You can subscribe to this list here.
| 2001 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
(1) |
Dec
(3) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2002 |
Jan
(3) |
Feb
(2) |
Mar
(8) |
Apr
(3) |
May
(6) |
Jun
(1) |
Jul
(15) |
Aug
(6) |
Sep
|
Oct
(10) |
Nov
(2) |
Dec
(4) |
| 2003 |
Jan
(1) |
Feb
(7) |
Mar
(3) |
Apr
(6) |
May
(7) |
Jun
(5) |
Jul
(5) |
Aug
(25) |
Sep
(14) |
Oct
(2) |
Nov
|
Dec
(2) |
| 2004 |
Jan
(7) |
Feb
(4) |
Mar
(12) |
Apr
(16) |
May
(43) |
Jun
(56) |
Jul
(43) |
Aug
(40) |
Sep
(66) |
Oct
(12) |
Nov
(26) |
Dec
(10) |
| 2005 |
Jan
(13) |
Feb
(33) |
Mar
(16) |
Apr
(7) |
May
(10) |
Jun
(34) |
Jul
(41) |
Aug
(8) |
Sep
(4) |
Oct
(32) |
Nov
(20) |
Dec
(25) |
| 2006 |
Jan
(30) |
Feb
(101) |
Mar
(5) |
Apr
(75) |
May
(74) |
Jun
(22) |
Jul
(6) |
Aug
(70) |
Sep
(19) |
Oct
(21) |
Nov
(31) |
Dec
(50) |
| 2007 |
Jan
(15) |
Feb
(20) |
Mar
(24) |
Apr
(33) |
May
(13) |
Jun
(18) |
Jul
(13) |
Aug
(7) |
Sep
(63) |
Oct
(68) |
Nov
(29) |
Dec
(68) |
| 2008 |
Jan
(30) |
Feb
(33) |
Mar
(30) |
Apr
(103) |
May
(78) |
Jun
(48) |
Jul
(72) |
Aug
(24) |
Sep
(62) |
Oct
(63) |
Nov
(70) |
Dec
(37) |
| 2009 |
Jan
(34) |
Feb
(35) |
Mar
(64) |
Apr
(34) |
May
(34) |
Jun
(58) |
Jul
(30) |
Aug
(30) |
Sep
(46) |
Oct
(52) |
Nov
(12) |
Dec
(23) |
| 2010 |
Jan
(121) |
Feb
(18) |
Mar
(53) |
Apr
(62) |
May
(62) |
Jun
(20) |
Jul
(33) |
Aug
(20) |
Sep
(36) |
Oct
(35) |
Nov
(44) |
Dec
(63) |
| 2011 |
Jan
(19) |
Feb
(32) |
Mar
(94) |
Apr
(41) |
May
(47) |
Jun
(25) |
Jul
(34) |
Aug
(20) |
Sep
(9) |
Oct
(41) |
Nov
(33) |
Dec
(24) |
| 2012 |
Jan
(12) |
Feb
(36) |
Mar
(48) |
Apr
(32) |
May
(20) |
Jun
(15) |
Jul
(32) |
Aug
(13) |
Sep
(33) |
Oct
(54) |
Nov
(25) |
Dec
(16) |
| 2013 |
Jan
(45) |
Feb
(39) |
Mar
(38) |
Apr
(50) |
May
(29) |
Jun
(30) |
Jul
(33) |
Aug
(12) |
Sep
(9) |
Oct
(25) |
Nov
(29) |
Dec
(20) |
| 2014 |
Jan
(25) |
Feb
(19) |
Mar
(16) |
Apr
(33) |
May
(27) |
Jun
(37) |
Jul
(29) |
Aug
(27) |
Sep
(37) |
Oct
(58) |
Nov
(109) |
Dec
(26) |
| 2015 |
Jan
(4) |
Feb
(35) |
Mar
(22) |
Apr
(35) |
May
(28) |
Jun
(20) |
Jul
(4) |
Aug
(16) |
Sep
(37) |
Oct
(13) |
Nov
(13) |
Dec
(14) |
| 2016 |
Jan
(22) |
Feb
(7) |
Mar
(23) |
Apr
(30) |
May
(10) |
Jun
(10) |
Jul
(15) |
Aug
(12) |
Sep
(22) |
Oct
(31) |
Nov
(5) |
Dec
(5) |
| 2017 |
Jan
(30) |
Feb
(25) |
Mar
(28) |
Apr
(4) |
May
(19) |
Jun
(13) |
Jul
(7) |
Aug
(1) |
Sep
(2) |
Oct
(5) |
Nov
(12) |
Dec
(2) |
| 2018 |
Jan
(7) |
Feb
|
Mar
(7) |
Apr
(2) |
May
(8) |
Jun
(18) |
Jul
(6) |
Aug
(3) |
Sep
(15) |
Oct
(33) |
Nov
(13) |
Dec
(7) |
| 2019 |
Jan
(5) |
Feb
(7) |
Mar
(30) |
Apr
(5) |
May
(4) |
Jun
(69) |
Jul
(86) |
Aug
(22) |
Sep
(6) |
Oct
(7) |
Nov
(5) |
Dec
(3) |
| 2020 |
Jan
(10) |
Feb
(12) |
Mar
(22) |
Apr
(5) |
May
(1) |
Jun
(4) |
Jul
(6) |
Aug
|
Sep
(9) |
Oct
|
Nov
|
Dec
(1) |
| 2021 |
Jan
(4) |
Feb
(11) |
Mar
(7) |
Apr
(7) |
May
|
Jun
(3) |
Jul
(10) |
Aug
(6) |
Sep
|
Oct
|
Nov
(18) |
Dec
(2) |
| 2022 |
Jan
(1) |
Feb
(1) |
Mar
|
Apr
|
May
|
Jun
(2) |
Jul
|
Aug
(4) |
Sep
|
Oct
|
Nov
|
Dec
|
| 2023 |
Jan
|
Feb
|
Mar
|
Apr
(1) |
May
(1) |
Jun
|
Jul
|
Aug
(5) |
Sep
|
Oct
|
Nov
|
Dec
|
|
From: <mau...@ib...> - 2016-03-03 15:10:24
|
Dear Tomas I don´t understand. The file internal.properties from community edition (v.6.3.1.1) that I get from www.ejbca.org shows me: app.version.number=6.3.1.1 svn.revision=r21429 app.edition.verbose=Community This version dont have files called .project, .classpath, .svn, or .settings When I try find the revision 21429 on repository https://svn.cesecore.eu/svn/ejbca/trunk/ejbca I don´t have sucess I just find the revisions 21423 or 21430. The revisions 21423 or 21430 have files called .project, .classpath, .svn, or .settings but not seems community editions. Where can I find the revision 21429 that have the files .project, .classpath, .svn, or .settings? In other words where can I get the source code from community edition (v.6.3.1.1) in a eclipse project format like the other versions released on the repository https://svn.cesecore.eu/svn/ejbca/trunk/ejbca that not are community edition? How can I put the community edition (v.6.3.1.1) to build and compile in eclipse? Yours sincerely, Maurício Giacomini Penteado Em 02/03/2016 15:40, Tomas Gustavsson escreveu: > It should all be there if you have a proper .classpath eclipse file. > > On 2016-03-02 10:15, mau...@ib...: > >> Hello all I am trying compile ejbca by eclipse but I am not understanding where find the cesecore lib. Eclipse shows me "The import org.cesecore cannot be resolved". How can I resolve this? Kind regards, Maurício Giacomini Penteado ------------------------------------------------------------------------------ Site24x7 APM Insight: Get Deep Visibility into Application Performance APM + Mobile APM + RUM: Monitor 3 App instances at just $35/Month Monitor end-to-end web transactions and take corrective actions now Troubleshoot faster and improve end-user experience. Signup Now! http://pubads.g.doubleclick.net/gampad/clk?id=272487151&iu=/4140 [1] _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop [2] > > ------------------------------------------------------------------------------ > Site24x7 APM Insight: Get Deep Visibility into Application Performance > APM + Mobile APM + RUM: Monitor 3 App instances at just $35/Month > Monitor end-to-end web transactions and take corrective actions now > Troubleshoot faster and improve end-user experience. Signup Now! > http://pubads.g.doubleclick.net/gampad/clk?id=272487151&iu=/4140 [1] > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop [2] Links: ------ [1] http://pubads.g.doubleclick.net/gampad/clk?id=272487151&iu=/4140 [2] https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Tomas G. <to...@pr...> - 2016-03-02 18:41:05
|
It should all be there if you have a proper .classpath eclipse file. On 2016-03-02 10:15, mau...@ib... wrote: > Hello all > > I am trying compile ejbca by eclipse but I am not understanding where > find the cesecore lib. Eclipse shows me "The import org.cesecore cannot > be resolved". > > How can I resolve this? > > Kind regards, > > Maurício Giacomini Penteado > > > > > ------------------------------------------------------------------------------ > Site24x7 APM Insight: Get Deep Visibility into Application Performance > APM + Mobile APM + RUM: Monitor 3 App instances at just $35/Month > Monitor end-to-end web transactions and take corrective actions now > Troubleshoot faster and improve end-user experience. Signup Now! > http://pubads.g.doubleclick.net/gampad/clk?id=272487151&iu=/4140 > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: <mau...@ib...> - 2016-03-02 18:15:09
|
Hello all I am trying compile ejbca by eclipse but I am not understanding where find the cesecore lib. Eclipse shows me "The import org.cesecore cannot be resolved". How can I resolve this? Kind regards, Maurício Giacomini Penteado |
|
From: <mau...@ib...> - 2016-03-02 00:02:04
|
Ok, I undertood. Thank you so much. Best regards, Mauricio Giacomini Penteado Em 01/03/2016 19:58, Tomas Gustavsson escreveu: > Hi, > > You can see on ejbca.org that 6.3.1.1 is the latest Community release, > while 6.5.0 is the latest Enterprise release. > Running 6.3.1.1 for example you can see the svn revision in the admin > GUI (and in src/internal.properties. > > For Community releases versions that you can download are stable ones. > For Enterprise releases you're depending on PrimeKey to provide the > stable releases. > > You can read about the versioning principles of EJBCA at > https://www.ejbca.org/releasecycle.html [4]. > > Kind regards, > Tomas > > On 2016-03-01 13:18, mau...@ib...: > >> Hello everybody. I am trying study the source code of EJBCA project to collaborate with something but I do not understand the version schema used. I saw in website www.ejbca.org [1] that the last release of edition EJBCA community was the version 6.3.1.1 but on the HEAD of the source codes EJBCA repository there is other version. The version 6.5.0. I believe that the version 6.3.1.1 is the last stable of the project therefore is the best version to initiate my studies. The repository on EJBCA source code shows a list with a lot of revisions. I tried search any relation between some revision and ejbca version 6.3.1.1 but I can not find it . How can I take a copy of the version 6.3.1.1 from source codes of EJBCA? How can I identify stable versions or intermediate versions on repository of EJBCA source code? Please help! ------------------------------------------------------------------------------ Site24x7 APM Insight: Get Deep Visibility into Application Performance APM + Mobile APM + RUM: Monitor 3 App instances at just $35/Month Monitor end-to-end web transactions and take corrective actions now Troubleshoot faster and improve end-user experience. Signup Now! http://pubads.g.doubleclick.net/gampad/clk?id=272487151&iu=/4140 [2] _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop [3] > > ------------------------------------------------------------------------------ > Site24x7 APM Insight: Get Deep Visibility into Application Performance > APM + Mobile APM + RUM: Monitor 3 App instances at just $35/Month > Monitor end-to-end web transactions and take corrective actions now > Troubleshoot faster and improve end-user experience. Signup Now! > http://pubads.g.doubleclick.net/gampad/clk?id=272487151&iu=/4140 [2] > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop [3] Links: ------ [1] http://www.ejbca.org [2] http://pubads.g.doubleclick.net/gampad/clk?id=272487151&iu=/4140 [3] https://lists.sourceforge.net/lists/listinfo/ejbca-develop [4] https://www.ejbca.org/releasecycle.html |
|
From: Tomas G. <to...@pr...> - 2016-03-01 22:58:42
|
Hi, You can see on ejbca.org that 6.3.1.1 is the latest Community release, while 6.5.0 is the latest Enterprise release. Running 6.3.1.1 for example you can see the svn revision in the admin GUI (and in src/internal.properties. For Community releases versions that you can download are stable ones. For Enterprise releases you're depending on PrimeKey to provide the stable releases. You can read about the versioning principles of EJBCA at https://www.ejbca.org/releasecycle.html. Kind regards, Tomas On 2016-03-01 13:18, mau...@ib... wrote: > Hello everybody. > > I am trying study the source code of EJBCA project to collaborate with > something but I do not understand the version schema used. > > I saw in website www.ejbca.org that the last release of edition EJBCA > community was the version 6.3.1.1 but on the HEAD of the source codes > EJBCA repository there is other version. The version 6.5.0. > > I believe that the version 6.3.1.1 is the last stable of the project > therefore is the best version to initiate my studies. > > The repository on EJBCA source code shows a list with a lot of > revisions. I tried search any relation between some revision and ejbca > version 6.3.1.1 but I can not find it . > > How can I take a copy of the version 6.3.1.1 from source codes of EJBCA? > How can I identify stable versions or intermediate versions on > repository of EJBCA source code? > > Please help! > > > > > ------------------------------------------------------------------------------ > Site24x7 APM Insight: Get Deep Visibility into Application Performance > APM + Mobile APM + RUM: Monitor 3 App instances at just $35/Month > Monitor end-to-end web transactions and take corrective actions now > Troubleshoot faster and improve end-user experience. Signup Now! > http://pubads.g.doubleclick.net/gampad/clk?id=272487151&iu=/4140 > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: <mau...@ib...> - 2016-03-01 21:33:39
|
Hello everybody. I am trying study the source code of EJBCA project to collaborate with something but I do not understand the version schema used. I saw in website www.ejbca.org that the last release of edition EJBCA community was the version 6.3.1.1 but on the HEAD of the source codes EJBCA repository there is other version. The version 6.5.0. I believe that the version 6.3.1.1 is the last stable of the project therefore is the best version to initiate my studies. The repository on EJBCA source code shows a list with a lot of revisions. I tried search any relation between some revision and ejbca version 6.3.1.1 but I can not find it . How can I take a copy of the version 6.3.1.1 from source codes of EJBCA? How can I identify stable versions or intermediate versions on repository of EJBCA source code? Please help! |
|
From: Donabedian, V. L (2443782) <v.d...@be...> - 2016-02-22 15:29:03
|
Thanks Thomas for your reply. It looks like I would need the Vendors CA Authentication to validate their certs all the way up to the root. So hopefully sales could give me a an evaluation copy for 60 days or so. Vahé Donabedian - P. Eng Packet Data Domain Architect | Wireless Technology Core Networks T: 905-282-2139 | M: 416-700-0022 Bell Mobility -----Original Message----- From: Tomas Gustavsson [mailto:to...@pr...] Sent: Monday, February 22, 2016 8:37 AM To: ejb...@li... Subject: Re: [Ejbca-develop] Trial License Hi, CMPv2 is available in all versions as described in the Admin Guide. Some functionality (Vendor CA authentication) is only available in Enterprise. We have an on-line demo environment where clients can test, and there is also an evaluation VM of EJBCA Enterprise. Contact sa...@pr... to explore these options. Kind regards, Tomas Gustavsson ********** PrimeKey Solutions AB Lundagatan 16, 171 63 Solna, Sweden Mob: +46 (0)707421096 Internet: www.primekey.se Twitter: twitter.com/primekeyPKI ********** On 2016-02-19 18:34, v.d...@be... wrote: > Hello: > > > > Is it possible to trial EJBCA with CMPv2 capability? I understand that > I would need an Enterprise license if I were to get the CMPv2 feature. > > If so, how would I be able to obtain one? > > > > Thanks > > > > *Vahe*** > > > > > > ---------------------------------------------------------------------- > -------- > Site24x7 APM Insight: Get Deep Visibility into Application Performance > APM + Mobile APM + RUM: Monitor 3 App instances at just $35/Month > Monitor end-to-end web transactions and take corrective actions now > Troubleshoot faster and improve end-user experience. Signup Now! > http://pubads.g.doubleclick.net/gampad/clk?id=272487151&iu=/4140 > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > ------------------------------------------------------------------------------ Site24x7 APM Insight: Get Deep Visibility into Application Performance APM + Mobile APM + RUM: Monitor 3 App instances at just $35/Month Monitor end-to-end web transactions and take corrective actions now Troubleshoot faster and improve end-user experience. Signup Now! http://pubads.g.doubleclick.net/gampad/clk?id=272487151&iu=/4140 _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Tomas G. <to...@pr...> - 2016-02-22 13:37:00
|
Hi, CMPv2 is available in all versions as described in the Admin Guide. Some functionality (Vendor CA authentication) is only available in Enterprise. We have an on-line demo environment where clients can test, and there is also an evaluation VM of EJBCA Enterprise. Contact sa...@pr... to explore these options. Kind regards, Tomas Gustavsson ********** PrimeKey Solutions AB Lundagatan 16, 171 63 Solna, Sweden Mob: +46 (0)707421096 Internet: www.primekey.se Twitter: twitter.com/primekeyPKI ********** On 2016-02-19 18:34, v.d...@be... wrote: > Hello: > > > > Is it possible to trial EJBCA with CMPv2 capability? I understand that I > would need an Enterprise license if I were to get the CMPv2 feature. > > If so, how would I be able to obtain one? > > > > Thanks > > > > *Vahe*** > > > > > > ------------------------------------------------------------------------------ > Site24x7 APM Insight: Get Deep Visibility into Application Performance > APM + Mobile APM + RUM: Monitor 3 App instances at just $35/Month > Monitor end-to-end web transactions and take corrective actions now > Troubleshoot faster and improve end-user experience. Signup Now! > http://pubads.g.doubleclick.net/gampad/clk?id=272487151&iu=/4140 > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: <v.d...@be...> - 2016-02-19 17:55:16
|
Hello: Is it possible to trial EJBCA with CMPv2 capability? I understand that I would need an Enterprise license if I were to get the CMPv2 feature. If so, how would I be able to obtain one? Thanks Vahe |
