You can subscribe to this list here.
| 2001 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
(1) |
Dec
(3) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2002 |
Jan
(3) |
Feb
(2) |
Mar
(8) |
Apr
(3) |
May
(6) |
Jun
(1) |
Jul
(15) |
Aug
(6) |
Sep
|
Oct
(10) |
Nov
(2) |
Dec
(4) |
| 2003 |
Jan
(1) |
Feb
(7) |
Mar
(3) |
Apr
(6) |
May
(7) |
Jun
(5) |
Jul
(5) |
Aug
(25) |
Sep
(14) |
Oct
(2) |
Nov
|
Dec
(2) |
| 2004 |
Jan
(7) |
Feb
(4) |
Mar
(12) |
Apr
(16) |
May
(43) |
Jun
(56) |
Jul
(43) |
Aug
(40) |
Sep
(66) |
Oct
(12) |
Nov
(26) |
Dec
(10) |
| 2005 |
Jan
(13) |
Feb
(33) |
Mar
(16) |
Apr
(7) |
May
(10) |
Jun
(34) |
Jul
(41) |
Aug
(8) |
Sep
(4) |
Oct
(32) |
Nov
(20) |
Dec
(25) |
| 2006 |
Jan
(30) |
Feb
(101) |
Mar
(5) |
Apr
(75) |
May
(74) |
Jun
(22) |
Jul
(6) |
Aug
(70) |
Sep
(19) |
Oct
(21) |
Nov
(31) |
Dec
(50) |
| 2007 |
Jan
(15) |
Feb
(20) |
Mar
(24) |
Apr
(33) |
May
(13) |
Jun
(18) |
Jul
(13) |
Aug
(7) |
Sep
(63) |
Oct
(68) |
Nov
(29) |
Dec
(68) |
| 2008 |
Jan
(30) |
Feb
(33) |
Mar
(30) |
Apr
(103) |
May
(78) |
Jun
(48) |
Jul
(72) |
Aug
(24) |
Sep
(62) |
Oct
(63) |
Nov
(70) |
Dec
(37) |
| 2009 |
Jan
(34) |
Feb
(35) |
Mar
(64) |
Apr
(34) |
May
(34) |
Jun
(58) |
Jul
(30) |
Aug
(30) |
Sep
(46) |
Oct
(52) |
Nov
(12) |
Dec
(23) |
| 2010 |
Jan
(121) |
Feb
(18) |
Mar
(53) |
Apr
(62) |
May
(62) |
Jun
(20) |
Jul
(33) |
Aug
(20) |
Sep
(36) |
Oct
(35) |
Nov
(44) |
Dec
(63) |
| 2011 |
Jan
(19) |
Feb
(32) |
Mar
(94) |
Apr
(41) |
May
(47) |
Jun
(25) |
Jul
(34) |
Aug
(20) |
Sep
(9) |
Oct
(41) |
Nov
(33) |
Dec
(24) |
| 2012 |
Jan
(12) |
Feb
(36) |
Mar
(48) |
Apr
(32) |
May
(20) |
Jun
(15) |
Jul
(32) |
Aug
(13) |
Sep
(33) |
Oct
(54) |
Nov
(25) |
Dec
(16) |
| 2013 |
Jan
(45) |
Feb
(39) |
Mar
(38) |
Apr
(50) |
May
(29) |
Jun
(30) |
Jul
(33) |
Aug
(12) |
Sep
(9) |
Oct
(25) |
Nov
(29) |
Dec
(20) |
| 2014 |
Jan
(25) |
Feb
(19) |
Mar
(16) |
Apr
(33) |
May
(27) |
Jun
(37) |
Jul
(29) |
Aug
(27) |
Sep
(37) |
Oct
(58) |
Nov
(109) |
Dec
(26) |
| 2015 |
Jan
(4) |
Feb
(35) |
Mar
(22) |
Apr
(35) |
May
(28) |
Jun
(20) |
Jul
(4) |
Aug
(16) |
Sep
(37) |
Oct
(13) |
Nov
(13) |
Dec
(14) |
| 2016 |
Jan
(22) |
Feb
(7) |
Mar
(23) |
Apr
(30) |
May
(10) |
Jun
(10) |
Jul
(15) |
Aug
(12) |
Sep
(22) |
Oct
(31) |
Nov
(5) |
Dec
(5) |
| 2017 |
Jan
(30) |
Feb
(25) |
Mar
(28) |
Apr
(4) |
May
(19) |
Jun
(13) |
Jul
(7) |
Aug
(1) |
Sep
(2) |
Oct
(5) |
Nov
(12) |
Dec
(2) |
| 2018 |
Jan
(7) |
Feb
|
Mar
(7) |
Apr
(2) |
May
(8) |
Jun
(18) |
Jul
(6) |
Aug
(3) |
Sep
(15) |
Oct
(33) |
Nov
(13) |
Dec
(7) |
| 2019 |
Jan
(5) |
Feb
(7) |
Mar
(30) |
Apr
(5) |
May
(4) |
Jun
(69) |
Jul
(86) |
Aug
(22) |
Sep
(6) |
Oct
(7) |
Nov
(5) |
Dec
(3) |
| 2020 |
Jan
(10) |
Feb
(12) |
Mar
(22) |
Apr
(5) |
May
(1) |
Jun
(4) |
Jul
(6) |
Aug
|
Sep
(9) |
Oct
|
Nov
|
Dec
(1) |
| 2021 |
Jan
(4) |
Feb
(11) |
Mar
(7) |
Apr
(7) |
May
|
Jun
(3) |
Jul
(10) |
Aug
(6) |
Sep
|
Oct
|
Nov
(18) |
Dec
(2) |
| 2022 |
Jan
(1) |
Feb
(1) |
Mar
|
Apr
|
May
|
Jun
(2) |
Jul
|
Aug
(4) |
Sep
|
Oct
|
Nov
|
Dec
|
| 2023 |
Jan
|
Feb
|
Mar
|
Apr
(1) |
May
(1) |
Jun
|
Jul
|
Aug
(5) |
Sep
|
Oct
|
Nov
|
Dec
|
|
From: CLIER, J. <joh...@at...> - 2017-01-17 09:41:27
|
Hello, I was wondering about the security updates for the community edition. As far as I know from Sourceforge, the current version 6.3.1.1 is from 2015 and has not been updated for potential security issues. I also did not found any list of the security issues for the Enterprise Edition. Is it available when buying the Enterprise Edition? Thanks Johan Clier |
|
From: Anders R. <and...@gm...> - 2017-01-07 06:08:21
|
On 2017-01-06 22:32, Willi Trace wrote: > Or we can kindly ask PrimeKey to include Peer Connectors and their new RA in Community Edition ;) Well, that's a possibility. I won't personally interfere with PrimeKey's business model and I also use the securityproxy in other projects. PrimeKey's Peer Connector solution appears to be covering the entire EJBCA. In my EJBCA implementation I didn't do anything with respect to administration and GUI, it was just a dedicated, bi-directional, mutually authenticated channel between two worlds, where one was considered as more secure than the other. http://webpki.org/papers/mobile-ra-guide.pdf The RA was written from scratch since my target built on having the user database outside of EJBCA, I.e. the CA became more like a certificate factory. Anders https://mobilepki.org/scc > > WT > > On Friday, January 6, 2017, Willi Trace <wil...@gm... <mailto:wil...@gm...>> wrote: > > Hi Anders, > > Seems exactly like I want to do so maybe I can use it with websockets and send it to you as update of securityproxy. > > As I understand you are proposing to create messages between EJBCA and clients in JSON. I was thinking about using ExtRA message format with its integrity and encryption. But it may be good idea to do it in JSON. > > I wonder how much work there is to integrate this with EJBCA. This is actually part where I am thinking about options and what would be the best way. It should be also in GUI in order to manage it easily and add, remove, etc. authorized clients. > > Currently I have updated ExtRA API package for EJBCA 6.5.0. Configuration of databases and ExtRAWorker can be done more or less effectivelly using predefined scripts but what I would like to eliminate is database polling every 5 seconds which is ineffective. > > WT > > > On Friday, January 6, 2017, Anders Rundgren <and...@gm... <javascript:_e(%7B%7D,'cvml','and...@gm...');>> wrote: > > On 2017-01-06 19:51, Willi Trace wrote: > > I am implementing websocket connection pool from EJBCA to clients primarily as a replacement of external RA and peer connections which are not available in Community Edition. > > is there any work done on this which I can reuse or build on it? > Of course I would like to publish it to community when it will be ready. > > My first concept is working similar to peer connections (although I do not know current implementation of Enterprise Edition) but through wss. It should be effective and easily managed through admin GUI authenticated by AKB. > > > Hi Willi, > > I'm a former PrimeKey employee who some years ago developed a replacement for the external RA: > https://cyberphone.github.io/doc/openkeystore/javaapi/org/webpki/securityproxy/package-summary.html <https://cyberphone.github.io/doc/openkeystore/javaapi/org/webpki/securityproxy/package-summary.html> > > I have integrated this with EJBCA but the integration is owned by PrimeKey. > > I have been thinking about upgrading the public part (the API above) to use WebSocket but haven't had any time to do that. > The current scheme uses serialized Java objects which I also want to shelve. > Today I have totally (and forever...) left the WS/XML/XSD camp in favor of JSON. > So a new system would (from my perspective) be built on JSON. > > https://cyberphone.github.io/doc/openkeystore/javaapi/org/webpki/json/package-summary.html <https://cyberphone.github.io/doc/openkeystore/javaapi/org/webpki/json/package-summary.html> > > Two-way TLS auth seems good to keep. In my setup I use a symmetric scheme so that the same cert+key is used in both directions. That is, the self-signed cert is both server and client. > > I had no problems integrating the proxy in EJBCA so I would still consider making a separate component. > > Best > Anders > > > > WT > > > ------------------------------------------------------------------------------ > Check out the vibrant tech community on one of the world's most > engaging tech sites, SlashDot.org! http://sdm.link/slashdot > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop <https://lists.sourceforge.net/lists/listinfo/ejbca-develop> > > |
|
From: Willi T. <wil...@gm...> - 2017-01-06 21:32:30
|
Or we can kindly ask PrimeKey to include Peer Connectors and their new RA in Community Edition ;) WT On Friday, January 6, 2017, Willi Trace <wil...@gm...> wrote: > Hi Anders, > > Seems exactly like I want to do so maybe I can use it with websockets and > send it to you as update of securityproxy. > > As I understand you are proposing to create messages between EJBCA and > clients in JSON. I was thinking about using ExtRA message format with its > integrity and encryption. But it may be good idea to do it in JSON. > > I wonder how much work there is to integrate this with EJBCA. This is > actually part where I am thinking about options and what would be the best > way. It should be also in GUI in order to manage it easily and add, remove, > etc. authorized clients. > > Currently I have updated ExtRA API package for EJBCA 6.5.0. Configuration > of databases and ExtRAWorker can be done more or less effectivelly using > predefined scripts but what I would like to eliminate is database polling > every 5 seconds which is ineffective. > > WT > > > On Friday, January 6, 2017, Anders Rundgren <and...@gm... > <javascript:_e(%7B%7D,'cvml','and...@gm...');>> wrote: > >> On 2017-01-06 19:51, Willi Trace wrote: >> >>> I am implementing websocket connection pool from EJBCA to clients >>> primarily as a replacement of external RA and peer connections which are >>> not available in Community Edition. >>> >>> is there any work done on this which I can reuse or build on it? >>> Of course I would like to publish it to community when it will be ready. >>> >>> My first concept is working similar to peer connections (although I do >>> not know current implementation of Enterprise Edition) but through wss. It >>> should be effective and easily managed through admin GUI authenticated by >>> AKB. >>> >> >> Hi Willi, >> >> I'm a former PrimeKey employee who some years ago developed a replacement >> for the external RA: >> https://cyberphone.github.io/doc/openkeystore/javaapi/org/we >> bpki/securityproxy/package-summary.html >> >> I have integrated this with EJBCA but the integration is owned by >> PrimeKey. >> >> I have been thinking about upgrading the public part (the API above) to >> use WebSocket but haven't had any time to do that. >> The current scheme uses serialized Java objects which I also want to >> shelve. >> Today I have totally (and forever...) left the WS/XML/XSD camp in favor >> of JSON. >> So a new system would (from my perspective) be built on JSON. >> >> https://cyberphone.github.io/doc/openkeystore/javaapi/org/we >> bpki/json/package-summary.html >> >> Two-way TLS auth seems good to keep. In my setup I use a symmetric >> scheme so that the same cert+key is used in both directions. That is, the >> self-signed cert is both server and client. >> >> I had no problems integrating the proxy in EJBCA so I would still >> consider making a separate component. >> >> Best >> Anders >> >> >> >>> WT >>> >>> >>> ------------------------------------------------------------ >>> ------------------ >>> Check out the vibrant tech community on one of the world's most >>> engaging tech sites, SlashDot.org! http://sdm.link/slashdot >>> >>> >>> >>> _______________________________________________ >>> Ejbca-develop mailing list >>> Ejb...@li... >>> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >>> >>> >> |
|
From: Willi T. <wil...@gm...> - 2017-01-06 20:29:10
|
Hi Anders, Seems exactly like I want to do so maybe I can use it with websockets and send it to you as update of securityproxy. As I understand you are proposing to create messages between EJBCA and clients in JSON. I was thinking about using ExtRA message format with its integrity and encryption. But it may be good idea to do it in JSON. I wonder how much work there is to integrate this with EJBCA. This is actually part where I am thinking about options and what would be the best way. It should be also in GUI in order to manage it easily and add, remove, etc. authorized clients. Currently I have updated ExtRA API package for EJBCA 6.5.0. Configuration of databases and ExtRAWorker can be done more or less effectivelly using predefined scripts but what I would like to eliminate is database polling every 5 seconds which is ineffective. WT On Friday, January 6, 2017, Anders Rundgren <and...@gm...> wrote: > On 2017-01-06 19:51, Willi Trace wrote: > >> I am implementing websocket connection pool from EJBCA to clients >> primarily as a replacement of external RA and peer connections which are >> not available in Community Edition. >> >> is there any work done on this which I can reuse or build on it? >> Of course I would like to publish it to community when it will be ready. >> >> My first concept is working similar to peer connections (although I do >> not know current implementation of Enterprise Edition) but through wss. It >> should be effective and easily managed through admin GUI authenticated by >> AKB. >> > > Hi Willi, > > I'm a former PrimeKey employee who some years ago developed a replacement > for the external RA: > https://cyberphone.github.io/doc/openkeystore/javaapi/org/we > bpki/securityproxy/package-summary.html > > I have integrated this with EJBCA but the integration is owned by PrimeKey. > > I have been thinking about upgrading the public part (the API above) to > use WebSocket but haven't had any time to do that. > The current scheme uses serialized Java objects which I also want to > shelve. > Today I have totally (and forever...) left the WS/XML/XSD camp in favor of > JSON. > So a new system would (from my perspective) be built on JSON. > > https://cyberphone.github.io/doc/openkeystore/javaapi/org/we > bpki/json/package-summary.html > > Two-way TLS auth seems good to keep. In my setup I use a symmetric scheme > so that the same cert+key is used in both directions. That is, the > self-signed cert is both server and client. > > I had no problems integrating the proxy in EJBCA so I would still consider > making a separate component. > > Best > Anders > > > >> WT >> >> >> ------------------------------------------------------------ >> ------------------ >> Check out the vibrant tech community on one of the world's most >> engaging tech sites, SlashDot.org! http://sdm.link/slashdot >> >> >> >> _______________________________________________ >> Ejbca-develop mailing list >> Ejb...@li... >> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >> >> > |
|
From: Anders R. <and...@gm...> - 2017-01-06 19:37:55
|
On 2017-01-06 19:51, Willi Trace wrote: > I am implementing websocket connection pool from EJBCA to clients primarily as a replacement of external RA and peer connections which are not available in Community Edition. > > is there any work done on this which I can reuse or build on it? > Of course I would like to publish it to community when it will be ready. > > My first concept is working similar to peer connections (although I do not know current implementation of Enterprise Edition) but through wss. It should be effective and easily managed through admin GUI authenticated by AKB. Hi Willi, I'm a former PrimeKey employee who some years ago developed a replacement for the external RA: https://cyberphone.github.io/doc/openkeystore/javaapi/org/webpki/securityproxy/package-summary.html I have integrated this with EJBCA but the integration is owned by PrimeKey. I have been thinking about upgrading the public part (the API above) to use WebSocket but haven't had any time to do that. The current scheme uses serialized Java objects which I also want to shelve. Today I have totally (and forever...) left the WS/XML/XSD camp in favor of JSON. So a new system would (from my perspective) be built on JSON. https://cyberphone.github.io/doc/openkeystore/javaapi/org/webpki/json/package-summary.html Two-way TLS auth seems good to keep. In my setup I use a symmetric scheme so that the same cert+key is used in both directions. That is, the self-signed cert is both server and client. I had no problems integrating the proxy in EJBCA so I would still consider making a separate component. Best Anders > > WT > > > ------------------------------------------------------------------------------ > Check out the vibrant tech community on one of the world's most > engaging tech sites, SlashDot.org! http://sdm.link/slashdot > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Willi T. <wil...@gm...> - 2017-01-06 18:51:44
|
I am implementing websocket connection pool from EJBCA to clients primarily as a replacement of external RA and peer connections which are not available in Community Edition. is there any work done on this which I can reuse or build on it? Of course I would like to publish it to community when it will be ready. My first concept is working similar to peer connections (although I do not know current implementation of Enterprise Edition) but through wss. It should be effective and easily managed through admin GUI authenticated by AKB. WT |
|
From: Willi T. <wil...@gm...> - 2017-01-06 17:15:45
|
You do not need to implement something on EJBCA. You should be able to do it from operational infrastructure point of view. EJBCA will have its standard authorisation mechanism through client certificate authentication. What you need to setup is a dual control, means no one is able to perform operation on CA alone. It is about definition of procedures and access restriction on different roles in your organisation. You need to implement restriction that your CA operator is not able to access CA server and web admin GUI and your CA server administrator will not have authorisation for CA. Also you should ensure that you are able generate audit trails for possible incidents to be able reconstruct access. The result will be dual control in case CA operator need to do some operation on CA. It is simple, without any changes to SW, and you will achieve your goal. WT On Friday, January 6, 2017, Carlos Rodrigues <cm...@eu...> wrote: > On Thu, 2017-01-05 at 19:54 +0100, Willi Trace wrote: > > You can achieve dual control by combining infrastructure access to CA and > logical access using CA operator token. > > > Could you please detail this implementation? Can you give some references > or how to implement on EJBCA? > > > Infrastructure administrator would not be able to do operations with CA > alone because of absence of authorization and CA operator wouldn't be able > to do operations on CA without infrastructure administrator (or call this > roles as you want). > > This will ensure dual control what you want. > Logs and procedural design will ensure audit trails. > > WT > > > Thank you. > > Regards, > Carlos Rodrigues > > > > On Thursday, January 5, 2017, Andreas Schwier < > and...@ca... > <javascript:_e(%7B%7D,'cvml','and...@ca...');>> wrote: > > The SmartCard-HSM supports n-of-m authentication [1]. However this is > currently only supported via JCE, but integration with EJBCA is done via > PKCS#11 [2]. > > If there is serious demand, then we could make it work via PKCS#11 as well. > > Andreas > > [1] > https://www.smartcard-hsm.com/2015/10/10/Shared_Control_over > _Key_Usage.html > [2] > https://www.smartcard-hsm.com/2014/09/05/Accessing_your_Smar > tCard-HSM_from_EJBCA.html > > On 01/05/2017 07:07 PM, Soluti Quintiliano wrote: > > Hummm...A smartcard or security token + password split between MofN, not > > great but still simple. > > > > You probably will have problems with backing this up. > > > > If you really need to segregate this, during the install EJBCA allows > > you to generate the Superadmin cert using a PKCS11 library so you can > > use a smartcard or token and have the superadmin cert protected. I > > personally wouldn't do this. Its easier to use the superadmin for > > initial config and then replace it for the CA operator's cert. > > > > Just out of curiosity, can you share you PKI architecture idea? I've > > been using EJBCA in large scale for 5 years and haven't had any issue > > regards limiting access to CA Administration. Using small number of > > trusted managers allowing only them to make changes on CA's and > > profiles. Even then, everything is verified from the logs, and, if > > something unusual or even not authorized happens ( the alarms go on, > > never happens), and then audited. > > > > []'s > > > > > > Proteja o endereço de email de seus contatos como estou protegendo o seu. > > Ao enviar mensagens para mais de um endereço use SEMPRE o > > "Cco" (cópia oculta) ou "Bcc" (Blind carbon copy). > > > > /Esta mensagem é enviada exclusivamente a seu destinatário e pode conter > > informações > > confidenciais, protegidas por sigilo profissional. Sua utilização > > desautorizada é ilegal e sujeita > > o infrator às penas da lei. Se você a recebeu indevidamente, queira, por > > gentileza, reenvia-la > > ao emitente, esclarecendo o equívoco. > > > > This message is directed exclusively to its addressee and may contain > > confidential data, > > protected under professional secrecy rules. Its unauthorized use is > > illegal and may subject > > the transgressor to the law's penalties. If you're not the addressee, > > please send it back, > > elucidating the failure./ > > > > 2017-01-05 15:47 GMT-02:00 Carlos Rodrigues <cm...@eu... > > <mailto:cm...@eu...>>: > > > > Hello, > > > > I don't have HSM device, there no another way to do that? > > > > Regards, > > Carlos Rodrigues > > > > On Thu, 2017-01-05 at 15:05 -0200, Soluti Quintiliano wrote: > >> HI, > >> > >> Out of the box, the easy option is to limit access to EJBCA CA > >> interface through user permissions. You can then storage the AC > >> Admin (Superadmin) certificate inside an HSM and ensure the access > >> to this specific key with MofN. You ll also need to isolate the > >> access to EJBCA's shell server... > >> > >> Att. > >> > >> > >> Proteja o endereço de email de seus contatos como estou protegendo > >> o seu. > >> Ao enviar mensagens para mais de um endereço use SEMPRE o > >> "Cco" (cópia oculta) ou "Bcc" (Blind carbon copy). > >> > >> /Esta mensagem é enviada exclusivamente a seu destinatário e pode > >> conter informações > >> confidenciais, protegidas por sigilo profissional. Sua utilização > >> desautorizada é ilegal e sujeita > >> o infrator às penas da lei. Se você a recebeu indevidamente, > >> queira, por gentileza, reenvia-la > >> ao emitente, esclarecendo o equívoco. > >> > >> This message is directed exclusively to its addressee and may > >> contain confidential data, > >> protected under professional secrecy rules. Its unauthorized use > >> is illegal and may subject > >> the transgressor to the law's penalties. If you're not the > >> addressee, please send it back, > >> elucidating the failure./ > >> > >> 2017-01-05 14:31 GMT-02:00 Carlos Rodrigues <cm...@eu... > >> <mailto:cm...@eu...>>: > >>> Hello, > >>> > >>> I would like to know how to configure EJBCA to requires more than > >>> one person to active Certification Authority and prevent to > >>> change the CA settings? > >>> > >>> Any one could help me? > >>> > >>> Regards, > >>> Carlos Rodrigues > >>> > >>> On Wed, 2016-12-28 at 14:16 +0000, Carlos Rodrigues wrote: > >>>> Hello, > >>>> > >>>> I need to create one Certification Authority that needs more > >>>> than one person to open CA to do any CA operation. > >>>> This should be including change CA to set approval settings. > >>>> > >>>> > >>>> Regards, > >>>> > >>>> -- > >>>> Carlos Rodrigues > >>>> > >>>> Engenheiro de Software Sénior > >>>> > >>>> Eurotux Informática, S.A. | www.eurotux.com > >>>> <http://www.eurotux.com/> > >>>> (t) +351 253 680 300 <tel:+351%20253%20680%20300> (m) +351 911 > >>>> 926 110 <tel:+351%20911%20926%20110> > >>>> > >>>> ----------------------------------------------------------- > ------------------- > >>>> Check out the vibrant tech community on one of the world's most > >>>> engaging tech sites, SlashDot.org! http://sdm.link/slashdot > >>>> _______________________________________________ > >>>> Ejbca-develop mailing list > >>>> Ejb...@li... > >>>> <mailto:Ejb...@li...> > >>>> https://lists.sourceforge.net/lists/listinfo/ejbca-develop > >>>> <https://lists.sourceforge.net/lists/listinfo/ejbca-develop> > >>> -- > >>> Carlos Rodrigues > >>> > >>> Engenheiro de Software Sénior > >>> > >>> Eurotux Informática, S.A. | www.eurotux.com < > http://www.eurotux.com/> > >>> (t) +351 253 680 300 <tel:+351%20253%20680%20300> (m) +351 911 > >>> 926 110 <tel:+351%20911%20926%20110> > >>> > >>> > >>> ----------------------------------------------------------- > ------------------- > >>> Check out the vibrant tech community on one of the world's most > >>> engaging tech sites, SlashDot.org! http://sdm.link/slashdot > >>> _______________________________________________ > >>> Ejbca-develop mailing list > >>> Ejb...@li... > >>> <mailto:Ejb...@li...> > >>> https://lists.sourceforge.net/lists/listinfo/ejbca-develop > >>> <https://lists.sourceforge.net/lists/listinfo/ejbca-develop> > >>> > >> > > -- > > > > Carlos Rodrigues > > > > Engenheiro de Software Sénior > > > > Eurotux Informática, S.A. | www.eurotux.com <http://www.eurotux.com/ > > > > (t) +351 253 680 300 <tel:+351%20253%20680%20300> (m) +351 911 926 > > 110 <tel:+351%20911%20926%20110> > > > > > > > > > > ------------------------------------------------------------ > ------------------ > > Check out the vibrant tech community on one of the world's most > > engaging tech sites, SlashDot.org! http://sdm.link/slashdot > > > > > > > > _______________________________________________ > > Ejbca-develop mailing list > > Ejb...@li... > > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > > -- > > --------- CardContact Systems GmbH > |.##> <##.| Schülerweg 38 > |# #| D-32429 Minden, Germany > |# #| Phone +49 571 56149 > |'##> <##'| http://www.cardcontact.de > --------- Registergericht Bad Oeynhausen HRB 14880 > Geschäftsführer Andreas Schwier > > -- > > --------- CardContact Systems GmbH > |.##> <##.| Schülerweg 38 > |# #| D-32429 Minden, Germany > |# #| Phone +49 571 56149 > |'##> <##'| http://www.cardcontact.de > --------- Registergericht Bad Oeynhausen HRB 14880 > Geschäftsführer Andreas Schwier > > > > ------------------------------------------------------------ > ------------------ > Check out the vibrant tech community on one of the world's most > engaging tech sites, SlashDot.org! http://sdm.link/slashdot > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > ------------------------------------------------------------------------------ > Check out the vibrant tech community on one of the world's most > engaging tech sites, SlashDot.org! http://sdm.link/slashdot > > _______________________________________________ > Ejbca-develop mailing lis...@li... <javascript:_e(%7B%7D,'cvml','Ejb...@li...');>https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > -- > > Carlos Rodrigues > > Engenheiro de Software Sénior > > Eurotux Informática, S.A. | www.eurotux.com > (t) +351 253 680 300 (m) +351 911 926 110 > > |
