You can subscribe to this list here.
| 2001 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
(1) |
Dec
(3) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2002 |
Jan
(3) |
Feb
(2) |
Mar
(8) |
Apr
(3) |
May
(6) |
Jun
(1) |
Jul
(15) |
Aug
(6) |
Sep
|
Oct
(10) |
Nov
(2) |
Dec
(4) |
| 2003 |
Jan
(1) |
Feb
(7) |
Mar
(3) |
Apr
(6) |
May
(7) |
Jun
(5) |
Jul
(5) |
Aug
(25) |
Sep
(14) |
Oct
(2) |
Nov
|
Dec
(2) |
| 2004 |
Jan
(7) |
Feb
(4) |
Mar
(12) |
Apr
(16) |
May
(43) |
Jun
(56) |
Jul
(43) |
Aug
(40) |
Sep
(66) |
Oct
(12) |
Nov
(26) |
Dec
(10) |
| 2005 |
Jan
(13) |
Feb
(33) |
Mar
(16) |
Apr
(7) |
May
(10) |
Jun
(34) |
Jul
(41) |
Aug
(8) |
Sep
(4) |
Oct
(32) |
Nov
(20) |
Dec
(25) |
| 2006 |
Jan
(30) |
Feb
(101) |
Mar
(5) |
Apr
(75) |
May
(74) |
Jun
(22) |
Jul
(6) |
Aug
(70) |
Sep
(19) |
Oct
(21) |
Nov
(31) |
Dec
(50) |
| 2007 |
Jan
(15) |
Feb
(20) |
Mar
(24) |
Apr
(33) |
May
(13) |
Jun
(18) |
Jul
(13) |
Aug
(7) |
Sep
(63) |
Oct
(68) |
Nov
(29) |
Dec
(68) |
| 2008 |
Jan
(30) |
Feb
(33) |
Mar
(30) |
Apr
(103) |
May
(78) |
Jun
(48) |
Jul
(72) |
Aug
(24) |
Sep
(62) |
Oct
(63) |
Nov
(70) |
Dec
(37) |
| 2009 |
Jan
(34) |
Feb
(35) |
Mar
(64) |
Apr
(34) |
May
(34) |
Jun
(58) |
Jul
(30) |
Aug
(30) |
Sep
(46) |
Oct
(52) |
Nov
(12) |
Dec
(23) |
| 2010 |
Jan
(121) |
Feb
(18) |
Mar
(53) |
Apr
(62) |
May
(62) |
Jun
(20) |
Jul
(33) |
Aug
(20) |
Sep
(36) |
Oct
(35) |
Nov
(44) |
Dec
(63) |
| 2011 |
Jan
(19) |
Feb
(32) |
Mar
(94) |
Apr
(41) |
May
(47) |
Jun
(25) |
Jul
(34) |
Aug
(20) |
Sep
(9) |
Oct
(41) |
Nov
(33) |
Dec
(24) |
| 2012 |
Jan
(12) |
Feb
(36) |
Mar
(48) |
Apr
(32) |
May
(20) |
Jun
(15) |
Jul
(32) |
Aug
(13) |
Sep
(33) |
Oct
(54) |
Nov
(25) |
Dec
(16) |
| 2013 |
Jan
(45) |
Feb
(39) |
Mar
(38) |
Apr
(50) |
May
(29) |
Jun
(30) |
Jul
(33) |
Aug
(12) |
Sep
(9) |
Oct
(25) |
Nov
(29) |
Dec
(20) |
| 2014 |
Jan
(25) |
Feb
(19) |
Mar
(16) |
Apr
(33) |
May
(27) |
Jun
(37) |
Jul
(29) |
Aug
(27) |
Sep
(37) |
Oct
(58) |
Nov
(109) |
Dec
(26) |
| 2015 |
Jan
(4) |
Feb
(35) |
Mar
(22) |
Apr
(35) |
May
(28) |
Jun
(20) |
Jul
(4) |
Aug
(16) |
Sep
(37) |
Oct
(13) |
Nov
(13) |
Dec
(14) |
| 2016 |
Jan
(22) |
Feb
(7) |
Mar
(23) |
Apr
(30) |
May
(10) |
Jun
(10) |
Jul
(15) |
Aug
(12) |
Sep
(22) |
Oct
(31) |
Nov
(5) |
Dec
(5) |
| 2017 |
Jan
(30) |
Feb
(25) |
Mar
(28) |
Apr
(4) |
May
(19) |
Jun
(13) |
Jul
(7) |
Aug
(1) |
Sep
(2) |
Oct
(5) |
Nov
(12) |
Dec
(2) |
| 2018 |
Jan
(7) |
Feb
|
Mar
(7) |
Apr
(2) |
May
(8) |
Jun
(18) |
Jul
(6) |
Aug
(3) |
Sep
(15) |
Oct
(33) |
Nov
(13) |
Dec
(7) |
| 2019 |
Jan
(5) |
Feb
(7) |
Mar
(30) |
Apr
(5) |
May
(4) |
Jun
(69) |
Jul
(86) |
Aug
(22) |
Sep
(6) |
Oct
(7) |
Nov
(5) |
Dec
(3) |
| 2020 |
Jan
(10) |
Feb
(12) |
Mar
(22) |
Apr
(5) |
May
(1) |
Jun
(4) |
Jul
(6) |
Aug
|
Sep
(9) |
Oct
|
Nov
|
Dec
(1) |
| 2021 |
Jan
(4) |
Feb
(11) |
Mar
(7) |
Apr
(7) |
May
|
Jun
(3) |
Jul
(10) |
Aug
(6) |
Sep
|
Oct
|
Nov
(18) |
Dec
(2) |
| 2022 |
Jan
(1) |
Feb
(1) |
Mar
|
Apr
|
May
|
Jun
(2) |
Jul
|
Aug
(4) |
Sep
|
Oct
|
Nov
|
Dec
|
| 2023 |
Jan
|
Feb
|
Mar
|
Apr
(1) |
May
(1) |
Jun
|
Jul
|
Aug
(5) |
Sep
|
Oct
|
Nov
|
Dec
|
|
From: Christian F. <pu...@fe...> - 2016-01-10 16:50:35
|
Tomas, there are plans to do so, pls. see https://github.com/ip6li/registration-authority/issues/7 At this time there are problems to integrate Apache Shiro into async architecture of latest version (not available to the public yet) At least username/password via oauth2 will be implemented. Regards Christian Am 08.01.2016 um 10:24 schrieb Tomas Gustavsson: > Nice demo. Did you consider any authentication or approval mechanism for > enrollment? > > Regards, > Tomas |
|
From: Tomas G. <to...@pr...> - 2016-01-08 09:24:09
|
Nice demo. Did you consider any authentication or approval mechanism for enrollment? Regards, Tomas On January 5, 2016 11:11:49 AM GMT+01:00, Christian Felsing <pu...@fe...> wrote: >Am 04.01.2016 um 14:55 schrieb Tomas Gustavsson: >> Cool, I'll try it out. >Today it got some improvements e.g. more configurable and validating >request before sending to EJBCA. > >> Did you see this btw, code to help people create CSRs. >> https://csrhelp.peculiarventures.com/ > >I did not know that, but also an interesting solution even it kills >mobile devices performance (AngularJS) >My solution is more plain vanilla JavaScript and may be usable even >with >mobile devices - if css is slightly improved and it has enough >performance to generate a RSA key. > >I set up a demo with EJBCA backend on https://demo.ip6.li/demo/ > >best regards >Christian > > > > >------------------------------------------------------------------------ > >------------------------------------------------------------------------------ > > >------------------------------------------------------------------------ > >_______________________________________________ >Ejbca-develop mailing list >Ejb...@li... >https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Quintin B. <qui...@ja...> - 2016-01-08 08:11:25