|
From: Tomas G. <to...@pr...> - 2016-02-16 07:35:58
|
Hi, EJBCA is mostly fit for larger installations. There are public CAs using EJBCA, and there are installations managing many many millions of certificates. Some older references: https://www.ejbca.org/installations.html Some new references: https://www.primekey.se/business-cases/explore-the-world-of-primekey/ Then there are lots non-public of course. National PKIs and multi-national enterprise. Regards, Tomas ----- Save time and money with an Enterprise support subscription. Please see www.primekey.se for more information. https://www.primekey.se/technologies/products-overview/ https://www.primekey.se/service-support/support/ On 2016-02-16 08:01, Zalezny Niezalezny wrote: > Hi, > > I have a short question, does this software is good enough to build > infrastructure for > 300 000 Certificates ? Is it proper solution ? Or > its fit more for small environments ? > > I would really appreciate for any feedback. > > > > With kind regards > > Zalezny > > > ------------------------------------------------------------------------------ > Site24x7 APM Insight: Get Deep Visibility into Application Performance > APM + Mobile APM + RUM: Monitor 3 App instances at just $35/Month > Monitor end-to-end web transactions and take corrective actions now > Troubleshoot faster and improve end-user experience. Signup Now! > http://pubads.g.doubleclick.net/gampad/clk?id=272487151&iu=/4140 > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Zalezny N. <zal...@gm...> - 2016-02-16 07:01:26
|
Hi, I have a short question, does this software is good enough to build infrastructure for > 300 000 Certificates ? Is it proper solution ? Or its fit more for small environments ? I would really appreciate for any feedback. With kind regards Zalezny |
|
From: Michael S. <mi...@st...> - 2016-02-12 19:16:51
|
Chirpy Soft wrote: > We are experimenting with the LDAP DN order flag but it does not seem to > make a difference. Short answer: Always switch this off. Long answer: https://sourceforge.net/p/ejbca/mailman/message/33029424/ Ciao, Michael. |
|
From: Chirpy S. <chi...@gm...> - 2016-02-12 18:52:03
|
Hi all, We are experimenting with the LDAP DN order flag but it does not seem to make a difference. Per EJBCA documentation, There are two places in EJBCA where this can be configured: - In the Certificate profile (Edit certificate profiles) - In the CA configuration (Edit Certificate Authorities) The relationship between the settings is that they are both evaluated in an OR expression. This means that if both are true the DN will have Ldap DN order, but if any one of them is false the DN will have X.500 order. What we are seeing is irrespective of setting both the flags, the RDN order in the input CSR is simply reversed by EJBCA. i.e. if CSR has RDN order CN=...C=, then EJBCA issued certificate has subject C=....CN= and vice versa. Is this expected behaviour or a bug? We are using EJBCA 6.4.0 Thank you. |
|
From: Ralf H. <rh...@hc...> - 2016-01-25 15:53:44
|
Try to create another admin Role using cli "./ejbca.sh admins addadmin ..." then go to the GUI, renew the AdminCA and then renew superadmin. (hth) -----Ursprüngliche Nachricht----- Von: Randy Yu [mailto:yu...@ec...] Gesendet: Montag, 25. Januar 2016 15:45 An: ejb...@li... Betreff: Re: [Ejbca-develop] Superadmin renewal problem Is there any other advice or has anyone else encountered this combination before? Superadmin cannot be renewed because the CA which signed the Superadmin is expired. Other CA's in the instance are not assigned to sign new superadmin's. -----Original Message----- From: Randy Yu [mailto:yu...@ec...] Sent: January-21-16 3:02 PM To: ejb...@li... Subject: Re: [Ejbca-develop] Superadmin renewal problem Thanks Tomas. We have renewed the superadmin ca before, but that was when our self signed CA that was used to sign the superadmin was not expired. What would be the best case to create a superadmin when the CA that signs it is now expired? -----Original Message----- From: Tomas Gustavsson [mailto:to...@pr...] Sent: January-20-16 11:07 AM To: ejb...@li... Subject: Re: [Ejbca-develop] Superadmin renewal problem https://www.ejbca.org/docs/userguide.html#Renewing%20Superadmin Regards, Tomas Save time and money with an Enterprise support subscription. Please see www.primekey.se for more information. https://www.primekey.se/technologies/products-overview/ https://www.primekey.se/service-support/support/ On 2016-01-20 16:19, Randy Yu wrote: > I don’t believe you can renew the admin CA via batch. If I’m missing > something please let me know. Has anyone run into this problem > before, or is there a way to sign new superadmin users with other CA’s > even though I am unable to access the superadmin UI currently? > > > > > > *From:*Ralf Hornik [mailto:rh...@hc...] > *Sent:* November-06-15 3:10 PM > *To:* ejb...@li... > *Subject:* Re: [Ejbca-develop] Superadmin renewal problem > > > > Cant you renew the Admin CA via batch? > > Von meinem Windows Phone gesendet > > ---------------------------------------------------------------------- > -- > > *Von: *Randy Yu <mailto:yu...@ec...> > *Gesendet: *06.11.2015 18:00 > *An: *ejb...@li... > <mailto:ejb...@li...> > *Betreff: *Re: [Ejbca-develop] Superadmin renewal problem > > Apologize for bumping this message. Has anyone else encountered this > combination before? Thanks. > > > > *From:*Randy Yu [mailto:yu...@ec...] > *Sent:* November-02-15 9:30 AM > *To:* ejb...@li... > <mailto:ejb...@li...> > *Subject:* [Ejbca-develop] Superadmin renewal problem > > > > Looking for help on a superadmin renewal issue in EJBCA 4.0.16. > > > > The initial EJBCA CA created in our EJBCA instance is expired, and was > the CA used to sign the superadmin user. The superadmin user key is > also expired so I no longer can gain access to the administration > section of EJBCA web interface. Trying to reset the superadmin > password results in the following stack trace. Would the expired self > signed CA be the reason for this, and does re-gaining access to the > administration section require generating a new self signed CA? > Thanks in advance for any input. > > > > An error happened, setting status to FAILED. > > javax.ejb.EJBException: Signing CA CN=someCA,O=some,C=US is not active. > > at > org.ejbca.core.ejb.ca.sign.RSASignSessionBean.createCertificate(RSASig > nSessionBean.java:420) > > at > org.ejbca.core.ejb.ca.sign.RSASignSessionBean.createCertificate(RSASig > nSessionBean.java:214) > > at > org.ejbca.core.ejb.ca.sign.RSASignSessionBean.createCertificate(RSASig > nSessionBean.java:232) > > at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method) > > at > sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.j > ava:39) > > at > sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccess > orImpl.java:25) > > at java.lang.reflect.Method.invoke(Method.java:597) > > at > org.jboss.aop.joinpoint.MethodInvocation.invokeTarget(MethodInvocation > .java:122) > > at > org.jboss.aop.joinpoint.MethodInvocation.invokeNext(MethodInvocation.j > ava:111) > > at > org.jboss.ejb3.EJBContainerInvocationWrapper.invokeNext(EJBContainerIn > vocationWrapper.java:69) > > at > org.jboss.ejb3.interceptors.aop.InterceptorSequencer.invoke(Intercepto > rSequencer.java:73) > > at > org.jboss.ejb3.interceptors.aop.InterceptorSequencer.aroundInvoke(Inte > rceptorSequencer.java:59) > > at sun.reflect.GeneratedMethodAccessor377.invoke(Unknown > Source) > > at > sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccess > orImpl.java:25) > > at java.lang.reflect.Method.invoke(Method.java:597) > > at > org.jboss.aop.advice.PerJoinpointAdvice.invoke(PerJoinpointAdvice.java > :174) > > at > org.jboss.aop.joinpoint.MethodInvocation.invokeNext(MethodInvocation.j > ava:102) > > at > org.jboss.ejb3.interceptors.aop.InvocationContextInterceptor.fillMetho > d(InvocationContextInterceptor.java:72) > > at > org.jboss.aop.advice.org.jboss.ejb3.interceptors.aop.InvocationContext > Interceptor_z_fillMethod_7578460.invoke(InvocationContextInterceptor_z > _fillMethod_7578460.java) > > at > org.jboss.aop.joinpoint.MethodInvocation.invokeNext(MethodInvocation.j > ava:102) > > at > org.jboss.ejb3.interceptors.aop.InvocationContextInterceptor.setup(Inv > ocationContextInterceptor.java:88) > > at > org.jboss.aop.advice.org.jboss.ejb3.interceptors.aop.InvocationContext > Interceptor_z_setup_7578460.invoke(InvocationContex > > > > So it’s stating the self signed CA is offline. But if I try to either > activate or deactivate the self signed CA from command line, it > doesn’t work. > > > > [root@server]# ./ejbca.sh ca activateca someCA > > Enter authorization code: > > > > CA or CAToken must be offline to be activated. > > > > [root@server]# ./ejbca.sh ca deactivateca someCA > > CA or CAToken must be active to be put offline. > > > > > > ---------------------------------------------------------------------- > -------- > Site24x7 APM Insight: Get Deep Visibility into Application Performance > APM + Mobile APM + RUM: Monitor 3 App instances at just $35/Month > Monitor end-to-end web transactions and take corrective actions now > Troubleshoot faster and improve end-user experience. Signup Now! > http://pubads.g.doubleclick.net/gampad/clk?id=267308311&iu=/4140 > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > ------------------------------------------------------------------------------ Site24x7 APM Insight: Get Deep Visibility into Application Performance APM + Mobile APM + RUM: Monitor 3 App instances at just $35/Month Monitor end-to-end web transactions and take corrective actions now Troubleshoot faster and improve end-user experience. Signup Now! http://pubads.g.doubleclick.net/gampad/clk?id=267308311&iu=/4140 _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop ------------------------------------------------------------------------------ Site24x7 APM Insight: Get Deep Visibility into Application Performance APM + Mobile APM + RUM: Monitor 3 App instances at just $35/Month Monitor end-to-end web transactions and take corrective actions now Troubleshoot faster and improve end-user experience. Signup Now! http://pubads.g.doubleclick.net/gampad/clk?id=267308311&iu=/4140 _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop ------------------------------------------------------------------------------ Site24x7 APM Insight: Get Deep Visibility into Application Performance APM + Mobile APM + RUM: Monitor 3 App instances at just $35/Month Monitor end-to-end web transactions and take corrective actions now Troubleshoot faster and improve end-user experience. Signup Now! http://pubads.g.doubleclick.net/gampad/clk?id=267308311&iu=/4140 _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Anders R. <and...@gm...> - 2016-01-25 15:31:06
|
On 2016-01-25 15:45, Randy Yu wrote: > Is there any other advice or has anyone else encountered this combination before? > Superadmin cannot be renewed because the CA which signed the Superadmin is expired. > Other CA's in the instance are not assigned to sign new superadmin's. I haven't done this myself but it seems that you could renew the expired CA from the command-line interface. Anders > > -----Original Message----- > From: Randy Yu [mailto:yu...@ec...] > Sent: January-21-16 3:02 PM > To: ejb...@li... > Subject: Re: [Ejbca-develop] Superadmin renewal problem > > Thanks Tomas. We have renewed the superadmin ca before, but that was when our self signed CA that was used to sign the superadmin was not expired. What would be the best case to create a superadmin when the CA that signs it is now expired? > > -----Original Message----- > From: Tomas Gustavsson [mailto:to...@pr...] > Sent: January-20-16 11:07 AM > To: ejb...@li... > Subject: Re: [Ejbca-develop] Superadmin renewal problem > > > https://www.ejbca.org/docs/userguide.html#Renewing%20Superadmin > > Regards, > Tomas > Save time and money with an Enterprise support subscription. Please see www.primekey.se for more information. > https://www.primekey.se/technologies/products-overview/ > https://www.primekey.se/service-support/support/ > > On 2016-01-20 16:19, Randy Yu wrote: >> I don’t believe you can renew the admin CA via batch. If I’m missing >> something please let me know. Has anyone run into this problem >> before, or is there a way to sign new superadmin users with other CA’s >> even though I am unable to access the superadmin UI currently? >> >> >> >> >> >> *From:*Ralf Hornik [mailto:rh...@hc...] >> *Sent:* November-06-15 3:10 PM >> *To:* ejb...@li... >> *Subject:* Re: [Ejbca-develop] Superadmin renewal problem >> >> >> >> Cant you renew the Admin CA via batch? >> >> Von meinem Windows Phone gesendet >> >> ---------------------------------------------------------------------- >> -- >> >> *Von: *Randy Yu <mailto:yu...@ec...> >> *Gesendet: *06.11.2015 18:00 >> *An: *ejb...@li... >> <mailto:ejb...@li...> >> *Betreff: *Re: [Ejbca-develop] Superadmin renewal problem >> >> Apologize for bumping this message. Has anyone else encountered this >> combination before? Thanks. >> >> >> >> *From:*Randy Yu [mailto:yu...@ec...] >> *Sent:* November-02-15 9:30 AM >> *To:* ejb...@li... >> <mailto:ejb...@li...> >> *Subject:* [Ejbca-develop] Superadmin renewal problem >> >> >> >> Looking for help on a superadmin renewal issue in EJBCA 4.0.16. >> >> >> >> The initial EJBCA CA created in our EJBCA instance is expired, and was >> the CA used to sign the superadmin user. The superadmin user key is >> also expired so I no longer can gain access to the administration >> section of EJBCA web interface. Trying to reset the superadmin >> password results in the following stack trace. Would the expired self >> signed CA be the reason for this, and does re-gaining access to the >> administration section require generating a new self signed CA? >> Thanks in advance for any input. >> >> >> >> An error happened, setting status to FAILED. >> >> javax.ejb.EJBException: Signing CA CN=someCA,O=some,C=US is not active. >> >> at >> org.ejbca.core.ejb.ca.sign.RSASignSessionBean.createCertificate(RSASig >> nSessionBean.java:420) >> >> at >> org.ejbca.core.ejb.ca.sign.RSASignSessionBean.createCertificate(RSASig >> nSessionBean.java:214) >> >> at >> org.ejbca.core.ejb.ca.sign.RSASignSessionBean.createCertificate(RSASig >> nSessionBean.java:232) >> >> at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method) >> >> at >> sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.j >> ava:39) >> >> at >> sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccess >> orImpl.java:25) >> >> at java.lang.reflect.Method.invoke(Method.java:597) >> >> at >> org.jboss.aop.joinpoint.MethodInvocation.invokeTarget(MethodInvocation >> .java:122) >> >> at >> org.jboss.aop.joinpoint.MethodInvocation.invokeNext(MethodInvocation.j >> ava:111) >> >> at >> org.jboss.ejb3.EJBContainerInvocationWrapper.invokeNext(EJBContainerIn >> vocationWrapper.java:69) >> >> at >> org.jboss.ejb3.interceptors.aop.InterceptorSequencer.invoke(Intercepto >> rSequencer.java:73) >> >> at >> org.jboss.ejb3.interceptors.aop.InterceptorSequencer.aroundInvoke(Inte >> rceptorSequencer.java:59) >> >> at sun.reflect.GeneratedMethodAccessor377.invoke(Unknown >> Source) >> >> at >> sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccess >> orImpl.java:25) >> >> at java.lang.reflect.Method.invoke(Method.java:597) >> >> at >> org.jboss.aop.advice.PerJoinpointAdvice.invoke(PerJoinpointAdvice.java >> :174) >> >> at >> org.jboss.aop.joinpoint.MethodInvocation.invokeNext(MethodInvocation.j >> ava:102) >> >> at >> org.jboss.ejb3.interceptors.aop.InvocationContextInterceptor.fillMetho >> d(InvocationContextInterceptor.java:72) >> >> at >> org.jboss.aop.advice.org.jboss.ejb3.interceptors.aop.InvocationContext >> Interceptor_z_fillMethod_7578460.invoke(InvocationContextInterceptor_z >> _fillMethod_7578460.java) >> >> at >> org.jboss.aop.joinpoint.MethodInvocation.invokeNext(MethodInvocation.j >> ava:102) >> >> at >> org.jboss.ejb3.interceptors.aop.InvocationContextInterceptor.setup(Inv >> ocationContextInterceptor.java:88) >> >> at >> org.jboss.aop.advice.org.jboss.ejb3.interceptors.aop.InvocationContext >> Interceptor_z_setup_7578460.invoke(InvocationContex >> >> >> >> So it’s stating the self signed CA is offline. But if I try to either >> activate or deactivate the self signed CA from command line, it >> doesn’t work. >> >> >> >> [root@server]# ./ejbca.sh ca activateca someCA >> >> Enter authorization code: >> >> >> >> CA or CAToken must be offline to be activated. >> >> >> >> [root@server]# ./ejbca.sh ca deactivateca someCA >> >> CA or CAToken must be active to be put offline. >> >> >> >> >> >> ---------------------------------------------------------------------- >> -------- >> Site24x7 APM Insight: Get Deep Visibility into Application Performance >> APM + Mobile APM + RUM: Monitor 3 App instances at just $35/Month >> Monitor end-to-end web transactions and take corrective actions now >> Troubleshoot faster and improve end-user experience. Signup Now! >> http://pubads.g.doubleclick.net/gampad/clk?id=267308311&iu=/4140 >> >> >> >> _______________________________________________ >> Ejbca-develop mailing list >> Ejb...@li... >> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >> > > ------------------------------------------------------------------------------ > Site24x7 APM Insight: Get Deep Visibility into Application Performance APM + Mobile APM + RUM: Monitor 3 App instances at just $35/Month Monitor end-to-end web transactions and take corrective actions now Troubleshoot faster and improve end-user experience. Signup Now! > http://pubads.g.doubleclick.net/gampad/clk?id=267308311&iu=/4140 > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > ------------------------------------------------------------------------------ > Site24x7 APM Insight: Get Deep Visibility into Application Performance > APM + Mobile APM + RUM: Monitor 3 App instances at just $35/Month > Monitor end-to-end web transactions and take corrective actions now > Troubleshoot faster and improve end-user experience. Signup Now! > http://pubads.g.doubleclick.net/gampad/clk?id=267308311&iu=/4140 > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > ------------------------------------------------------------------------------ > Site24x7 APM Insight: Get Deep Visibility into Application Performance > APM + Mobile APM + RUM: Monitor 3 App instances at just $35/Month > Monitor end-to-end web transactions and take corrective actions now > Troubleshoot faster and improve end-user experience. Signup Now! > http://pubads.g.doubleclick.net/gampad/clk?id=267308311&iu=/4140 > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Randy Yu <yu...@ec...> - 2016-01-25 14:45:26
|
Is there any other advice or has anyone else encountered this combination before? Superadmin cannot be renewed because the CA which signed the Superadmin is expired. Other CA's in the instance are not assigned to sign new superadmin's. -----Original Message----- From: Randy Yu [mailto:yu...@ec...] Sent: January-21-16 3:02 PM To: ejb...@li... Subject: Re: [Ejbca-develop] Superadmin renewal problem Thanks Tomas. We have renewed the superadmin ca before, but that was when our self signed CA that was used to sign the superadmin was not expired. What would be the best case to create a superadmin when the CA that signs it is now expired? -----Original Message----- From: Tomas Gustavsson [mailto:to...@pr...] Sent: January-20-16 11:07 AM To: ejb...@li... Subject: Re: [Ejbca-develop] Superadmin renewal problem https://www.ejbca.org/docs/userguide.html#Renewing%20Superadmin Regards, Tomas Save time and money with an Enterprise support subscription. Please see www.primekey.se for more information. https://www.primekey.se/technologies/products-overview/ https://www.primekey.se/service-support/support/ On 2016-01-20 16:19, Randy Yu wrote: > I don’t believe you can renew the admin CA via batch. If I’m missing > something please let me know. Has anyone run into this problem > before, or is there a way to sign new superadmin users with other CA’s > even though I am unable to access the superadmin UI currently? > > > > > > *From:*Ralf Hornik [mailto:rh...@hc...] > *Sent:* November-06-15 3:10 PM > *To:* ejb...@li... > *Subject:* Re: [Ejbca-develop] Superadmin renewal problem > > > > Cant you renew the Admin CA via batch? > > Von meinem Windows Phone gesendet > > ---------------------------------------------------------------------- > -- > > *Von: *Randy Yu <mailto:yu...@ec...> > *Gesendet: *06.11.2015 18:00 > *An: *ejb...@li... > <mailto:ejb...@li...> > *Betreff: *Re: [Ejbca-develop] Superadmin renewal problem > > Apologize for bumping this message. Has anyone else encountered this > combination before? Thanks. > > > > *From:*Randy Yu [mailto:yu...@ec...] > *Sent:* November-02-15 9:30 AM > *To:* ejb...@li... > <mailto:ejb...@li...> > *Subject:* [Ejbca-develop] Superadmin renewal problem > > > > Looking for help on a superadmin renewal issue in EJBCA 4.0.16. > > > > The initial EJBCA CA created in our EJBCA instance is expired, and was > the CA used to sign the superadmin user. The superadmin user key is > also expired so I no longer can gain access to the administration > section of EJBCA web interface. Trying to reset the superadmin > password results in the following stack trace. Would the expired self > signed CA be the reason for this, and does re-gaining access to the > administration section require generating a new self signed CA? > Thanks in advance for any input. > > > > An error happened, setting status to FAILED. > > javax.ejb.EJBException: Signing CA CN=someCA,O=some,C=US is not active. > > at > org.ejbca.core.ejb.ca.sign.RSASignSessionBean.createCertificate(RSASig > nSessionBean.java:420) > > at > org.ejbca.core.ejb.ca.sign.RSASignSessionBean.createCertificate(RSASig > nSessionBean.java:214) > > at > org.ejbca.core.ejb.ca.sign.RSASignSessionBean.createCertificate(RSASig > nSessionBean.java:232) > > at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method) > > at > sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.j > ava:39) > > at > sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccess > orImpl.java:25) > > at java.lang.reflect.Method.invoke(Method.java:597) > > at > org.jboss.aop.joinpoint.MethodInvocation.invokeTarget(MethodInvocation > .java:122) > > at > org.jboss.aop.joinpoint.MethodInvocation.invokeNext(MethodInvocation.j > ava:111) > > at > org.jboss.ejb3.EJBContainerInvocationWrapper.invokeNext(EJBContainerIn > vocationWrapper.java:69) > > at > org.jboss.ejb3.interceptors.aop.InterceptorSequencer.invoke(Intercepto > rSequencer.java:73) > > at > org.jboss.ejb3.interceptors.aop.InterceptorSequencer.aroundInvoke(Inte > rceptorSequencer.java:59) > > at sun.reflect.GeneratedMethodAccessor377.invoke(Unknown > Source) > > at > sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccess > orImpl.java:25) > > at java.lang.reflect.Method.invoke(Method.java:597) > > at > org.jboss.aop.advice.PerJoinpointAdvice.invoke(PerJoinpointAdvice.java > :174) > > at > org.jboss.aop.joinpoint.MethodInvocation.invokeNext(MethodInvocation.j > ava:102) > > at > org.jboss.ejb3.interceptors.aop.InvocationContextInterceptor.fillMetho > d(InvocationContextInterceptor.java:72) > > at > org.jboss.aop.advice.org.jboss.ejb3.interceptors.aop.InvocationContext > Interceptor_z_fillMethod_7578460.invoke(InvocationContextInterceptor_z > _fillMethod_7578460.java) > > at > org.jboss.aop.joinpoint.MethodInvocation.invokeNext(MethodInvocation.j > ava:102) > > at > org.jboss.ejb3.interceptors.aop.InvocationContextInterceptor.setup(Inv > ocationContextInterceptor.java:88) > > at > org.jboss.aop.advice.org.jboss.ejb3.interceptors.aop.InvocationContext > Interceptor_z_setup_7578460.invoke(InvocationContex > > > > So it’s stating the self signed CA is offline. But if I try to either > activate or deactivate the self signed CA from command line, it > doesn’t work. > > > > [root@server]# ./ejbca.sh ca activateca someCA > > Enter authorization code: > > > > CA or CAToken must be offline to be activated. > > > > [root@server]# ./ejbca.sh ca deactivateca someCA > > CA or CAToken must be active to be put