|
From: Carlos R. <cm...@eu...> - 2017-01-06 10:46:02
|
On Thu, 2017-01-05 at 19:54 +0100, Willi Trace wrote: > > You can achieve dual control by combining infrastructure access to CA and logical access using CA operator token. Could you please detail this implementation? Can you give some references or how to implement on EJBCA? > > Infrastructure administrator would not be able to do operations with CA alone because of absence of authorization and CA operator wouldn't be able to do operations on CA without infrastructure administrator (or call this roles as you want). > > This will ensure dual control what you want. > Logs and procedural design will ensure audit trails. > > WT Thank you. Regards, Carlos Rodrigues > > On Thursday, January 5, 2017, Andreas Schwier <and...@ca...> wrote: > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > The SmartCard-HSM supports n-of-m authentication [1]. However this is currently only supported via JCE, but integration with EJBCA is done via PKCS#11 [2]. If there is serious demand, then we could make it work via PKCS#11 as well. Andreas [1] https://www.smartcard-hsm.com/2015/10/10/Shared_Control_over_Key_Usage.html [2] https://www.smartcard-hsm.com/2014/09/05/Accessing_your_SmartCard-HSM_from_EJBCA.html On 01/05/2017 07:07 PM, Soluti Quintiliano wrote: > Hummm...A smartcard or security token + password split between MofN, not > great but still simple. > > You probably will have problems with backing this up. > > If you really need to segregate this, during the install EJBCA allows > you to generate the Superadmin cert using a PKCS11 library so you can > use a smartcard or token and have the superadmin cert protected. I > personally wouldn't do this. Its easier to use the superadmin for > initial config and then replace it for the CA operator's cert. > > Just out of curiosity, can you share you PKI architecture idea? I've > been using EJBCA in large scale for 5 years and haven't had any issue > regards limiting access to CA Administration. Using small number of > trusted managers allowing only them to make changes on CA's and > profiles. Even then, everything is verified from the logs, and, if > something unusual or even not authorized happens ( the alarms go on, > never happens), and then audited. > > []'s > > > Proteja o endereço de email de seus contatos como estou protegendo o seu. > Ao enviar mensagens para mais de um endereço use SEMPRE o > "Cco" (cópia oculta) ou "Bcc" (Blind carbon copy). > > /Esta mensagem é enviada exclusivamente a seu destinatário e pode conter > informações > confidenciais, protegidas por sigilo profissional. Sua utilização > desautorizada é ilegal e sujeita > o infrator às penas da lei. Se você a recebeu indevidamente, queira, por > gentileza, reenvia-la > ao emitente, esclarecendo o equívoco. > > This message is directed exclusively to its addressee and may contain > confidential data, > protected under professional secrecy rules. Its unauthorized use is > illegal and may subject > the transgressor to the law's penalties. If you're not the addressee, > please send it back, > elucidating the failure./ > > 2017-01-05 15:47 GMT-02:00 Carlos Rodrigues <cm...@eu... > <mailto:cm...@eu...>>: > > Hello, > > I don't have HSM device, there no another way to do that? > > Regards, > Carlos Rodrigues > > On Thu, 2017-01-05 at 15:05 -0200, Soluti Quintiliano wrote: >> HI, >> >> Out of the box, the easy option is to limit access to EJBCA CA >> interface through user permissions. You can then storage the AC >> Admin (Superadmin) certificate inside an HSM and ensure the access >> to this specific key with MofN. You ll also need to isolate the >> access to EJBCA's shell server... >> >> Att. >> >> >> Proteja o endereço de email de seus contatos como estou protegendo >> o seu. >> Ao enviar mensagens para mais de um endereço use SEMPRE o >> "Cco" (cópia oculta) ou "Bcc" (Blind carbon copy). >> >> /Esta mensagem é enviada exclusivamente a seu destinatário e pode >> conter informações >> confidenciais, protegidas por sigilo profissional. Sua utilização >> desautorizada é ilegal e sujeita >> o infrator às penas da lei. Se você a recebeu indevidamente, >> queira, por gentileza, reenvia-la >> ao emitente, esclarecendo o equívoco. >> >> This message is directed exclusively to its addressee and may >> contain confidential data, >> protected under professional secrecy rules. Its unauthorized use >> is illegal and may subject >> the transgressor to the law's penalties. If you're not the >> addressee, please send it back, >> elucidating the failure./ >> >> 2017-01-05 14:31 GMT-02:00 Carlos Rodrigues <cm...@eu... >> <mailto:cm...@eu...>>: >>> Hello, >>> >>> I would like to know how to configure EJBCA to requires more than >>> one person to active Certification Authority and prevent to >>> change the CA settings? >>> >>> Any one could help me? >>> >>> Regards, >>> Carlos Rodrigues >>> >>> On Wed, 2016-12-28 at 14:16 +0000, Carlos Rodrigues wrote: >>>> Hello, >>>> >>>> I need to create one Certification Authority that needs more >>>> than one person to open CA to do any CA operation. >>>> This should be including change CA to set approval settings. >>>> >>>> >>>> Regards, >>>> >>>> -- >>>> Carlos Rodrigues >>>> >>>> Engenheiro de Software Sénior >>>> >>>> Eurotux Informática, S.A. | www.eurotux.com >>>> <http://www.eurotux.com/> >>>> (t) +351 253 680 300 <tel:+351%20253%20680%20300> (m) +351 911 >>>> 926 110 <tel:+351%20911%20926%20110> >>>> >>>> ------------------------------------------------------------------------------ >>>> Check out the vibrant tech community on one of the world's most >>>> engaging tech sites, SlashDot.org! http://sdm.link/slashdot >>>> _______________________________________________ >>>> Ejbca-develop mailing list >>>> Ejb...@li... >>>> <mailto:Ejb...@li...> >>>> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >>>> <https://lists.sourceforge.net/lists/listinfo/ejbca-develop> >>> -- >>> Carlos Rodrigues >>> >>> Engenheiro de Software Sénior >>> >>> Eurotux Informática, S.A. | www.eurotux.com <http://www.eurotux.com/> >>> (t) +351 253 680 300 <tel:+351%20253%20680%20300> (m) +351 911 >>> 926 110 <tel:+351%20911%20926%20110> >>> >>> >>> ------------------------------------------------------------------------------ >>> Check out the vibrant tech community on one of the world's most >>> engaging tech sites, SlashDot.org! http://sdm.link/slashdot >>> _______________________________________________ >>> Ejbca-develop mailing list >>> Ejb...@li... >>> <mailto:Ejb...@li...> >>> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >>> <https://lists.sourceforge.net/lists/listinfo/ejbca-develop> >>> >> > -- > > Carlos Rodrigues > > Engenheiro de Software Sénior > > Eurotux Informática, S.A. | www.eurotux.com <http://www.eurotux.com/> > (t) +351 253 680 300 <tel:+351%20253%20680%20300> (m) +351 911 926 > 110 <tel:+351%20911%20926%20110> > > > > > ------------------------------------------------------------------------------ > Check out the vibrant tech community on one of the world's most > engaging tech sites, SlashDot.org! http://sdm.link/slashdot > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > -- --------- CardContact Systems GmbH |.##> <##.| Schülerweg 38 |# #| D-32429 Minden, Germany |# #| Phone +49 571 56149 |'##> <##'| http://www.cardcontact.de --------- Registergericht Bad Oeynhausen HRB 14880 Geschäftsführer Andreas Schwier -- --------- CardContact Systems GmbH |.##> <##.| Schülerweg 38 |# #| D-32429 Minden, Germany |# #| Phone +49 571 56149 |'##> <##'| http://www.cardcontact.de --------- Registergericht Bad Oeynhausen HRB 14880 Geschäftsführer Andreas Schwier ------------------------------------------------------------------------------ Check out the vibrant tech community on one of the world's most engaging tech sites, SlashDot.org! http://sdm.link/slashdot _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop > ------------------------------------------------------------------------------ Check out the vibrant tech community on one of the world's most engaging tech sites, SlashDot.org! http://sdm.link/slashdot > > > _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop -- Carlos Rodrigues Engenheiro de Software Sénior Eurotux Informática, S.A. | www.eurotux.com (t) +351 253 680 300 (m) +351 911 926 110 |
|
From: Willi T. <wil...@gm...> - 2017-01-05 18:54:08
|
You can achieve dual control by combining infrastructure access to CA and logical access using CA operator token. Infrastructure administrator would not be able to do operations with CA alone because of absence of authorization and CA operator wouldn't be able to do operations on CA without infrastructure administrator (or call this roles as you want). This will ensure dual control what you want. Logs and procedural design will ensure audit trails. WT On Thursday, January 5, 2017, Andreas Schwier < and...@ca...> wrote: > The SmartCard-HSM supports n-of-m authentication [1]. However this is > currently only supported via JCE, but integration with EJBCA is done via > PKCS#11 [2]. > > If there is serious demand, then we could make it work via PKCS#11 as well. > > Andreas > > [1] > https://www.smartcard-hsm.com/2015/10/10/Shared_Control_ > over_Key_Usage.html > [2] > https://www.smartcard-hsm.com/2014/09/05/Accessing_your_ > SmartCard-HSM_from_EJBCA.html > > On 01/05/2017 07:07 PM, Soluti Quintiliano wrote: > > Hummm...A smartcard or security token + password split between MofN, not > > great but still simple. > > > > You probably will have problems with backing this up. > > > > If you really need to segregate this, during the install EJBCA allows > > you to generate the Superadmin cert using a PKCS11 library so you can > > use a smartcard or token and have the superadmin cert protected. I > > personally wouldn't do this. Its easier to use the superadmin for > > initial config and then replace it for the CA operator's cert. > > > > Just out of curiosity, can you share you PKI architecture idea? I've > > been using EJBCA in large scale for 5 years and haven't had any issue > > regards limiting access to CA Administration. Using small number of > > trusted managers allowing only them to make changes on CA's and > > profiles. Even then, everything is verified from the logs, and, if > > something unusual or even not authorized happens ( the alarms go on, > > never happens), and then audited. > > > > []'s > > > > > > Proteja o endereço de email de seus contatos como estou protegendo o seu. > > Ao enviar mensagens para mais de um endereço use SEMPRE o > > "Cco" (cópia oculta) ou "Bcc" (Blind carbon copy). > > > > /Esta mensagem é enviada exclusivamente a seu destinatário e pode conter > > informações > > confidenciais, protegidas por sigilo profissional. Sua utilização > > desautorizada é ilegal e sujeita > > o infrator às penas da lei. Se você a recebeu indevidamente, queira, por > > gentileza, reenvia-la > > ao emitente, esclarecendo o equívoco. > > > > This message is directed exclusively to its addressee and may contain > > confidential data, > > protected under professional secrecy rules. Its unauthorized use is > > illegal and may subject > > the transgressor to the law's penalties. If you're not the addressee, > > please send it back, > > elucidating the failure./ > > > > 2017-01-05 15:47 GMT-02:00 Carlos Rodrigues <cm...@eu... > <javascript:;> > > <mailto:cm...@eu... <javascript:;>>>: > > > > Hello, > > > > I don't have HSM device, there no another way to do that? > > > > Regards, > > Carlos Rodrigues > > > > On Thu, 2017-01-05 at 15:05 -0200, Soluti Quintiliano wrote: > >> HI, > >> > >> Out of the box, the easy option is to limit access to EJBCA CA > >> interface through user permissions. You can then storage the AC > >> Admin (Superadmin) certificate inside an HSM and ensure the access > >> to this specific key with MofN. You ll also need to isolate the > >> access to EJBCA's shell server... > >> > >> Att. > >> > >> > >> Proteja o endereço de email de seus contatos como estou protegendo > >> o seu. > >> Ao enviar mensagens para mais de um endereço use SEMPRE o > >> "Cco" (cópia oculta) ou "Bcc" (Blind carbon copy). > >> > >> /Esta mensagem é enviada exclusivamente a seu destinatário e pode > >> conter informações > >> confidenciais, protegidas por sigilo profissional. Sua utilização > >> desautorizada é ilegal e sujeita > >> o infrator às penas da lei. Se você a recebeu indevidamente, > >> queira, por gentileza, reenvia-la > >> ao emitente, esclarecendo o equívoco. > >> > >> This message is directed exclusively to its addressee and may > >> contain confidential data, > >> protected under professional secrecy rules. Its unauthorized use > >> is illegal and may subject > >> the transgressor to the law's penalties. If you're not the > >> addressee, please send it back, > >> elucidating the failure./ > >> > >> 2017-01-05 14:31 GMT-02:00 Carlos Rodrigues <cm...@eu... > <javascript:;> > >> <mailto:cm...@eu... <javascript:;>>>: > >>> Hello, > >>> > >>> I would like to know how to configure EJBCA to requires more than > >>> one person to active Certification Authority and prevent to > >>> change the CA settings? > >>> > >>> Any one could help me? > >>> > >>> Regards, > >>> Carlos Rodrigues > >>> > >>> On Wed, 2016-12-28 at 14:16 +0000, Carlos Rodrigues wrote: > >>>> Hello, > >>>> > >>>> I need to create one Certification Authority that needs more > >>>> than one person to open CA to do any CA operation. > >>>> This should be including change CA to set approval settings. > >>>> > >>>> > >>>> Regards, > >>>> > >>>> -- > >>>> Carlos Rodrigues > >>>> > >>>> Engenheiro de Software Sénior > >>>> > >>>> Eurotux Informática, S.A. | www.eurotux.com > >>>> <http://www.eurotux.com/> > >>>> (t) +351 253 680 300 <tel:+351%20253%20680%20300> (m) +351 911 > >>>> 926 110 <tel:+351%20911%20926%20110> > >>>> > >>>> ------------------------------------------------------------ > ------------------ > >>>> Check out the vibrant tech community on one of the world's most > >>>> engaging tech sites, SlashDot.org! http://sdm.link/slashdot > >>>> _______________________________________________ > >>>> Ejbca-develop mailing list > >>>> Ejb...@li... <javascript:;> > >>>> <mailto:Ejb...@li... <javascript:;>> > >>>> https://lists.sourceforge.net/lists/listinfo/ejbca-develop > >>>> <https://lists.sourceforge.net/lists/listinfo/ejbca-develop> > >>> -- > >>> Carlos Rodrigues > >>> > >>> Engenheiro de Software Sénior > >>> > >>> Eurotux Informática, S.A. | www.eurotux.com < > http://www.eurotux.com/> > >>> (t) +351 253 680 300 <tel:+351%20253%20680%20300> (m) +351 911 > >>> 926 110 <tel:+351%20911%20926%20110> > >>> > >>> > >>> ------------------------------------------------------------ > ------------------ > >>> Check out the vibrant tech community on one of the world's most > >>> engaging tech sites, SlashDot.org! http://sdm.link/slashdot > >>> _______________________________________________ > >>> Ejbca-develop mailing list > >>> Ejb...@li... <javascript:;> > >>> <mailto:Ejb...@li... <javascript:;>> > >>> https://lists.sourceforge.net/lists/listinfo/ejbca-develop > >>> <https://lists.sourceforge.net/lists/listinfo/ejbca-develop> > >>> > >> > > -- > > > > Carlos Rodrigues > > > > Engenheiro de Software Sénior > > > > Eurotux Informática, S.A. | www.eurotux.com <http://www.eurotux.com/ > > > > (t) +351 253 680 300 <tel:+351%20253%20680%20300> (m) +351 911 926 > > 110 <tel:+351%20911%20926%20110> > > > > > > > > > > ------------------------------------------------------------ > ------------------ > > Check out the vibrant tech community on one of the world's most > > engaging tech sites, SlashDot.org! http://sdm.link/slashdot > > > > > > > > _______________________________________________ > > Ejbca-develop mailing list > > Ejb...@li... <javascript:;> > > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > > -- > > --------- CardContact Systems GmbH > |.##> <##.| Schülerweg 38 > |# #| D-32429 Minden, Germany > |# #| Phone +49 571 56149 > |'##> <##'| http://www.cardcontact.de > --------- Registergericht Bad Oeynhausen HRB 14880 > Geschäftsführer Andreas Schwier > > -- > > --------- CardContact Systems GmbH > |.##> <##.| Schülerweg 38 > |# #| D-32429 Minden, Germany > |# #| Phone +49 571 56149 > |'##> <##'| http://www.cardcontact.de > --------- Registergericht Bad Oeynhausen HRB 14880 > Geschäftsführer Andreas Schwier > > > > ------------------------------------------------------------ > ------------------ > Check out the vibrant tech community on one of the world's most > engaging tech sites, SlashDot.org! http://sdm.link/slashdot > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... <javascript:;> > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Andreas S. <and...@ca...> - 2017-01-05 18:43:47
|
The SmartCard-HSM supports n-of-m authentication [1]. However this is currently only supported via JCE, but integration with EJBCA is done via PKCS#11 [2]. If there is serious demand, then we could make it work via PKCS#11 as well. Andreas [1] https://www.smartcard-hsm.com/2015/10/10/Shared_Control_over_Key_Usage.html [2] https://www.smartcard-hsm.com/2014/09/05/Accessing_your_SmartCard-HSM_from_EJBCA.html On 01/05/2017 07:07 PM, Soluti Quintiliano wrote: > Hummm...A smartcard or security token + password split between MofN, not > great but still simple. > > You probably will have problems with backing this up. > > If you really need to segregate this, during the install EJBCA allows > you to generate the Superadmin cert using a PKCS11 library so you can > use a smartcard or token and have the superadmin cert protected. I > personally wouldn't do this. Its easier to use the superadmin for > initial config and then replace it for the CA operator's cert. > > Just out of curiosity, can you share you PKI architecture idea? I've > been using EJBCA in large scale for 5 years and haven't had any issue > regards limiting access to CA Administration. Using small number of > trusted managers allowing only them to make changes on CA's and > profiles. Even then, everything is verified from the logs, and, if > something unusual or even not authorized happens ( the alarms go on, > never happens), and then audited. > > []'s > > > Proteja o endereço de email de seus contatos como estou protegendo o seu. > Ao enviar mensagens para mais de um endereço use SEMPRE o > "Cco" (cópia oculta) ou "Bcc" (Blind carbon copy). > > /Esta mensagem é enviada exclusivamente a seu destinatário e pode conter > informações > confidenciais, protegidas por sigilo profissional. Sua utilização > desautorizada é ilegal e sujeita > o infrator às penas da lei. Se você a recebeu indevidamente, queira, por > gentileza, reenvia-la > ao emitente, esclarecendo o equívoco. > > This message is directed exclusively to its addressee and may contain > confidential data, > protected under professional secrecy rules. Its unauthorized use is > illegal and may subject > the transgressor to the law's penalties. If you're not the addressee, > please send it back, > elucidating the failure./ > > 2017-01-05 15:47 GMT-02:00 Carlos Rodrigues <cm...@eu... > <mailto:cm...@eu...>>: > > Hello, > > I don't have HSM device, there no another way to do that? > > Regards, > Carlos Rodrigues > > On Thu, 2017-01-05 at 15:05 -0200, Soluti Quintiliano wrote: >> HI, >> >> Out of the box, the easy option is to limit access to EJBCA CA >> interface through user permissions. You can then storage the AC >> Admin (Superadmin) certificate inside an HSM and ensure the access >> to this specific key with MofN. You ll also need to isolate the >> access to EJBCA's shell server... >> >> Att. >> >> >> Proteja o endereço de email de seus contatos como estou protegendo >> o seu. >> Ao enviar mensagens para mais de um endereço use SEMPRE o >> "Cco" (cópia oculta) ou "Bcc" (Blind carbon copy). >> >> /Esta mensagem é enviada exclusivamente a seu destinatário e pode >> conter informações >> confidenciais, protegidas por sigilo profissional. Sua utilização >> desautorizada é ilegal e sujeita >> o infrator às penas da lei. Se você a recebeu indevidamente, >> queira, por gentileza, reenvia-la >> ao emitente, esclarecendo o equívoco. >> >> This message is directed exclusively to its addressee and may >> contain confidential data, >> protected under professional secrecy rules. Its unauthorized use >> is illegal and may subject >> the transgressor to the law's penalties. If you're not the >> addressee, please send it back, >> elucidating the failure./ >> >> 2017-01-05 14:31 GMT-02:00 Carlos Rodrigues <cm...@eu... >> <mailto:cm...@eu...>>: >>> Hello, >>> >>> I would like to know how to configure EJBCA to requires more than >>> one person to active Certification Authority and prevent to >>> change the CA settings? >>> >>> Any one could help me? >>> >>> Regards, >>> Carlos Rodrigues >>> >>> On Wed, 2016-12-28 at 14:16 +0000, Carlos Rodrigues wrote: >>>> Hello, >>>> >>>> I need to create one Certification Authority that needs more >>>> than one person to open CA to do any CA operation. >>>> This should be including change CA to set approval settings. >>>> >>>> >>>> Regards, >>>> >>>> -- >>>> Carlos Rodrigues >>>> >>>> Engenheiro de Software Sénior >>>> >>>> Eurotux Informática, S.A. | www.eurotux.com >>>> <http://www.eurotux.com/> >>>> (t) +351 253 680 300 <tel:+351%20253%20680%20300> (m) +351 911 >>>> 926 110 <tel:+351%20911%20926%20110> >>>> >>>> ------------------------------------------------------------------------------ >>>> Check out the vibrant tech community on one of the world's most >>>> engaging tech sites, SlashDot.org! http://sdm.link/slashdot >>>> _______________________________________________ >>>> Ejbca-develop mailing list >>>> Ejb...@li... >>>> <mailto:Ejb...@li...> >>>> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >>>> <https://lists.sourceforge.net/lists/listinfo/ejbca-develop> >>> -- >>> Carlos Rodrigues >>> >>> Engenheiro de Software Sénior >>> >>> Eurotux Informática, S.A. | www.eurotux.com <http://www.eurotux.com/> >>> (t) +351 253 680 300 <tel:+351%20253%20680%20300> (m) +351 911 >>> 926 110 <tel:+351%20911%20926%20110> >>> >>> >>> ------------------------------------------------------------------------------ >>> Check out the vibrant tech community on one of the world's most >>> engaging tech sites, SlashDot.org! http://sdm.link/slashdot >>> _______________________________________________ >>> Ejbca-develop mailing list >>> Ejb...@li... >>> <mailto:Ejb...@li...> >>> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >>> <https://lists.sourceforge.net/lists/listinfo/ejbca-develop> >>> >> > -- > > Carlos Rodrigues > > Engenheiro de Software Sénior > > Eurotux Informática, S.A. | www.eurotux.com <http://www.eurotux.com/> > (t) +351 253 680 300 <tel:+351%20253%20680%20300> (m) +351 911 926 > 110 <tel:+351%20911%20926%20110> > > > > > ------------------------------------------------------------------------------ > Check out the vibrant tech community on one of the world's most > engaging tech sites, SlashDot.org! http://sdm.link/slashdot > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > -- --------- CardContact Systems GmbH |.##> <##.| Schülerweg 38 |# #| D-32429 Minden, Germany |# #| Phone +49 571 56149 |'##> <##'| http://www.cardcontact.de --------- Registergericht Bad Oeynhausen HRB 14880 Geschäftsführer Andreas Schwier -- --------- CardContact Systems GmbH |.##> <##.| Schülerweg 38 |# #| D-32429 Minden, Germany |# #| Phone +49 571 56149 |'##> <##'| http://www.cardcontact.de --------- Registergericht Bad Oeynhausen HRB 14880 Geschäftsführer Andreas Schwier |
|
From: Carlos R. <cm...@eu...> - 2017-01-05 18:35:15
|
On Thu, 2017-01-05 at 16:07 -0200, Soluti Quintiliano wrote: > > Hummm...A smartcard or security token + password split between MofN, not great but still simple. > > You probably will have problems with backing this up. > > > > > > If you really need to segregate this, during the install EJBCA allows you to generate the Superadmin cert using a PKCS11 library so you can use a smartcard or token and have the superadmin cert protected. I personally wouldn't do this. Its easier to use the superadmin for initial config and then replace it for the CA operator's cert. > I already have this implemented, but with one soft token and for each CA operator. > > Just out of curiosity, can you share you PKI architecture idea? I've been using EJBCA in large scale for 5 years and haven't had any issue regards limiting access to CA Administration. Using small number of trusted managers allowing only them to make changes on CA's and profiles. Even then, everything is verified from the logs, and, if something unusual or even not authorized happens ( the alarms go on, never happens), and then audited. The idea is to have a CA that need a minimal of 2 administrator's approvals to open CA to create, renew or revoke certificates. > > > []'s > > > Proteja o endereço de email de seus contatos como estou protegendo o seu. > Ao enviar mensagens para mais de um endereço use SEMPRE o > "Cco" (cópia oculta) ou "Bcc" (Blind carbon copy).> > > > > > > > > > Esta mensagem é enviada exclusivamente a seu destinatário e pode conter informações confidenciais, protegidas por sigilo profissional. Sua utilização desautorizada é ilegal e sujeita o infrator às penas da lei. Se você a recebeu indevidamente, queira, por gentileza, reenvia-la ao emitente, esclarecendo o equívoco. This message is directed exclusively to its addressee and may contain confidential data, protected under professional secrecy rules. Its unauthorized use is illegal and may subject the transgressor to the law's penalties. If you're not the addressee, please send it back, elucidating the failure. > > 2017-01-05 15:47 GMT-02:00 Carlos Rodrigues > > <cm...@eu...>: > > Hello, > > > > I don't have HSM device, there no another way to do that? > > > > Regards, > > Carlos Rodrigues > > > > On Thu, 2017-01-05 at 15:05 -0200, Soluti Quintiliano wrote: > > > > > > > > > HI, > > > Out of the box, the easy option is to limit access to EJBCA CA interface through user permissions. You can then storage the AC Admin (Superadmin) certificate inside an HSM and ensure the access to this specific key with MofN. You ll also need to isolate the access to EJBCA's shell server...> > > Att. > > > > > > > > > Proteja o endereço de email de seus contatos como estou protegendo o seu. > > > Ao enviar mensagens para mais de um endereço use SEMPRE o > > > "Cco" (cópia oculta) ou "Bcc" (Blind carbon copy).> > > > > > > > > > > > > > > > > > > > > > > > > > > > > > Esta mensagem é enviada exclusivamente a seu destinatário e pode conter informações confidenciais, protegidas por sigilo profissional. Sua utilização desautorizada é ilegal e sujeita o infrator às penas da lei. Se você a recebeu indevidamente, queira, por gentileza, reenvia-la ao emitente, esclarecendo o equívoco. This message is directed exclusively to its addressee and may contain confidential data, protected under professional secrecy rules. Its unauthorized use is illegal and may subject the transgressor to the law's penalties. If you're not the addressee, please send it back, elucidating the failure. > > > > > > 2017-01-05 14:31 GMT-02:00 Carlos Rodrigues > > > > > > <cm...@eu...>: > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > Hello, > > > > > > > > I would like to know how to configure EJBCA to requires more than one person to active Certification Authority and prevent to change the CA settings? > > > > > > > > Any one could help me? > > > > > > > > Regards, > > > > Carlos Rodrigues > > > > > > > > On Wed, 2016-12-28 at 14:16 +0000, Carlos Rodrigues wrote: > > > > > Hello, > > > > > > > > > > I need to create one Certification Authority that needs more than one person to open CA to do any CA operation. > > > > > This should be including change CA to set approval settings. > > > > > > > > > > > > > > > Regards, > > > > > > > > > > -- > > > > > > > > > > > > > > > > > > > > > > > > > Carlos Rodrigues > > > > > Engenheiro de Software Sénior> > > > > Eurotux Informática, S.A. | www.eurotux.com (t) +351 253 680 300 (m) +351 911 926 110> > > > > > > > > > > > > > > > > > > > ------------------------------------------------------------------------------ Check out the vibrant tech community on one of the world's most engaging tech sites, SlashDot.org! http://sdm.link/slashdot > > > > > > > > > > > > > > > > > > > > _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > -- > > > > > > > > > > > > > > > > > > > > Carlos Rodrigues > > > > Engenheiro de Software Sénior> > > > Eurotux Informática, S.A. | www.eurotux.com (t) +351 253 680 300 (m) +351 911 926 110> > > > ------------------------------------------------------------------------------ Check out the vibrant tech community on one of the world's most engaging tech sites, SlashDot.org! http://sdm.link/slashdot _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > > -- > > > > > > > > > > Carlos Rodrigues > > Engenheiro de Software Sénior> > Eurotux Informática, S.A. | www.eurotux.com (t) +351 253 680 300 (m) +351 911 926 110> > -- Carlos Rodrigues Engenheiro de Software Sénior Eurotux Informática, S.A. | www.eurotux.com (t) +351 253 680 300 (m) +351 911 926 110 |
|
From: Soluti Q. <qui...@so...> - 2017-01-05 18:08:08
|
Hummm...A smartcard or security token + password split between MofN, not great but still simple. You probably will have problems with backing this up. If you really need to segregate this, during the install EJBCA allows you to generate the Superadmin cert using a PKCS11 library so you can use a smartcard or token and have the superadmin cert protected. I personally wouldn't do this. Its easier to use the superadmin for initial config and then replace it for the CA operator's cert. Just out of curiosity, can you share you PKI architecture idea? I've been using EJBCA in large scale for 5 years and haven't had any issue regards limiting access to CA Administration. Using small number of trusted managers allowing only them to make changes on CA's and profiles. Even then, everything is verified from the logs, and, if something unusual or even not authorized happens ( the alarms go on, never happens), and then audited. []'s Proteja o endereço de email de seus contatos como estou protegendo o seu. Ao enviar mensagens para mais de um endereço use SEMPRE o "Cco" (cópia oculta) ou "Bcc" (Blind carbon copy). *Esta mensagem é enviada exclusivamente a seu destinatário e pode conter informações confidenciais, protegidas por sigilo profissional. Sua utilização desautorizada é ilegal e sujeitao infrator às penas da lei. Se você a recebeu indevidamente, queira, por gentileza, reenvia-laao emitente, esclarecendo o equívoco. This message is directed exclusively to its addressee and may contain confidential data,protected under professional secrecy rules. Its unauthorized use is illegal and may subjectthe transgressor to the law's penalties. If you're not the addressee, please send it back, elucidating the failure.* 2017-01-05 15:47 GMT-02:00 Carlos Rodrigues <cm...@eu...>: > Hello, > > I don't have HSM device, there no another way to do that? > > Regards, > Carlos Rodrigues > > On Thu, 2017-01-05 at 15:05 -0200, Soluti Quintiliano wrote: > > HI, > > Out of the box, the easy option is to limit access to EJBCA CA interface > through user permissions. You can then storage the AC Admin (Superadmin) > certificate inside an HSM and ensure the access to this specific key with > MofN. You ll also need to isolate the access to EJBCA's shell server... > > Att. > > > Proteja o endereço de email de seus contatos como estou protegendo o seu. > Ao enviar mensagens para mais de um endereço use SEMPRE o > "Cco" (cópia oculta) ou "Bcc" (Blind carbon copy). > > > > > > > > > > *Esta mensagem é enviada exclusivamente a seu destinatário e pode conter > informações confidenciais, protegidas por sigilo profissional. Sua > utilização desautorizada é ilegal e sujeitao infrator às penas da lei. Se > você a recebeu indevidamente, queira, por gentileza, reenvia-laao emitente, > esclarecendo o equívoco. This message is directed exclusively to its > addressee and may contain confidential data,protected under professional > secrecy rules. Its unauthorized use is illegal and may subjectthe > transgressor to the law's penalties. If you're not the addressee, please > send it back, elucidating the failure.* > > 2017-01-05 14:31 GMT-02:00 Carlos Rodrigues <cm...@eu...>: > > Hello, > > I would like to know how to configure EJBCA to requires more than one > person to active Certification Authority and prevent to change the CA > settings? > > Any one could help me? > > Regards, > Carlos Rodrigues > > On Wed, 2016-12-28 at 14:16 +0000, Carlos Rodrigues wrote: > > Hello, > > I need to create one Certification Authority that needs more than one > person to open CA to do any CA operation. > This should be including change CA to set approval settings. > > > Regards, > > -- > > Carlos Rodrigues > > Engenheiro de Software Sénior > > Eurotux Informática, S.A. | www.eurotux.com > (t) +351 253 680 300 <+351%20253%20680%20300> (m) +351 911 926 110 > <+351%20911%20926%20110> > > ------------------------------------------------------------------------------ > Check out the vibrant tech community on one of the world's most > engaging tech sites, SlashDot.org! http://sdm.link/slashdot > > _______________________________________________ > Ejbca-develop mailing lis...@li...://lists.sourceforge.net/lists/listinfo/ejbca-develop > > -- > > Carlos Rodrigues > > Engenheiro de Software Sénior > > Eurotux Informática, S.A. | www.eurotux.com > (t) +351 253 680 300 <+351%20253%20680%20300> (m) +351 911 926 110 > <+351%20911%20926%20110> > > > ------------------------------------------------------------ > ------------------ > Check out the vibrant tech community on one of the world's most > engaging tech sites, SlashDot.org! http://sdm.link/slashdot > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > -- > > Carlos Rodrigues > > Engenheiro de Software Sénior > > Eurotux Informática, S.A. | www.eurotux.com > (t) +351 253 680 300 <+351%20253%20680%20300> (m) +351 911 926 110 > <+351%20911%20926%20110> > > |
|
From: Carlos R. <cm...@eu...> - 2017-01-05 17:47:18
|
Hello, I don't have HSM device, there no another way to do that? Regards, Carlos Rodrigues On Thu, 2017-01-05 at 15:05 -0200, Soluti Quintiliano wrote: > HI, > > > > > > Out of the box, the easy option is to limit access to EJBCA CA interface through user permissions. You can then storage the AC Admin (Superadmin) certificate inside an HSM and ensure the access to this specific key with MofN. You ll also need to isolate the access to EJBCA's shell server... > > Att. > > > > Proteja o endereço de email de seus contatos como estou protegendo o seu. > Ao enviar mensagens para mais de um endereço use SEMPRE o > > "Cco" (cópia oculta) ou "Bcc" (Blind carbon copy). > > > Esta mensagem é enviada exclusivamente a seu destinatário e pode conter informações > > > confidenciais, protegidas por sigilo profissional. Sua utilização desautorizada é ilegal e sujeita > > o infrator às penas da lei. Se você a recebeu indevidamente, queira, por gentileza, reenvia-la > ao emitente, esclarecendo o equívoco. > > > > This message is directed exclusively to its addressee and may contain confidential data, > > protected under professional secrecy rules. Its unauthorized use is illegal and may subject > > the transgressor to the law's penalties. If you're not the addressee, please send it back, > > elucidating the failure. > > > > > > > > > > 2017-01-05 14:31 GMT-02:00 Carlos Rodrigues <cm...@eu...>: > > Hello, > > > > > > I would like to know how to configure EJBCA to requires more than one person to active Certification Authority and prevent to change the CA settings? > > > > Any one could help me? > > > > Regards, > > Carlos Rodrigues > > > > On Wed, 2016-12-28 at 14:16 +0000, Carlos Rodrigues wrote: > > > > > > > Hello, > > > > > > I need to create one Certification Authority that needs more than one person to open CA to do any CA operation. > > > This should be including change CA to set approval settings. > > > > > > > > > > > > Regards, > > > > > > -- > > > Carlos Rodrigues > > > > > > Engenheiro de Software Sénior > > > > > > Eurotux Informática, S.A. | www.eurotux.com > > > (t) +351 253 680 300 (m) +351 911 926 110 > > > > > > > > > > > > > > > > > > --------------------------------------------------------------- --------------- > > > Check out the vibrant tech community on one of the world's most > > > > > > engaging tech sites, SlashDot.org! http://sdm.link/slashdot______ _________________________________________ > > > Ejbca-develop mailing list > > > Ejb...@li... > > > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > -- > > Carlos Rodrigues > > > > Engenheiro de Software Sénior > > > > Eurotux Informática, S.A. | www.eurotux.com > > (t) +351 253 680 300 (m) +351 911 926 110 > > > > > > > > > > > > ----------------------------------------------------------------- ------------- > > > > Check out the vibrant tech community on one of the world's most > > > > engaging tech sites, SlashDot.org! http://sdm.link/slashdot > > _______________________________________________ > > > > Ejbca-develop mailing list > > > > Ejb...@li... > > > > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > > > > -- Carlos Rodrigues Engenheiro de Software Sénior Eurotux Informática, S.A. | www.eurotux.com (t) +351 253 680 300 (m) +351 911 926 110 |
|
From: Soluti Q. <qui...@so...> - 2017-01-05 17:33:58
|
HI, Out of the box, the easy option is to limit access to EJBCA CA interface through user permissions. You can then storage the AC Admin (Superadmin) certificate inside an HSM and ensure the access to this specific key with MofN. You ll also need to isolate the access to EJBCA's shell server... Att. Proteja o endereço de email de seus contatos como estou protegendo o seu. Ao enviar mensagens para mais de um endereço use SEMPRE o "Cco" (cópia oculta) ou "Bcc" (Blind carbon copy). *Esta mensagem é enviada exclusivamente a seu destinatário e pode conter informações confidenciais, protegidas por sigilo profissional. Sua utilização desautorizada é ilegal e sujeitao infrator às penas da lei. Se você a recebeu indevidamente, queira, por gentileza, reenvia-laao emitente, esclarecendo o equívoco. This message is directed exclusively to its addressee and may contain confidential data,protected under professional secrecy rules. Its unauthorized use is illegal and may subjectthe transgressor to the law's penalties. If you're not the addressee, please send it back, elucidating the failure.* 2017-01-05 14:31 GMT-02:00 Carlos Rodrigues <cm...@eu...>: > Hello, > > I would like to know how to configure EJBCA to requires more than one > person to active Certification Authority and prevent to change the CA > settings? > > Any one could help me? > > Regards, > Carlos Rodrigues > > On Wed, 2016-12-28 at 14:16 +0000, Carlos Rodrigues wrote: > > Hello, > > I need to create one Certification Authority that needs more than one > person to open CA to do any CA operation. > This should be including change CA to set approval settings. > > > Regards, > > -- > > Carlos Rodrigues > > Engenheiro de Software Sénior > > Eurotux Informática, S.A. | www.eurotux.com > (t) +351 253 680 300 <+351%20253%20680%20300> (m) +351 911 926 110 > <+351%20911%20926%20110> > > ------------------------------------------------------------------------------ > Check out the vibrant tech community on one of the world's most > engaging tech sites, SlashDot.org! http://sdm.link/slashdot > > _______________________________________________ > Ejbca-develop mailing lis...@li...://lists.sourceforge.net/lists/listinfo/ejbca-develop > > -- > > Carlos Rodrigues > > Engenheiro de Software Sénior > > Eurotux Informática, S.A. | www.eurotux.com > (t) +351 253 680 300 <+351%20253%20680%20300> (m) +351 911 926 110 > <+351%20911%20926%20110> > > > ------------------------------------------------------------ > ------------------ > Check out the vibrant tech community on one of the world's most > engaging tech sites, SlashDot.org! http://sdm.link/slashdot > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > |
|
From: Carlos R. <cm...@eu...> - 2017-01-05 16:31:13
|
Hello, I would like to know how to configure EJBCA to requires more than one person to active Certification Authority and prevent to change the CA settings? Any one could help me? Regards, Carlos Rodrigues On Wed, 2016-12-28 at 14:16 +0000, Carlos Rodrigues wrote: > Hello, > > > I need to create one Certification Authority that needs more than one person to open CA to do any CA operation. > This should be including change CA to set approval settings. > > > > Regards, > > -- > Carlos Rodrigues > > Engenheiro de Software Sénior > > Eurotux Informática, S.A. | www.eurotux.com > (t) +351 253 680 300 (m) +351 911 926 110 > > > > ------------------------------------------------------------------- ----------- > Check out the vibrant tech community on one of the world's most > > engaging tech sites, SlashDot.org! http://sdm.link/slashdot__________ _____________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop -- Carlos Rodrigues Engenheiro de Software Sénior Eurotux Informática, S.A. | www.eurotux.com (t) +351 253 680 300 (m) +351 911 926 110 |
|
From: Willi T. <wil...@gm...> - 2017-01-02 09:39:08
|
Hello Tomas, I am using EJBCA Community 6.5.0. WT On Monday, January 2, 2017, Tomas Gustavsson <to...@pr...> wrote: > > Hi, > > What version of Community? > > Yes, in Enterprise database protection works with publishing. > > Regards, > Tomas > > On 2017-01-02 10:21, Willi Trace wrote: > > Hello Tomas, > > > > I am using Community version of EJBCA with rewritten VA Publisher from > > older release of Community version. > > > > Does it mean, that in Enterprise version, the database protection in VA > > Publisher works (is implemented)? > > > > WT > > > > On Monday, January 2, 2017, Tomas Gustavsson <to...@pr... > <javascript:;> > > <mailto:to...@pr... <javascript:;>>> wrote: > > > > > > Hi Willi, > > > > If you are using database integrity protection you are using EJBCA > > Enterprise? > > > > In that case you should contact PrimeKey Support to get a good > > resolution, which there is for Enterprise. > > > > Kind regards, > > Tomas > > ********** > > PrimeKey Solutions AB > > Lundagatan 16, 171 63 Solna, Sweden > > Mob: +46 (0)707421096 > > Internet: www.primekey.se <http://www.primekey.se> > > Twitter: twitter.com/primekeyPKI <http://twitter.com/primekeyPKI> > > ********** > > > > On 2016-12-29 13:35, Willi Trace wrote: > > > Hello, > > > > > > I have a setup with one VA as OCSP responder and one CA which > > > has configured Validation Authority Publisher to publish CRLs and > > issued > > > certificated to VA. > > > > > > VA has enabled database integrity protection. > > > > > > The problem is that when CRL or certificate is published from CA > to VA > > > database, it will not have rowprotection and the VA will handle > > this as > > > exception, thus not working. > > > > > > How to handle this? Is there any way how to add rowprotection when > > > publishing through VAlidation Authority Publisher? I don't want to > > > disable database protection on VA. > > > > > > With regards, > > > WT > > > > > > > > > > > ------------------------------------------------------------ > ------------------ > > > Check out the vibrant tech community on one of the world's most > > > engaging tech sites, SlashDot.org! http://sdm.link/slashdot > > > > > > > > > > > > _______________________________________________ > > > Ejbca-develop mailing list > > > Ejb...@li... <javascript:;> <javascript:;> > > > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > <https://lists.sourceforge.net/lists/listinfo/ejbca-develop> > > > > > > > ------------------------------------------------------------ > ------------------ > > Check out the vibrant tech community on one of the world's most > > engaging tech sites, SlashDot.org! http://sdm.link/slashdot > > _______________________________________________ > > Ejbca-develop mailing list > > Ejb...@li... <javascript:;> <javascript:;> > > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > <https://lists.sourceforge.net/lists/listinfo/ejbca-develop> > > > > > > > > ------------------------------------------------------------ > ------------------ > > Check out the vibrant tech community on one of the world's most > > engaging tech sites, SlashDot.org! http://sdm.link/slashdot > > > > > > > > _______________________________________________ > > Ejbca-develop mailing list > > Ejb...@li... <javascript:;> > > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > ------------------------------------------------------------ > ------------------ > Check out the vibrant tech community on one of the world's most > engaging tech sites, SlashDot.org! http://sdm.link/slashdot > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... <javascript:;> > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Tomas G. <to...@pr...> - 2017-01-02 09:31:28
|
Hi, What version of Community? Yes, in Enterprise database protection works with publishing. Regards, Tomas On 2017-01-02 10:21, Willi Trace wrote: > Hello Tomas, > > I am using Community version of EJBCA with rewritten VA Publisher from > older release of Community version. > > Does it mean, that in Enterprise version, the database protection in VA > Publisher works (is implemented)? > > WT > > On Monday, January 2, 2017, Tomas Gustavsson <to...@pr... > <mailto:to...@pr...>> wrote: > > > Hi Willi, > > If you are using database integrity protection you are using EJBCA > Enterprise? > > In that case you should contact PrimeKey Support to get a good > resolution, which there is for Enterprise. > > Kind regards, > Tomas > ********** > PrimeKey Solutions AB > Lundagatan 16, 171 63 Solna, Sweden > Mob: +46 (0)707421096 > Internet: www.primekey.se <http://www.primekey.se> > Twitter: twitter.com/primekeyPKI <http://twitter.com/primekeyPKI> > ********** > > On 2016-12-29 13:35, Willi Trace wrote: > > Hello, > > > > I have a setup with one VA as OCSP responder and one CA which > > has configured Validation Authority Publisher to publish CRLs and > issued > > certificated to VA. > > > > VA has enabled database integrity protection. > > > > The problem is that when CRL or certificate is published from CA to VA > > database, it will not have rowprotection and the VA will handle > this as > > exception, thus not working. > > > > How to handle this? Is there any way how to add rowprotection when > > publishing through VAlidation Authority Publisher? I don't want to > > disable database protection on VA. > > > > With regards, > > WT > > > > > > > ------------------------------------------------------------------------------ > > Check out the vibrant tech community on one of the world's most > > engaging tech sites, SlashDot.org! http://sdm.link/slashdot > > > > > > > > _______________________________________________ > > Ejbca-develop mailing list > > Ejb...@li... <javascript:;> > > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > <https://lists.sourceforge.net/lists/listinfo/ejbca-develop> > > > > ------------------------------------------------------------------------------ > Check out the vibrant tech community on one of the world's most > engaging tech sites, SlashDot.org! http://sdm.link/slashdot > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... <javascript:;> > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > <https://lists.sourceforge.net/lists/listinfo/ejbca-develop> > > > > ------------------------------------------------------------------------------ > Check out the vibrant tech community on one of the world's most > engaging tech sites, SlashDot.org! http://sdm.link/slashdot > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Willi T. <wil...@gm...> - 2017-01-02 09:22:02
|
Hello Tomas, I am using Community version of EJBCA with rewritten VA Publisher from older release of Community version. Does it mean, that in Enterprise version, the database protection in VA Publisher works (is implemented)? WT On Monday, January 2, 2017, Tomas Gustavsson <to...@pr...> wrote: > > Hi Willi, > > If you are using database integrity protection you are using EJBCA > Enterprise? > > In that case you should contact PrimeKey Support to get a good > resolution, which there is for Enterprise. > > Kind regards, > Tomas > ********** > PrimeKey Solutions AB > Lundagatan 16, 171 63 Solna, Sweden > Mob: +46 (0)707421096 > Internet: www.primekey.se > Twitter: twitter.com/primekeyPKI > ********** > > On 2016-12-29 13:35, Willi Trace wrote: > > Hello, > > > > I have a setup with one VA as OCSP responder and one CA which > > has configured Validation Authority Publisher to publish CRLs and issued > > certificated to VA. > > > > VA has enabled database integrity protection. > > > > The problem is that when CRL or certificate is published from CA to VA > > database, it will not have rowprotection and the VA will handle this as > > exception, thus not working. > > > > How to handle this? Is there any way how to add rowprotection when > > publishing through VAlidation Authority Publisher? I don't want to > > disable database protection on VA. > > > > With regards, > > WT > > > > > > ------------------------------------------------------------ > ------------------ > > Check out the vibrant tech community on one of the world's most > > engaging tech sites, SlashDot.org! http://sdm.link/slashdot > > > > > > > > _______________________________________________ > > Ejbca-develop mailing list > > Ejb...@li... <javascript:;> > > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > ------------------------------------------------------------ > ------------------ > Check out the vibrant tech community on one of the world's most > engaging tech sites, SlashDot.org! http://sdm.link/slashdot > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... <javascript:;> > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Tomas G. <to...@pr...> - 2017-01-02 09:16:42
|
Hi Willi, If you are using database integrity protection you are using EJBCA Enterprise? In that case you should contact PrimeKey Support to get a good resolution, which there is for Enterprise. Kind regards, Tomas ********** PrimeKey Solutions AB Lundagatan 16, 171 63 Solna, Sweden Mob: +46 (0)707421096 Internet: www.primekey.se Twitter: twitter.com/primekeyPKI ********** On 2016-12-29 13:35, Willi Trace wrote: > Hello, > > I have a setup with one VA as OCSP responder and one CA which > has configured Validation Authority Publisher to publish CRLs and issued > certificated to VA. > > VA has enabled database integrity protection. > > The problem is that when CRL or certificate is published from CA to VA > database, it will not have rowprotection and the VA will handle this as > exception, thus not working. > > How to handle this? Is there any way how to add rowprotection when > publishing through VAlidation Authority Publisher? I don't want to > disable database protection on VA. > > With regards, > WT > > > ------------------------------------------------------------------------------ > Check out the vibrant tech community on one of the world's most > engaging tech sites, SlashDot.org! http://sdm.link/slashdot > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Willi T. <wil...@gm...> - 2016-12-29 12:35:29
|
Hello, I have a setup with one VA as OCSP responder and one CA which has configured Validation Authority Publisher to publish CRLs and issued certificated to VA. VA has enabled database integrity protection. The problem is that when CRL or certificate is published from CA to VA database, it will not have rowprotection and the VA will handle this as exception, thus not working. How to handle this? Is there any way how to add rowprotection when publishing through VAlidation Authority Publisher? I don't want to disable database protection on VA. With regards, WT |
|
From: Carlos R. <cm...@eu...> - 2016-12-28 14:17:00
|
Hello, I need to create one Certification Authority that needs more than one person to open CA to do any CA operation. This should be including change CA to set approval settings. Regards, -- Carlos Rodrigues Engenheiro de Software Sénior Eurotux Informática, S.A. | www.eurotux.com (t) +351 253 680 300 (m) +351 911 926 110 |
|
From: Ramakrishna, R. <Ram...@co...> - 2016-12-16 11:09:24
|
Hi,
I had installed the EJBCA server and it was working fine.
I had to power cycle the system for some reason after which I'm not able to open the adminweb. I have run "standalone.sh" after restarting the system .
I get the following error:
"
Authorization Denied
Cause : Authentication failed for certificate: CN=SuperAdmin
"
I have loaded the certificate properly in the browser and also the certificate is still valid.
But it throws error.
On the JBOSS console I get following error.
"
12:44:28,984 INFO [org.ejbca.core.ejb.authentication.web.WebAuthenticationProviderSessionBean] (http--0.0.0.0-8443-2) The certificate is revoked or cannot be located in the database. SubjectDN 'CN=SuperAdmin'.
"
If I send certificate authentication (IR or KUR) from client then CA server is authenticating the client.
Only adminweb is not accessible.
Could you please let me know if there is anything wrong.
Thanks
Ramya
|
|
From: Tomas G. <to...@pr...> - 2016-12-01 09:00:36
|
Your error is in your SCEP client. You are not encoding the key usage extension correctly. Cheers, Tomas ********** PrimeKey Solutions AB Lundagatan 16, 171 63 Solna, Sweden Mob: +46 (0)707421096 Internet: https://www.primekey.se/ Twitter: twitter.com/primekeyPKI ********** On 2016-12-01 04:42, P Ghosh wrote: > java.lang.IllegalArgumentException: illegal object in getInstance: > org.bouncycastle.asn1.DEROctetString > > at org.bouncycastle.asn1.DERBitString.getInstance(Unknown Source) > [bcprov-jdk15on-154.jar:1.54.0] > > at org.bouncycastle.asn1.x509.KeyUsage.getInstance(Unknown Source) > [bcprov-jdk15on-154.jar:1.54.0] > > at org.bouncycastle.asn1.x509.KeyUsage.fromExtensions(Unknown > Source) [bcprov-jdk15on-154.jar:1.54.0] > |
|
From: P G. <p....@ve...> - 2016-12-01 04:11:00
|
Hello,
My environment is EJBCA 6.5 built in OpenJDK 8 on Windows 7, JBOSS EAP 6.4
using BouncyCastle 1.54.
The basic deployment seems to be working fine and I'm able to create SCEP
alias (SCEPCA) and End Entity (SCEP-Usr1) using the Admin web GUI. I'm using
the End-entity Enrolment Code as the PKCS10 ChallengePassword in the SCEP
request.
I've build a SCEP client test program to connect (on localhost); the
response to the initial SCEP cmd "GetCACertChain" seems to work fine but
when I send the PKCS10 CSR with SCEP cmd "PKIOperation" , I'm getting an
error.
Note: I've tried building and deploying the server on Ubuntu 14 as well and
get similar errors.
Thanks in advance for any help on this.
Here's the sever.log from JBOSS :
07:55:01,382 INFO [org.jboss.as] (Controller Boot Thread) JBAS015961: Http
management interface listening on http://127.0.0.1:9990/management
07:55:01,383 INFO [org.jboss.as] (Controller Boot Thread) JBAS015951: Admin
console listening on http://127.0.0.1:9990
07:55:01,385 INFO [org.jboss.as] (Controller Boot Thread) JBAS015874: JBoss
EAP 6.4.0.GA (AS 7.5.0.Final-redhat-21) started in 37953ms - Started 2806 of
2843 services (101 services are lazy, passive or on-demand)
07:55:36,429 INFO [org.ejbca.ui.web.protocol.ScepServlet]
(http-/0.0.0.0:8080-1) Received a SCEP message from 127.0.0.1.
07:55:36,519 INFO [org.cesecore.audit.impl.log4j.Log4jDevice]
(http-/0.0.0.0:8080-1) 2016-12-01
07:55:36+05:30;ACCESS_CONTROL;SUCCESS;ACCESSCONTROL;CORE;127.0.0.1;;;;resour
ce0=/ca/1652389506
07:55:36,546 INFO [org.cesecore.audit.impl.log4j.Log4jDevice]
(http-/0.0.0.0:8080-1) 2016-12-01
07:55:36+05:30;ACCESS_CONTROL;SUCCESS;ACCESSCONTROL;CORE;127.0.0.1;;;;resour
ce0=/ca/1652389506
07:55:36,651 INFO [org.cesecore.keys.token.SoftCryptoToken]
(http-/0.0.0.0:8080-1) Activated Crypto Token with id 425137210.
07:55:36,896 INFO [org.ejbca.ui.web.protocol.ScepServlet]
(http-/0.0.0.0:8080-1) Sent a SCEP GetCACertChain response to 127.0.0.1.
07:56:09,558 INFO [org.ejbca.ui.web.protocol.ScepServlet]
(http-/0.0.0.0:8080-1) Received a SCEP message from 127.0.0.1.
07:56:09,664 INFO [org.cesecore.keys.token.SoftCryptoToken]
(http-/0.0.0.0:8080-1) Activated Crypto Token with id 425137210.
07:56:09,788 INFO [org.cesecore.audit.impl.log4j.Log4jDevice]
(http-/0.0.0.0:8080-1) 2016-12-01
07:56:09+05:30;CA_USERAUTH;SUCCESS;CA;EJBCA;127.0.0.1;1652389506;;SCEP-Usr1;
msg=Authenticated user SCEP-Usr1.
07:56:09,827 ERROR [org.jboss.as.ejb3] (http-/0.0.0.0:8080-1) JBAS014268:
Failure in caller transaction.: java.lang.IllegalArgumentException: illegal
object in getInstance: org.bouncycastle.asn1.DEROctetString
at org.bouncycastle.asn1.DERBitString.getInstance(Unknown Source)
[bcprov-jdk15on-154.jar:1.54.0]
at org.bouncycastle.asn1.x509.KeyUsage.getInstance(Unknown Source)
[bcprov-jdk15on-154.jar:1.54.0]
at org.bouncycastle.asn1.x509.KeyUsage.fromExtensions(Unknown Source)
[bcprov-jdk15on-154.jar:1.54.0]
at
org.cesecore.certificates.certificate.CertificateCreateSessionBean.createCer
tificate(CertificateCreateSessionBean.java:189) [cesecore-ejb.jar:]
at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
[rt.jar:1.8.0_111-1-redhat]
at
sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62
) [rt.jar:1.8.0_111-1-redhat]
at
sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl
.java:43) [rt.jar:1.8.0_111-1-redhat]
at java.lang.reflect.Method.invoke(Method.java:498)
[rt.jar:1.8.0_111-1-redhat]
at
org.jboss.as.ee.component.ManagedReferenceMethodInterceptor.processInvocatio
n(ManagedReferenceMethodInterceptor.java:52)
[jboss-as-ee-7.5.0.Final-redhat-21.jar:7.5.0.Final-redhat-21]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.invocation.WeavedInterceptor.processInvocation(WeavedInterceptor.j
ava:53) [jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.as.ee.component.interceptors.UserInterceptorFactory$1.processInvoc
ation(UserInterceptorFactory.java:63)
[jboss-as-ee-7.5.0.Final-redhat-21.jar:7.5.0.Final-redhat-21]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.invocation.WeavedInterceptor.processInvocation(WeavedInterceptor.j
ava:53) [jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.as.ee.component.interceptors.UserInterceptorFactory$1.processInvoc
ation(UserInterceptorFactory.java:63)
[jboss-as-ee-7.5.0.Final-redhat-21.jar:7.5.0.Final-redhat-21]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.as.ejb3.component.invocationmetrics.ExecutionTimeInterceptor.proce
ssInvocation(ExecutionTimeInterceptor.java:43)
[jboss-as-ejb3-7.5.0.Final-redhat-21.jar:7.5.0.Final-redhat-21]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.as.jpa.interceptor.SBInvocationInterceptor.processInvocation(SBInv
ocationInterceptor.java:47)
[jboss-as-jpa-7.5.0.Final-redhat-21.jar:7.5.0.Final-redhat-21]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.invocation.InitialInterceptor.processInvocation(InitialInterceptor
.java:21) [jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.invocation.ChainedInterceptor.processInvocation(ChainedInterceptor
.java:61) [jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.as.ee.component.interceptors.ComponentDispatcherInterceptor.proces
sInvocation(ComponentDispatcherInterceptor.java:53)
[jboss-as-ee-7.5.0.Final-redhat-21.jar:7.5.0.Final-redhat-21]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.as.ejb3.component.pool.PooledInstanceInterceptor.processInvocation
(PooledInstanceInterceptor.java:51)
[jboss-as-ejb3-7.5.0.Final-redhat-21.jar:7.5.0.Final-redhat-21]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.as.ejb3.tx.CMTTxInterceptor.invokeInCallerTx(CMTTxInterceptor.java
:258) [jboss-as-ejb3-7.5.0.Final-redhat-21.jar:7.5.0.Final-redhat-21]
at
org.jboss.as.ejb3.tx.CMTTxInterceptor.required(CMTTxInterceptor.java:347)
[jboss-as-ejb3-7.5.0.Final-redhat-21.jar:7.5.0.Final-redhat-21]
at
org.jboss.as.ejb3.tx.CMTTxInterceptor.processInvocation(CMTTxInterceptor.jav
a:243) [jboss-as-ejb3-7.5.0.Final-redhat-21.jar:7.5.0.Final-redhat-21]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.as.ejb3.component.interceptors.CurrentInvocationContextInterceptor
.processInvocation(CurrentInvocationContextInterceptor.java:41)
[jboss-as-ejb3-7.5.0.Final-redhat-21.jar:7.5.0.Final-redhat-21]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.as.ejb3.component.invocationmetrics.WaitTimeInterceptor.processInv
ocation(WaitTimeInterceptor.java:43)
[jboss-as-ejb3-7.5.0.Final-redhat-21.jar:7.5.0.Final-redhat-21]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.as.ejb3.component.interceptors.ShutDownInterceptorFactory$1.proces
sInvocation(ShutDownInterceptorFactory.java:64)
[jboss-as-ejb3-7.5.0.Final-redhat-21.jar:7.5.0.Final-redhat-21]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.as.ejb3.component.interceptors.LoggingInterceptor.processInvocatio
n(LoggingInterceptor.java:59)
[jboss-as-ejb3-7.5.0.Final-redhat-21.jar:7.5.0.Final-redhat-21]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.as.ee.component.NamespaceContextInterceptor.processInvocation(Name
spaceContextInterceptor.java:50)
[jboss-as-ee-7.5.0.Final-redhat-21.jar:7.5.0.Final-redhat-21]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.as.ejb3.component.interceptors.AdditionalSetupInterceptor.processI
nvocation(AdditionalSetupInterceptor.java:55)
[jboss-as-ejb3-7.5.0.Final-redhat-21.jar:7.5.0.Final-redhat-21]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.as.ee.component.TCCLInterceptor.processInvocation(TCCLInterceptor.
java:45) [jboss-as-ee-7.5.0.Final-redhat-21.jar:7.5.0.Final-redhat-21]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.invocation.ChainedInterceptor.processInvocation(ChainedInterceptor
.java:61) [jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.as.ee.component.ViewService$View.invoke(ViewService.java:185)
[jboss-as-ee-7.5.0.Final-redhat-21.jar:7.5.0.Final-redhat-21]
at
org.jboss.as.ee.component.ViewDescription$1.processInvocation(ViewDescriptio
n.java:185) [jboss-as-ee-7.5.0.Final-redhat-21.jar:7.5.0.Final-redhat-21]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.invocation.ChainedInterceptor.processInvocation(ChainedInterceptor
.java:61) [jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.as.ee.component.ProxyInvocationHandler.invoke(ProxyInvocationHandl
er.java:73) [jboss-as-ee-7.5.0.Final-redhat-21.jar:7.5.0.Final-redhat-21]
at
org.cesecore.certificates.certificate.CertificateCreateSessionLocal$$$view59
.createCertificate(Unknown Source) [cesecore-ejb-interface.jar:]
at
org.ejbca.core.ejb.ca.sign.SignSessionBean.createCertificate(SignSessionBean
.java:432)
at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
[rt.jar:1.8.0_111-1-redhat]
at
sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62
) [rt.jar:1.8.0_111-1-redhat]
at
sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl
.java:43) [rt.jar:1.8.0_111-1-redhat]
at java.lang.reflect.Method.invoke(Method.java:498)
[rt.jar:1.8.0_111-1-redhat]
at
org.jboss.as.ee.component.ManagedReferenceMethodInterceptor.processInvocatio
n(ManagedReferenceMethodInterceptor.java:52)
[jboss-as-ee-7.5.0.Final-redhat-21.jar:7.5.0.Final-redhat-21]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.invocation.WeavedInterceptor.processInvocation(WeavedInterceptor.j
ava:53) [jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.as.ee.component.interceptors.UserInterceptorFactory$1.processInvoc
ation(UserInterceptorFactory.java:63)
[jboss-as-ee-7.5.0.Final-redhat-21.jar:7.5.0.Final-redhat-21]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.invocation.WeavedInterceptor.processInvocation(WeavedInterceptor.j
ava:53) [jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.as.ee.component.interceptors.UserInterceptorFactory$1.processInvoc
ation(UserInterceptorFactory.java:63)
[jboss-as-ee-7.5.0.Final-redhat-21.jar:7.5.0.Final-redhat-21]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.as.ejb3.component.invocationmetrics.ExecutionTimeInterceptor.proce
ssInvocation(ExecutionTimeInterceptor.java:43)
[jboss-as-ejb3-7.5.0.Final-redhat-21.jar:7.5.0.Final-redhat-21]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.as.jpa.interceptor.SBInvocationInterceptor.processInvocation(SBInv
ocationInterceptor.java:47)
[jboss-as-jpa-7.5.0.Final-redhat-21.jar:7.5.0.Final-redhat-21]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.invocation.InitialInterceptor.processInvocation(InitialInterceptor
.java:21) [jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.invocation.ChainedInterceptor.processInvocation(ChainedInterceptor
.java:61) [jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.as.ee.component.interceptors.ComponentDispatcherInterceptor.proces
sInvocation(ComponentDispatcherInterceptor.java:53)
[jboss-as-ee-7.5.0.Final-redhat-21.jar:7.5.0.Final-redhat-21]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.as.ejb3.component.pool.PooledInstanceInterceptor.processInvocation
(PooledInstanceInterceptor.java:51)
[jboss-as-ejb3-7.5.0.Final-redhat-21.jar:7.5.0.Final-redhat-21]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.as.ejb3.tx.CMTTxInterceptor.invokeInOurTx(CMTTxInterceptor.java:28
0) [jboss-as-ejb3-7.5.0.Final-redhat-21.jar:7.5.0.Final-redhat-21]
at
org.jboss.as.ejb3.tx.CMTTxInterceptor.required(CMTTxInterceptor.java:345)
[jboss-as-ejb3-7.5.0.Final-redhat-21.jar:7.5.0.Final-redhat-21]
at
org.jboss.as.ejb3.tx.CMTTxInterceptor.processInvocation(CMTTxInterceptor.jav
a:243) [jboss-as-ejb3-7.5.0.Final-redhat-21.jar:7.5.0.Final-redhat-21]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.as.ejb3.component.interceptors.CurrentInvocationContextInterceptor
.processInvocation(CurrentInvocationContextInterceptor.java:41)
[jboss-as-ejb3-7.5.0.Final-redhat-21.jar:7.5.0.Final-redhat-21]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.as.ejb3.component.invocationmetrics.WaitTimeInterceptor.processInv
ocation(WaitTimeInterceptor.java:43)
[jboss-as-ejb3-7.5.0.Final-redhat-21.jar:7.5.0.Final-redhat-21]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.as.ejb3.component.interceptors.ShutDownInterceptorFactory$1.proces
sInvocation(ShutDownInterceptorFactory.java:64)
[jboss-as-ejb3-7.5.0.Final-redhat-21.jar:7.5.0.Final-redhat-21]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.as.ejb3.component.interceptors.LoggingInterceptor.processInvocatio
n(LoggingInterceptor.java:59)
[jboss-as-ejb3-7.5.0.Final-redhat-21.jar:7.5.0.Final-redhat-21]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.as.ee.component.NamespaceContextInterceptor.processInvocation(Name
spaceContextInterceptor.java:50)
[jboss-as-ee-7.5.0.Final-redhat-21.jar:7.5.0.Final-redhat-21]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.as.ejb3.component.interceptors.AdditionalSetupInterceptor.processI
nvocation(AdditionalSetupInterceptor.java:55)
[jboss-as-ejb3-7.5.0.Final-redhat-21.jar:7.5.0.Final-redhat-21]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.as.ee.component.TCCLInterceptor.processInvocation(TCCLInterceptor.
java:45) [jboss-as-ee-7.5.0.Final-redhat-21.jar:7.5.0.Final-redhat-21]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.invocation.ChainedInterceptor.processInvocation(ChainedInterceptor
.java:61) [jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.as.ee.component.ViewService$View.invoke(ViewService.java:185)
[jboss-as-ee-7.5.0.Final-redhat-21.jar:7.5.0.Final-redhat-21]
at
org.jboss.as.ee.component.ViewDescription$1.processInvocation(ViewDescriptio
n.java:185) [jboss-as-ee-7.5.0.Final-redhat-21.jar:7.5.0.Final-redhat-21]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.invocation.ChainedInterceptor.processInvocation(ChainedInterceptor
.java:61) [jboss-invocation-1.1.2.Final-redhat-1.jar:1.1.2.Final-redhat-1]
at
org.jboss.as.ee.component.ProxyInvocationHandler.invoke(ProxyInvocationHandl
er.java:73) [jboss-as-ee-7.5.0.Final-redhat-21.jar:7.5.0.Final-redhat-21]
at
org.ejbca.core.ejb.ca.sign.SignSessionLocal$$$view74.createCertificate(Unkno
wn Source)
at
org.ejbca.ui.web.protocol.ScepServlet.scepCertRequest(ScepServlet.java:610)
at org.ejbca.ui.web.protocol.ScepServlet.service(ScepServlet.java:305)
at org.ejbca.ui.web.protocol.ScepServlet.doGet(ScepServlet.java:251)
at javax.servlet.http.HttpServlet.service(HttpServlet.java:734)
[jboss-servlet-api_3.0_spec-1.0.2.Final-redhat-2.jar:1.0.2.Final-redhat-2]
at javax.servlet.http.HttpServlet.service(HttpServlet.java:847)
[jboss-servlet-api_3.0_spec-1.0.2.Final-redhat-2.jar:1.0.2.Final-redhat-2]
at
org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(Application
FilterChain.java:295)
at
org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterCh
ain.java:214)
at
org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.ja
va:231)
at
org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.ja
va:149)
at
org.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase
.java:420)
at
org.jboss.as.jpa.interceptor.WebNonTxEmCloserValve.invoke(WebNonTxEmCloserVa
lve.java:50) [jboss-as-jpa-7.5.0.Final-redhat-21.jar:7.5.0.Final-redhat-21]
at
org.jboss.as.jpa.interceptor.WebNonTxEmCloserValve.invoke(WebNonTxEmCloserVa
lve.java:50) [jboss-as-jpa-7.5.0.Final-redhat-21.jar:7.5.0.Final-redhat-21]
at
org.jboss.as.web.security.SecurityContextAssociationValve.invoke(SecurityCon
textAssociationValve.java:169)
at
org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:150
)
at
org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:97)
at
org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java
:102)
at
org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:344)
at
org.apache.coyote.http11.Http11Processor.process(Http11Processor.java:854)
at
org.apache.coyote.http11.Http11Protocol$Http11ConnectionHandler.process(Http
11Protocol.java:653)
at
org.apache.tomcat.util.net.JIoEndpoint$Worker.run(JIoEndpoint.java:926)
at java.lang.Thread.run(Thread.java:745) [rt.jar:1.8.0_111-1-redhat]
|
|
From: ajay k. <aja...@gm...> - 2016-11-24 13:18:50
|
Hello Required Your assistance ! 1. The whole scenario is that i have created a root CA on one virtual machine on ejbca and other sub Ca on second virtual machine on ejbca 2. The Root CA has status Active and the Sub Ca has status (waiting for certificate response) 3. What i want is that Root CA should sign the Sub CA, i had gobe through the documentation but no luck Could you please let me know step by step how to do that What i am doing is i am generating a cert.pem of Root CA After that going to the SUB CA on certificate Authorities and on Receive certificate response i am attaching the cert.pem file but it is throwing errors Please guide me how to achieve that . Regards, *Ajay koul **I* *Technical Associate.* |