You can subscribe to this list here.
| 2001 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
(1) |
Dec
(3) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2002 |
Jan
(3) |
Feb
(2) |
Mar
(8) |
Apr
(3) |
May
(6) |
Jun
(1) |
Jul
(15) |
Aug
(6) |
Sep
|
Oct
(10) |
Nov
(2) |
Dec
(4) |
| 2003 |
Jan
(1) |
Feb
(7) |
Mar
(3) |
Apr
(6) |
May
(7) |
Jun
(5) |
Jul
(5) |
Aug
(25) |
Sep
(14) |
Oct
(2) |
Nov
|
Dec
(2) |
| 2004 |
Jan
(7) |
Feb
(4) |
Mar
(12) |
Apr
(16) |
May
(43) |
Jun
(56) |
Jul
(43) |
Aug
(40) |
Sep
(66) |
Oct
(12) |
Nov
(26) |
Dec
(10) |
| 2005 |
Jan
(13) |
Feb
(33) |
Mar
(16) |
Apr
(7) |
May
(10) |
Jun
(34) |
Jul
(41) |
Aug
(8) |
Sep
(4) |
Oct
(32) |
Nov
(20) |
Dec
(25) |
| 2006 |
Jan
(30) |
Feb
(101) |
Mar
(5) |
Apr
(75) |
May
(74) |
Jun
(22) |
Jul
(6) |
Aug
(70) |
Sep
(19) |
Oct
(21) |
Nov
(31) |
Dec
(50) |
| 2007 |
Jan
(15) |
Feb
(20) |
Mar
(24) |
Apr
(33) |
May
(13) |
Jun
(18) |
Jul
(13) |
Aug
(7) |
Sep
(63) |
Oct
(68) |
Nov
(29) |
Dec
(68) |
| 2008 |
Jan
(30) |
Feb
(33) |
Mar
(30) |
Apr
(103) |
May
(78) |
Jun
(48) |
Jul
(72) |
Aug
(24) |
Sep
(62) |
Oct
(63) |
Nov
(70) |
Dec
(37) |
| 2009 |
Jan
(34) |
Feb
(35) |
Mar
(64) |
Apr
(34) |
May
(34) |
Jun
(58) |
Jul
(30) |
Aug
(30) |
Sep
(46) |
Oct
(52) |
Nov
(12) |
Dec
(23) |
| 2010 |
Jan
(121) |
Feb
(18) |
Mar
(53) |
Apr
(62) |
May
(62) |
Jun
(20) |
Jul
(33) |
Aug
(20) |
Sep
(36) |
Oct
(35) |
Nov
(44) |
Dec
(63) |
| 2011 |
Jan
(19) |
Feb
(32) |
Mar
(94) |
Apr
(41) |
May
(47) |
Jun
(25) |
Jul
(34) |
Aug
(20) |
Sep
(9) |
Oct
(41) |
Nov
(33) |
Dec
(24) |
| 2012 |
Jan
(12) |
Feb
(36) |
Mar
(48) |
Apr
(32) |
May
(20) |
Jun
(15) |
Jul
(32) |
Aug
(13) |
Sep
(33) |
Oct
(54) |
Nov
(25) |
Dec
(16) |
| 2013 |
Jan
(45) |
Feb
(39) |
Mar
(38) |
Apr
(50) |
May
(29) |
Jun
(30) |
Jul
(33) |
Aug
(12) |
Sep
(9) |
Oct
(25) |
Nov
(29) |
Dec
(20) |
| 2014 |
Jan
(25) |
Feb
(19) |
Mar
(16) |
Apr
(33) |
May
(27) |
Jun
(37) |
Jul
(29) |
Aug
(27) |
Sep
(37) |
Oct
(58) |
Nov
(109) |
Dec
(26) |
| 2015 |
Jan
(4) |
Feb
(35) |
Mar
(22) |
Apr
(35) |
May
(28) |
Jun
(20) |
Jul
(4) |
Aug
(16) |
Sep
(37) |
Oct
(13) |
Nov
(13) |
Dec
(14) |
| 2016 |
Jan
(22) |
Feb
(7) |
Mar
(23) |
Apr
(30) |
May
(10) |
Jun
(10) |
Jul
(15) |
Aug
(12) |
Sep
(22) |
Oct
(31) |
Nov
(5) |
Dec
(5) |
| 2017 |
Jan
(30) |
Feb
(25) |
Mar
(28) |
Apr
(4) |
May
(19) |
Jun
(13) |
Jul
(7) |
Aug
(1) |
Sep
(2) |
Oct
(5) |
Nov
(12) |
Dec
(2) |
| 2018 |
Jan
(7) |
Feb
|
Mar
(7) |
Apr
(2) |
May
(8) |
Jun
(18) |
Jul
(6) |
Aug
(3) |
Sep
(15) |
Oct
(33) |
Nov
(13) |
Dec
(7) |
| 2019 |
Jan
(5) |
Feb
(7) |
Mar
(30) |
Apr
(5) |
May
(4) |
Jun
(69) |
Jul
(86) |
Aug
(22) |
Sep
(6) |
Oct
(7) |
Nov
(5) |
Dec
(3) |
| 2020 |
Jan
(10) |
Feb
(12) |
Mar
(22) |
Apr
(5) |
May
(1) |
Jun
(4) |
Jul
(6) |
Aug
|
Sep
(9) |
Oct
|
Nov
|
Dec
(1) |
| 2021 |
Jan
(4) |
Feb
(11) |
Mar
(7) |
Apr
(7) |
May
|
Jun
(3) |
Jul
(10) |
Aug
(6) |
Sep
|
Oct
|
Nov
(18) |
Dec
(2) |
| 2022 |
Jan
(1) |
Feb
(1) |
Mar
|
Apr
|
May
|
Jun
(2) |
Jul
|
Aug
(4) |
Sep
|
Oct
|
Nov
|
Dec
|
| 2023 |
Jan
|
Feb
|
Mar
|
Apr
(1) |
May
(1) |
Jun
|
Jul
|
Aug
(5) |
Sep
|
Oct
|
Nov
|
Dec
|
|
From: Ronald O. <ro...@ke...> - 2015-05-25 10:52:48
|
Hi Michael, Works like charm! Thank you so much. Ronald. On 05/25/2015 01:43 PM, Michael Ströder wrote: > Ronald Osure wrote: >> Thanks for the response. On which section/form field of the certificate >> profiles is this done? I am using EJBCA 6.2.0. > The X.509v3 extension is called "Authority Information Access". > > I don't have a running EJBCA instance at home. But IIRC the input fields are > expanded if you enable a check box. > > Ciao, Michael. > > > > ------------------------------------------------------------------------------ > One dashboard for servers and applications across Physical-Virtual-Cloud > Widest out-of-the-box monitoring support with 50+ applications > Performance metrics, stats and reports that give you Actionable Insights > Deep dive visibility with transaction tracing using APM Insight. > http://ad.doubleclick.net/ddm/clk/290420510;117567292;y > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Michael S. <mi...@st...> - 2015-05-25 10:43:13
|
Ronald Osure wrote: > Thanks for the response. On which section/form field of the certificate > profiles is this done? I am using EJBCA 6.2.0. The X.509v3 extension is called "Authority Information Access". I don't have a running EJBCA instance at home. But IIRC the input fields are expanded if you enable a check box. Ciao, Michael. |
|
From: Ronald O. <ro...@ke...> - 2015-05-25 10:35:08
|
Hi Michael, Thanks for the response. On which section/form field of the certificate profiles is this done? I am using EJBCA 6.2.0. I am using a clean custom url in the format ocsp.example.com and I have configured Apache as a Reverse proxy to handle the communication with the JBOSS server. On 05/25/2015 12:58 PM, Michael Ströder wrote: > Ronald Osure wrote: >> I have successfully setup EJBCA on two boxes to serve the functions of both CA >> and OCSP on separate servers. The OCSP server answers correctly for >> certificates issued from the CA server. >> >> My problem is that when I execute the below command to try and establish if an >> issued certificate has na OCSP Url, none is printed out and I believe it >> should be part of the certificate. >> >> openssl x509 -noout -ocsp_uri -in TestUser.pem >> >> What could I have missed in the configuration? > OCSP responder URLs are configured in the certificate profile. > > For better flexibility with HA setup of external OCSP responders I would *not* > use the automatically generated URLs. > > Ciao, Michael. > > > > ------------------------------------------------------------------------------ > One dashboard for servers and applications across Physical-Virtual-Cloud > Widest out-of-the-box monitoring support with 50+ applications > Performance metrics, stats and reports that give you Actionable Insights > Deep dive visibility with transaction tracing using APM Insight. > http://ad.doubleclick.net/ddm/clk/290420510;117567292;y > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Michael S. <mi...@st...> - 2015-05-25 09:58:37
|
Ronald Osure wrote: > I have successfully setup EJBCA on two boxes to serve the functions of both CA > and OCSP on separate servers. The OCSP server answers correctly for > certificates issued from the CA server. > > My problem is that when I execute the below command to try and establish if an > issued certificate has na OCSP Url, none is printed out and I believe it > should be part of the certificate. > > openssl x509 -noout -ocsp_uri -in TestUser.pem > > What could I have missed in the configuration? OCSP responder URLs are configured in the certificate profile. For better flexibility with HA setup of external OCSP responders I would *not* use the automatically generated URLs. Ciao, Michael. |
|
From: Ronald O. <ro...@ke...> - 2015-05-25 07:04:25
|
Hi, I have successfully setup EJBCA on two boxes to serve the functions of both CA and OCSP on separate servers. The OCSP server answers correctly for certificates issued from the CA server. My problem is that when I execute the below command to try and establish if an issued certificate has na OCSP Url, none is printed out and I believe it should be part of the certificate. openssl x509 -noout -ocsp_uri -in TestUser.pem What could I have missed in the configuration? Cheers. Ronald. |
|
From: Andrea D. <ado...@in...> - 2015-05-20 13:29:14
|
Hello all, I'm trying to insert a value with character apex ( ' ) into field cityOfBirth but EJBCA return this error: org.ejbca.core.model.ra.raadmin.UserDoesntFullfillEndEntityProfile: Invalid L'Aquila. Contains illegal characters. If use the same value into field Name or Surname doesn't have this problem. How can I resolve this problem about cityOfBirth field? Thanks in advance Andrea -- Andrea Dondoni ------------------------------------------------------------------------ *Intesi Group S.p.A. <http://www.intesigroup.com>* | Via Torino, 48 | 20123 Milano - Italia | T. +39 0267606484 |
|
From: Markus K. <ma...@pr...> - 2015-05-19 17:14:38
|
Hi Marcin, We do not recommend running both EJBCA and SignServer in the same JBoss instance. It might be possible but we are not currently testing for that use case. Try with only SignServer deployed in standalone/deployments/. Usually if JBoss fails to start like this there is an configuration error. Check that you have followed all steps in the installation guide in the manual. Especially the steps for configuring the database driver and datasource etc. If you need more help troubleshooting the SignServer installation you can use the signserver-develop mailinglist. Cheers, Markus On 05/19/2015 02:44 PM, Marcin FabiaÅczyk wrote: > Deployment of Signserver was successful > > More details: > > 14:36:50,080 INFO [org.jboss.as.server] (DeploymentScanner-threads - 2) > JBAS015870: Deploy of deployment "signserver.ear" was rolled back with > failure message Operation cancelled > 14:36:50,081 ERROR [org.jboss.as.server.deployment.scanner] > (DeploymentScanner-threads - 1) JBAS015052: Did not receive a response > to the deployment operation within the allowed timeout period [60 > seconds]. Check the server configuration file and the server logs to > find more about the status of the deployment. > 14:36:50,083 ERROR [org.jboss.as.server.deployment.scanner] > (DeploymentScanner-threads - 1) JBAS015052: Did not receive a response > to the deployment operation within the allowed timeout period [60 > seconds]. Check the server configuration file and the server logs to > find more about the status of the deployment. > 14:36:50,085 INFO [org.jboss.as.server] (DeploymentScanner-threads - 2) > JBAS015871: Deploy of deployment "ejbca.ear" was rolled back with no > failure message > 14:36:50,116 INFO [org.jboss.as.webservices] (MSC service thread 1-5) > JBAS015540: Stopping service > jboss.ws.endpoint."signserver.ear"."SignServer-ejb-ValidationWS.jar".ValidationWS > 14:36:50,117 INFO > [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service > thread 1-5) remove: > jboss.ws:context=signserver/ValidationWSService,endpoint=ValidationWS > 14:36:50,121 INFO [org.jboss.as.webservices] (MSC service thread 1-2) > JBAS015540: Stopping service > jboss.ws.endpoint."signserver.ear"."SignServer-ejb-SignServerWS.jar".SignServerWS > 14:36:50,122 INFO > [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service > thread 1-2) remove: > jboss.ws:context=signserver/SignServerWSService,endpoint=SignServerWS > 14:36:50,150 INFO [org.jboss.as.webservices] (MSC service thread 1-4) > JBAS015540: Stopping service > jboss.ws.endpoint."signserver.ear"."SignServer-ejb-AdminWS.jar".AdminWS > 14:36:50,151 INFO > [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service > thread 1-4) remove: > jboss.ws:context=signserver/AdminWSService,endpoint=AdminWS > 14:36:50,173 INFO [org.jboss.as.webservices] (MSC service thread 1-7) > JBAS015540: Stopping service > jboss.ws.endpoint."signserver.ear"."SignServer-ejb-ClientWS.jar".ClientWS > 14:36:50,174 INFO > [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service > thread 1-7) remove: > jboss.ws:context=signserver/ClientWSService,endpoint=ClientWS > 14:36:50,187 INFO [org.jboss.as.webservices] (MSC service thread 1-7) > JBAS015540: Stopping service > jboss.ws.endpoint."ejbca.ear"."ejbca-ws-ejb.jar".EjbcaWS > 14:36:50,188 INFO > [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service > thread 1-7) remove: jboss.ws:context=ejbca/ejbcaws,endpoint=EjbcaWS > 14:36:50,235 INFO > [org.ejbca.ui.web.admin.configuration.StartServicesServlet] (MSC service > thread 1-8) Destroy, EJBCA shutdown. > 14:36:50,292 INFO [org.jboss.as.jpa] (MSC service thread 1-5) > JBAS011403: Stopping Persistence Unit Service 'ejbca.ear#ejbca' > 14:36:50,399 INFO [org.jboss.as.webservices] (MSC service thread 1-1) > JBAS015540: Stopping service jboss.ws.port-component-link > 14:36:50,484 INFO [org.jboss.as.server.deployment] (MSC service thread > 1-5) JBAS015877: Stopped deployment webdist.war in 397ms > 14:36:50,483 INFO [org.jboss.as.server.deployment] (MSC service thread > 1-7) JBAS015877: Stopped deployment cesecore-ejb.jar in 396ms > 14:36:50,484 INFO [org.jboss.as.server.deployment] (MSC service thread > 1-8) JBAS015877: Stopped deployment healthcheck.war in 397ms > 14:36:50,483 INFO [org.jboss.as.server.deployment] (MSC service thread > 1-4) JBAS015877: Stopped deployment status.war in 396ms > 14:36:50,487 INFO [org.jboss.as.server.deployment] (MSC service thread > 1-7) JBAS015877: Stopped deployment ejbca-ejb.jar in 400ms > 14:36:50,488 INFO [org.jboss.as.server.deployment] (MSC service thread > 1-4) JBAS015877: Stopped deployment systemtests-ejb.jar in 401ms > 14:36:50,486 INFO [org.jboss.as.server.deployment] (MSC service thread > 1-5) JBAS015877: Stopped deployment cmp.war in 400ms > 14:36:50,491 INFO [org.jboss.as.server.deployment] (MSC service thread > 1-1) JBAS015877: Stopped deployment scep.war in 404ms > 14:36:50,496 INFO [org.jboss.as.server.deployment] (MSC service thread > 1-4) JBAS015877: Stopped deployment clearcache.war in 410ms > 14:36:50,488 INFO [org.jboss.as.server.deployment] (MSC service thread > 1-7) JBAS015877: Stopped deployment ejbca-ws-ejb.jar in 401ms > 14:36:50,487 INFO [org.jboss.as.server.deployment] (MSC service thread > 1-8) JBAS015877: Stopped deployment crlstore.war in 401ms > 14:36:50,497 INFO [org.jboss.as.server.deployment] (MSC service thread > 1-1) JBAS015877: Stopped deployment doc.war in 410ms > 14:36:50,497 INFO [org.jboss.as.server.deployment] (MSC service thread > 1-5) JBAS015877: Stopped deployment publicweb.war in 410ms > 14:36:50,525 INFO [org.jboss.as.server.deployment] (MSC service thread > 1-3) JBAS015877: Stopped deployment adminweb.war in 438ms > 14:36:50,552 INFO [org.jboss.as.server.deployment] (MSC service thread > 1-3) JBAS015877: Stopped deployment ejbca.ear in 466ms > > ------------------------------------------------------------------------ > *Od: *"Marcin FabiaÅczyk" <mar...@en...> > *Do: *ejb...@li... > *WysÅane: *wtorek, 19 maj 2015 14:33:19 > *Temat: *Re: [Ejbca-develop] Timestamp service > > Hello, > > After the implementation of SignServer in my environment Ejbca and > reload the JBoss service I have a problem. Log below: > > > 14:21:59,105 INFO [org.jboss.as.webservices] (MSC service thread 1-1) > JBAS015540: Stopping service > jboss.ws.endpoint."signserver.ear"."SignServer-ejb-ValidationWS.jar".ValidationWS > 14:21:59,106 INFO > [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service > thread 1-1) remove: > jboss.ws:context=signserver/ValidationWSService,endpoint=ValidationWS > 14:21:59,108 INFO [org.jboss.as.webservices] (MSC service thread 1-6) > JBAS015540: Stopping service > jboss.ws.endpoint."signserver.ear"."SignServer-ejb-AdminWS.jar".AdminWS > 14:21:59,109 INFO > [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service > thread 1-6) remove: > jboss.ws:context=signserver/AdminWSService,endpoint=AdminWS > 14:21:59,117 INFO [org.jboss.as.webservices] (MSC service thread 1-2) > JBAS015540: Stopping service > jboss.ws.endpoint."signserver.ear"."SignServer-ejb-SignServerWS.jar".SignServerWS > 14:21:59,118 INFO > [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service > thread 1-2) remove: > jboss.ws:context=signserver/SignServerWSService,endpoint=SignServerWS > 14:21:59,119 INFO [org.jboss.as.webservices] (MSC service thread 1-5) > JBAS015540: Stopping service > jboss.ws.endpoint."signserver.ear"."SignServer-ejb-ClientWS.jar".ClientWS > 14:21:59,121 INFO > [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service > thread 1-5) remove: > jboss.ws:context=signserver/ClientWSService,endpoint=ClientWS > 14:21:59,158 INFO [org.jboss.as.webservices] (MSC service thread 1-1) > JBAS015540: Stopping service > jboss.ws.endpoint."ejbca.ear"."ejbca-ws-ejb.jar".EjbcaWS > 14:21:59,163 INFO > [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service > thread 1-1) remove: jboss.ws:context=ejbca/ejbcaws,endpoint=EjbcaWS > 14:21:59,236 INFO > [org.ejbca.ui.web.admin.configuration.StartServicesServlet] (MSC service > thread 1-6) Destroy, EJBCA shutdown. > 14:21:59,299 INFO [org.jboss.as.jpa] (MSC service thread 1-4) > JBAS011403: Stopping Persistence Unit Service 'ejbca.ear#ejbca' > 14:21:59,406 INFO [org.jboss.as.webservices] (MSC service thread 1-1) > JBAS015540: Stopping service jboss.ws.port-component-link > 14:21:59,469 INFO [org.jboss.as.server.deployment] (MSC service thread > 1-1) JBAS015877: Stopped deployment status.war in 405ms > 14:21:59,469 INFO [org.jboss.as.server.deployment] (MSC service thread > 1-3) JBAS015877: Stopped deployment cesecore-ejb.jar in 406ms > 14:21:59,470 INFO [org.jboss.as.server.deployment] (MSC service thread > 1-1) JBAS015877: Stopped deployment webdist.war in 406ms > 14:21:59,471 INFO [org.jboss.as.server.deployment] (MSC service thread > 1-4) JBAS015877: Stopped deployment cmp.war in 407ms > 14:21:59,472 INFO [org.jboss.as.server.deployment] (MSC service thread > 1-4) JBAS015877: Stopped deployment systemtests-ejb.jar in 409ms > 14:21:59,471 INFO [org.jboss.as.server.deployment] (MSC service thread > 1-8) JBAS015877: Stopped deployment ejbca-ejb.jar in 407ms > 14:21:59,473 INFO [org.jboss.as.server.deployment] (MSC service thread > 1-2) JBAS015877: Stopped deployment ejbca-ws-ejb.jar in 409ms > 14:21:59,470 INFO [org.jboss.as.server.deployment] (MSC service thread > 1-3) JBAS015877: Stopped deployment healthcheck.war in 407ms > 14:21:59,473 INFO [org.jboss.as.server.deployment] (MSC service thread > 1-4) JBAS015877: Stopped deployment clearcache.war in 409ms > 14:21:59,471 INFO [org.jboss.as.server.deployment] (MSC service thread > 1-1) JBAS015877: Stopped deployment crlstore.war in 407ms > 14:21:59,475 INFO [org.jboss.as.server.deployment] (MSC service thread > 1-3) JBAS015877: Stopped deployment publicweb.war in 412ms > 14:21:59,475 INFO [org.jboss.as.server.deployment] (MSC service thread > 1-4) JBAS015877: Stopped deployment scep.war in 411ms > 14:21:59,478 INFO [org.jboss.as.server.deployment] (MSC service thread > 1-5) JBAS015877: Stopped deployment doc.war in 415ms > 14:21:59,498 INFO [org.jboss.as.server.deployment] (MSC service thread > 1-6) JBAS015877: Stopped deployment adminweb.war in 435ms > 14:21:59,525 INFO [org.jboss.as.server.deployment] (MSC service thread > 1-8) JBAS015877: Stopped deployment ejbca.ear in 463ms > > > ------------------------------------------------------------------------ > *Od: *"Andreas Kuehne" <ku...@tr...> > *Do: *ejb...@li... > *WysÅane: *poniedziaÅek, 18 maj 2015 23:22:37 > *Temat: *Re: [Ejbca-develop] Timestamp service > > Hi Marcin, > > ejbca is about certificates, not about timestamps. > If you are looking for a simple RFC 3161 timestamp, try the timestamp > servers of Bouncy Castle or iaik. > > Greetings, > > Andreas > > Hello, > > > On the EJBCE 6.2 is ability to sign documents timestamp? If yes, can I ask > where and how it works? because I can not find information on this case. > > > > Regards, > Martin > > > > > > > > > ------------------------------------------------------------------------------ > One dashboard for servers and applications across Physical-Virtual-Cloud > Widest out-of-the-box monitoring support with 50+ applications > Performance metrics, stats and reports that give you Actionable Insights > Deep dive visibility with transaction tracing using APM Insight. > http://ad.doubleclick.net/ddm/clk/290420510;117567292;y > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > -- > Andreas Kühne > phone: +49 177 293 24 97 > mailto: ku...@tr... > > Trustable Ltd. Niederlassung Deutschland Ströverstr. 18 - 59427 Unna Amtsgericht Hamm HRB 5868 > > Directors Andreas Kühne, Heiko Veit > > Company UK Company No: 5218868 Registered in England and Wales > > |
|
From: Ralf H. <rh...@hc...> - 2015-05-19 15:17:34
|
Hi Tomas, ./ejbca.sh ca changecertprofile CAName CertProfile Thank you! Ralf -----Ursprüngliche Nachricht----- Von: Tomas Gustavsson [mailto:to...@pr...] Gesendet: Dienstag, 19. Mai 2015 17:00 An: ejb...@li... Betreff: Re: [Ejbca-develop] Renewing intermediate CA with sha2 signature algorithm (ejbca 4.0.16) There is a CLI command to change certificate profile of a CA. Regards, Tomas ----- Save time and money with an Enterprise support subscription. Please see www.primekey.se for more information. https://www.primekey.se/technologies/products-overview/ https://www.primekey.se/service-support/support/ On 2015-05-19 16:17, Ralf Hornik wrote: > Hello, > > some weeks before i wrote about a sha fingerprint and was confused about it. > Now i figured out that Chrome only allows sha2 signature algorithms in > end entities AND its issuing intermediate certificates. > > So i now try to renew the internal Sub CA and issue with new sha2 > signature algorithm. > To avoid renewing all end entities (that already have sha2) i want to > use the same key for the new CA Certificate. > > The problem is, that it is fixed issued with the SUBCA certificate > profile that can not be edited to change the signature algorithm. > > So far i have one question: How can the existing SubCA Certificate be > renewed using a customized cert profile? > Thank you and regards > > Ralf > > > > ---------------------------------------------------------------------- > -------- One dashboard for servers and applications across > Physical-Virtual-Cloud Widest out-of-the-box monitoring support with > 50+ applications Performance metrics, stats and reports that give you > Actionable Insights Deep dive visibility with transaction tracing > using APM Insight. > http://ad.doubleclick.net/ddm/clk/290420510;117567292;y > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > ---------------------------------------------------------------------------- -- One dashboard for servers and applications across Physical-Virtual-Cloud Widest out-of-the-box monitoring support with 50+ applications Performance metrics, stats and reports that give you Actionable Insights Deep dive visibility with transaction tracing using APM Insight. http://ad.doubleclick.net/ddm/clk/290420510;117567292;y _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Tomas G. <to...@pr...> - 2015-05-19 15:00:11
|
There is a CLI command to change certificate profile of a CA. Regards, Tomas ----- Save time and money with an Enterprise support subscription. Please see www.primekey.se for more information. https://www.primekey.se/technologies/products-overview/ https://www.primekey.se/service-support/support/ On 2015-05-19 16:17, Ralf Hornik wrote: > Hello, > > some weeks before i wrote about a sha fingerprint and was confused about it. > Now i figured out that Chrome only allows sha2 signature algorithms in end > entities AND its issuing intermediate certificates. > > So i now try to renew the internal Sub CA and issue with new sha2 signature > algorithm. > To avoid renewing all end entities (that already have sha2) i want to use > the same key for the new CA Certificate. > > The problem is, that it is fixed issued with the SUBCA certificate profile > that can not be edited to change the signature algorithm. > > So far i have one question: How can the existing SubCA Certificate be > renewed using a customized cert profile? > Thank you and regards > > Ralf > > > > ------------------------------------------------------------------------------ > One dashboard for servers and applications across Physical-Virtual-Cloud > Widest out-of-the-box monitoring support with 50+ applications > Performance metrics, stats and reports that give you Actionable Insights > Deep dive visibility with transaction tracing using APM Insight. > http://ad.doubleclick.net/ddm/clk/290420510;117567292;y > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Ralf H. <rh...@hc...> - 2015-05-19 14:17:26
|
Hello, some weeks before i wrote about a sha fingerprint and was confused about it. Now i figured out that Chrome only allows sha2 signature algorithms in end entities AND its issuing intermediate certificates. So i now try to renew the internal Sub CA and issue with new sha2 signature algorithm. To avoid renewing all end entities (that already have sha2) i want to use the same key for the new CA Certificate. The problem is, that it is fixed issued with the SUBCA certificate profile that can not be edited to change the signature algorithm. So far i have one question: How can the existing SubCA Certificate be renewed using a customized cert profile? Thank you and regards Ralf |
|
From: Marcin F. <mar...@en...> - 2015-05-19 12:40:54
|
Deployment of Signserver was successful More details: 14:36:50,080 INFO [org.jboss.as.server] (DeploymentScanner-threads - 2) JBAS015870: Deploy of deployment "signserver.ear" was rolled back with failure message Operation cancelled 14:36:50,081 ERROR [org.jboss.as.server.deployment.scanner] (DeploymentScanner-threads - 1) JBAS015052: Did not receive a response to the deployment operation within the allowed timeout period [60 seconds]. Check the server configuration file and the server logs to find more about the status of the deployment. 14:36:50,083 ERROR [org.jboss.as.server.deployment.scanner] (DeploymentScanner-threads - 1) JBAS015052: Did not receive a response to the deployment operation within the allowed timeout period [60 seconds]. Check the server configuration file and the server logs to find more about the status of the deployment. 14:36:50,085 INFO [org.jboss.as.server] (DeploymentScanner-threads - 2) JBAS015871: Deploy of deployment "ejbca.ear" was rolled back with no failure message 14:36:50,116 INFO [org.jboss.as.webservices] (MSC service thread 1-5) JBAS015540: Stopping service jboss.ws.endpoint."signserver.ear"."SignServer-ejb-ValidationWS.jar".ValidationWS 14:36:50,117 INFO [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service thread 1-5) remove: jboss.ws:context=signserver/ValidationWSService,endpoint=ValidationWS 14:36:50,121 INFO [org.jboss.as.webservices] (MSC service thread 1-2) JBAS015540: Stopping service jboss.ws.endpoint."signserver.ear"."SignServer-ejb-SignServerWS.jar".SignServerWS 14:36:50,122 INFO [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service thread 1-2) remove: jboss.ws:context=signserver/SignServerWSService,endpoint=SignServerWS 14:36:50,150 INFO [org.jboss.as.webservices] (MSC service thread 1-4) JBAS015540: Stopping service jboss.ws.endpoint."signserver.ear"."SignServer-ejb-AdminWS.jar".AdminWS 14:36:50,151 INFO [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service thread 1-4) remove: jboss.ws:context=signserver/AdminWSService,endpoint=AdminWS 14:36:50,173 INFO [org.jboss.as.webservices] (MSC service thread 1-7) JBAS015540: Stopping service jboss.ws.endpoint."signserver.ear"."SignServer-ejb-ClientWS.jar".ClientWS 14:36:50,174 INFO [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service thread 1-7) remove: jboss.ws:context=signserver/ClientWSService,endpoint=ClientWS 14:36:50,187 INFO [org.jboss.as.webservices] (MSC service thread 1-7) JBAS015540: Stopping service jboss.ws.endpoint."ejbca.ear"."ejbca-ws-ejb.jar".EjbcaWS 14:36:50,188 INFO [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service thread 1-7) remove: jboss.ws:context=ejbca/ejbcaws,endpoint=EjbcaWS 14:36:50,235 INFO [org.ejbca.ui.web.admin.configuration.StartServicesServlet] (MSC service thread 1-8) Destroy, EJBCA shutdown. 14:36:50,292 INFO [org.jboss.as.jpa] (MSC service thread 1-5) JBAS011403: Stopping Persistence Unit Service 'ejbca.ear#ejbca' 14:36:50,399 INFO [org.jboss.as.webservices] (MSC service thread 1-1) JBAS015540: Stopping service jboss.ws.port-component-link 14:36:50,484 INFO [org.jboss.as.server.deployment] (MSC service thread 1-5) JBAS015877: Stopped deployment webdist.war in 397ms 14:36:50,483 INFO [org.jboss.as.server.deployment] (MSC service thread 1-7) JBAS015877: Stopped deployment cesecore-ejb.jar in 396ms 14:36:50,484 INFO [org.jboss.as.server.deployment] (MSC service thread 1-8) JBAS015877: Stopped deployment healthcheck.war in 397ms 14:36:50,483 INFO [org.jboss.as.server.deployment] (MSC service thread 1-4) JBAS015877: Stopped deployment status.war in 396ms 14:36:50,487 INFO [org.jboss.as.server.deployment] (MSC service thread 1-7) JBAS015877: Stopped deployment ejbca-ejb.jar in 400ms 14:36:50,488 INFO [org.jboss.as.server.deployment] (MSC service thread 1-4) JBAS015877: Stopped deployment systemtests-ejb.jar in 401ms 14:36:50,486 INFO [org.jboss.as.server.deployment] (MSC service thread 1-5) JBAS015877: Stopped deployment cmp.war in 400ms 14:36:50,491 INFO [org.jboss.as.server.deployment] (MSC service thread 1-1) JBAS015877: Stopped deployment scep.war in 404ms 14:36:50,496 INFO [org.jboss.as.server.deployment] (MSC service thread 1-4) JBAS015877: Stopped deployment clearcache.war in 410ms 14:36:50,488 INFO [org.jboss.as.server.deployment] (MSC service thread 1-7) JBAS015877: Stopped deployment ejbca-ws-ejb.jar in 401ms 14:36:50,487 INFO [org.jboss.as.server.deployment] (MSC service thread 1-8) JBAS015877: Stopped deployment crlstore.war in 401ms 14:36:50,497 INFO [org.jboss.as.server.deployment] (MSC service thread 1-1) JBAS015877: Stopped deployment doc.war in 410ms 14:36:50,497 INFO [org.jboss.as.server.deployment] (MSC service thread 1-5) JBAS015877: Stopped deployment publicweb.war in 410ms 14:36:50,525 INFO [org.jboss.as.server.deployment] (MSC service thread 1-3) JBAS015877: Stopped deployment adminweb.war in 438ms 14:36:50,552 INFO [org.jboss.as.server.deployment] (MSC service thread 1-3) JBAS015877: Stopped deployment ejbca.ear in 466ms Od: "Marcin Fabiańczyk" <mar...@en...> Do: ejb...@li... Wysłane: wtorek, 19 maj 2015 14:33:19 Temat: Re: [Ejbca-develop] Timestamp service Hello, After the implementation of SignServer in my environment Ejbca and reload the JBoss service I have a problem . Log below : 14:21:59,105 INFO [org.jboss.as.webservices] (MSC service thread 1-1) JBAS015540: Stopping service jboss.ws.endpoint."signserver.ear"."SignServer-ejb-ValidationWS.jar".ValidationWS 14:21:59,106 INFO [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service thread 1-1) remove: jboss.ws:context=signserver/ValidationWSService,endpoint=ValidationWS 14:21:59,108 INFO [org.jboss.as.webservices] (MSC service thread 1-6) JBAS015540: Stopping service jboss.ws.endpoint."signserver.ear"."SignServer-ejb-AdminWS.jar".AdminWS 14:21:59,109 INFO [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service thread 1-6) remove: jboss.ws:context=signserver/AdminWSService,endpoint=AdminWS 14:21:59,117 INFO [org.jboss.as.webservices] (MSC service thread 1-2) JBAS015540: Stopping service jboss.ws.endpoint."signserver.ear"."SignServer-ejb-SignServerWS.jar".SignServerWS 14:21:59,118 INFO [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service thread 1-2) remove: jboss.ws:context=signserver/SignServerWSService,endpoint=SignServerWS 14:21:59,119 INFO [org.jboss.as.webservices] (MSC service thread 1-5) JBAS015540: Stopping service jboss.ws.endpoint."signserver.ear"."SignServer-ejb-ClientWS.jar".ClientWS 14:21:59,121 INFO [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service thread 1-5) remove: jboss.ws:context=signserver/ClientWSService,endpoint=ClientWS 14:21:59,158 INFO [org.jboss.as.webservices] (MSC service thread 1-1) JBAS015540: Stopping service jboss.ws.endpoint."ejbca.ear"."ejbca-ws-ejb.jar".EjbcaWS 14:21:59,163 INFO [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service thread 1-1) remove: jboss.ws:context=ejbca/ejbcaws,endpoint=EjbcaWS 14:21:59,236 INFO [org.ejbca.ui.web.admin.configuration.StartServicesServlet] (MSC service thread 1-6) Destroy, EJBCA shutdown. 14:21:59,299 INFO [org.jboss.as.jpa] (MSC service thread 1-4) JBAS011403: Stopping Persistence Unit Service 'ejbca.ear#ejbca' 14:21:59,406 INFO [org.jboss.as.webservices] (MSC service thread 1-1) JBAS015540: Stopping service jboss.ws.port-component-link 14:21:59,469 INFO [org.jboss.as.server.deployment] (MSC service thread 1-1) JBAS015877: Stopped deployment status.war in 405ms 14:21:59,469 INFO [org.jboss.as.server.deployment] (MSC service thread 1-3) JBAS015877: Stopped deployment cesecore-ejb.jar in 406ms 14:21:59,470 INFO [org.jboss.as.server.deployment] (MSC service thread 1-1) JBAS015877: Stopped deployment webdist.war in 406ms 14:21:59,471 INFO [org.jboss.as.server.deployment] (MSC service thread 1-4) JBAS015877: Stopped deployment cmp.war in 407ms 14:21:59,472 INFO [org.jboss.as.server.deployment] (MSC service thread 1-4) JBAS015877: Stopped deployment systemtests-ejb.jar in 409ms 14:21:59,471 INFO [org.jboss.as.server.deployment] (MSC service thread 1-8) JBAS015877: Stopped deployment ejbca-ejb.jar in 407ms 14:21:59,473 INFO [org.jboss.as.server.deployment] (MSC service thread 1-2) JBAS015877: Stopped deployment ejbca-ws-ejb.jar in 409ms 14:21:59,470 INFO [org.jboss.as.server.deployment] (MSC service thread 1-3) JBAS015877: Stopped deployment healthcheck.war in 407ms 14:21:59,473 INFO [org.jboss.as.server.deployment] (MSC service thread 1-4) JBAS015877: Stopped deployment clearcache.war in 409ms 14:21:59,471 INFO [org.jboss.as.server.deployment] (MSC service thread 1-1) JBAS015877: Stopped deployment crlstore.war in 407ms 14:21:59,475 INFO [org.jboss.as.server.deployment] (MSC service thread 1-3) JBAS015877: Stopped deployment publicweb.war in 412ms 14:21:59,475 INFO [org.jboss.as.server.deployment] (MSC service thread 1-4) JBAS015877: Stopped deployment scep.war in 411ms 14:21:59,478 INFO [org.jboss.as.server.deployment] (MSC service thread 1-5) JBAS015877: Stopped deployment doc.war in 415ms 14:21:59,498 INFO [org.jboss.as.server.deployment] (MSC service thread 1-6) JBAS015877: Stopped deployment adminweb.war in 435ms 14:21:59,525 INFO [org.jboss.as.server.deployment] (MSC service thread 1-8) JBAS015877: Stopped deployment ejbca.ear in 463ms Od: "Andreas Kuehne" <ku...@tr...> Do: ejb...@li... Wysłane: poniedziałek, 18 maj 2015 23:22:37 Temat: Re: [Ejbca-develop] Timestamp service Hi Marcin, ejbca is about certificates, not about timestamps. If you are looking for a simple RFC 3161 timestamp, try the timestamp servers of Bouncy Castle or iaik. Greetings, Andreas Hello, On the EJBCE 6.2 is ability to sign documents timestamp? If yes, can I ask where and how it works? because I can not find information on this case. Regards, Martin ------------------------------------------------------------------------------ One dashboard for servers and applications across Physical-Virtual-Cloud Widest out-of-the-box monitoring support with 50+ applications Performance metrics, stats and reports that give you Actionable Insights Deep dive visibility with transaction tracing using APM Insight. http://ad.doubleclick.net/ddm/clk/290420510;117567292;y _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop -- Andreas Kühne phone: +49 177 293 24 97 mailto: ku...@tr... Trustable Ltd. Niederlassung Deutschland Ströverstr. 18 - 59427 Unna Amtsgericht Hamm HRB 5868 Directors Andreas Kühne, Heiko Veit Company UK Company No: 5218868 Registered in England and Wales ------------------------------------------------------------------------------ One dashboard for servers and applications across Physical-Virtual-Cloud Widest out-of-the-box monitoring support with 50+ applications Performance metrics, stats and reports that give you Actionable Insights Deep dive visibility with transaction tracing using APM Insight. http://ad.doubleclick.net/ddm/clk/290420510;117567292;y _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop ------------------------------------------------------------------------------ One dashboard for servers and applications across Physical-Virtual-Cloud Widest out-of-the-box monitoring support with 50+ applications Performance metrics, stats and reports that give you Actionable Insights Deep dive visibility with transaction tracing using APM Insight. http://ad.doubleclick.net/ddm/clk/290420510;117567292;y _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Marcin F. <mar...@en...> - 2015-05-19 12:29:17
|
Hello, After the implementation of SignServer in my environment Ejbca and reload the JBoss service I have a problem . Log below : 14:21:59,105 INFO [org.jboss.as.webservices] (MSC service thread 1-1) JBAS015540: Stopping service jboss.ws.endpoint."signserver.ear"."SignServer-ejb-ValidationWS.jar".ValidationWS 14:21:59,106 INFO [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service thread 1-1) remove: jboss.ws:context=signserver/ValidationWSService,endpoint=ValidationWS 14:21:59,108 INFO [org.jboss.as.webservices] (MSC service thread 1-6) JBAS015540: Stopping service jboss.ws.endpoint."signserver.ear"."SignServer-ejb-AdminWS.jar".AdminWS 14:21:59,109 INFO [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service thread 1-6) remove: jboss.ws:context=signserver/AdminWSService,endpoint=AdminWS 14:21:59,117 INFO [org.jboss.as.webservices] (MSC service thread 1-2) JBAS015540: Stopping service jboss.ws.endpoint."signserver.ear"."SignServer-ejb-SignServerWS.jar".SignServerWS 14:21:59,118 INFO [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service thread 1-2) remove: jboss.ws:context=signserver/SignServerWSService,endpoint=SignServerWS 14:21:59,119 INFO [org.jboss.as.webservices] (MSC service thread 1-5) JBAS015540: Stopping service jboss.ws.endpoint."signserver.ear"."SignServer-ejb-ClientWS.jar".ClientWS 14:21:59,121 INFO [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service thread 1-5) remove: jboss.ws:context=signserver/ClientWSService,endpoint=ClientWS 14:21:59,158 INFO [org.jboss.as.webservices] (MSC service thread 1-1) JBAS015540: Stopping service jboss.ws.endpoint."ejbca.ear"."ejbca-ws-ejb.jar".EjbcaWS 14:21:59,163 INFO [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service thread 1-1) remove: jboss.ws:context=ejbca/ejbcaws,endpoint=EjbcaWS 14:21:59,236 INFO [org.ejbca.ui.web.admin.configuration.StartServicesServlet] (MSC service thread 1-6) Destroy, EJBCA shutdown. 14:21:59,299 INFO [org.jboss.as.jpa] (MSC service thread 1-4) JBAS011403: Stopping Persistence Unit Service 'ejbca.ear#ejbca' 14:21:59,406 INFO [org.jboss.as.webservices] (MSC service thread 1-1) JBAS015540: Stopping service jboss.ws.port-component-link 14:21:59,469 INFO [org.jboss.as.server.deployment] (MSC service thread 1-1) JBAS015877: Stopped deployment status.war in 405ms 14:21:59,469 INFO [org.jboss.as.server.deployment] (MSC service thread 1-3) JBAS015877: Stopped deployment cesecore-ejb.jar in 406ms 14:21:59,470 INFO [org.jboss.as.server.deployment] (MSC service thread 1-1) JBAS015877: Stopped deployment webdist.war in 406ms 14:21:59,471 INFO [org.jboss.as.server.deployment] (MSC service thread 1-4) JBAS015877: Stopped deployment cmp.war in 407ms 14:21:59,472 INFO [org.jboss.as.server.deployment] (MSC service thread 1-4) JBAS015877: Stopped deployment systemtests-ejb.jar in 409ms 14:21:59,471 INFO [org.jboss.as.server.deployment] (MSC service thread 1-8) JBAS015877: Stopped deployment ejbca-ejb.jar in 407ms 14:21:59,473 INFO [org.jboss.as.server.deployment] (MSC service thread 1-2) JBAS015877: Stopped deployment ejbca-ws-ejb.jar in 409ms 14:21:59,470 INFO [org.jboss.as.server.deployment] (MSC service thread 1-3) JBAS015877: Stopped deployment healthcheck.war in 407ms 14:21:59,473 INFO [org.jboss.as.server.deployment] (MSC service thread 1-4) JBAS015877: Stopped deployment clearcache.war in 409ms 14:21:59,471 INFO [org.jboss.as.server.deployment] (MSC service thread 1-1) JBAS015877: Stopped deployment crlstore.war in 407ms 14:21:59,475 INFO [org.jboss.as.server.deployment] (MSC service thread 1-3) JBAS015877: Stopped deployment publicweb.war in 412ms 14:21:59,475 INFO [org.jboss.as.server.deployment] (MSC service thread 1-4) JBAS015877: Stopped deployment scep.war in 411ms 14:21:59,478 INFO [org.jboss.as.server.deployment] (MSC service thread 1-5) JBAS015877: Stopped deployment doc.war in 415ms 14:21:59,498 INFO [org.jboss.as.server.deployment] (MSC service thread 1-6) JBAS015877: Stopped deployment adminweb.war in 435ms 14:21:59,525 INFO [org.jboss.as.server.deployment] (MSC service thread 1-8) JBAS015877: Stopped deployment ejbca.ear in 463ms Od: "Andreas Kuehne" <ku...@tr...> Do: ejb...@li... Wysłane: poniedziałek, 18 maj 2015 23:22:37 Temat: Re: [Ejbca-develop] Timestamp service Hi Marcin, ejbca is about certificates, not about timestamps. If you are looking for a simple RFC 3161 timestamp, try the timestamp servers of Bouncy Castle or iaik. Greetings, Andreas Hello, On the EJBCE 6.2 is ability to sign documents timestamp? If yes, can I ask where and how it works? because I can not find information on this case. Regards, Martin ------------------------------------------------------------------------------ One dashboard for servers and applications across Physical-Virtual-Cloud Widest out-of-the-box monitoring support with 50+ applications Performance metrics, stats and reports that give you Actionable Insights Deep dive visibility with transaction tracing using APM Insight. http://ad.doubleclick.net/ddm/clk/290420510;117567292;y _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop -- Andreas Kühne phone: +49 177 293 24 97 mailto: ku...@tr... Trustable Ltd. Niederlassung Deutschland Ströverstr. 18 - 59427 Unna Amtsgericht Hamm HRB 5868 Directors Andreas Kühne, Heiko Veit Company UK Company No: 5218868 Registered in England and Wales ------------------------------------------------------------------------------ One dashboard for servers and applications across Physical-Virtual-Cloud Widest out-of-the-box monitoring support with 50+ applications Performance metrics, stats and reports that give you Actionable Insights Deep dive visibility with transaction tracing using APM Insight. http://ad.doubleclick.net/ddm/clk/290420510;117567292;y _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Anthony A. <asc...@gm...> - 2015-05-19 02:07:06
|
Hi EJBCAers, Using EJBCA to generate a ECDSA key on a Luna I am getting CKR_KEY_TYPE_INCONSISTENT when running the test, as a result I cannot use this Crypto Token for a CA, as CA creation always fails at CRL sign. Any suggestions? 1. JDK 7u79 2. EJBCA SVN r20553 (approx. v6.3.0) # web.properties cryptotoken.p11.lib.20.name=SafeNet Luna SA cryptotoken.p11.lib.20.file=/usr/lib/libCryptoki2_64.so ## ./ejbcaClientToolBox.sh PKCS11HSMKeyTool generate /usr/lib/libCryptoki2_64.so secp521r1 secp521r1_1 1 2015-05-19 09:58:13,676 INFO [org.cesecore.config.ConfigurationHolder] Allow external re-configuration: false Using Slot Reference Type: Slot Number. 2015-05-19 09:58:13,926 INFO [org.cesecore.keys.token.p11.Pkcs11SlotLabel] Using SUN PKCS11 provider: sun.security.pkcs11.SunPKCS11 2015-05-19 09:58:13,972 INFO [org.cesecore.keys.token.p11.Pkcs11SlotLabel] Using SUN PKCS11 provider: sun.security.pkcs11.SunPKCS11 PKCS11 Token [SunPKCS11-libCryptoki2_64.so-slot1] Password: Created certificate with entry secp521r1_1. Testing of key: secp521r1_1 Private part: SunPKCS11-libCryptoki2_64.so-slot1 EC private key, 521 bits (id 581, token object, sensitive, unextractable) Elliptic curve key: the affine x-coordinate: 1fdd98236da83f314145433... the affine y-coordinate: 1da6e7a34e8a28d6fffbc4c... java.security.ProviderException: sun.security.pkcs11.wrapper.PKCS11Exception: CKR_KEY_TYPE_INCONSISTENT at sun.security.pkcs11.P11Signature.engineVerify(P11Signature.java:621) at java.security.Signature$Delegate.engineVerify(Signature.java:1192) at java.security.Signature.verify(Signature.java:626) at org.ejbca.ui.cli.KeyStoreContainerTest$Sign.verify(KeyStoreContainerTest.java:347) at org.ejbca.ui.cli.KeyStoreContainerTest$NormalTest.test(KeyStoreContainerTest.java:468) at org.ejbca.ui.cli.KeyStoreContainerTest$NormalTest.doIt(KeyStoreContainerTest.java:491) at org.ejbca.ui.cli.KeyStoreContainerTest.startNormal(KeyStoreContainerTest.java:148) at org.ejbca.ui.cli.KeyStoreContainerTest.test(KeyStoreContainerTest.java:76) at org.ejbca.ui.cli.HSMKeyTool.doIt(HSMKeyTool.java:400) at org.ejbca.ui.cli.HSMKeyTool.execute(HSMKeyTool.java:449) at org.ejbca.ui.cli.PKCS11HSMKeyTool.execute(PKCS11HSMKeyTool.java:47) at org.ejbca.ui.cli.ClientToolBox.executeIfSelected(ClientToolBox.java:40) at org.ejbca.ui.cli.ClientToolBox.main(ClientToolBox.java:66) Caused by: sun.security.pkcs11.wrapper.PKCS11Exception: CKR_KEY_TYPE_INCONSISTENT at sun.security.pkcs11.wrapper.PKCS11.C_VerifyFinal(Native Method) at sun.security.pkcs11.P11Signature.engineVerify(P11Signature.java:575) ... 12 more Signing not possible with this key. See exception. No crypto available for this key. - Anthony |
|
From: Andreas K. <ku...@tr...> - 2015-05-18 21:35:55
|
Hi Marcin, ejbca is about certificates, not about timestamps. If you are looking for a simple RFC 3161 timestamp, try the timestamp servers of Bouncy Castle or iaik. Greetings, Andreas > Hello, > > > On the EJBCE 6.2 is ability to sign documents timestamp? If yes, can I ask > where and how it works? because I can not find information on this case. > > > > Regards, > Martin > > > > > > > > > ------------------------------------------------------------------------------ > One dashboard for servers and applications across Physical-Virtual-Cloud > Widest out-of-the-box monitoring support with 50+ applications > Performance metrics, stats and reports that give you Actionable Insights > Deep dive visibility with transaction tracing using APM Insight. > http://ad.doubleclick.net/ddm/clk/290420510;117567292;y > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop -- Andreas Kühne phone: +49 177 293 24 97 mailto: ku...@tr... Trustable Ltd. Niederlassung Deutschland Ströverstr. 18 - 59427 Unna Amtsgericht Hamm HRB 5868 Directors Andreas Kühne, Heiko Veit Company UK Company No: 5218868 Registered in England and Wales |
|
From: Herman V. <hv...@gm...> - 2015-05-18 20:42:14
|
Marcin, EJBCA allow to deploy digital certificates for timestamping authority, and the SignServer (or other RFC3161 compliance) soluction to allow to sign and stamp documents, http://signserver.org/features.html Regards. On Mon, May 18, 2015 at 5:07 PM, Marcin Fabiańczyk < mar...@en...> wrote: > Hello, > > > On the EJBCE 6.2 is ability to sign documents timestamp? If yes, can I > ask where and how it works? because I can not find information on this > case. > > > > Regards, > > > *Martin* > > > > > ------------------------------------------------------------------------------ > One dashboard for servers and applications across Physical-Virtual-Cloud > Widest out-of-the-box monitoring support with 50+ applications > Performance metrics, stats and reports that give you Actionable Insights > Deep dive visibility with transaction tracing using APM Insight. > http://ad.doubleclick.net/ddm/clk/290420510;117567292;y > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > -- Herman Vega Jara hvegax[a]gmail.com |
|
From: Marcin F. <mar...@en...> - 2015-05-18 20:26:54
|
Hello, On the EJBCE 6.2 is ability to sign documents timestamp? If yes, can I ask where and how it works? because I can not find information on this case. Regards, Martin |
|
From: Branko M. <br...@ma...> - 2015-05-10 12:01:30
|
On Fri, 8 May 2015 08:39:56 -0100 "Gaudencio Fernandes" <gfe...@si...> wrote: > Dear All; > > > > We are working on a PKI installation project with software EJBCA but we need > to integrate it with HSM; > > We use Atalla HSM "Ata...@hp..."; > > In this sense I wonder if EJBCA integrates with HSM Atalla, Atalla > communicates over TCP / IP, follows attached document Atalla HSM; > > Best Regards As long as the HSM software comes with a library implementing the PKCS#11, and the HSM itself supports the standard cryptographic algorithms, it should work. However, you probably want to test it out first. The easiest way to do a couple of tests is to initialise your HSM, and then try to test slots with the EJBCA client toolbox (the PKCS11HSMKeyTool command). See: http://ejbca.org/docs/userguide.html#EJBCA%20client%20toolbox Best regards -- Branko Majic Jabber: br...@ma... Please use only Free formats when sending attachments to me. Бранко Мајић Џабер: br...@ma... Молим вас да додатке шаљете искључиво у слободним форматима. |
|
From: Roman C. <rom...@wi...> - 2015-05-09 10:21:38
|
Hi there, I'm trying to use SmartCard-HSM together with EJCBA 6.2.0 using brainpool320r1 named curve. Is there any way how to do that, as Java PKCS#11 does not currently support this type of named curve? I tried to patch ECParameters.java and NamedCurve.java classes in rt.jar, but with no success. Now I can generate brainpool320r1 keys through clientToolBox and see it in CryptoTokens as ECDSA "unknown" key type, but I can't create a test certification authority using this key. The following is always a problem: [org.cesecore.certificates.crl.CrlCreateSessionBean] (http--0.0.0.0-8443-3) Error generating CRL: : org.bouncycastle.operator.RuntimeOperatorException: exception obtaining signature: Could not verify signature Is it even possible to get EJBCA working with brainpool3201r curve? With regards, Roman |
|
From: Gaudencio F. <gfe...@si...> - 2015-05-08 09:43:50
|
Dear All; We are working on a PKI installation project with software EJBCA but we need to integrate it with HSM; We use Atalla HSM "Ata...@hp..."; In this sense I wonder if EJBCA integrates with HSM Atalla, Atalla communicates over TCP / IP, follows attached document Atalla HSM; Best Regards Gaudêncio Fernandes System Administrator SISP - Sociedade Interbancaria e Sistemas de Pagamentos, SA Phone: +238 2626318 Mail:gfe...@si... www.vinti4.cv <http://www.vinti4.cv/> ____________________________________________________________________________ __________________________________________ P Before you print Think about ENVIRONMENTAL responsibility and commitment ____________________________________________________________________________ ___________________________________________ CONFIDENTIALITY NOTICE: This message, as well as existing attached files, is confidential and intended exclusively for the individual(s) named as addressees. If you are not the intended recipient, or if it was sent to you by error, you are kindly requested not to make any use of its contents and to proceed to the destruction of the message, thereby notifying the sender. DISCLAIMER: The sender of this message can not ensure the security of its electronical transmission and consequently does not accept liability for any fact which may interfere with the integrity of its content. _____ |
|
From: Michael S. <mi...@st...> - 2015-05-06 12:04:25
|
Ralf Hornik wrote: >> What is the fingerprint extension? > > [root@ca-pb ~]# openssl x509 -in cert.pem -noout -fingerprint > SHA1 Fingerprint=2B:D1:C3:77:42:95:F4:09:CC:A0:4D:3F:05:5F:44:15:27:1A:0D:42 This is simply the hash checksum calculated for the raw binary data, in this case by OpenSSL. => You have to consult the OpenSSL docs to see how to use another hash algorithm for fingerprint calculation. BTW: If you want to provide fingerprints for out-of-band verification of trust anchor certs you have to provide each algorithm any client might use. Ciao, Michael. |
|
From: Ralf H. <rh...@hc...> - 2015-05-06 11:57:32
|
Hi, > What is the fingerprint extension? [root@ca-pb ~]# openssl x509 -in cert.pem -noout -fingerprint SHA1 Fingerprint=2B:D1:C3:77:42:95:F4:09:CC:A0:4D:3F:05:5F:44:15:27:1A:0D:42 This also defaults to sha1 in Browsers displays. But as i see this is not a real x509 extension as openssl does not show it. I'll need to look for another problem. :-) >If you mean digital signature algorithm to be SHA256WithRSA, you can select it in the web gui. This I already set :-) Thank you Ralf |
|
From: Anders R. <and...@gm...> - 2015-05-06 11:55:09
|
AKI and SKI? Anders On 2015-05-06 13:45, Michael Ströder wrote: > Ralf Hornik wrote: >> I use EJBCA 4.0.16 (r17223) Jboss 5.1.0 GA. >> >> I dont see any chance to change the algorithm for the fingerprint extension >> to anything else than sha1. >> Browsers like chrome require certificate fingerprints of sha2. > Are you talking about certificate fingerprints or the certificate signature > algorithm? I guess it's the latter. > >> How can this extension be changed? > It's likely not a X.509v3 extension what you're talking about. > > You should look into the certificate profile(s): > > There you can choose SHA256WithRSA as the signature algorithm used when > issuing certs. IIRC this already worked with EJBCA 4.0.16 though I'm not sure > whether the Java version you're using is capable of doing that. > > Ciao, Michael. > > > > > ------------------------------------------------------------------------------ > One dashboard for servers and applications across Physical-Virtual-Cloud > Widest out-of-the-box monitoring support with 50+ applications > Performance metrics, stats and reports that give you Actionable Insights > Deep dive visibility with transaction tracing using APM Insight. > http://ad.doubleclick.net/ddm/clk/290420510;117567292;y > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Michael S. <mi...@st...> - 2015-05-06 11:45:50
|
Ralf Hornik wrote: > I use EJBCA 4.0.16 (r17223) Jboss 5.1.0 GA. > > I dont see any chance to change the algorithm for the fingerprint extension > to anything else than sha1. > Browsers like chrome require certificate fingerprints of sha2. Are you talking about certificate fingerprints or the certificate signature algorithm? I guess it's the latter. > How can this extension be changed? It's likely not a X.509v3 extension what you're talking about. You should look into the certificate profile(s): There you can choose SHA256WithRSA as the signature algorithm used when issuing certs. IIRC this already worked with EJBCA 4.0.16 though I'm not sure whether the Java version you're using is capable of doing that. Ciao, Michael. |
|
From: Tomas G. <to...@pr...> - 2015-05-06 11:42:55
|
What is the fingerprint extension? If you mean digital signature algorithm to be SHA256WithRSA, you can select it in the web gui. Regards, Tomas On 2015-05-06 13:18, Ralf Hornik wrote: > Hello, > > I use EJBCA 4.0.16 (r17223) Jboss 5.1.0 GA. > > I dont see any chance to change the algorithm for the fingerprint extension > to anything else than sha1. > Browsers like chrome require certificate fingerprints of sha2. > > How can this extension be changed? > Thanks and best regards > > Ralf > > > > ------------------------------------------------------------------------------ > One dashboard for servers and applications across Physical-Virtual-Cloud > Widest out-of-the-box monitoring support with 50+ applications > Performance metrics, stats and reports that give you Actionable Insights > Deep dive visibility with transaction tracing using APM Insight. > http://ad.doubleclick.net/ddm/clk/290420510;117567292;y > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Ralf H. <rh...@hc...> - 2015-05-06 11:35:04
|
Hello, I use EJBCA 4.0.16 (r17223) Jboss 5.1.0 GA. I dont see any chance to change the algorithm for the fingerprint extension to anything else than sha1. Browsers like chrome require certificate fingerprints of sha2. How can this extension be changed? Thanks and best regards Ralf |