offline. > > > > > > ---------------------------------------------------------------------- > -------- > Site24x7 APM Insight: Get Deep Visibility into Application Performance > APM + Mobile APM + RUM: Monitor 3 App instances at just $35/Month > Monitor end-to-end web transactions and take corrective actions now > Troubleshoot faster and improve end-user experience. Signup Now! > http://pubads.g.doubleclick.net/gampad/clk?id=267308311&iu=/4140 > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > ------------------------------------------------------------------------------ Site24x7 APM Insight: Get Deep Visibility into Application Performance APM + Mobile APM + RUM: Monitor 3 App instances at just $35/Month Monitor end-to-end web transactions and take corrective actions now Troubleshoot faster and improve end-user experience. Signup Now! http://pubads.g.doubleclick.net/gampad/clk?id=267308311&iu=/4140 _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop ------------------------------------------------------------------------------ Site24x7 APM Insight: Get Deep Visibility into Application Performance APM + Mobile APM + RUM: Monitor 3 App instances at just $35/Month Monitor end-to-end web transactions and take corrective actions now Troubleshoot faster and improve end-user experience. Signup Now! http://pubads.g.doubleclick.net/gampad/clk?id=267308311&iu=/4140 _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Randy Yu <yu...@ec...> - 2016-01-21 20:36:19
|
Thanks Tomas. We have renewed the superadmin ca before, but that was when our self signed CA that was used to sign the superadmin was not expired. What would be the best case to create a superadmin when the CA that signs it is now expired? -----Original Message----- From: Tomas Gustavsson [mailto:to...@pr...] Sent: January-20-16 11:07 AM To: ejb...@li... Subject: Re: [Ejbca-develop] Superadmin renewal problem https://www.ejbca.org/docs/userguide.html#Renewing%20Superadmin Regards, Tomas Save time and money with an Enterprise support subscription. Please see www.primekey.se for more information. https://www.primekey.se/technologies/products-overview/ https://www.primekey.se/service-support/support/ On 2016-01-20 16:19, Randy Yu wrote: > I don’t believe you can renew the admin CA via batch. If I’m missing > something please let me know. Has anyone run into this problem > before, or is there a way to sign new superadmin users with other CA’s > even though I am unable to access the superadmin UI currently? > > > > > > *From:*Ralf Hornik [mailto:rh...@hc...] > *Sent:* November-06-15 3:10 PM > *To:* ejb...@li... > *Subject:* Re: [Ejbca-develop] Superadmin renewal problem > > > > Cant you renew the Admin CA via batch? > > Von meinem Windows Phone gesendet > > ---------------------------------------------------------------------- > -- > > *Von: *Randy Yu <mailto:yu...@ec...> > *Gesendet: *06.11.2015 18:00 > *An: *ejb...@li... > <mailto:ejb...@li...> > *Betreff: *Re: [Ejbca-develop] Superadmin renewal problem > > Apologize for bumping this message. Has anyone else encountered this > combination before? Thanks. > > > > *From:*Randy Yu [mailto:yu...@ec...] > *Sent:* November-02-15 9:30 AM > *To:* ejb...@li... > <mailto:ejb...@li...> > *Subject:* [Ejbca-develop] Superadmin renewal problem > > > > Looking for help on a superadmin renewal issue in EJBCA 4.0.16. > > > > The initial EJBCA CA created in our EJBCA instance is expired, and was > the CA used to sign the superadmin user. The superadmin user key is > also expired so I no longer can gain access to the administration > section of EJBCA web interface. Trying to reset the superadmin > password results in the following stack trace. Would the expired self > signed CA be the reason for this, and does re-gaining access to the > administration section require generating a new self signed CA? > Thanks in advance for any input. > > > > An error happened, setting status to FAILED. > > javax.ejb.EJBException: Signing CA CN=someCA,O=some,C=US is not active. > > at > org.ejbca.core.ejb.ca.sign.RSASignSessionBean.createCertificate(RSASig > nSessionBean.java:420) > > at > org.ejbca.core.ejb.ca.sign.RSASignSessionBean.createCertificate(RSASig > nSessionBean.java:214) > > at > org.ejbca.core.ejb.ca.sign.RSASignSessionBean.createCertificate(RSASig > nSessionBean.java:232) > > at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method) > > at > sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.j > ava:39) > > at > sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccess > orImpl.java:25) > > at java.lang.reflect.Method.invoke(Method.java:597) > > at > org.jboss.aop.joinpoint.MethodInvocation.invokeTarget(MethodInvocation > .java:122) > > at > org.jboss.aop.joinpoint.MethodInvocation.invokeNext(MethodInvocation.j > ava:111) > > at > org.jboss.ejb3.EJBContainerInvocationWrapper.invokeNext(EJBContainerIn > vocationWrapper.java:69) > > at > org.jboss.ejb3.interceptors.aop.InterceptorSequencer.invoke(Intercepto > rSequencer.java:73) > > at > org.jboss.ejb3.interceptors.aop.InterceptorSequencer.aroundInvoke(Inte > rceptorSequencer.java:59) > > at sun.reflect.GeneratedMethodAccessor377.invoke(Unknown > Source) > > at > sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccess > orImpl.java:25) > > at java.lang.reflect.Method.invoke(Method.java:597) > > at > org.jboss.aop.advice.PerJoinpointAdvice.invoke(PerJoinpointAdvice.java > :174) > > at > org.jboss.aop.joinpoint.MethodInvocation.invokeNext(MethodInvocation.j > ava:102) > > at > org.jboss.ejb3.interceptors.aop.InvocationContextInterceptor.fillMetho > d(InvocationContextInterceptor.java:72) > > at > org.jboss.aop.advice.org.jboss.ejb3.interceptors.aop.InvocationContext > Interceptor_z_fillMethod_7578460.invoke(InvocationContextInterceptor_z > _fillMethod_7578460.java) > > at > org.jboss.aop.joinpoint.MethodInvocation.invokeNext(MethodInvocation.j > ava:102) > > at > org.jboss.ejb3.interceptors.aop.InvocationContextInterceptor.setup(Inv > ocationContextInterceptor.java:88) > > at > org.jboss.aop.advice.org.jboss.ejb3.interceptors.aop.InvocationContext > Interceptor_z_setup_7578460.invoke(InvocationContex > > > > So it’s stating the self signed CA is offline. But if I try to either > activate or deactivate the self signed CA from command line, it > doesn’t work. > > > > [root@server]# ./ejbca.sh ca activateca someCA > > Enter authorization code: > > > > CA or CAToken must be offline to be activated. > > > > [root@server]# ./ejbca.sh ca deactivateca someCA > > CA or CAToken must be active to be put offline. > > > > > > ---------------------------------------------------------------------- > -------- > Site24x7 APM Insight: Get Deep Visibility into Application Performance > APM + Mobile APM + RUM: Monitor 3 App instances at just $35/Month > Monitor end-to-end web transactions and take corrective actions now > Troubleshoot faster and improve end-user experience. Signup Now! > http://pubads.g.doubleclick.net/gampad/clk?id=267308311&iu=/4140 > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > ------------------------------------------------------------------------------ Site24x7 APM Insight: Get Deep Visibility into Application Performance APM + Mobile APM + RUM: Monitor 3 App instances at just $35/Month Monitor end-to-end web transactions and take corrective actions now Troubleshoot faster and improve end-user experience. Signup Now! http://pubads.g.doubleclick.net/gampad/clk?id=267308311&iu=/4140 _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Tomas G. <to...@pr...> - 2016-01-20 16:07:20
|
https://www.ejbca.org/docs/userguide.html#Renewing%20Superadmin Regards, Tomas Save time and money with an Enterprise support subscription. Please see www.primekey.se for more information. https://www.primekey.se/technologies/products-overview/ https://www.primekey.se/service-support/support/ On 2016-01-20 16:19, Randy Yu wrote: > I don’t believe you can renew the admin CA via batch. If I’m missing > something please let me know. Has anyone run into this problem before, > or is there a way to sign new superadmin users with other CA’s even > though I am unable to access the superadmin UI currently? > > > > > > *From:*Ralf Hornik [mailto:rh...@hc...] > *Sent:* November-06-15 3:10 PM > *To:* ejb...@li... > *Subject:* Re: [Ejbca-develop] Superadmin renewal problem > > > > Cant you renew the Admin CA via batch? > > Von meinem Windows Phone gesendet > > ------------------------------------------------------------------------ > > *Von: *Randy Yu <mailto:yu...@ec...> > *Gesendet: *06.11.2015 18:00 > *An: *ejb...@li... > <mailto:ejb...@li...> > *Betreff: *Re: [Ejbca-develop] Superadmin renewal problem > > Apologize for bumping this message. Has anyone else encountered this > combination before? Thanks. > > > > *From:*Randy Yu [mailto:yu...@ec...] > *Sent:* November-02-15 9:30 AM > *To:* ejb...@li... > <mailto:ejb...@li...> > *Subject:* [Ejbca-develop] Superadmin renewal problem > > > > Looking for help on a superadmin renewal issue in EJBCA 4.0.16. > > > > The initial EJBCA CA created in our EJBCA instance is expired, and was > the CA used to sign the superadmin user. The superadmin user key is > also expired so I no longer can gain access to the administration > section of EJBCA web interface. Trying to reset the superadmin password > results in the following stack trace. Would the expired self signed CA > be the reason for this, and does re-gaining access to the administration > section require generating a new self signed CA? Thanks in advance for > any input. > > > > An error happened, setting status to FAILED. > > javax.ejb.EJBException: Signing CA CN=someCA,O=some,C=US is not active. > > at > org.ejbca.core.ejb.ca.sign.RSASignSessionBean.createCertificate(RSASignSessionBean.java:420) > > at > org.ejbca.core.ejb.ca.sign.RSASignSessionBean.createCertificate(RSASignSessionBean.java:214) > > at > org.ejbca.core.ejb.ca.sign.RSASignSessionBean.createCertificate(RSASignSessionBean.java:232) > > at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method) > > at > sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:39) > > at > sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:25) > > at java.lang.reflect.Method.invoke(Method.java:597) > > at > org.jboss.aop.joinpoint.MethodInvocation.invokeTarget(MethodInvocation.java:122) > > at > org.jboss.aop.joinpoint.MethodInvocation.invokeNext(MethodInvocation.java:111) > > at > org.jboss.ejb3.EJBContainerInvocationWrapper.invokeNext(EJBContainerInvocationWrapper.java:69) > > at > org.jboss.ejb3.interceptors.aop.InterceptorSequencer.invoke(InterceptorSequencer.java:73) > > at > org.jboss.ejb3.interceptors.aop.InterceptorSequencer.aroundInvoke(InterceptorSequencer.java:59) > > at sun.reflect.GeneratedMethodAccessor377.invoke(Unknown Source) > > at > sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:25) > > at java.lang.reflect.Method.invoke(Method.java:597) > > at > org.jboss.aop.advice.PerJoinpointAdvice.invoke(PerJoinpointAdvice.java:174) > > at > org.jboss.aop.joinpoint.MethodInvocation.invokeNext(MethodInvocation.java:102) > > at > org.jboss.ejb3.interceptors.aop.InvocationContextInterceptor.fillMethod(InvocationContextInterceptor.java:72) > > at > org.jboss.aop.advice.org.jboss.ejb3.interceptors.aop.InvocationContextInterceptor_z_fillMethod_7578460.invoke(InvocationContextInterceptor_z_fillMethod_7578460.java) > > at > org.jboss.aop.joinpoint.MethodInvocation.invokeNext(MethodInvocation.java:102) > > at > org.jboss.ejb3.interceptors.aop.InvocationContextInterceptor.setup(InvocationContextInterceptor.java:88) > > at > org.jboss.aop.advice.org.jboss.ejb3.interceptors.aop.InvocationContextInterceptor_z_setup_7578460.invoke(InvocationContex > > > > So it’s stating the self signed CA is offline. But if I try to either > activate or deactivate the self signed CA from command line, it doesn’t > work. > > > > [root@server]# ./ejbca.sh ca activateca someCA > > Enter authorization code: > > > > CA or CAToken must be offline to be activated. > > > > [root@server]# ./ejbca.sh ca deactivateca someCA > > CA or CAToken must be active to be put offline. > > > > > > ------------------------------------------------------------------------------ > Site24x7 APM Insight: Get Deep Visibility into Application Performance > APM + Mobile APM + RUM: Monitor 3 App instances at just $35/Month > Monitor end-to-end web transactions and take corrective actions now > Troubleshoot faster and improve end-user experience. Signup Now! > http://pubads.g.doubleclick.net/gampad/clk?id=267308311&iu=/4140 > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Randy Yu <yu...@ec...> - 2016-01-20 15:53:55
|
I don’t believe you can renew the admin CA via batch. If I’m missing something please let me know. Has anyone run into this problem before, or is there a way to sign new superadmin users with other CA’s even though I am unable to access the superadmin UI currently?
From: Ralf Hornik [mailto:rh...@hc...]
Sent: November-06-15 3:10 PM
To: ejb...@li...
Subject: Re: [Ejbca-develop] Superadmin renewal problem
Cant you renew the Admin CA via batch?
Von meinem Windows Phone gesendet
________________________________
Von: Randy Yu<mailto:yu...@ec...>
Gesendet: 06.11.2015 18:00
An: ejb...@li...<mailto:ejb...@li...>
Betreff: Re: [Ejbca-develop] Superadmin renewal problem
Apologize for bumping this message. Has anyone else encountered this combination before? Thanks.
From: Randy Yu [mailto:yu...@ec...]
Sent: November-02-15 9:30 AM
To: ejb...@li...<mailto:ejb...@li...>
Subject: [Ejbca-develop] Superadmin renewal problem
Looking for help on a superadmin renewal issue in EJBCA 4.0.16.
The initial EJBCA CA created in our EJBCA instance is expired, and was the CA used to sign the superadmin user. The superadmin user key is also expired so I no longer can gain access to the administration section of EJBCA web interface. Trying to reset the superadmin password results in the following stack trace. Would the expired self signed CA be the reason for this, and does re-gaining access to the administration section require generating a new self signed CA? Thanks in advance for any input.
An error happened, setting status to FAILED.
javax.ejb.EJBException: Signing CA CN=someCA,O=some,C=US is not active.
at org.ejbca.core.ejb.ca.sign.RSASignSessionBean.createCertificate(RSASignSessionBean.java:420)
at org.ejbca.core.ejb.ca.sign.RSASignSessionBean.createCertificate(RSASignSessionBean.java:214)
at org.ejbca.core.ejb.ca.sign.RSASignSessionBean.createCertificate(RSASignSessionBean.java:232)
at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:39)
at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:25)
at java.lang.reflect.Method.invoke(Method.java:597)
at org.jboss.aop.joinpoint.MethodInvocation.invokeTarget(MethodInvocation.java:122)
at org.jboss.aop.joinpoint.MethodInvocation.invokeNext(MethodInvocation.java:111)
at org.jboss.ejb3.EJBContainerInvocationWrapper.invokeNext(EJBContainerInvocationWrapper.java:69)
at org.jboss.ejb3.interceptors.aop.InterceptorSequencer.invoke(InterceptorSequencer.java:73)
at org.jboss.ejb3.interceptors.aop.InterceptorSequencer.aroundInvoke(InterceptorSequencer.java:59)
at sun.reflect.GeneratedMethodAccessor377.invoke(Unknown Source)
at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:25)
at java.lang.reflect.Method.invoke(Method.java:597)
at org.jboss.aop.advice.PerJoinpointAdvice.invoke(PerJoinpointAdvice.java:174)
at org.jboss.aop.joinpoint.MethodInvocation.invokeNext(MethodInvocation.java:102)
at org.jboss.ejb3.interceptors.aop.InvocationContextInterceptor.fillMethod(InvocationContextInterceptor.java:72)
at org.jboss.aop.advice.org.jboss.ejb3.interceptors.aop.InvocationContextInterceptor_z_fillMethod_7578460.invoke(InvocationContextInterceptor_z_fillMethod_7578460.java)
at org.jboss.aop.joinpoint.MethodInvocation.invokeNext(MethodInvocation.java:102)
at org.jboss.ejb3.interceptors.aop.InvocationContextInterceptor.setup(InvocationContextInterceptor.java:88)
at org.jboss.aop.advice.org.jboss.ejb3.interceptors.aop.InvocationContextInterceptor_z_setup_7578460.invoke(InvocationContex
So it’s stating the self signed CA is offline. But if I try to either activate or deactivate the self signed CA from command line, it doesn’t work.
[root@server]# ./ejbca.sh ca activateca someCA
Enter authorization code:
CA or CAToken must be offline to be activated.
[root@server]# ./ejbca.sh ca deactivateca someCA
CA or CAToken must be active to be put offline.
|
|
From: Quintin B. <qui...@ja...> - 2016-01-20 08:40:12
|
Hi Nick, Manuel raised a valid concern. I had some a lot of problems deploying EJBCA to JBoss 7, running on a VM with a single core. When I gave the VM an extra core the problems disappeared. Quintin ----- Original Message ----- From: "Manuel Dejonghe" <ma...@de...> To: "ejbca-develop" <ejb...@li...> Sent: Wednesday, 20 January, 2016 10:23:32 AM Subject: Re: [Ejbca-develop] Hanging when creating a new CA On Tue, Jan 19, 2016 at 8:14 PM, Nick Clark <nic...@k3...> wrote: > Thanks for responding to what I know is a rather generic question. The > environment is as follows: > > Fresh install > Keysize is/will be: 4096 > Environment: Docker > CPU: 1 > Threads: 1 > Java: 1.6.0_45 > JBoss: 7.1.1 > EJBCA CE 6.3.1.1 > > I'll look into increasing the CPU's. Jep, I strongly recommend that. I am only lurking here, but as far as I understand, some JBoss versions have issues with having only a total of one core assigned. cheers, Manuel ------------------------------------------------------------------------------ Site24x7 APM Insight: Get Deep Visibility into Application Performance APM + Mobile APM + RUM: Monitor 3 App instances at just $35/Month Monitor end-to-end web transactions and take corrective actions now Troubleshoot faster and improve end-user experience. Signup Now! http://pubads.g.doubleclick.net/gampad/clk?id=267308311&iu=/4140 _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop JACKLIN ENTERPRISES Quintin Beukes Tel: +27 11 265 4442 Fax: +27 11 314 2984 Email: qui...@ja... @|from|wwwhomepage|@ This e-mail may contain confidential information belonging to the sender which is legally privileged. It is the responsibility of the recipient to ensure that any e-mails or attachments are virus free as Jacklin Enterprises accepts no responsibility. Should you not be the intended recipient then any disclosure, copying, distribution or the taking of any action in reliance of the contents of this email is strictly prohibited. If you have received this transmission in error, please notify the sender immediately. Jacklin Enterprises Limited is registered in England No. 4398837 Registered office: 3rd Floor, 12 Gough Square, London, EC4A 3DW. VAT Registration No: 831 0256 68. Please consider the environment before printing this email. |
|
From: Manuel D. <ma...@de...> - 2016-01-20 08:24:19
|
On Tue, Jan 19, 2016 at 8:14 PM, Nick Clark <nic...@k3...> wrote: > Thanks for responding to what I know is a rather generic question. The > environment is as follows: > > Fresh install > Keysize is/will be: 4096 > Environment: Docker > CPU: 1 > Threads: 1 > Java: 1.6.0_45 > JBoss: 7.1.1 > EJBCA CE 6.3.1.1 > > I'll look into increasing the CPU's. Jep, I strongly recommend that. I am only lurking here, but as far as I understand, some JBoss versions have issues with having only a total of one core assigned. cheers, Manuel |
|
From: Nick C. <nic...@k3...> - 2016-01-19 19:14:47
|
Thanks for responding to what I know is a rather generic question. The environment is as follows: Fresh install Keysize is/will be: 4096 Environment: Docker CPU: 1 Threads: 1 Java: 1.6.0_45 JBoss: 7.1.1 EJBCA CE 6.3.1.1 I'll look into increasing the CPU's. Thanks, Nick On Mon, Jan 18, 2016 at 6:48 PM Manuel Dejonghe <ma...@de...> wrote: > On Tue, Jan 19, 2016 at 2:09 AM, Nick Clark > <nic...@k3...> wrote: > > Hi, > > > > I'm setting up a new deployment. Upon making a new CA from the management > > page, It hangs indefinitely. The logs don't show anything and CPU maxes > out. > > > > Any direction on what I should be looking at to debug this problem would > be > > handy. > > Could it perhaps be that the key generation actually takes that long ? > Keysize, virtual machine perhaps, only little CPU ressources assigned, > SoftKeys, very little entropy existing in the virtual machine ? > > Is there an HSM involved ? > > Otherwise I guess the guys will need your EJBCA version, your Java/JVM > version, your application server and version of that, number of CPU > cores assigned to the virtual machine and if possible, the logfile of > the application server, even if you say they don't show anything. > Is it a fresh installation, or have you been playing with it before, > did you upgrade recently ? > > cheers, > Manuel > > > ------------------------------------------------------------------------------ > Site24x7 APM Insight: Get Deep Visibility into Application Performance > APM + Mobile APM + RUM: Monitor 3 App instances at just $35/Month > Monitor end-to-end web transactions and take corrective actions now > Troubleshoot faster and improve end-user experience. Signup Now! > http://pubads.g.doubleclick.net/gampad/clk?id=267308311&iu=/4140 > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Manuel D. <ma...@de...> - 2016-01-19 02:48:22
|
On Tue, Jan 19, 2016 at 2:09 AM, Nick Clark <nic...@k3...> wrote: > Hi, > > I'm setting up a new deployment. Upon making a new CA from the management > page, It hangs indefinitely. The logs don't show anything and CPU maxes out. > > Any direction on what I should be looking at to debug this problem would be > handy. Could it perhaps be that the key generation actually takes that long ? Keysize, virtual machine perhaps, only little CPU ressources assigned, SoftKeys, very little entropy existing in the virtual machine ? Is there an HSM involved ? Otherwise I guess the guys will need your EJBCA version, your Java/JVM version, your application server and version of that, number of CPU cores assigned to the virtual machine and if possible, the logfile of the application server, even if you say they don't show anything. Is it a fresh installation, or have you been playing with it before, did you upgrade recently ? cheers, Manuel |
|
From: Nick C. <nic...@k3...> - 2016-01-19 01:32:25
|
Hi, I'm setting up a new deployment. Upon making a new CA from the management page, It hangs indefinitely. The logs don't show anything and CPU maxes out. Any direction on what I should be looking at to debug this problem would be handy. Thanks, Nick |
|
From: Tomas G. <to...@pr...> - 2016-01-16 07:35:06
|
I added the sample file to the EJBCA repo. https://jira.primekey.se/browse/ECA-4717 Regards, Tomas On 2016-01-07 04:05, Christian Felsing wrote: > Hello, > > this is a ejbca.service file which works with EJBCA, it should be > located at /usr/lib/systemd/system and works with CentOS7.2. > > ---cut here-- > [Unit] > Description=EJBCA PKI > After=network.target mariadb.service > > [Service] > Type=simple > User=ejbca > Group=ejbca > WorkingDirectory=/home/ejbca > ExecStart=/home/ejbca/jboss/bin/standalone.sh -b 127.0.0.1 > ExecStop=/home/ejbca/jboss/bin/jboss-cli.sh --connect command=:shutdown > Restart=on-failure > RestartSec=300s > > [Install] > WantedBy=multi-user.target > ---cut here-- > > It assumes: > > * EJBCA is running as user ejbca > * JBoss is installed on /home/ejbca/jboss > * not forking > * database is MariaDB > > see also https://gist.github.com/ip6li/1b92a019567afdb5ff62 > > Christian > > > > ------------------------------------------------------------------------------ > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |