished som e stuff I liked and thought, "best to release before more major work starts" or something like that. /Tomas |
|
From: Tomas G. <to...@ta...> - 2002-01-02 16:32:28
|
I changed my mind and made the mySQL configuration optional, so the default JBoss database works out of the box. To use mySQL now jaws-mysql.xml must be renamed to jaws.xml. I think PostgreSQL wil work with default settings as well, I I can just get the jdbc driver to work in JBoss... /Tomas |
|
From: Tomas G. <to...@ta...> - 2002-01-02 13:06:50
|
I changed in the CVS tree so the default database that works is mySQL. To be able to use the JBoss default database (hypersonicDB) the file src/ca/META-INF/jaws.xml must be removed before building with ant. I made relevant documentation (now in doc subdirectory) to use mySQL. I'm now trying to get PostgreSQL to work. Have anyone used it with JBoss? /Tomas |
|
From: Tomas G. <to...@ta...> - 2001-12-31 15:03:15
|
I am staring to work on a new CertificateStore/Publisher architecture. The old architecture works simply by the CA putting certificates and CRLs in the CertificateStoreSession defined in ca/ejb-jar.xml. To be able to also use LDAP directories etc, I will make a new architecture. New architecture: ----------------- The CertificateStore/Publisher architecture is defined by the two interfaces IPublisherSession and ICertificateStoreSession: public interface IPublisherSession; public interface ICertificateStoreSession extends IPublisherSession; The CertificateStoreSession is the primary storage for certificates and CRL. The CA always puts certificates and CRLs in the CertificateStoreSession session bean defined in ca/ejb-jar.xml. The CertificateStoreSession is also used to retrieve and find certificates, retrieve CRLs, check for revocation etc. the CertificateStoreSession implements the interface ICertificateStoreSession. Certificates and CRLs can also be published to any number of other certificate stores, which are defined by session beans PublisherSession1, PublisherSession2, etc. A PublisherSession is a simple subset of the CertificateStoreSession and can only be used to store certificates and CRLs. PublisherSession's implement the interface IPublisherSession. The IPublisherSession is a simple interface which is only used to store a certificate or a CRL. The ICertificateStoreSession extends the IPublisherSession interface with capabilities to find certificates and CRL etc. A class implementing the ICertificateStoreSession interface can thus also be used a PublisherSession and a class implementing the IPublisherSession can easily (well maybe not so easily) be extended to a fully fledged CertificateStore. This architecture gives us the choice of for example an SQL database aa CertificateStoreSession where we also publish certificates to an LDAP directory, or the LDAP directory as the primary CertificateStoreSession where we also publish certificates to a specific SQL database for a specific purpose. Any objections? I didn't think so :-) /Tomas |
|
From: Tomas G. <to...@ta...> - 2001-12-05 13:03:12
|
EJBCA is a fully functional OpenSource Java CA building on the J2EE plattform. EJBCA runs on the JBoss J2EE application server. This is version 1.0 to be user as stand-alone CA or integrated into any J2EE application. Changes since 1.0b2 ------------------- Fixed bug with not returning correct content-length to browser when returning PE M-certificates. New version of BouncyCastle provider with minor PKCS12 fix. Updated docs. Added FAQ. |
|
From: Tomas G. <to...@ta...> - 2001-12-05 09:51:55
|
I branched version 1.0 final with tag Rel_1_0 today. No known outstanding bugs exist. Now new fantastic development can start in the HEAD branch. ETA for the next version should be several months away I think. /Tomas |
|
From: Tomas G. <to...@ta...> - 2001-11-27 08:02:50
|
I checked in two more bugfixed. When returning certs from manual certificate requests or retrieveing the CA cert in PEM-format the content-length was not set correctly causing the cert file to be truncated in some browsers (mozilla doesn't seem to care about content-length though). /Tomas |