|
Good morning, I think the public web only allows retrieving the *certificate* for any user, and not the private key as well. The certificate is part of the public component. Quintin On 2016-01-08 08:04, Benedikt Weyer wrote: > good morning, why can i retrieve any certificate (even the superadmin) > in ejbca's public web interface without authenitification? am using > ejbca_ce_6_3_1_1, jboss-as-7.1.1.Final, H2, openjdk-7 on debian 8. > thanx a lot in advance. > > ------------------------------------------------------------------------------ > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > ------------------------------------------------------------------------------ _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop JACKLIN ENTERPRISES Quintin Beukes Tel: +27 11 265 4442 Fax: +27 11 314 2984 Email: qui...@ja... @|from|wwwhomepage|@ This e-mail may contain confidential information belonging to the sender which is legally privileged. It is the responsibility of the recipient to ensure that any e-mails or attachments are virus free as Jacklin Enterprises accepts no responsibility. Should you not be the intended recipient then any disclosure, copying, distribution or the taking of any action in reliance of the contents of this email is strictly prohibited. If you have received this transmission in error, please notify the sender immediately. Jacklin Enterprises Limited is registered in England No. 4398837 Registered office: 3rd Floor, 12 Gough Square, London, EC4A 3DW. VAT Registration No: 831 0256 68. Please consider the environment before printing this email. |
|
From: Tomas G. <to...@pr...> - 2016-01-08 07:19:36
|
Hi, It's because certificates are by design "public". There is no security information in them by "X.509/PKI" design, as the security lies with the private key. It's common to publish all issued user certificates in a directory for example. You can of course easily restrict access to public web by removign access to publicly accessible ports. Cheers, Tomas ********** PrimeKey Solutions AB Lundagatan 16, 171 63 Solna, Sweden Mob: +46 (0)707421096 Internet: www.primekey.se Twitter: twitter.com/primekeyPKI ********** On 2016-01-08 08:04, Benedikt Weyer wrote: > good morning, why can i retrieve any certificate (even the superadmin) > in ejbca's public web interface without authenitification? am using > ejbca_ce_6_3_1_1, jboss-as-7.1.1.Final, H2, openjdk-7 on debian 8. > thanx a lot in advance. > > ------------------------------------------------------------------------------ > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Benedikt W. <ben...@t-...> - 2016-01-08 07:04:22
|
good morning, why can i retrieve any certificate (even the superadmin) in ejbca's public web interface without authenitification? am using ejbca_ce_6_3_1_1, jboss-as-7.1.1.Final, H2, openjdk-7 on debian 8. thanx a lot in advance. |
|
From: Christian F. <pu...@fe...> - 2016-01-07 03:05:38
|
Hello, this is a ejbca.service file which works with EJBCA, it should be located at /usr/lib/systemd/system and works with CentOS7.2. ---cut here-- [Unit] Description=EJBCA PKI After=network.target mariadb.service [Service] Type=simple User=ejbca Group=ejbca WorkingDirectory=/home/ejbca ExecStart=/home/ejbca/jboss/bin/standalone.sh -b 127.0.0.1 ExecStop=/home/ejbca/jboss/bin/jboss-cli.sh --connect command=:shutdown Restart=on-failure RestartSec=300s [Install] WantedBy=multi-user.target ---cut here-- It assumes: * EJBCA is running as user ejbca * JBoss is installed on /home/ejbca/jboss * not forking * database is MariaDB see also https://gist.github.com/ip6li/1b92a019567afdb5ff62 Christian |
|
From: Christian F. <pu...@fe...> - 2016-01-05 10:11:59
|
Am 04.01.2016 um 14:55 schrieb Tomas Gustavsson: > Cool, I'll try it out. Today it got some improvements e.g. more configurable and validating request before sending to EJBCA. > Did you see this btw, code to help people create CSRs. > https://csrhelp.peculiarventures.com/ I did not know that, but also an interesting solution even it kills mobile devices performance (AngularJS) My solution is more plain vanilla JavaScript and may be usable even with mobile devices - if css is slightly improved and it has enough performance to generate a RSA key. I set up a demo with EJBCA backend on https://demo.ip6.li/demo/ best regards Christian |
|
From: Tomas G. <to...@pr...> - 2016-01-04 13:55:58
|
Cool, I'll try it out. Did you see this btw, code to help people create CSRs. https://csrhelp.peculiarventures.com/ Regards, Tomas On 2016-01-02 14:19, Christian Felsing wrote: > Hello, > > while playing around with WebcryptoAPI and EJBCA I made a small Java > software which presents a simple playground for EJBCA webservice and > WebcryptoAPI to user. > > Feel free to play around with that code: > https://github.com/ip6li/registration-authority > > best regards > Christian Felsing > > > > ------------------------------------------------------------------------------ > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Christian F. <pu...@fe...> - 2016-01-02 13:35:10
|
Hello, while playing around with WebcryptoAPI and EJBCA I made a small Java software which presents a simple playground for EJBCA webservice and WebcryptoAPI to user. Feel free to play around with that code: https://github.com/ip6li/registration-authority best regards Christian Felsing |
|
From: Tomas G. <to...@pr...> - 2015-12-21 15:55:18
|
Also are you sure it's the indefinite-length vs definite length, and not something else pyasn1 doesn't like? It could for instance be content encapsulation that can be done in a couple of ways. It's not possible to test this on a command line? (i.e. for me without having to write a python program). Cheers, Tomas On 2015-12-17 10:34, Anthony Alba wrote: > When using WSDL certificateRequest () with PKCS7WITHCHAIN, the > returned structure use indefinite length encoding: > > 0:d=0 hl=2 l=inf cons: SEQUENCE > 2:d=1 hl=2 l= 9 prim: OBJECT :pkcs7-signedData > 13:d=1 hl=2 l=inf cons: cont [ 0 ] > 15:d=2 hl=2 l=inf cons: SEQUENCE > 17:d=3 hl=2 l= 1 prim: INTEGER :01 > 20:d=3 hl=2 l= 11 cons: SET > 22:d=4 hl=2 l= 9 cons: SEQUENCE > 24:d=5 hl=2 l= 5 prim: OBJECT :sha1 > > however the contents of the data structure, "d=1 cont[0]" contains 00 > 00 so that some ASN.1 parsers terminate , they treat 00 00 as > end-of-content and drop bytes. Is the ASN.1 stream malformed? > > For example pyasn1 will strip out all 00 00 in stream and throw the > following error: > > pkcs7_asn1 = decoder.decode(<PKCS7_DER_FROM_EJBCA>, asn1Spec = > rfc2315.ContentInfo()) > > pyasn1.error.SubstrateUnderrunError: No EOO seen before substrate ends > > Could you consider using definite length encoding? > > However, OpenSSL utility pkcs7 handles these PKCS7 streams fine: maybe > it assumes the 2nd component continues to the end of file. > > Anthony > > ------------------------------------------------------------------------------ > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Tomas G. <to...@pr...> - 2015-12-21 15:48:18
|
Hi, Which version of EJBCA do you use? We produce the PKCS#7 using BouncyCastle standard routines, which should really be compatible with most clients. Regards, Tomas On 2015-12-17 10:34, Anthony Alba wrote: > When using WSDL certificateRequest () with PKCS7WITHCHAIN, the > returned structure use indefinite length encoding: > > 0:d=0 hl=2 l=inf cons: SEQUENCE > 2:d=1 hl=2 l= 9 prim: OBJECT :pkcs7-signedData > 13:d=1 hl=2 l=inf cons: cont [ 0 ] > 15:d=2 hl=2 l=inf cons: SEQUENCE > 17:d=3 hl=2 l= 1 prim: INTEGER :01 > 20:d=3 hl=2 l= 11 cons: SET > 22:d=4 hl=2 l= 9 cons: SEQUENCE > 24:d=5 hl=2 l= 5 prim: OBJECT :sha1 > > however the contents of the data structure, "d=1 cont[0]" contains 00 > 00 so that some ASN.1 parsers terminate , they treat 00 00 as > end-of-content and drop bytes. Is the ASN.1 stream malformed? > > For example pyasn1 will strip out all 00 00 in stream and throw the > following error: > > pkcs7_asn1 = decoder.decode(<PKCS7_DER_FROM_EJBCA>, asn1Spec = > rfc2315.ContentInfo()) > > pyasn1.error.SubstrateUnderrunError: No EOO seen before substrate ends > > Could you consider using definite length encoding? > > However, OpenSSL utility pkcs7 handles these PKCS7 streams fine: maybe > it assumes the 2nd component continues to the end of file. > > Anthony > > ------------------------------------------------------------------------------ > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Anthony A. <asc...@gm...> - 2015-12-17 09:34:31
|
When using WSDL certificateRequest () with PKCS7WITHCHAIN, the
returned structure use indefinite length encoding:
0:d=0 hl=2 l=inf cons: SEQUENCE
2:d=1 hl=2 l= 9 prim: OBJECT :pkcs7-signedData
13:d=1 hl=2 l=inf cons: cont [ 0 ]
15:d=2 hl=2 l=inf cons: SEQUENCE
17:d=3 hl=2 l= 1 prim: INTEGER :01
20:d=3 hl=2 l= 11 cons: SET
22:d=4 hl=2 l= 9 cons: SEQUENCE
24:d=5 hl=2 l= 5 prim: OBJECT :sha1
however the contents of the data structure, "d=1 cont[0]" contains 00
00 so that some ASN.1 parsers terminate , they treat 00 00 as
end-of-content and drop bytes. Is the ASN.1 stream malformed?
For example pyasn1 will strip out all 00 00 in stream and throw the
following error:
pkcs7_asn1 = decoder.decode(<PKCS7_DER_FROM_EJBCA>, asn1Spec =
rfc2315.ContentInfo())
pyasn1.error.SubstrateUnderrunError: No EOO seen before substrate ends
Could you consider using definite length encoding?
However, OpenSSL utility pkcs7 handles these PKCS7 streams fine: maybe
it assumes the 2nd component continues to the end of file.
Anthony
|
|
From: Ralf H. <rh...@hc...> - 2015-12-16 16:25:59
|
Yes i see it now. Clients try to fetch a delta CRL. Thanks. Thats enough :-) -----Ursprüngliche Nachricht----- Von: Tomas Gustavsson [mailto:to...@pr...] Gesendet: Mittwoch, 16. Dezember 2015 15:42 An: ejb...@li... Betreff: Re: [Ejbca-develop] NullPointerException in CRL retrieval Ok, can it then be an invalid URL in some cases that makes them try to fetch a deltaCRL. You can experiment by clicking on the links in publicweb. If there is no CRL, or deltaCRL the corresponding link will give this message. /Tomas On 2015-12-16 03:49, Ralf Hornik wrote: > Hi, yes because there are also successfull retrievals but with serial > 0: > > 2015-12-11 14:37:56,573 DEBUG [org.ejbca.ui.web.RequestHelper] > (default > task-7) Setting encoding to default value: UTF-8 > 2015-12-11 14:37:56,576 INFO > [org.cesecore.certificates.crl.CrlStoreSessionBean] (default task-7) > Retrieved CRL from issuer 'CN=Root CA,O=MyCompany,C=DE', with CRL > number 153. > 2015-12-11 14:37:56,578 DEBUG [org.ejbca.ui.web.pub.CertDistServlet] > (default task-7) Sent latest CRL to client at 10.51.226.125 > > I wonder why and what process wants to look up a CRL with number 0. > What is CertDistServlet used for? I guess its CDP lookup from the end devices. > > -----Ursprüngliche Nachricht----- > Von: Tomas Gustavsson [mailto:to...@pr...] > Gesendet: Montag, 14. Dezember 2015 18:37 > An: ejb...@li... > Betreff: Re: [Ejbca-develop] NullPointerException in CRL retrieval > > > Hi are you sure the "CN=Root CA,O=MyCompany,C=DE" have CRL available, > and not just a Sub CA? > > Regards, > Tomas > > On 2015-12-11 07:32, Ralf Hornik wrote: >> Hi, >> >> i just noticed that there are several exceptions from various clients >> in the wildfly log: >> >> 2015-12-11 14:36:18,817 DEBUG [org.ejbca.ui.web.RequestHelper] >> (default >> task-31) Setting encoding to default value: UTF-8 >> 2015-12-11 14:36:18,820 INFO >> [org.cesecore.certificates.crl.CrlStoreSessionBean] (default task-31) >> Error retrieving CRL for issuer 'CN=Root CA,O=MyCompany,C=DE' with >> CRL > number 0. >> 2015-12-11 14:36:18,820 DEBUG [org.ejbca.ui.web.pub.CertDistServlet] >> (default task-31) Error sending latest CRL to 10.51.18.138: : >> java.lang.NullPointerException >> >> Other log entries with CRL number >0 are successfull. >> The clients are mostly windows PCs. I think they try to lookup the >> CDP and want to retrieve the CRL. >> >> Any hints why ejbca tries to send a CRL with serial 0? The current >> CRL number is 15. >> Thanks and best regards >> >> Ralf Hornik >> Hosting Consulting Services >> Abt-Gallus-Str. 23 >> 86609 Donauwörth >> Tel: +49 906 20430 12 >> Fax: +49 906 20430 15 >> Mobil: +49 151 50721262 >> email: rh...@hc... >> www: http://www.hcservices.de >> >> >> >> --------------------------------------------------------------------- >> - >> -------- >> >> >> >> _______________________________________________ >> Ejbca-develop mailing list >> Ejb...@li... >> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >> > > ---------------------------------------------------------------------- > ------ > -- > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > ---------------------------------------------------------------------- > -------- > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > ---------------------------------------------------------------------------- -- _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Tomas G. <to...@pr...> - 2015-12-16 14:41:58
|
Ok, can it then be an invalid URL in some cases that makes them try to fetch a deltaCRL. You can experiment by clicking on the links in publicweb. If there is no CRL, or deltaCRL the corresponding link will give this message. /Tomas On 2015-12-16 03:49, Ralf Hornik wrote: > Hi, yes because there are also successfull retrievals but with serial > 0: > > 2015-12-11 14:37:56,573 DEBUG [org.ejbca.ui.web.RequestHelper] (default > task-7) Setting encoding to default value: UTF-8 > 2015-12-11 14:37:56,576 INFO > [org.cesecore.certificates.crl.CrlStoreSessionBean] (default task-7) > Retrieved CRL from issuer 'CN=Root CA,O=MyCompany,C=DE', with CRL number > 153. > 2015-12-11 14:37:56,578 DEBUG [org.ejbca.ui.web.pub.CertDistServlet] > (default task-7) Sent latest CRL to client at 10.51.226.125 > > I wonder why and what process wants to look up a CRL with number 0. What is > CertDistServlet used for? I guess its CDP lookup from the end devices. > > -----Ursprüngliche Nachricht----- > Von: Tomas Gustavsson [mailto:to...@pr...] > Gesendet: Montag, 14. Dezember 2015 18:37 > An: ejb...@li... > Betreff: Re: [Ejbca-develop] NullPointerException in CRL retrieval > > > Hi are you sure the "CN=Root CA,O=MyCompany,C=DE" have CRL available, and > not just a Sub CA? > > Regards, > Tomas > > On 2015-12-11 07:32, Ralf Hornik wrote: >> Hi, >> >> i just noticed that there are several exceptions from various clients >> in the wildfly log: >> >> 2015-12-11 14:36:18,817 DEBUG [org.ejbca.ui.web.RequestHelper] >> (default >> task-31) Setting encoding to default value: UTF-8 >> 2015-12-11 14:36:18,820 INFO >> [org.cesecore.certificates.crl.CrlStoreSessionBean] (default task-31) >> Error retrieving CRL for issuer 'CN=Root CA,O=MyCompany,C=DE' with CRL > number 0. >> 2015-12-11 14:36:18,820 DEBUG [org.ejbca.ui.web.pub.CertDistServlet] >> (default task-31) Error sending latest CRL to 10.51.18.138: : >> java.lang.NullPointerException >> >> Other log entries with CRL number >0 are successfull. >> The clients are mostly windows PCs. I think they try to lookup the CDP >> and want to retrieve the CRL. >> >> Any hints why ejbca tries to send a CRL with serial 0? The current CRL >> number is 15. >> Thanks and best regards >> >> Ralf Hornik >> Hosting Consulting Services >> Abt-Gallus-Str. 23 >> 86609 Donauwörth >> Tel: +49 906 20430 12 >> Fax: +49 906 20430 15 >> Mobil: +49 151 50721262 >> email: rh...@hc... >> www: http://www.hcservices.de >> >> >> >> ---------------------------------------------------------------------- >> -------- >> >> >> >> _______________________________________________ >> Ejbca-develop mailing list >> Ejb...@li... >> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >> > > ---------------------------------------------------------------------------- > -- > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > ------------------------------------------------------------------------------ > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Ralf H. <rh...@hc...> - 2015-12-16 10:50:11
|
Hi, yes because there are also successfull retrievals but with serial > 0: 2015-12-11 14:37:56,573 DEBUG [org.ejbca.ui.web.RequestHelper] (default task-7) Setting encoding to default value: UTF-8 2015-12-11 14:37:56,576 INFO [org.cesecore.certificates.crl.CrlStoreSessionBean] (default task-7) Retrieved CRL from issuer 'CN=Root CA,O=MyCompany,C=DE', with CRL number 153. 2015-12-11 14:37:56,578 DEBUG [org.ejbca.ui.web.pub.CertDistServlet] (default task-7) Sent latest CRL to client at 10.51.226.125 I wonder why and what process wants to look up a CRL with number 0. What is CertDistServlet used for? I guess its CDP lookup from the end devices. -----Ursprüngliche Nachricht----- Von: Tomas Gustavsson [mailto:to...@pr...] Gesendet: Montag, 14. Dezember 2015 18:37 An: ejb...@li... Betreff: Re: [Ejbca-develop] NullPointerException in CRL retrieval Hi are you sure the "CN=Root CA,O=MyCompany,C=DE" have CRL available, and not just a Sub CA? Regards, Tomas On 2015-12-11 07:32, Ralf Hornik wrote: > Hi, > > i just noticed that there are several exceptions from various clients > in the wildfly log: > > 2015-12-11 14:36:18,817 DEBUG [org.ejbca.ui.web.RequestHelper] > (default > task-31) Setting encoding to default value: UTF-8 > 2015-12-11 14:36:18,820 INFO > [org.cesecore.certificates.crl.CrlStoreSessionBean] (default task-31) > Error retrieving CRL for issuer 'CN=Root CA,O=MyCompany,C=DE' with CRL number 0. > 2015-12-11 14:36:18,820 DEBUG [org.ejbca.ui.web.pub.CertDistServlet] > (default task-31) Error sending latest CRL to 10.51.18.138: : > java.lang.NullPointerException > > Other log entries with CRL number >0 are successfull. > The clients are mostly windows PCs. I think they try to lookup the CDP > and want to retrieve the CRL. > > Any hints why ejbca tries to send a CRL with serial 0? The current CRL > number is 15. > Thanks and best regards > > Ralf Hornik > Hosting Consulting Services > Abt-Gallus-Str. 23 > 86609 Donauwörth > Tel: +49 906 20430 12 > Fax: +49 906 20430 15 > Mobil: +49 151 50721262 > email: rh...@hc... > www: http://www.hcservices.de > > > > ---------------------------------------------------------------------- > -------- > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > ---------------------------------------------------------------------------- -- _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Tomas G. <to...@pr...> - 2015-12-15 14:42:54
|
Yes, this has been done. I'm not sure if it requires SCEP RA mode or not though. We will be working on an integration guide for EJBCA Enterprise with Airwatch. Cheers, Tomas On 2015-12-15 02:48, nouchi david wrote: > Hi, > > Does anyone has already integrated PKI EJBCA with EMM AIR WATCH to > generate and push certificates on smartphones (Android, IOS) using EJBCA > Web Services (SOAP ?)? > > Thanks in advance for your return > > Regards > > ------------------- > David NOUCHI > > > ------------------------------------------------------------------------------ > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: nouchi d. <dno...@ya...> - 2015-12-15 09:48:43
|
Hi, Does anyone has already integrated PKI EJBCA with EMM AIR WATCH to generate and push certificates on smartphones (Android, IOS) using EJBCA Web Services (SOAP ?)? Thanks in advance for your return Regards ------------------- David NOUCHI |
|
From: Tomas G. <to...@pr...> - 2015-12-14 17:36:51
|
Hi are you sure the "CN=Root CA,O=MyCompany,C=DE" have CRL available, and not just a Sub CA? Regards, Tomas On 2015-12-11 07:32, Ralf Hornik wrote: > Hi, > > i just noticed that there are several exceptions from various clients in the > wildfly log: > > 2015-12-11 14:36:18,817 DEBUG [org.ejbca.ui.web.RequestHelper] (default > task-31) Setting encoding to default value: UTF-8 > 2015-12-11 14:36:18,820 INFO > [org.cesecore.certificates.crl.CrlStoreSessionBean] (default task-31) Error > retrieving CRL for issuer 'CN=Root CA,O=MyCompany,C=DE' with CRL number 0. > 2015-12-11 14:36:18,820 DEBUG [org.ejbca.ui.web.pub.CertDistServlet] > (default task-31) Error sending latest CRL to 10.51.18.138: : > java.lang.NullPointerException > > Other log entries with CRL number >0 are successfull. > The clients are mostly windows PCs. I think they try to lookup the CDP and > want to retrieve the CRL. > > Any hints why ejbca tries to send a CRL with serial 0? The current CRL > number is 15. > Thanks and best regards > > Ralf Hornik > Hosting Consulting Services > Abt-Gallus-Str. 23 > 86609 Donauwörth > Tel: +49 906 20430 12 > Fax: +49 906 20430 15 > Mobil: +49 151 50721262 > email: rh...@hc... > www: http://www.hcservices.de > > > > ------------------------------------------------------------------------------ > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Ralf H. <rh...@hc...> - 2015-12-11 14:32:17
|
Hi, i just noticed that there are several exceptions from various clients in the wildfly log: 2015-12-11 14:36:18,817 DEBUG [org.ejbca.ui.web.RequestHelper] (default task-31) Setting encoding to default value: UTF-8 2015-12-11 14:36:18,820 INFO [org.cesecore.certificates.crl.CrlStoreSessionBean] (default task-31) Error retrieving CRL for issuer 'CN=Root CA,O=MyCompany,C=DE' with CRL number 0. 2015-12-11 14:36:18,820 DEBUG [org.ejbca.ui.web.pub.CertDistServlet] (default task-31) Error sending latest CRL to 10.51.18.138: : java.lang.NullPointerException Other log entries with CRL number >0 are successfull. The clients are mostly windows PCs. I think they try to lookup the CDP and want to retrieve the CRL. Any hints why ejbca tries to send a CRL with serial 0? The current CRL number is 15. Thanks and best regards Ralf Hornik Hosting Consulting Services Abt-Gallus-Str. 23 86609 Donauwörth Tel: +49 906 20430 12 Fax: +49 906 20430 15 Mobil: +49 151 50721262 email: rh...@hc... www: http://www.hcservices.de |
|
From: Tomas G. <to...@pr...> - 2015-12-11 13:39:46
|
Hi, "No EJB receiver available..." Means that EJBCA did not deploy correctly. After the step "ant clean deployear" you should check the wildfly server.log. Now I see btw, WildFly 9 does not work with EJBCA 6.3. Unfortunately I see that this is described in the section about wildfly 8. So you should use Wildfly 8 until the next release of EJBCA Community, then wildfly 9 will work as well. Cheers, Tomas Save time and money with an Enterprise support subscription. Please see www.primekey.se for more information. https://www.primekey.se/technologies/products-overview/ https://www.primekey.se/service-support/support/ On 2015-12-11 02:58, Phil Daws wrote: > Hello, > > Am attempting to install EJBCA with Wildfly to learn more about PKI. I have been following http://ejbca.org/docs/installation.html and so far got Wildfly 9 up and running plus the data source connection to a MariaDB database. > > What I am struggling with now is what to do next ? I have tried: > > ant clean deployear > and install > > But once that runs and I enter SuperAdmin password etc it errors with: > > ejbca:initCA: > [echo] Initializing CA with 'MYCA' 'CN=MYCA,O=TESTLAB,C=GB' 'soft' <ca.tokenpassword hidden> '2048' 'RSA' '3650' 'null' 'SHA256WithRSA' -superadmincn 'SuperAdmin'... > [java] Exception in thread "main" java.util.ServiceConfigurationError: org.ejbca.ui.cli.infrastructure.command.CliCommandPlugin: Provider org.ejbca.ui.cli.ra.AddEndEntityCommand could not be instantiated > [java] at java.util.ServiceLoader.fail(ServiceLoader.java:224) > [java] at java.util.ServiceLoader.access$100(ServiceLoader.java:181) > [java] at java.util.ServiceLoader$LazyIterator.next(ServiceLoader.java:377) > [java] at java.util.ServiceLoader$1.next(ServiceLoader.java:445) > [java] at org.ejbca.ui.cli.infrastructure.library.CommandLibrary.<init>(CommandLibrary.java:53) > [java] at org.ejbca.ui.cli.infrastructure.library.CommandLibrary.<clinit>(CommandLibrary.java:38) > [java] at org.ejbca.ui.cli.EjbcaEjbCli.main(EjbcaEjbCli.java:29) > [java] Caused by: java.lang.IllegalStateException: EJBCLIENT000025: No EJB receiver available for handling [appName:ejbca, moduleName:cesecore-ejb, distinctName:] combination for invocation context org.jboss.ejb.client.EJBClientInvocationContext@682efa99 > [java] at org.jboss.ejb.client.EJBClientContext.requireEJBReceiver(EJBClientContext.java:774) > [java] at org.jboss.ejb.client.ReceiverInterceptor.handleInvocation(ReceiverInterceptor.java:116) > [java] at org.jboss.ejb.client.EJBClientInvocationContext.sendRequest(EJBClientInvocationContext.java:186) > [java] at org.jboss.ejb.client.EJBInvocationHandler.sendRequestWithPossibleRetries(EJBInvocationHandler.java:255) > [java] at org.jboss.ejb.client.EJBInvocationHandler.doInvoke(EJBInvocationHandler.java:200) > [java] at org.jboss.ejb.client.EJBInvocationHandler.doInvoke(EJBInvocationHandler.java:183) > [java] at org.jboss.ejb.client.EJBInvocationHandler.invoke(EJBInvocationHandler.java:146) > [java] at com.sun.proxy.$Proxy0.getCachedConfiguration(Unknown Source) > [java] at org.ejbca.ui.cli.ra.AddEndEntityCommand.<init>(AddEndEntityCommand.java:89) > [java] at sun.reflect.NativeConstructorAccessorImpl.newInstance0(Native Method) > [java] at sun.reflect.NativeConstructorAccessorImpl.newInstance(NativeConstructorAccessorImpl.java:57) > [java] at sun.reflect.DelegatingConstructorAccessorImpl.newInstance(DelegatingConstructorAccessorImpl.java:45) > [java] at java.lang.reflect.Constructor.newInstance(Constructor.java:526) > [java] at java.lang.Class.newInstance(Class.java:383) > [java] at java.util.ServiceLoader$LazyIterator.next(ServiceLoader.java:373) > [java] ... 4 more > > BUILD FAILED > > What steps have I missed please ? > > Thanks, Phil > > > > ------------------------------------------------------------------------------ > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Tomas G. <to...@pr...> - 2015-12-11 12:48:13
|
Hi, This message is nothing to worry about. Completely normal. Regards, Tomas On 2015-12-11 02:23, Phil Daws wrote: > Hello Tomas: > > Am attempting to get EBJCA running on Wildfly 9 but keep receiving this error: > > [java] 0 [main] INFO org.cesecore.keys.token.CryptoTokenFactory - Class not found: se.primeKey.caToken.card.PrimeCAToken. > [java] 1 [main] INFO org.cesecore.keys.token.CryptoTokenFactory - Can not register se.primeKey.caToken.card.PrimeCAToken. This is normally not an error. > > Is that anything to worry about ? > > Thanks, Phil > > > ----- On 10 Sep, 2015, at 12:02, Tomas Gustavsson to...@pr... wrote: > >> This link should work better. >> >> http://ejbca.org/docs/installation.html#WildFly%208 >> >> Cheers, >> Tomas >> >> On 2015-09-10 12:51, Tomas Gustavsson wrote: >>> >>> Hi, >>> >>> We have completed the documentation how to run EJBCA on WildFly. Latest >>> Community should run well on WildFly 8, while running on WildFly 9 >>> requires a small change to build classpath which is in svn trunk. >>> >>> http://ejbca.org/docs/installation.html#WildFly 8 >>> >>> If you see any issues, please report. >>> >>> Cheers, >>> Tomas >>> >>> ------------------------------------------------------------------------------ >>> Monitor Your Dynamic Infrastructure at Any Scale With Datadog! >>> Get real-time metrics from all of your servers, apps and tools >>> in one place. >>> SourceForge users - Click here to start your Free Trial of Datadog now! >>> http://pubads.g.doubleclick.net/gampad/clk?id=241902991&iu=/4140 >>> _______________________________________________ >>> Ejbca-develop mailing list >>> Ejb...@li... >>> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >>> >> >> ------------------------------------------------------------------------------ >> Monitor Your Dynamic Infrastructure at Any Scale With Datadog! >> Get real-time metrics from all of your servers, apps and tools >> in one place. >> SourceForge users - Click here to start your Free Trial of Datadog now! >> http://pubads.g.doubleclick.net/gampad/clk?id=241902991&iu=/4140 >> _______________________________________________ >> Ejbca-develop mailing list >> Ejb...@li... >> https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > ------------------------------------------------------------------------------ > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Phil D. <ux...@sp...> - 2015-12-11 09:58:26
|
Hello, Am attempting to install EJBCA with Wildfly to learn more about PKI. I have been following http://ejbca.org/docs/installation.html and so far got Wildfly 9 up and running plus the data source connection to a MariaDB database. What I am struggling with now is what to do next ? I have tried: ant clean deployear and install But once that runs and I enter SuperAdmin password etc it errors with: ejbca:initCA: [echo] Initializing CA with 'MYCA' 'CN=MYCA,O=TESTLAB,C=GB' 'soft' <ca.tokenpassword hidden> '2048' 'RSA' '3650' 'null' 'SHA256WithRSA' -superadmincn 'SuperAdmin'... [java] Exception in thread "main" java.util.ServiceConfigurationError: org.ejbca.ui.cli.infrastructure.command.CliCommandPlugin: Provider org.ejbca.ui.cli.ra.AddEndEntityCommand could not be instantiated [java] at java.util.ServiceLoader.fail(ServiceLoader.java:224) [java] at java.util.ServiceLoader.access$100(ServiceLoader.java:181) [java] at java.util.ServiceLoader$LazyIterator.next(ServiceLoader.java:377) [java] at java.util.ServiceLoader$1.next(ServiceLoader.java:445) [java] at org.ejbca.ui.cli.infrastructure.library.CommandLibrary.<init>(CommandLibrary.java:53) [java] at org.ejbca.ui.cli.infrastructure.library.CommandLibrary.<clinit>(CommandLibrary.java:38) [java] at org.ejbca.ui.cli.EjbcaEjbCli.main(EjbcaEjbCli.java:29) [java] Caused by: java.lang.IllegalStateException: EJBCLIENT000025: No EJB receiver available for handling [appName:ejbca, moduleName:cesecore-ejb, distinctName:] combination for invocation context org.jboss.ejb.client.EJBClientInvocationContext@682efa99 [java] at org.jboss.ejb.client.EJBClientContext.requireEJBReceiver(EJBClientContext.java:774) [java] at org.jboss.ejb.client.ReceiverInterceptor.handleInvocation(ReceiverInterceptor.java:116) [java] at org.jboss.ejb.client.EJBClientInvocationContext.sendRequest(EJBClientInvocationContext.java:186) [java] at org.jboss.ejb.client.EJBInvocationHandler.sendRequestWithPossibleRetries(EJBInvocationHandler.java:255) [java] at org.jboss.ejb.client.EJBInvocationHandler.doInvoke(EJBInvocationHandler.java:200) [java] at org.jboss.ejb.client.EJBInvocationHandler.doInvoke(EJBInvocationHandler.java:183) [java] at org.jboss.ejb.client.EJBInvocationHandler.invoke(EJBInvocationHandler.java:146) [java] at com.sun.proxy.$Proxy0.getCachedConfiguration(Unknown Source) [java] at org.ejbca.ui.cli.ra.AddEndEntityCommand.<init>(AddEndEntityCommand.java:89) [java] at sun.reflect.NativeConstructorAccessorImpl.newInstance0(Native Method) [java] at sun.reflect.NativeConstructorAccessorImpl.newInstance(NativeConstructorAccessorImpl.java:57) [java] at sun.reflect.DelegatingConstructorAccessorImpl.newInstance(DelegatingConstructorAccessorImpl.java:45) [java] at java.lang.reflect.Constructor.newInstance(Constructor.java:526) [java] at java.lang.Class.newInstance(Class.java:383) [java] at java.util.ServiceLoader$LazyIterator.next(ServiceLoader.java:373) [java] ... 4 more BUILD FAILED What steps have I missed please ? Thanks, Phil |
|
From: Phil D. <ux...@sp...> - 2015-12-11 09:24:08
|
Hello Tomas: Am attempting to get EBJCA running on Wildfly 9 but keep receiving this error: [java] 0 [main] INFO org.cesecore.keys.token.CryptoTokenFactory - Class not found: se.primeKey.caToken.card.PrimeCAToken. [java] 1 [main] INFO org.cesecore.keys.token.CryptoTokenFactory - Can not register se.primeKey.caToken.card.PrimeCAToken. This is normally not an error. Is that anything to worry about ? Thanks, Phil ----- On 10 Sep, 2015, at 12:02, Tomas Gustavsson to...@pr... wrote: > This link should work better. > > http://ejbca.org/docs/installation.html#WildFly%208 > > Cheers, > Tomas > > On 2015-09-10 12:51, Tomas Gustavsson wrote: >> >> Hi, >> >> We have completed the documentation how to run EJBCA on WildFly. Latest >> Community should run well on WildFly 8, while running on WildFly 9 >> requires a small change to build classpath which is in svn trunk. >> >> http://ejbca.org/docs/installation.html#WildFly 8 >> >> If you see any issues, please report. >> >> Cheers, >> Tomas >> >> ------------------------------------------------------------------------------ >> Monitor Your Dynamic Infrastructure at Any Scale With Datadog! >> Get real-time metrics from all of your servers, apps and tools >> in one place. >> SourceForge users - Click here to start your Free Trial of Datadog now! >> http://pubads.g.doubleclick.net/gampad/clk?id=241902991&iu=/4140 >> _______________________________________________ >> Ejbca-develop mailing list >> Ejb...@li... >> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >> > > ------------------------------------------------------------------------------ > Monitor Your Dynamic Infrastructure at Any Scale With Datadog! > Get real-time metrics from all of your servers, apps and tools > in one place. > SourceForge users - Click here to start your Free Trial of Datadog now! > http://pubads.g.doubleclick.net/gampad/clk?id=241902991&iu=/4140 > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Ralf H. <rh...@hc...> - 2015-11-20 12:25:12
|
Ok I got it working using the following "hack" cd $EJBCA_HOME/dist zip -0 doc.war static.html zip -0 ejbca.ear doc.war cd .. && and deployear If anyone else has a better idea, just drop it here :-) Regards Ralf -----Ursprüngliche Nachricht----- Von: Ralf Hornik [mailto:rh...@hc...] Gesendet: Donnerstag, 19. November 2015 11:53 An: ejb...@li... Betreff: Re: [Ejbca-develop] Adding static content to ejbca/doc in ejbca 6.3.1.1.CE Unfortunately not. "Ant build" also removes any temp content, compiles and buildes the ejbca.ear. "Ant deployear" only copies the file to the deployment folder of JBoss. It seems i will have to patch the dist/ejbca.ear afterwards -----Ursprüngliche Nachricht----- Von: Tomas Gustavsson [mailto:to...@pr...] Gesendet: Donnerstag, 19. November 2015 10:40 An: ejb...@li... Betreff: Re: [Ejbca-develop] Adding static content to ejbca/doc in ejbca 6.3.1.1.CE Did you try "ant build deployear"? /T On 2015-11-18 17:28, Ralf Hornik wrote: > Hello, > > we use a specific info site under https://server/ejbca/doc With > version 4 it was possible to add this content in "$EJBCA_HOME/tmp/htdocs/info.html" followed by an "ant deploy". > But since version 6 this seems to be not working any more. > > With "ant deployear" the file is not added to the "ejbca.ear" and removing the old "dist/ejbca.ear" leads to a complete cleanup that removes anything before building the new file. > How can we add persistent static content (independend from the EJBCA Source documentation) to the "/doc" directive? > > Thanks and kind regards > > Ralf > > > ---------------------------------------------------------------------- > -------- _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > ---------------------------------------------------------------------------- -- _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Ralf H. <rh...@hc...> - 2015-11-19 10:53:16
|
Unfortunately not. "Ant build" also removes any temp content, compiles and buildes the ejbca.ear. "Ant deployear" only copies the file to the deployment folder of JBoss. It seems i will have to patch the dist/ejbca.ear afterwards -----Ursprüngliche Nachricht----- Von: Tomas Gustavsson [mailto:to...@pr...] Gesendet: Donnerstag, 19. November 2015 10:40 An: ejb...@li... Betreff: Re: [Ejbca-develop] Adding static content to ejbca/doc in ejbca 6.3.1.1.CE Did you try "ant build deployear"? /T On 2015-11-18 17:28, Ralf Hornik wrote: > Hello, > > we use a specific info site under https://server/ejbca/doc With > version 4 it was possible to add this content in "$EJBCA_HOME/tmp/htdocs/info.html" followed by an "ant deploy". > But since version 6 this seems to be not working any more. > > With "ant deployear" the file is not added to the "ejbca.ear" and removing the old "dist/ejbca.ear" leads to a complete cleanup that removes anything before building the new file. > How can we add persistent static content (independend from the EJBCA Source documentation) to the "/doc" directive? > > Thanks and kind regards > > Ralf > > > ---------------------------------------------------------------------- > -------- _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > ---------------------------------------------------------------------------- -- _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop |