You can subscribe to this list here.
| 2001 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
(1) |
Dec
(3) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2002 |
Jan
(3) |
Feb
(2) |
Mar
(8) |
Apr
(3) |
May
(6) |
Jun
(1) |
Jul
(15) |
Aug
(6) |
Sep
|
Oct
(10) |
Nov
(2) |
Dec
(4) |
| 2003 |
Jan
(1) |
Feb
(7) |
Mar
(3) |
Apr
(6) |
May
(7) |
Jun
(5) |
Jul
(5) |
Aug
(25) |
Sep
(14) |
Oct
(2) |
Nov
|
Dec
(2) |
| 2004 |
Jan
(7) |
Feb
(4) |
Mar
(12) |
Apr
(16) |
May
(43) |
Jun
(56) |
Jul
(43) |
Aug
(40) |
Sep
(66) |
Oct
(12) |
Nov
(26) |
Dec
(10) |
| 2005 |
Jan
(13) |
Feb
(33) |
Mar
(16) |
Apr
(7) |
May
(10) |
Jun
(34) |
Jul
(41) |
Aug
(8) |
Sep
(4) |
Oct
(32) |
Nov
(20) |
Dec
(25) |
| 2006 |
Jan
(30) |
Feb
(101) |
Mar
(5) |
Apr
(75) |
May
(74) |
Jun
(22) |
Jul
(6) |
Aug
(70) |
Sep
(19) |
Oct
(21) |
Nov
(31) |
Dec
(50) |
| 2007 |
Jan
(15) |
Feb
(20) |
Mar
(24) |
Apr
(33) |
May
(13) |
Jun
(18) |
Jul
(13) |
Aug
(7) |
Sep
(63) |
Oct
(68) |
Nov
(29) |
Dec
(68) |
| 2008 |
Jan
(30) |
Feb
(33) |
Mar
(30) |
Apr
(103) |
May
(78) |
Jun
(48) |
Jul
(72) |
Aug
(24) |
Sep
(62) |
Oct
(63) |
Nov
(70) |
Dec
(37) |
| 2009 |
Jan
(34) |
Feb
(35) |
Mar
(64) |
Apr
(34) |
May
(34) |
Jun
(58) |
Jul
(30) |
Aug
(30) |
Sep
(46) |
Oct
(52) |
Nov
(12) |
Dec
(23) |
| 2010 |
Jan
(121) |
Feb
(18) |
Mar
(53) |
Apr
(62) |
May
(62) |
Jun
(20) |
Jul
(33) |
Aug
(20) |
Sep
(36) |
Oct
(35) |
Nov
(44) |
Dec
(63) |
| 2011 |
Jan
(19) |
Feb
(32) |
Mar
(94) |
Apr
(41) |
May
(47) |
Jun
(25) |
Jul
(34) |
Aug
(20) |
Sep
(9) |
Oct
(41) |
Nov
(33) |
Dec
(24) |
| 2012 |
Jan
(12) |
Feb
(36) |
Mar
(48) |
Apr
(32) |
May
(20) |
Jun
(15) |
Jul
(32) |
Aug
(13) |
Sep
(33) |
Oct
(54) |
Nov
(25) |
Dec
(16) |
| 2013 |
Jan
(45) |
Feb
(39) |
Mar
(38) |
Apr
(50) |
May
(29) |
Jun
(30) |
Jul
(33) |
Aug
(12) |
Sep
(9) |
Oct
(25) |
Nov
(29) |
Dec
(20) |
| 2014 |
Jan
(25) |
Feb
(19) |
Mar
(16) |
Apr
(33) |
May
(27) |
Jun
(37) |
Jul
(29) |
Aug
(27) |
Sep
(37) |
Oct
(58) |
Nov
(109) |
Dec
(26) |
| 2015 |
Jan
(4) |
Feb
(35) |
Mar
(22) |
Apr
(35) |
May
(28) |
Jun
(20) |
Jul
(4) |
Aug
(16) |
Sep
(37) |
Oct
(13) |
Nov
(13) |
Dec
(14) |
| 2016 |
Jan
(22) |
Feb
(7) |
Mar
(23) |
Apr
(30) |
May
(10) |
Jun
(10) |
Jul
(15) |
Aug
(12) |
Sep
(22) |
Oct
(31) |
Nov
(5) |
Dec
(5) |
| 2017 |
Jan
(30) |
Feb
(25) |
Mar
(28) |
Apr
(4) |
May
(19) |
Jun
(13) |
Jul
(7) |
Aug
(1) |
Sep
(2) |
Oct
(5) |
Nov
(12) |
Dec
(2) |
| 2018 |
Jan
(7) |
Feb
|
Mar
(7) |
Apr
(2) |
May
(8) |
Jun
(18) |
Jul
(6) |
Aug
(3) |
Sep
(15) |
Oct
(33) |
Nov
(13) |
Dec
(7) |
| 2019 |
Jan
(5) |
Feb
(7) |
Mar
(30) |
Apr
(5) |
May
(4) |
Jun
(69) |
Jul
(86) |
Aug
(22) |
Sep
(6) |
Oct
(7) |
Nov
(5) |
Dec
(3) |
| 2020 |
Jan
(10) |
Feb
(12) |
Mar
(22) |
Apr
(5) |
May
(1) |
Jun
(4) |
Jul
(6) |
Aug
|
Sep
(9) |
Oct
|
Nov
|
Dec
(1) |
| 2021 |
Jan
(4) |
Feb
(11) |
Mar
(7) |
Apr
(7) |
May
|
Jun
(3) |
Jul
(10) |
Aug
(6) |
Sep
|
Oct
|
Nov
(18) |
Dec
(2) |
| 2022 |
Jan
(1) |
Feb
(1) |
Mar
|
Apr
|
May
|
Jun
(2) |
Jul
|
Aug
(4) |
Sep
|
Oct
|
Nov
|
Dec
|
| 2023 |
Jan
|
Feb
|
Mar
|
Apr
(1) |
May
(1) |
Jun
|
Jul
|
Aug
(5) |
Sep
|
Oct
|
Nov
|
Dec
|
|
From: Tomas G. <to...@pr...> - 2015-05-04 21:04:04
|
Hi Ryan, At this point there is only a SOAP API. Some context specific REST API has been developed as plug-ins (see EJBCA plug-in mechanism). Regards, Tomas On May 4, 2015 8:40:02 PM GMT+02:00, Ryan Treat <tr...@ho...> wrote: >Hi, does the EJBCA have a REST API? If so, where can I find >documentation detailing the REST API calls? I've only found the >following which is for the SOAP Web Services API: >http://ejbca.org/docs/ws/org/ejbca/core/protocol/ws/client/gen/EjbcaWS.html > > >Thanks! >Ryan > > > >------------------------------------------------------------------------ > >------------------------------------------------------------------------------ >One dashboard for servers and applications across >Physical-Virtual-Cloud >Widest out-of-the-box monitoring support with 50+ applications >Performance metrics, stats and reports that give you Actionable >Insights >Deep dive visibility with transaction tracing using APM Insight. >http://ad.doubleclick.net/ddm/clk/290420510;117567292;y > >------------------------------------------------------------------------ > >_______________________________________________ >Ejbca-develop mailing list >Ejb...@li... >https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Ryan T. <tr...@ho...> - 2015-05-04 18:40:09
|
Hi, does the EJBCA have a REST API? If so, where can I find documentation detailing the REST API calls? I've only found the following which is for the SOAP Web Services API: http://ejbca.org/docs/ws/org/ejbca/core/protocol/ws/client/gen/EjbcaWS.html Thanks! Ryan |
|
From: Tomas G. <to...@pr...> - 2015-05-01 14:54:49
|
Good catch. Seems to be a flaw? Created: https://jira.primekey.se/browse/ECA-4243 Regards, Tomas On 2015-04-30 20:21, Jaime Hablutzel Egoavil wrote: > On EJBCA 6.2.0 (r19221), the WS method > org.ejbca.core.protocol.ws.EjbcaWS#certificateRequest, called like this > from a client: > > ejbcaWS.certificateRequest(ejbcaUser, pkcs10inPemFormat, > CertificateHelper.CERT_REQ_TYPE_PKCS10, null, > CertificateHelper.RESPONSETYPE_CERTIFICATE); > > Isn't performing POP, I can see it is quickly transformed to a > org.cesecore.certificates.certificate.request.SimpleRequestMessage by > the method > org.cesecore.certificates.certificate.request.RequestMessageUtils#getSimpleRequestMessageFromType, > and this SimpleRequestMessage always return true when its method > #verify is called. > > Is this behaviour by design or is it a bug? > > > -- > Jaime Hablutzel -  RPC 994690880 > > > ------------------------------------------------------------------------------ > One dashboard for servers and applications across Physical-Virtual-Cloud > Widest out-of-the-box monitoring support with 50+ applications > Performance metrics, stats and reports that give you Actionable Insights > Deep dive visibility with transaction tracing using APM Insight. > http://ad.doubleclick.net/ddm/clk/290420510;117567292;y > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Supun T. <sup...@gm...> - 2015-04-30 18:31:01
|
No it does not display any on that. On Thu, Apr 30, 2015 at 11:10 AM, Jaime Hablutzel Egoavil < hab...@gm...> wrote: > As far as I know the service is already started on boot, try browsing > http://localhost:8080 from inside the VM. > > On Tue, Apr 28, 2015 at 1:07 AM, Supun Tharaka <sup...@gm...> > wrote: > >> Hi , >> >> >> I have installed EJBCA+SignServer live CD as aVM on VMWare.It was xubuntu >> and could you please reply how to start jboss application server by >> terminal . I have tried service jbossas start like commands but it did not >> work. >> >> Thanks >> >> On Tue, Apr 28, 2015 at 11:26 AM, Supun Tharaka <sup...@gm...> >> wrote: >> >>> Hi , >>> >>> >>> I have installed EJBCA+SignServer live CD as aVM on VMWare.It was >>> xubuntu and could you please reply how to start jboss application server by >>> terminal . I have tried service jbossas start like commands but it did not >>> work. >>> >>> Thanks >>> >> >> >> >> ------------------------------------------------------------------------------ >> One dashboard for servers and applications across Physical-Virtual-Cloud >> Widest out-of-the-box monitoring support with 50+ applications >> Performance metrics, stats and reports that give you Actionable Insights >> Deep dive visibility with transaction tracing using APM Insight. >> http://ad.doubleclick.net/ddm/clk/290420510;117567292;y >> _______________________________________________ >> Ejbca-develop mailing list >> Ejb...@li... >> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >> >> > > > -- > Jaime Hablutzel - RPC 994690880 > > > ------------------------------------------------------------------------------ > One dashboard for servers and applications across Physical-Virtual-Cloud > Widest out-of-the-box monitoring support with 50+ applications > Performance metrics, stats and reports that give you Actionable Insights > Deep dive visibility with transaction tracing using APM Insight. > http://ad.doubleclick.net/ddm/clk/290420510;117567292;y > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > |
|
From: Jaime H. E. <hab...@gm...> - 2015-04-30 18:21:49
|
On EJBCA 6.2.0 (r19221), the WS method org.ejbca.core.protocol.ws.EjbcaWS#certificateRequest, called like this from a client: ejbcaWS.certificateRequest(ejbcaUser, pkcs10inPemFormat, CertificateHelper.CERT_REQ_TYPE_PKCS10, null, CertificateHelper.RESPONSETYPE_CERTIFICATE); Isn't performing POP, I can see it is quickly transformed to a org.cesecore.certificates.certificate.request.SimpleRequestMessage by the method org.cesecore.certificates.certificate.request.RequestMessageUtils#getSimpleRequestMessageFromType, and this SimpleRequestMessage always return true when its method #verify is called. Is this behaviour by design or is it a bug? -- Jaime Hablutzel - RPC 994690880 |
|
From: Jaime H. E. <hab...@gm...> - 2015-04-30 18:10:38
|
As far as I know the service is already started on boot, try browsing http://localhost:8080 from inside the VM. On Tue, Apr 28, 2015 at 1:07 AM, Supun Tharaka <sup...@gm...> wrote: > Hi , > > > I have installed EJBCA+SignServer live CD as aVM on VMWare.It was xubuntu > and could you please reply how to start jboss application server by > terminal . I have tried service jbossas start like commands but it did not > work. > > Thanks > > On Tue, Apr 28, 2015 at 11:26 AM, Supun Tharaka <sup...@gm...> > wrote: > >> Hi , >> >> >> I have installed EJBCA+SignServer live CD as aVM on VMWare.It was xubuntu >> and could you please reply how to start jboss application server by >> terminal . I have tried service jbossas start like commands but it did not >> work. >> >> Thanks >> > > > > ------------------------------------------------------------------------------ > One dashboard for servers and applications across Physical-Virtual-Cloud > Widest out-of-the-box monitoring support with 50+ applications > Performance metrics, stats and reports that give you Actionable Insights > Deep dive visibility with transaction tracing using APM Insight. > http://ad.doubleclick.net/ddm/clk/290420510;117567292;y > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > -- Jaime Hablutzel - RPC 994690880 |
|
From: Supun T. <sup...@gm...> - 2015-04-28 06:07:30
|
Hi , I have installed EJBCA+SignServer live CD as aVM on VMWare.It was xubuntu and could you please reply how to start jboss application server by terminal . I have tried service jbossas start like commands but it did not work. Thanks On Tue, Apr 28, 2015 at 11:26 AM, Supun Tharaka <sup...@gm...> wrote: > Hi , > > > I have installed EJBCA+SignServer live CD as aVM on VMWare.It was xubuntu > and could you please reply how to start jboss application server by > terminal . I have tried service jbossas start like commands but it did not > work. > > Thanks > |
|
From: Wei S. <wei...@gm...> - 2015-04-27 06:35:04
|
Hi all, I'm an experienced DBA, however I'm new to EJBCA. Currently, I'm trying to tune the EJBCA PostgreSQL database for best performance. Is there any thing I should take note in particular? I will be following the general PostgreSQL best practice in general.. Cheers! -- Regards, Ang Wei Shan |
|
From: Anil K. <an...@gm...> - 2015-04-24 15:11:11
|
Hi, I am trying to configure EJBCA external RA referring http://ejbca.org/older_releases/ejbca_4_0/htdocs/externalra.html . I am stuck at the configuration from Admin for the RA setup, Not able to find the Services menu/link. Step: “In the EJBCA Admin GUI, go to Services and create a new Custom Worker that runs at short intervals. The shorter the interval the more often the worker will poll the DataSource for new messages.” . Can you please guide me how to proceed. Warm Regards, Anil |
|
From: Tomas G. <to...@pr...> - 2015-04-24 05:59:24
|
Hi, See User guide how to manage CAs and requests. For example: http://ejbca.org/docs/userguide.html#Requesting%20a%20cross%20or%20bridge%20certificate Regards, Tomas ----- Save time and money with an Enterprise support subscription. Please see www.primekey.se for more information. http://www.primekey.se/Products/EJBCA+PKI/ http://www.primekey.se/Services/Support/ On 2015-04-23 08:11, Tomasz Rakowski wrote: > Hi, > > I'm trying to cross-certify external CA. > > How can I do it in EJBCA ? > > I can't find a way to issue a certificate signing another certificate. > > > It seems that I will need a CSR from that CA (and then use > 'bin/ejbca.sh createcert' to create required cross-certified > certificate), is that true ? > > Are there any specific requirements for SUBCA certificate profile used > to generate this certificate ? > > Regards > Tomasz > > > > ------------------------------------------------------------------------------ > BPM Camp - Free Virtual Workshop May 6th at 10am PDT/1PM EDT > Develop your own process in accordance with the BPMN 2 standard > Learn Process modeling best practices with Bonita BPM through live exercises > http://www.bonitasoft.com/be-part-of-it/events/bpm-camp-virtual- event?utm_ > source=Sourceforge_BPM_Camp_5_6_15&utm_medium=email&utm_campaign=VA_SF > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Tomasz R. <mo...@gm...> - 2015-04-23 15:11:27
|
Hi, I'm trying to cross-certify external CA. How can I do it in EJBCA ? I can't find a way to issue a certificate signing another certificate. It seems that I will need a CSR from that CA (and then use 'bin/ejbca.sh createcert' to create required cross-certified certificate), is that true ? Are there any specific requirements for SUBCA certificate profile used to generate this certificate ? Regards Tomasz |
|
From: Andreas S. <and...@ca...> - 2015-04-21 12:07:54
|
The Howto for integrating EJBCA with a SmartCard-HSM can be found here [1]. Andreas [1] http://www.smartcard-hsm.com/2014/09/05/Accessing_your_SmartCard-HSM_from_EJBCA.html On 04/21/2015 08:06 AM, Ebtehal Hassan wrote: > Hi Tomas; > which list you are talking about?if you discussed before in the forum please give me the link > > From: Tomas Gustavsson <to...@pr...> > To: ejb...@li... > Sent: Sunday, 19 April 2015, 8:20:13 > Subject: Re: [Ejbca-develop] PrimeCard > > > Hi, > > PrimeCard is not supported. Perhaps you should take a look at > SmartCard-HSM that has been discussed on the list before? > > Cheers, > Tomas > > > > On 2015-04-18 22:49, Ebtehal Hassan wrote: >> Hello all; >> we want to implement CA keys in smartCard-HSM with primeCard module >> how to accomplish that and it that supported in ejbca 6.0.4 >> >> >> >> ------------------------------------------------------------------------------ >> BPM Camp - Free Virtual Workshop May 6th at 10am PDT/1PM EDT >> Develop your own process in accordance with the BPMN 2 standard >> Learn Process modeling best practices with Bonita BPM through live exercises >> http://www.bonitasoft.com/be-part-of-it/events/bpm-camp-virtual- event?utm_ >> source=Sourceforge_BPM_Camp_5_6_15&utm_medium=email&utm_campaign=VA_SF >> >> >> >> _______________________________________________ >> Ejbca-develop mailing list >> Ejb...@li... >> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >> > > ------------------------------------------------------------------------------ > BPM Camp - Free Virtual Workshop May 6th at 10am PDT/1PM EDT > Develop your own process in accordance with the BPMN 2 standard > Learn Process modeling best practices with Bonita BPM through live exercises > http://www.bonitasoft.com/be-part-of-it/events/bpm-camp-virtual- event?utm_ > source=Sourceforge_BPM_Camp_5_6_15&utm_medium=email&utm_campaign=VA_SF > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > > > > ------------------------------------------------------------------------------ > BPM Camp - Free Virtual Workshop May 6th at 10am PDT/1PM EDT > Develop your own process in accordance with the BPMN 2 standard > Learn Process modeling best practices with Bonita BPM through live exercises > http://www.bonitasoft.com/be-part-of-it/events/bpm-camp-virtual- event?utm_ > source=Sourceforge_BPM_Camp_5_6_15&utm_medium=email&utm_campaign=VA_SF > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > -- --------- CardContact Software & System Consulting |.##> <##.| Andreas Schwier |# #| Schülerweg 38 |# #| 32429 Minden, Germany |'##> <##'| Phone +49 571 56149 --------- http://www.cardcontact.de http://www.tscons.de http://www.openscdp.org http://www.smartcard-hsm.com -- --------- CardContact Software & System Consulting |.##> <##.| Andreas Schwier |# #| Schülerweg 38 |# #| 32429 Minden, Germany |'##> <##'| Phone +49 571 56149 --------- http://www.cardcontact.de http://www.tscons.de http://www.openscdp.org http://www.smartcard-hsm.com |
|
From: Roman C. <rom...@wi...> - 2015-04-21 08:47:33
|
Yes, please see the following: I have EJBCA configured with USB cryptographic tokens from ACS, particularly CryptoMate64. These USB tokens have security certification and are capable to generate and use RSA key pairs up to 4096 bits. Also it is in a form of smart card, if you prefer it. For certificate authority that doesn't need much performance, this is really secure and cheap solution. If you need more performance, use more of these tokens with the same RSA key pair (security procedures for backing up must be in place). You should create your own SunPCKS11 configuration file for CryptoMate64 token to use it in EJBCA and its working fine. Moreover there is a possibility to use it through network with PKCS11 Proxy that could be secured using TLS. Here are useful links: http://www.acs.com.hk/en/products/18/cryptomate64-cryptographic-usb-tokens/ http://www.acs.com.hk/en/products/308/acos5-64-cryptographic-card-contact/ https://github.com/ANSSI-FR/caml-crush Everything is working without any problems. With regards, Roman -----Original Message----- From: Michael Ströder [mailto:mi...@st...] Sent: Tuesday, April 21, 2015 10:06 AM To: ejb...@li...; Ebtehal Hassan Subject: Re: [Ejbca-develop] PrimeCard Roman Cinkais wrote: > What you would like to achieve? > You don't want to buy a full HW HSM? > > Maybe I can propose a solution for you. I am managing EJBCA securely on tokens without HSM. > Let me know. Could you please elaborate on your solution? I'd also like to hear more about it. Are you e.g. using a soft token with PKCS#11 proxy? Ciao, Michael. |
|
From: Michael S. <mi...@st...> - 2015-04-21 08:06:40
|
Roman Cinkais wrote: > What you would like to achieve? > You don't want to buy a full HW HSM? > > Maybe I can propose a solution for you. I am managing EJBCA securely on tokens without HSM. > Let me know. Could you please elaborate on your solution? I'd also like to hear more about it. Are you e.g. using a soft token with PKCS#11 proxy? Ciao, Michael. |
|
From: Ebtehal H. <h.e...@ya...> - 2015-04-21 06:09:19
|
Hi Tomas;
which list you are talking about?if you discussed before in the forum please give me the link
From: Tomas Gustavsson <to...@pr...>
To: ejb...@li...
Sent: Sunday, 19 April 2015, 8:20:13
Subject: Re: [Ejbca-develop] PrimeCard
Hi,
PrimeCard is not supported. Perhaps you should take a look at
SmartCard-HSM that has been discussed on the list before?
Cheers,
Tomas
On 2015-04-18 22:49, Ebtehal Hassan wrote:
> Hello all;
> we want to implement CA keys in smartCard-HSM with primeCard module
> how to accomplish that and it that supported in ejbca 6.0.4
>
>
>
> ------------------------------------------------------------------------------
> BPM Camp - Free Virtual Workshop May 6th at 10am PDT/1PM EDT
> Develop your own process in accordance with the BPMN 2 standard
> Learn Process modeling best practices with Bonita BPM through live exercises
> http://www.bonitasoft.com/be-part-of-it/events/bpm-camp-virtual- event?utm_
> source=Sourceforge_BPM_Camp_5_6_15&utm_medium=email&utm_campaign=VA_SF
>
>
>
> _______________________________________________
> Ejbca-develop mailing list
> Ejb...@li...
> https://lists.sourceforge.net/lists/listinfo/ejbca-develop
>
------------------------------------------------------------------------------
BPM Camp - Free Virtual Workshop May 6th at 10am PDT/1PM EDT
Develop your own process in accordance with the BPMN 2 standard
Learn Process modeling best practices with Bonita BPM through live exercises
http://www.bonitasoft.com/be-part-of-it/events/bpm-camp-virtual- event?utm_
source=Sourceforge_BPM_Camp_5_6_15&utm_medium=email&utm_campaign=VA_SF
_______________________________________________
Ejbca-develop mailing list
Ejb...@li...
https://lists.sourceforge.net/lists/listinfo/ejbca-develop
|
|
From: Ebtehal H. <h.e...@ya...> - 2015-04-21 06:07:13
|
Hello Roman;
please explain more about your solution
From: Roman Cinkais <rom...@wi...>
To: Ebtehal Hassan <h.e...@ya...>; "ejb...@li..." <ejb...@li...>
Sent: Sunday, 19 April 2015, 8:51:18
Subject: Re: [Ejbca-develop] PrimeCard
Dear Ebtehal,
What you would like to achieve?You don't want to buy a full HW HSM?
Maybe I can propose a solution for you. I am managing EJBCA securely on tokens without HSM.Let me know.
With regards,Roman
On 19 Apr 2015, at 07:50, Ebtehal Hassan <h.e...@ya...> wrote:
Hello all;we want to implement CA keys in smartCard-HSM with primeCard module how to accomplish that and it that supported in ejbca 6.0.4
------------------------------------------------------------------------------
BPM Camp - Free Virtual Workshop May 6th at 10am PDT/1PM EDT
Develop your own process in accordance with the BPMN 2 standard
Learn Process modeling best practices with Bonita BPM through live exercises
http://www.bonitasoft.com/be-part-of-it/events/bpm-camp-virtual- event?utm_
source=Sourceforge_BPM_Camp_5_6_15&utm_medium=email&utm_campaign=VA_SF
_______________________________________________
Ejbca-develop mailing list
Ejb...@li...
https://lists.sourceforge.net/lists/listinfo/ejbca-develop
|
|
From: Roman C. <rom...@wi...> - 2015-04-19 16:21:46
|
Dear Ebtehal, What you would like to achieve? You don't want to buy a full HW HSM? Maybe I can propose a solution for you. I am managing EJBCA securely on tokens without HSM. Let me know. With regards, Roman > On 19 Apr 2015, at 07:50, Ebtehal Hassan <h.e...@ya...> wrote: > > Hello all; > we want to implement CA keys in smartCard-HSM with primeCard module > how to accomplish that and it that supported in ejbca 6.0.4 > > ------------------------------------------------------------------------------ > BPM Camp - Free Virtual Workshop May 6th at 10am PDT/1PM EDT > Develop your own process in accordance with the BPMN 2 standard > Learn Process modeling best practices with Bonita BPM through live exercises > http://www.bonitasoft.com/be-part-of-it/events/bpm-camp-virtual- event?utm_ > source=Sourceforge_BPM_Camp_5_6_15&utm_medium=email&utm_campaign=VA_SF > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Tomas G. <to...@pr...> - 2015-04-19 15:20:28
|
Hi, PrimeCard is not supported. Perhaps you should take a look at SmartCard-HSM that has been discussed on the list before? Cheers, Tomas On 2015-04-18 22:49, Ebtehal Hassan wrote: > Hello all; > we want to implement CA keys in smartCard-HSM with primeCard module > how to accomplish that and it that supported in ejbca 6.0.4 > > > > ------------------------------------------------------------------------------ > BPM Camp - Free Virtual Workshop May 6th at 10am PDT/1PM EDT > Develop your own process in accordance with the BPMN 2 standard > Learn Process modeling best practices with Bonita BPM through live exercises > http://www.bonitasoft.com/be-part-of-it/events/bpm-camp-virtual- event?utm_ > source=Sourceforge_BPM_Camp_5_6_15&utm_medium=email&utm_campaign=VA_SF > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Ebtehal H. <h.e...@ya...> - 2015-04-19 05:49:23
|
Hello all;we want to implement CA keys in smartCard-HSM with primeCard module how to accomplish that and it that supported in ejbca 6.0.4 |
|
From: Jean-Luc C. <jea...@at...> - 2015-04-17 08:21:46
|
Hi, catoken looks like this: $ pwd /appli/ejbca/install/ejbca_ce_6_2_0 $ cat conf/catoken.properties sharedLibrary /logiciels/API_PKCS11_v3.5.2/lib/libpkcs11c2p.so slotLabelType=SLOT_NUMBER #slotLabelValue=1 slotListIndex=0 # CA key configuration defaultKey defaultRoot certSignKey signRoot crlSignKey signRoot testKey testRoot Best Regards Jean-Luc -----Message d'origine----- De : Michael Ströder [mailto:mi...@st...] Envoyé : vendredi 17 avril 2015 10:10 À : ejb...@li... Objet : Re: [Ejbca-develop] Can't create a pkcs#11 crypto token Jean-Luc Chardon wrote: > I'm trying to install EJBCA 6.2 using an HSM as a crypto provider. > > I can't see "PKCS11" option as type of provider in the crypto token > creation GUI. I can only see "SOFT" as token type. How does your catoken.properties look like? Ciao, Michael. |
|
From: Tomas G. <to...@pr...> - 2015-04-17 08:20:37
|
See: http://ejbca.org/docs/adminguide.html#HSM%20modules%20available%20in%20the%20Admin%20GUI Regards, Tomas ----- Save time and money with an Enterprise support subscription. Please see www.primekey.se for more information. http://www.primekey.se/Products/EJBCA+PKI/ http://www.primekey.se/Services/Support/ On 2015-04-17 09:24, Jean-Luc Chardon wrote: > Hi, > > I’m trying to install EJBCA 6.2 using an HSM as a crypto provider. > > I can’t see “PKCS11” option as type of provider in the crypto token > creation GUI. I can only see “SOFT” as token type. > > What should I do to be able to create a new PKCS#11 crypto token? > > EJBCA Shell script communicates properly with the HSM: > > $ cd /appli/ejbca/install/ejbca_ce_6_2_0 > > $ bin/pkcs11HSM.sh generate > /logiciels/API_PKCS11_v3.5.2/lib/libpkcs11c2p.so 2048 defaultRoot i0 > > 2015-04-15 17:40:55,811 INFO [org.cesecore.config.ConfigurationHolder] > Allow external re-configuration: false > > Using Slot Reference Type: Slot Index. > > 2015-04-15 17:40:56,144 INFO > [org.cesecore.keys.token.p11.Pkcs11SlotLabel] Using SUN PKCS11 provider: > sun.security.pkcs11.SunPKCS11 > > Created certificate with entry defaultRoot. > > $ > > EJBCA ant client also works fine: > > $ ./ejbcaClientToolBox.sh PKCS11HSMKeyTool test > /logiciels/API_PKCS11_v3.5.2/lib/libpkcs11c2p.so 1 > > 2015-04-15 17:52:58,283 INFO [org.cesecore.config.ConfigurationHolder] > Allow external re-configuration: false > > Test of keystore with ID 1. > > 2015-04-15 17:52:58,559 INFO > [org.cesecore.keys.token.p11.Pkcs11SlotLabel] Using SUN PKCS11 provider: > sun.security.pkcs11.SunPKCS11 > > Not testing keys with alias TransportKey. Not a private key. > > Testing of key: defaultRoot > > Private part: > > SunPKCS11-libpkcs11c2p.so-slot1 RSA private key, 2048 bits (id 16777217, > token object, sensitive, unextractable) > > RSA key: > > modulus: > aa3eb6a3bf651aac56e623b66f65b158d91b76f800de0186d1295408d8f47fd0ed2e73332945fe5e14cb9a7e93bcaa8f331e3c9529f24ef7b758dc40e7ad60dabbbc3a56e3317303a453a419c2d766ba3861dd75e6c969852378bfdc394f80fa13792ad1376fcbaf17dcb010831bba4b1253f67ad3c5d20e7e8d2cd25dc932fb35daa49972307990efea66e339f61ce8ed1ce421f63a85b8497c7a05c3d33dee6bc14e6681d581d212090ffc52fbd0857e0f3118afd65f23b91497e4aae29fbafb6f6527ee59e518f7d6d6e1e6aa34c3355a3e9020066a6af12dfcd936967980c35707ef282f824ff810a8198ee550e87c5d9b7da6204ae9c34a72b2223c4a07 > > public exponent: 10001 > > encryption provider: SunJCE version 1.7; decryption provider: > SunPKCS11-libpkcs11c2p.so-slot1 version 1.7; modulus length: 2048; byte > length 245. The decoded byte string is equal to the original! > > Signature test of key defaultRoot: signature length 256; first byte 64; > verifying true > > Signings per second: 131 > > Decryptions per second: 132 > > Hit RETURN to run again. Type x and hit RETURN to quit. > > Thanks. > > JL > > > > ------------------------------------------------------------------------------ > BPM Camp - Free Virtual Workshop May 6th at 10am PDT/1PM EDT > Develop your own process in accordance with the BPMN 2 standard > Learn Process modeling best practices with Bonita BPM through live exercises > http://www.bonitasoft.com/be-part-of-it/events/bpm-camp-virtual- event?utm_ > source=Sourceforge_BPM_Camp_5_6_15&utm_medium=email&utm_campaign=VA_SF > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Michael S. <mi...@st...> - 2015-04-17 08:10:28
|
Jean-Luc Chardon wrote: > I'm trying to install EJBCA 6.2 using an HSM as a crypto provider. > > I can't see "PKCS11" option as type of provider in the crypto token > creation GUI. I can only see "SOFT" as token type. How does your catoken.properties look like? Ciao, Michael. |
|
From: Jean-Luc C. <jea...@at...> - 2015-04-17 07:24:54
|
Hi, I'm trying to install EJBCA 6.2 using an HSM as a crypto provider. I can't see "PKCS11" option as type of provider in the crypto token creation GUI. I can only see "SOFT" as token type. What should I do to be able to create a new PKCS#11 crypto token? EJBCA Shell script communicates properly with the HSM: $ cd /appli/ejbca/install/ejbca_ce_6_2_0 $ bin/pkcs11HSM.sh generate /logiciels/API_PKCS11_v3.5.2/lib/libpkcs11c2p.so 2048 defaultRoot i0 2015-04-15 17:40:55,811 INFO [org.cesecore.config.ConfigurationHolder] Allow external re-configuration: false Using Slot Reference Type: Slot Index. 2015-04-15 17:40:56,144 INFO [org.cesecore.keys.token.p11.Pkcs11SlotLabel] Using SUN PKCS11 provider: sun.security.pkcs11.SunPKCS11 Created certificate with entry defaultRoot. $ EJBCA ant client also works fine: $ ./ejbcaClientToolBox.sh PKCS11HSMKeyTool test /logiciels/API_PKCS11_v3.5.2/lib/libpkcs11c2p.so 1 2015-04-15 17:52:58,283 INFO [org.cesecore.config.ConfigurationHolder] Allow external re-configuration: false Test of keystore with ID 1. 2015-04-15 17:52:58,559 INFO [org.cesecore.keys.token.p11.Pkcs11SlotLabel] Using SUN PKCS11 provider: sun.security.pkcs11.SunPKCS11 Not testing keys with alias TransportKey. Not a private key. Testing of key: defaultRoot Private part: SunPKCS11-libpkcs11c2p.so-slot1 RSA private key, 2048 bits (id 16777217, token object, sensitive, unextractable) RSA key: modulus: aa3eb6a3bf651aac56e623b66f65b158d91b76f800de0186d1295408d8f47fd0ed2e73332945fe5e14cb9a7e93bcaa8f331e3c9529f24ef7b758dc40e7ad60dabbbc3a56e3317303a453a419c2d766ba3861dd75e6c969852378bfdc394f80fa13792ad1376fcbaf17dcb010831bba4b1253f67ad3c5d20e7e8d2cd25dc932fb35daa49972307990efea66e339f61ce8ed1ce421f63a85b8497c7a05c3d33dee6bc14e6681d581d212090ffc52fbd0857e0f3118afd65f23b91497e4aae29fbafb6f6527ee59e518f7d6d6e1e6aa34c3355a3e9020066a6af12dfcd936967980c35707ef282f824ff810a8198ee550e87c5d9b7da6204ae9c34a72b2223c4a07 public exponent: 10001 encryption provider: SunJCE version 1.7; decryption provider: SunPKCS11-libpkcs11c2p.so-slot1 version 1.7; modulus length: 2048; byte length 245. The decoded byte string is equal to the original! Signature test of key defaultRoot: signature length 256; first byte 64; verifying true Signings per second: 131 Decryptions per second: 132 Hit RETURN to run again. Type x and hit RETURN to quit. Thanks. JL |
|
From: Jean-Luc C. <jea...@at...> - 2015-04-16 14:35:03
|
Hi, I'm trying to install EJBCA 6.2 using an HSM as a crypto provider. I can't see "PKCS11" option as type of provider in the crypto token creation GUI. I can only see "SOFT" as token type. What should I do to be able to create a new PKCS#11 crypto token? EJBCA Shell script communicates properly with the HSM: $ cd /appli/ejbca/install/ejbca_ce_6_2_0 $ bin/pkcs11HSM.sh generate /logiciels/API_PKCS11_v3.5.2/lib/libpkcs11c2p.so 2048 defaultRoot i0 2015-04-15 17:40:55,811 INFO [org.cesecore.config.ConfigurationHolder] Allow external re-configuration: false Using Slot Reference Type: Slot Index. 2015-04-15 17:40:56,144 INFO [org.cesecore.keys.token.p11.Pkcs11SlotLabel] Using SUN PKCS11 provider: sun.security.pkcs11.SunPKCS11 Created certificate with entry defaultRoot. $ EJBCA ant client also works fine: $ ./ejbcaClientToolBox.sh PKCS11HSMKeyTool test /logiciels/API_PKCS11_v3.5.2/lib/libpkcs11c2p.so 1 2015-04-15 17:52:58,283 INFO [org.cesecore.config.ConfigurationHolder] Allow external re-configuration: false Test of keystore with ID 1. 2015-04-15 17:52:58,559 INFO [org.cesecore.keys.token.p11.Pkcs11SlotLabel] Using SUN PKCS11 provider: sun.security.pkcs11.SunPKCS11 Not testing keys with alias TransportKey. Not a private key. Testing of key: defaultRoot Private part: SunPKCS11-libpkcs11c2p.so-slot1 RSA private key, 2048 bits (id 16777217, token object, sensitive, unextractable) RSA key: modulus: aa3eb6a3bf651aac56e623b66f65b158d91b76f800de0186d1295408d8f47fd0ed2e73332945fe5e14cb9a7e93bcaa8f331e3c9529f24ef7b758dc40e7ad60dabbbc3a56e3317303a453a419c2d766ba3861dd75e6c969852378bfdc394f80fa13792ad1376fcbaf17dcb010831bba4b1253f67ad3c5d20e7e8d2cd25dc932fb35daa49972307990efea66e339f61ce8ed1ce421f63a85b8497c7a05c3d33dee6bc14e6681d581d212090ffc52fbd0857e0f3118afd65f23b91497e4aae29fbafb6f6527ee59e518f7d6d6e1e6aa34c3355a3e9020066a6af12dfcd936967980c35707ef282f824ff810a8198ee550e87c5d9b7da6204ae9c34a72b2223c4a07 public exponent: 10001 encryption provider: SunJCE version 1.7; decryption provider: SunPKCS11-libpkcs11c2p.so-slot1 version 1.7; modulus length: 2048; byte length 245. The decoded byte string is equal to the original! Signature test of key defaultRoot: signature length 256; first byte 64; verifying true Signings per second: 131 Decryptions per second: 132 Hit RETURN to run again. Type x and hit RETURN to quit. Jean-Luc. |
|
From: Andrea D. <ado...@in...> - 2015-04-15 12:48:40
|
Thanks a lot Tomas. Regards Andrea Il 15/04/2015 14:26, Tomas Gustavsson ha scritto: > You need to add them as ExtendedInformation, like. > > new ExtendedInformationWS(ExtendedInformation.SUBJECTDIRATTRIBUTES, > "DATEOFBIRTH=19761123") > > Regards, > Tomas > ----- > Save time and money with an Enterprise support subscription. Please see > www.primekey.se for more information. > http://www.primekey.se/Products/EJBCA+PKI/ > http://www.primekey.se/Services/Support/ > > > On 2015-04-14 17:33, Andrea Dondoni wrote: >> Hello all, >> can anyone tell me how I can set attributes DateOfBirth and PlaceOfBirth >> (part of Subject Directory Attribute) through the WS in EJBCA 4.0.16? >> Actually i'm using WS API *editUser* passing as input object UserDataVOWS >> >> Thanks in advance. >> Regards >> >> Andrea >> >> >> ------------------------------------------------------------------------------ >> BPM Camp - Free Virtual Workshop May 6th at 10am PDT/1PM EDT >> Develop your own process in accordance with the BPMN 2 standard >> Learn Process modeling best practices with Bonita BPM through live exercises >> http://www.bonitasoft.com/be-part-of-it/events/bpm-camp-virtual- event?utm_ >> source=Sourceforge_BPM_Camp_5_6_15&utm_medium=email&utm_campaign=VA_SF >> >> >> >> _______________________________________________ >> Ejbca-develop mailing list >> Ejb...@li... >> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >> > ------------------------------------------------------------------------------ > BPM Camp - Free Virtual Workshop May 6th at 10am PDT/1PM EDT > Develop your own process in accordance with the BPMN 2 standard > Learn Process modeling best practices with Bonita BPM through live exercises > http://www.bonitasoft.com/be-part-of-it/events/bpm-camp-virtual- event?utm_ > source=Sourceforge_BPM_Camp_5_6_15&utm_medium=email&utm_campaign=VA_SF > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop -- Andrea Dondoni ------------------------------------------------------------------------ *Intesi Group S.p.A. <http://www.intesigroup.com>* | Via Torino, 48 | 20123 Milano - Italia | T. +39 0267606484 |