You can subscribe to this list here.
| 2001 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
(1) |
Dec
(3) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2002 |
Jan
(3) |
Feb
(2) |
Mar
(8) |
Apr
(3) |
May
(6) |
Jun
(1) |
Jul
(15) |
Aug
(6) |
Sep
|
Oct
(10) |
Nov
(2) |
Dec
(4) |
| 2003 |
Jan
(1) |
Feb
(7) |
Mar
(3) |
Apr
(6) |
May
(7) |
Jun
(5) |
Jul
(5) |
Aug
(25) |
Sep
(14) |
Oct
(2) |
Nov
|
Dec
(2) |
| 2004 |
Jan
(7) |
Feb
(4) |
Mar
(12) |
Apr
(16) |
May
(43) |
Jun
(56) |
Jul
(43) |
Aug
(40) |
Sep
(66) |
Oct
(12) |
Nov
(26) |
Dec
(10) |
| 2005 |
Jan
(13) |
Feb
(33) |
Mar
(16) |
Apr
(7) |
May
(10) |
Jun
(34) |
Jul
(41) |
Aug
(8) |
Sep
(4) |
Oct
(32) |
Nov
(20) |
Dec
(25) |
| 2006 |
Jan
(30) |
Feb
(101) |
Mar
(5) |
Apr
(75) |
May
(74) |
Jun
(22) |
Jul
(6) |
Aug
(70) |
Sep
(19) |
Oct
(21) |
Nov
(31) |
Dec
(50) |
| 2007 |
Jan
(15) |
Feb
(20) |
Mar
(24) |
Apr
(33) |
May
(13) |
Jun
(18) |
Jul
(13) |
Aug
(7) |
Sep
(63) |
Oct
(68) |
Nov
(29) |
Dec
(68) |
| 2008 |
Jan
(30) |
Feb
(33) |
Mar
(30) |
Apr
(103) |
May
(78) |
Jun
(48) |
Jul
(72) |
Aug
(24) |
Sep
(62) |
Oct
(63) |
Nov
(70) |
Dec
(37) |
| 2009 |
Jan
(34) |
Feb
(35) |
Mar
(64) |
Apr
(34) |
May
(34) |
Jun
(58) |
Jul
(30) |
Aug
(30) |
Sep
(46) |
Oct
(52) |
Nov
(12) |
Dec
(23) |
| 2010 |
Jan
(121) |
Feb
(18) |
Mar
(53) |
Apr
(62) |
May
(62) |
Jun
(20) |
Jul
(33) |
Aug
(20) |
Sep
(36) |
Oct
(35) |
Nov
(44) |
Dec
(63) |
| 2011 |
Jan
(19) |
Feb
(32) |
Mar
(94) |
Apr
(41) |
May
(47) |
Jun
(25) |
Jul
(34) |
Aug
(20) |
Sep
(9) |
Oct
(41) |
Nov
(33) |
Dec
(24) |
| 2012 |
Jan
(12) |
Feb
(36) |
Mar
(48) |
Apr
(32) |
May
(20) |
Jun
(15) |
Jul
(32) |
Aug
(13) |
Sep
(33) |
Oct
(54) |
Nov
(25) |
Dec
(16) |
| 2013 |
Jan
(45) |
Feb
(39) |
Mar
(38) |
Apr
(50) |
May
(29) |
Jun
(30) |
Jul
(33) |
Aug
(12) |
Sep
(9) |
Oct
(25) |
Nov
(29) |
Dec
(20) |
| 2014 |
Jan
(25) |
Feb
(19) |
Mar
(16) |
Apr
(33) |
May
(27) |
Jun
(37) |
Jul
(29) |
Aug
(27) |
Sep
(37) |
Oct
(58) |
Nov
(109) |
Dec
(26) |
| 2015 |
Jan
(4) |
Feb
(35) |
Mar
(22) |
Apr
(35) |
May
(28) |
Jun
(20) |
Jul
(4) |
Aug
(16) |
Sep
(37) |
Oct
(13) |
Nov
(13) |
Dec
(14) |
| 2016 |
Jan
(22) |
Feb
(7) |
Mar
(23) |
Apr
(30) |
May
(10) |
Jun
(10) |
Jul
(15) |
Aug
(12) |
Sep
(22) |
Oct
(31) |
Nov
(5) |
Dec
(5) |
| 2017 |
Jan
(30) |
Feb
(25) |
Mar
(28) |
Apr
(4) |
May
(19) |
Jun
(13) |
Jul
(7) |
Aug
(1) |
Sep
(2) |
Oct
(5) |
Nov
(12) |
Dec
(2) |
| 2018 |
Jan
(7) |
Feb
|
Mar
(7) |
Apr
(2) |
May
(8) |
Jun
(18) |
Jul
(6) |
Aug
(3) |
Sep
(15) |
Oct
(33) |
Nov
(13) |
Dec
(7) |
| 2019 |
Jan
(5) |
Feb
(7) |
Mar
(30) |
Apr
(5) |
May
(4) |
Jun
(69) |
Jul
(86) |
Aug
(22) |
Sep
(6) |
Oct
(7) |
Nov
(5) |
Dec
(3) |
| 2020 |
Jan
(10) |
Feb
(12) |
Mar
(22) |
Apr
(5) |
May
(1) |
Jun
(4) |
Jul
(6) |
Aug
|
Sep
(9) |
Oct
|
Nov
|
Dec
(1) |
| 2021 |
Jan
(4) |
Feb
(11) |
Mar
(7) |
Apr
(7) |
May
|
Jun
(3) |
Jul
(10) |
Aug
(6) |
Sep
|
Oct
|
Nov
(18) |
Dec
(2) |
| 2022 |
Jan
(1) |
Feb
(1) |
Mar
|
Apr
|
May
|
Jun
(2) |
Jul
|
Aug
(4) |
Sep
|
Oct
|
Nov
|
Dec
|
| 2023 |
Jan
|
Feb
|
Mar
|
Apr
(1) |
May
(1) |
Jun
|
Jul
|
Aug
(5) |
Sep
|
Oct
|
Nov
|
Dec
|
|
From: Tomas G. <to...@pr...> - 2015-04-15 12:26:47
|
You need to add them as ExtendedInformation, like. new ExtendedInformationWS(ExtendedInformation.SUBJECTDIRATTRIBUTES, "DATEOFBIRTH=19761123") Regards, Tomas ----- Save time and money with an Enterprise support subscription. Please see www.primekey.se for more information. http://www.primekey.se/Products/EJBCA+PKI/ http://www.primekey.se/Services/Support/ On 2015-04-14 17:33, Andrea Dondoni wrote: > Hello all, > can anyone tell me how I can set attributes DateOfBirth and PlaceOfBirth > (part of Subject Directory Attribute) through the WS in EJBCA 4.0.16? > Actually i'm using WS API *editUser* passing as input object UserDataVOWS > > Thanks in advance. > Regards > > Andrea > > > ------------------------------------------------------------------------------ > BPM Camp - Free Virtual Workshop May 6th at 10am PDT/1PM EDT > Develop your own process in accordance with the BPMN 2 standard > Learn Process modeling best practices with Bonita BPM through live exercises > http://www.bonitasoft.com/be-part-of-it/events/bpm-camp-virtual- event?utm_ > source=Sourceforge_BPM_Camp_5_6_15&utm_medium=email&utm_campaign=VA_SF > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Andrea D. <ado...@in...> - 2015-04-14 16:01:46
|
Hello all, can anyone tell me how I can set attributes DateOfBirth and PlaceOfBirth (part of Subject Directory Attribute) through the WS in EJBCA 4.0.16? Actually i'm using WS API *editUser* passing as input object UserDataVOWS Thanks in advance. Regards Andrea |
|
From: Tomas G. <to...@pr...> - 2015-04-07 14:52:20
|
You should check the content of a generated CRL, then you can see that
it follows exactly what RFC5280 says.
openssl crl -inform DER -in ManagementCA.crl -text
Serial Number: 37606FCBBCDF2D31
Revocation Date: Dec 10 14:27:43 2014 GMT
CRL entry extensions:
X509v3 CRL Reason Code:
Superseded
Serial Number: 5BCF9BA74FF3F424
Revocation Date: Dec 10 14:26:53 2014 GMT
Regards,
Tomas
On 2015-04-07 16:43, Michael Postmann wrote:
> I can select "unspecified" but as far as I understand the RFC if you have no meaningful reason the reason SHOULD be omitted instead of just specifying "unspecified".
> I know it's only cosmetic and it doesn't bother me at all, but I thought it might be worth thinking about. It's only a "SHOULD" though, which according to RFC means
> "... that there may exist valid reasons in particular circumstances to ignore a particular item, but the full implications must be understood and carefully weighed before choosing a different course."
> so it's not really mandatory.
>
> As for the revocation reasons:
>
> "Cessation of operation" as far as I understand should be used if an (Intermediate) CA is brought out of service (0). "Superseded" on the other hand is used if you replace a certificate with a new one.
> For now I've chosen "Affiliation changed" as the client certificate was for a non-existing test-person who is now no longer doing "business" with us, I think that's the most appropriate.
>
> At the end it doesn't matter at all. We use the PKI internally and nobody will ever bother with the CRL's I guess ;-).
>
> cheers
> nomike
>
> -----Ursprüngliche Nachricht-----
> Von: Tomas Gustavsson [mailto:to...@pr...]
> Gesendet: Dienstag, 7. April 2015 16:25
> An: ejb...@li...
> Betreff: Re: [Ejbca-develop] Revoke certificate without reason
>
>
> I have no problem selecting "unspecified" as revocation reason, from the list of revocation reasons. What do you see? Which screen in the admin GUI?
>
> "Cessation of operation" or "Superseded" sounds like a suitable reason for test certificates.
>
> Cheers,
> Tomas
> -----
> Save time and money with an Enterprise support subscription. Please see www.primekey.se for more information.
> http://www.primekey.se/Products/EJBCA+PKI/
> http://www.primekey.se/Services/Support/
>
>
> On 2015-04-07 15:07, Michael Postmann wrote:
>> Hi!
>>
>> According to RFC 5280 (p. 69) "CRL issuers are strongly
>>
>> encouraged to include meaningful reason codes in CRL entries;
>>
>> however, the reason code CRL entry extension SHOULD be absent instead
>>
>> of using the unspecified (0) reasonCode value."
>>
>> However when I want to revoke a certificate on the web interface it's
>> not possible to select no reason.
>>
>> Is this intentionally left out or is there another way to achieve this?
>>
>> Besides that, what I actually want to do is to revoke some certificates
>> I issued for testing the PKI. What's the most appropriate reason for that?
>>
>> regards
>>
>> nomike
>>
>> --
>>
>> *Michael Postmann*
>>
>> Application Engineer
>>
>> paysafecard.com <http://paysafecard.com/>Wertkarten GmbH
>> Am Euro Platz 2, A-1120 Wien
>>
>> phone: +43 1 / 720 83 80 - 649
>> fax: +43 1 / 720 83 80 - 12
>>
>> mobile: +43 676 / 765 77 31
>>
>> skype: nomike31
>> mail: m.p...@pa... <mailto:m.p...@pa...>
>>
>> web: www.paysafecard.com <http://www.paysafecard.com/>
>>
>> Firmenbuch: FN 194434h
>> Handelsgericht Wien
>>
>>
>>
>> ------------------------------------------------------------------------------
>> BPM Camp - Free Virtual Workshop May 6th at 10am PDT/1PM EDT
>> Develop your own process in accordance with the BPMN 2 standard
>> Learn Process modeling best practices with Bonita BPM through live exercises
>> http://www.bonitasoft.com/be-part-of-it/events/bpm-camp-virtual- event?utm_
>> source=Sourceforge_BPM_Camp_5_6_15&utm_medium=email&utm_campaign=VA_SF
>>
>>
>>
>> _______________________________________________
>> Ejbca-develop mailing list
>> Ejb...@li...
>> https://lists.sourceforge.net/lists/listinfo/ejbca-develop
>>
>
> ------------------------------------------------------------------------------
> BPM Camp - Free Virtual Workshop May 6th at 10am PDT/1PM EDT
> Develop your own process in accordance with the BPMN 2 standard
> Learn Process modeling best practices with Bonita BPM through live exercises
> http://www.bonitasoft.com/be-part-of-it/events/bpm-camp-virtual- event?utm_
> source=Sourceforge_BPM_Camp_5_6_15&utm_medium=email&utm_campaign=VA_SF
> _______________________________________________
> Ejbca-develop mailing list
> Ejb...@li...
> https://lists.sourceforge.net/lists/listinfo/ejbca-develop
>
> ------------------------------------------------------------------------------
> BPM Camp - Free Virtual Workshop May 6th at 10am PDT/1PM EDT
> Develop your own process in accordance with the BPMN 2 standard
> Learn Process modeling best practices with Bonita BPM through live exercises
> http://www.bonitasoft.com/be-part-of-it/events/bpm-camp-virtual- event?utm_
> source=Sourceforge_BPM_Camp_5_6_15&utm_medium=email&utm_campaign=VA_SF
> _______________________________________________
> Ejbca-develop mailing list
> Ejb...@li...
> https://lists.sourceforge.net/lists/listinfo/ejbca-develop
>
|
|
From: Michael P. <M.P...@pa...> - 2015-04-07 14:43:13
|
I can select "unspecified" but as far as I understand the RFC if you have no meaningful reason the reason SHOULD be omitted instead of just specifying "unspecified". I know it's only cosmetic and it doesn't bother me at all, but I thought it might be worth thinking about. It's only a "SHOULD" though, which according to RFC means "... that there may exist valid reasons in particular circumstances to ignore a particular item, but the full implications must be understood and carefully weighed before choosing a different course." so it's not really mandatory. As for the revocation reasons: "Cessation of operation" as far as I understand should be used if an (Intermediate) CA is brought out of service (0). "Superseded" on the other hand is used if you replace a certificate with a new one. For now I've chosen "Affiliation changed" as the client certificate was for a non-existing test-person who is now no longer doing "business" with us, I think that's the most appropriate. At the end it doesn't matter at all. We use the PKI internally and nobody will ever bother with the CRL's I guess ;-). cheers nomike -----Ursprüngliche Nachricht----- Von: Tomas Gustavsson [mailto:to...@pr...] Gesendet: Dienstag, 7. April 2015 16:25 An: ejb...@li... Betreff: Re: [Ejbca-develop] Revoke certificate without reason I have no problem selecting "unspecified" as revocation reason, from the list of revocation reasons. What do you see? Which screen in the admin GUI? "Cessation of operation" or "Superseded" sounds like a suitable reason for test certificates. Cheers, Tomas ----- Save time and money with an Enterprise support subscription. Please see www.primekey.se for more information. http://www.primekey.se/Products/EJBCA+PKI/ http://www.primekey.se/Services/Support/ On 2015-04-07 15:07, Michael Postmann wrote: > Hi! > > According to RFC 5280 (p. 69) "CRL issuers are strongly > > encouraged to include meaningful reason codes in CRL entries; > > however, the reason code CRL entry extension SHOULD be absent instead > > of using the unspecified (0) reasonCode value." > > However when I want to revoke a certificate on the web interface it's > not possible to select no reason. > > Is this intentionally left out or is there another way to achieve this? > > Besides that, what I actually want to do is to revoke some certificates > I issued for testing the PKI. What's the most appropriate reason for that? > > regards > > nomike > > -- > > *Michael Postmann* > > Application Engineer > > paysafecard.com <http://paysafecard.com/>Wertkarten GmbH > Am Euro Platz 2, A-1120 Wien > > phone: +43 1 / 720 83 80 - 649 > fax: +43 1 / 720 83 80 - 12 > > mobile: +43 676 / 765 77 31 > > skype: nomike31 > mail: m.p...@pa... <mailto:m.p...@pa...> > > web: www.paysafecard.com <http://www.paysafecard.com/> > > Firmenbuch: FN 194434h > Handelsgericht Wien > > > > ------------------------------------------------------------------------------ > BPM Camp - Free Virtual Workshop May 6th at 10am PDT/1PM EDT > Develop your own process in accordance with the BPMN 2 standard > Learn Process modeling best practices with Bonita BPM through live exercises > http://www.bonitasoft.com/be-part-of-it/events/bpm-camp-virtual- event?utm_ > source=Sourceforge_BPM_Camp_5_6_15&utm_medium=email&utm_campaign=VA_SF > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > ------------------------------------------------------------------------------ BPM Camp - Free Virtual Workshop May 6th at 10am PDT/1PM EDT Develop your own process in accordance with the BPMN 2 standard Learn Process modeling best practices with Bonita BPM through live exercises http://www.bonitasoft.com/be-part-of-it/events/bpm-camp-virtual- event?utm_ source=Sourceforge_BPM_Camp_5_6_15&utm_medium=email&utm_campaign=VA_SF _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Tomas G. <to...@pr...> - 2015-04-07 14:40:55
|
Doesn't look like exactly the same, since your ca.toketype looks more correct. I think this is something that has been fixed already. In Enterprise, and upcoming Community. Regards, Tomas On 2015-04-07 16:27, Damian Wabisch wrote: > Hi together, > > I have absolutely the same problem. > > In my case I am using a Thales connect 500 as keystore. > With EJBCA version 6_0_3 everything is running fine. > > Now I tried to use the EJBCA version 6_2_0 and got the same error: > > ejbca:init: > [echo] > [echo] ------------------- CA Properties ---------------- > [echo] ca.name : ManagementCA > [echo] ca.dn : CN=ManagementCA,O=EJBCA Sample,C=SE > [echo] ca.tokentype : > org.cesecore.keys.token.PKCS11CryptoToken > [echo] ca.keytype : RSA > [echo] ca.keyspec : 2048 > [echo] ca.signaturealgorithm : SHA1WithRSA > [echo] ca.validity : 3650 > [echo] ca.policy : null > [echo] ca.tokenproperties : > /home/damian/ejbca/newHsm/ejbca_ce_6_2_0/conf/catoken.properties > [echo] httpsserver.hostname : localhost > [echo] httpsserver.dn : CN=localhost,O=EJBCA Sample,C=SE > [echo] superadmin.cn : SuperAdmin > [echo] superadmin.dn : CN=SuperAdmin > [echo] superadmin.batch : true > [echo] appserver.home : > /home/damian/ejbca/newHsm/jboss-as-7.1.1.Final > [echo] > > ejbca:install: > > ejbca:initCA: > [echo] Initializing CA with 'ManagementCA' > 'CN=ManagementCA,O=EJBCA Sample,C=SE' > 'org.cesecore.keys.token.PKCS11CryptoToken' <ca.tokenpassword hidden> > '2048' 'RSA' '3650' 'null' 'SHA1WithRSA' > /home/damian/ejbca/newHsm/ejbca_ce_6_2_0/conf/catoken.properties > -superadmincn 'SuperAdmin'... > [java] SETTING: --caname as ManagementCA > [java] SETTING: --dn as CN=ManagementCA,O=EJBCA Sample,C=SE > [java] SETTING: --tokenType as > org.cesecore.keys.token.PKCS11CryptoToken > [java] SETTING: --tokenPass as null > [java] SETTING: --keyspec as 2048 > [java] SETTING: --keytype as RSA > [java] SETTING: -v as 3650 > [java] SETTING: --policy as null > [java] SETTING: -s as SHA1WithRSA > [java] SETTING: -superadmincn as SuperAdmin > [java] ERROR: Incorrect parameter usage. > [java] The following arguments are unknown: > [java] > /home/damian/ejbca/newHsm/ejbca_ce_6_2_0/conf/catoken.properties > [java] > [java] Run command with "--help" to see full manual page. > > > Here is also my configuration: > # catoken.properties > defaultKey defaultRoot > testKey test > keyEncryptKey cryptRoot > hardTokenEncrypt cryptRoot > > pin dummy > slotLabelType SLOT_INDEX > slotLabelValue 1 > sharedLibrary /opt/nfast/toolkits/pkcs11/libcknfast.so > > > # install.properties > # ------------ Administrative CA configuration --------------------- > ca.name=ManagementCA > ca.dn=CN=ManagementCA,O=EJBCA Sample,C=SE > > ca.tokentype=org.cesecore.keys.token.PKCS11CryptoToken > ca.tokenpassword=null > ca.tokenproperties=/home/damian/ejbca/newHsm/ejbca_ce_6_2_0/conf/catoken.properties > > ca.keyspec=2048 > ca.keytype=RSA > ca.signaturealgorithm=SHA1WithRSA > > ca.validity=3650 > ca.policy=null > > > Did you change something in catoken.properties??? > > Cheers from Germany > Damian > > > Am 23.03.2015 um 11:36 schrieb Anh Pham Van The (FIS FPS HN): >> Dear all, >> I installing EJBCA version 6.2.0 use CA key created into AEP HSM >> Enterprise. >> I run "ant bootstrap" is successful but when I run "ant install" then >> have an error. >> Can you check and get me a recommend? >> Please check attach file for more information include: error screen >> shot, catoken.properties file. >> >> Thank you, >> Mr. Anh >> From Hanoi, Vietnam. >> >> >> ------------------------------------------------------------------------------ >> Dive into the World of Parallel Programming The Go Parallel Website, sponsored >> by Intel and developed in partnership with Slashdot Media, is your hub for all >> things parallel software development, from weekly thought leadership blogs to >> news, videos, case studies, tutorials and more. Take a look and join the >> conversation now.http://goparallel.sourceforge.net/ >> >> >> _______________________________________________ >> Ejbca-develop mailing list >> Ejb...@li... >> https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > ------------------------------------------------------------------------------ > BPM Camp - Free Virtual Workshop May 6th at 10am PDT/1PM EDT > Develop your own process in accordance with the BPMN 2 standard > Learn Process modeling best practices with Bonita BPM through live exercises > http://www.bonitasoft.com/be-part-of-it/events/bpm-camp-virtual- event?utm_ > source=Sourceforge_BPM_Camp_5_6_15&utm_medium=email&utm_campaign=VA_SF > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Damian W. <Dam...@ru...> - 2015-04-07 14:27:33
|
Hi together,
I have absolutely the same problem.
In my case I am using a Thales connect 500 as keystore.
With EJBCA version 6_0_3 everything is running fine.
Now I tried to use the EJBCA version 6_2_0 and got the same error:
ejbca:init:
[echo]
[echo] ------------------- CA Properties ----------------
[echo] ca.name : ManagementCA
[echo] ca.dn : CN=ManagementCA,O=EJBCA Sample,C=SE
[echo] ca.tokentype :
org.cesecore.keys.token.PKCS11CryptoToken
[echo] ca.keytype : RSA
[echo] ca.keyspec : 2048
[echo] ca.signaturealgorithm : SHA1WithRSA
[echo] ca.validity : 3650
[echo] ca.policy : null
[echo] ca.tokenproperties :
/home/damian/ejbca/newHsm/ejbca_ce_6_2_0/conf/catoken.properties
[echo] httpsserver.hostname : localhost
[echo] httpsserver.dn : CN=localhost,O=EJBCA Sample,C=SE
[echo] superadmin.cn : SuperAdmin
[echo] superadmin.dn : CN=SuperAdmin
[echo] superadmin.batch : true
[echo] appserver.home :
/home/damian/ejbca/newHsm/jboss-as-7.1.1.Final
[echo]
ejbca:install:
ejbca:initCA:
[echo] Initializing CA with 'ManagementCA' 'CN=ManagementCA,O=EJBCA
Sample,C=SE' 'org.cesecore.keys.token.PKCS11CryptoToken'
<ca.tokenpassword hidden> '2048' 'RSA' '3650' 'null' 'SHA1WithRSA'
/home/damian/ejbca/newHsm/ejbca_ce_6_2_0/conf/catoken.properties
-superadmincn 'SuperAdmin'...
[java] SETTING: --caname as ManagementCA
[java] SETTING: --dn as CN=ManagementCA,O=EJBCA Sample,C=SE
[java] SETTING: --tokenType as
org.cesecore.keys.token.PKCS11CryptoToken
[java] SETTING: --tokenPass as null
[java] SETTING: --keyspec as 2048
[java] SETTING: --keytype as RSA
[java] SETTING: -v as 3650
[java] SETTING: --policy as null
[java] SETTING: -s as SHA1WithRSA
[java] SETTING: -superadmincn as SuperAdmin
[java] ERROR: Incorrect parameter usage.
[java] The following arguments are unknown:
[java]
/home/damian/ejbca/newHsm/ejbca_ce_6_2_0/conf/catoken.properties
[java]
[java] Run command with "--help" to see full manual page.
Here is also my configuration:
# catoken.properties
defaultKey defaultRoot
testKey test
keyEncryptKey cryptRoot
hardTokenEncrypt cryptRoot
pin dummy
slotLabelType SLOT_INDEX
slotLabelValue 1
sharedLibrary /opt/nfast/toolkits/pkcs11/libcknfast.so
# install.properties
# ------------ Administrative CA configuration ---------------------
ca.name=ManagementCA
ca.dn=CN=ManagementCA,O=EJBCA Sample,C=SE
ca.tokentype=org.cesecore.keys.token.PKCS11CryptoToken
ca.tokenpassword=null
ca.tokenproperties=/home/damian/ejbca/newHsm/ejbca_ce_6_2_0/conf/catoken.properties
ca.keyspec=2048
ca.keytype=RSA
ca.signaturealgorithm=SHA1WithRSA
ca.validity=3650
ca.policy=null
Did you change something in catoken.properties???
Cheers from Germany
Damian
Am 23.03.2015 um 11:36 schrieb Anh Pham Van The (FIS FPS HN):
> Dear all,
> I installing EJBCA version 6.2.0 use CA key created into AEP HSM
> Enterprise.
> I run "ant bootstrap" is successful but when I run "ant install" then
> have an error.
> Can you check and get me a recommend?
> Please check attach file for more information include: error screen
> shot, catoken.properties file.
>
> Thank you,
> Mr. Anh
> From Hanoi, Vietnam.
>
>
> ------------------------------------------------------------------------------
> Dive into the World of Parallel Programming The Go Parallel Website, sponsored
> by Intel and developed in partnership with Slashdot Media, is your hub for all
> things parallel software development, from weekly thought leadership blogs to
> news, videos, case studies, tutorials and more. Take a look and join the
> conversation now. http://goparallel.sourceforge.net/
>
>
> _______________________________________________
> Ejbca-develop mailing list
> Ejb...@li...
> https://lists.sourceforge.net/lists/listinfo/ejbca-develop
|
|
From: Tomas G. <to...@pr...> - 2015-04-07 14:24:42
|
I have no problem selecting "unspecified" as revocation reason, from the list of revocation reasons. What do you see? Which screen in the admin GUI? "Cessation of operation" or "Superseded" sounds like a suitable reason for test certificates. Cheers, Tomas ----- Save time and money with an Enterprise support subscription. Please see www.primekey.se for more information. http://www.primekey.se/Products/EJBCA+PKI/ http://www.primekey.se/Services/Support/ On 2015-04-07 15:07, Michael Postmann wrote: > Hi! > > According to RFC 5280 (p. 69) „CRL issuers are strongly > > encouraged to include meaningful reason codes in CRL entries; > > however, the reason code CRL entry extension SHOULD be absent instead > > of using the unspecified (0) reasonCode value.” > > However when I want to revoke a certificate on the web interface it’s > not possible to select no reason. > > Is this intentionally left out or is there another way to achieve this? > > Besides that, what I actually want to do is to revoke some certificates > I issued for testing the PKI. What’s the most appropriate reason for that? > > regards > > nomike > > -- > > *Michael Postmann* > > Application Engineer > > paysafecard.com <http://paysafecard.com/>Wertkarten GmbH > Am Euro Platz 2, A-1120 Wien > > phone: +43 1 / 720 83 80 – 649 > fax: +43 1 / 720 83 80 – 12 > > mobile: +43 676 / 765 77 31 > > skype: nomike31 > mail: m.p...@pa... <mailto:m.p...@pa...> > > web: www.paysafecard.com <http://www.paysafecard.com/> > > Firmenbuch: FN 194434h > Handelsgericht Wien > > > > ------------------------------------------------------------------------------ > BPM Camp - Free Virtual Workshop May 6th at 10am PDT/1PM EDT > Develop your own process in accordance with the BPMN 2 standard > Learn Process modeling best practices with Bonita BPM through live exercises > http://www.bonitasoft.com/be-part-of-it/events/bpm-camp-virtual- event?utm_ > source=Sourceforge_BPM_Camp_5_6_15&utm_medium=email&utm_campaign=VA_SF > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Michael P. <M.P...@pa...> - 2015-04-07 13:07:40
|
Hi! According to RFC 5280 (p. 69) "CRL issuers are strongly encouraged to include meaningful reason codes in CRL entries; however, the reason code CRL entry extension SHOULD be absent instead of using the unspecified (0) reasonCode value." However when I want to revoke a certificate on the web interface it's not possible to select no reason. Is this intentionally left out or is there another way to achieve this? Besides that, what I actually want to do is to revoke some certificates I issued for testing the PKI. What's the most appropriate reason for that? regards nomike -- Michael Postmann Application Engineer paysafecard.com<http://paysafecard.com/> Wertkarten GmbH Am Euro Platz 2, A-1120 Wien phone: +43 1 / 720 83 80 - 649 fax: +43 1 / 720 83 80 - 12 mobile: +43 676 / 765 77 31 skype: nomike31 mail: m.p...@pa...<mailto:m.p...@pa...> web: www.paysafecard.com<http://www.paysafecard.com/> Firmenbuch: FN 194434h Handelsgericht Wien |
|
From: Tomas G. <to...@pr...> - 2015-04-06 12:39:24
|
Hi, It's MariaDB. Regards, Tomas On 2015-04-06 10:11, Wei Shan wrote: > Hi Tomas, > > Possible the share the database running internally in the appliance? > > Thanks! > > On 5 April 2015 at 21:35, Tomas Gustavsson <to...@pr... > <mailto:to...@pr...>> wrote: > > > There is a new EJBCA blog post up, describing EJBCA High Availability in > PrimeKey PKI Appliance. > > http://blog.ejbca.org/2015/04/high-availability-for-pki-in-8-simple.html > > Regards, > Tomas > > ------------------------------------------------------------------------------ > Dive into the World of Parallel Programming The Go Parallel Website, > sponsored > by Intel and developed in partnership with Slashdot Media, is your > hub for all > things parallel software development, from weekly thought leadership > blogs to > news, videos, case studies, tutorials and more. Take a look and join the > conversation now. http://goparallel.sourceforge.net/ > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > <mailto:Ejb...@li...> > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > > -- > Regards, > Ang Wei Shan > > > ------------------------------------------------------------------------------ > BPM Camp - Free Virtual Workshop May 6th at 10am PDT/1PM EDT > Develop your own process in accordance with the BPMN 2 standard > Learn Process modeling best practices with Bonita BPM through live exercises > http://www.bonitasoft.com/be-part-of-it/events/bpm-camp-virtual- event?utm_ > source=Sourceforge_BPM_Camp_5_6_15&utm_medium=email&utm_campaign=VA_SF > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Wei S. <wei...@gm...> - 2015-04-06 08:11:20
|
Hi Tomas, Possible the share the database running internally in the appliance? Thanks! On 5 April 2015 at 21:35, Tomas Gustavsson <to...@pr...> wrote: > > There is a new EJBCA blog post up, describing EJBCA High Availability in > PrimeKey PKI Appliance. > > http://blog.ejbca.org/2015/04/high-availability-for-pki-in-8-simple.html > > Regards, > Tomas > > > ------------------------------------------------------------------------------ > Dive into the World of Parallel Programming The Go Parallel Website, > sponsored > by Intel and developed in partnership with Slashdot Media, is your hub for > all > things parallel software development, from weekly thought leadership blogs > to > news, videos, case studies, tutorials and more. Take a look and join the > conversation now. http://goparallel.sourceforge.net/ > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > -- Regards, Ang Wei Shan |
|
From: Tomas G. <to...@pr...> - 2015-04-05 13:35:30
|
There is a new EJBCA blog post up, describing EJBCA High Availability in PrimeKey PKI Appliance. http://blog.ejbca.org/2015/04/high-availability-for-pki-in-8-simple.html Regards, Tomas |
|
From: Tomas G. <to...@pr...> - 2015-04-05 13:16:48
|
As long as the database behaves like a good Postgres, EJBCA should work with it. The most common HA database used in production is MariaDB-Glaera, Oracle and DB2. Cheers, Tomas --- Save time and money with an Enterprise support subscription. Please see www.primekey.se for more information. http://www.primekey.se/Products/EJBCA+PKI/ http://www.primekey.se/Services/Support/ On 2015-04-05 08:24, Wei Shan wrote: > Hi all, > > I have been googling quite a bit on this but I still can't manage to > find any answers on this. Does EJBCA supports multi-master replication > for PostgreSQL like PostgreSQL-XC or Burcado? > > What is the common HA architecture deployed in production? > > Thanks! > > -- > Regards, > Ang Wei Shan > > > ------------------------------------------------------------------------------ > Dive into the World of Parallel Programming The Go Parallel Website, sponsored > by Intel and developed in partnership with Slashdot Media, is your hub for all > things parallel software development, from weekly thought leadership blogs to > news, videos, case studies, tutorials and more. Take a look and join the > conversation now. http://goparallel.sourceforge.net/ > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Wei S. <wei...@gm...> - 2015-04-05 06:24:41
|
Hi all, I have been googling quite a bit on this but I still can't manage to find any answers on this. Does EJBCA supports multi-master replication for PostgreSQL like PostgreSQL-XC or Burcado? What is the common HA architecture deployed in production? Thanks! -- Regards, Ang Wei Shan |
|
From: Anthony A. <asc...@gm...> - 2015-03-26 14:59:14
|
Buidling in ejbca rev 21021:
ant clean
ant build
BUILD FAILED
/opt/ejbca/ejbca/build.xml:1057: The following error occurred while
executing this line:
/opt/ejbca/ejbca/modules/build.xml:437: The following error occurred
while executing this line:
/opt/ejbca/ejbca/modules/ejbca-scep-war/build.xml:42: Compile failed;
see the compiler error output for details.
compile:
[mkdir] Created dir:
/opt/ejbca/ejbca/modules/ejbca-scep-war/build/WEB-INF/classes
[javac] Compiling 3 source files to
/opt/ejbca/ejbca/modules/ejbca-scep-war/build/WEB-INF/classes
[javac] /opt/ejbca/ejbca/modules/ejbca-scep-war/src/org/ejbca/ui/web/protocol/ScepServlet.ja$
a:137: error: cannot find symbol
[javac] private transient ClientCertificateRenewalExtension
scepClientCertificateRenewal
= null;
[javac] ^
[javac] symbol: class ClientCertificateRenewalExtension
[javac] location: class ScepServlet
[javac] /opt/ejbca/ejbca/modules/ejbca-scep-war/src/org/ejbca/ui/web/protocol/ScepServlet.ja$
a:157: error: cannot find symbol
[javac] Class<ClientCertificateRenewalExtension>
extensionClass = (Class<ClientC$
rtificateRenewalExtension>)
Class.forName(SCEP_CLIENT_CERTIFICATE_RENEWAL_CLASSNAME);
[javac] ^
[javac] symbol: class ClientCertificateRenewalExtension
[javac] location: class ScepServlet
[javac] /opt/ejbca/ejbca/modules/ejbca-scep-war/src/org/ejbca/ui/web/protocol/ScepServlet.ja$
a:157: error: cannot find symbol
[javac] Class<ClientCertificateRenewalExtension>
extensionClass = (Class<ClientC$
rtificateRenewalExtension>)
Class.forName(SCEP_CLIENT_CERTIFICATE_RENEWAL_CLASSNAME);
[javac]
^
[javac] symbol: class ClientCertificateRenewalExtension
[javac] location: class ScepServlet
[javac] 3 errors
|
|
From: Anh P. V. T. (F. F. HN) <an...@FP...> - 2015-03-23 10:54:25
|
Dear all, I installing EJBCA version 6.2.0 use CA key created into AEP HSM Enterprise. I run "ant bootstrap" is successful but when I run "ant install" then have an error. Can you check and get me a recommend? Please check attach file for more information include: error screen shot, catoken.properties file. Thank you, Mr. Anh >From Hanoi, Vietnam. |
|
From: Eduardo M. <emt...@ya...> - 2015-03-21 11:43:22
|
Hi, I'm tring to include my own OID's in subject alternative name . I change the profilemappings.properties with:ALTNAME;TIPOCERTIFICADOINDENTIFIER;201;TIPOCERTIFICADOINDENTIFIER;201;Tipo certificado;TIPOCERTIFICADOINDENTIFIER TIPOCERTIFICADOINDENTIFIER contains my own OID like 2.16.724.1.3.5.3.2.10 for example. When I configure my end entity profile it appears in the item list of Subject Alternative Names. I get a final entity instance with this field complete with real content, but in my certificate instance this new field doesn't appear. The subject alternative name contains all fields that I included but no new OID. Is this correct way to include custom OID in Subject Alternative Name field? Is necessary to modify any java file to include this new OID in the entity certificate? Which java file? I'm using EJBCA 6.2.0 release. Thanks in advance Regards Eduardo |
|
From: Andreas K. <ku...@tr...> - 2015-03-19 14:04:17
|
Hi Tomas, > For Token management we have worked with companies like SecureMetric, > AET, Aventra and SecMaker, as well as other big companies for things > like ePassport/eID, but I'm assuming you are looking for something > smaller... > > Quite common as well is integration with Access Mgmt solutions like > OpenAM, where you do user mgmt there, integrating with EJBCA in the > background. Or with MDM software like MobileIron, Cisco ISE, ... > > As well there are of course many customer specific developments, where > companies have their own RA integrating with EJBCA through WebService or > CMP. > > You can do almost anything :-), you "just" have to know your use case. thanks for your wrap up of solutions in place! My current use case is 'flexibility' ;-) I'm looking for a solution in front of ejbca implementing a whole bunch of different RA processes. Think of a service CA plugged into different certificate requesting scenarios, spanning from requests triggered by an assembly line where a unit's serial needs to be checked against an inventory db. And a manual request and complex conformation process on the other end. The system outlined in Johan's thesis fits very well .. but if there isn't any solution like this available I'll have to think about implementing it ;-) Greetings, Andreas -- Andreas Kühne phone: +49 177 293 24 97 mailto: ku...@tr... Trustable Ltd. Niederlassung Deutschland Ströverstr. 18 - 59427 Unna Amtsgericht Hamm HRB 5868 Directors Andreas Kühne, Heiko Veit Company UK Company No: 5218868 Registered in England and Wales |
|
From: Tomas G. <to...@pr...> - 2015-03-19 13:38:23
|
For Token management we have worked with companies like SecureMetric, AET, Aventra and SecMaker, as well as other big companies for things like ePassport/eID, but I'm assuming you are looking for something smaller... Quite common as well is integration with Access Mgmt solutions like OpenAM, where you do user mgmt there, integrating with EJBCA in the background. Or with MDM software like MobileIron, Cisco ISE, ... As well there are of course many customer specific developments, where companies have their own RA integrating with EJBCA through WebService or CMP. You can do almost anything :-), you "just" have to know your use case. Cheers, Tomas On 2015-03-18 15:31, Andreas Kuehne wrote: > Hi Tomas, >> Nice that you found Johans thesis :-) > brave work! Relevant information on difficult topics! >> There are several card management systems out there that implement >> work-flow like configuration of the RA component. But I do not know of >> anything open source available. > And apart from Open Source? Does primekey recommend a workflow solution? > > Greetings, > > Andreas > > > ------------------------------------------------------------------------------ > Dive into the World of Parallel Programming The Go Parallel Website, sponsored > by Intel and developed in partnership with Slashdot Media, is your hub for all > things parallel software development, from weekly thought leadership blogs to > news, videos, case studies, tutorials and more. Take a look and join the > conversation now. http://goparallel.sourceforge.net/ > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Andreas K. <ku...@tr...> - 2015-03-18 14:31:52
|
Hi Tomas, > Nice that you found Johans thesis :-) brave work! Relevant information on difficult topics! > There are several card management systems out there that implement > work-flow like configuration of the RA component. But I do not know of > anything open source available. And apart from Open Source? Does primekey recommend a workflow solution? Greetings, Andreas |
|
From: Tomas G. <to...@pr...> - 2015-03-18 08:41:36
|
Hi Andreas, Nice that you found Johans thesis :-) There are several card management systems out there that implement work-flow like configuration of the RA component. But I do not know of anything open source available. Regards, Tomas On 2015-03-17 12:07, Andreas Kuehne wrote: > Hi Folks, > > I'm looking for a flexible workflow engine for flexible definition and > easy integration of the RA part. There once was this paper from Johan > Eklund > (http://www.nada.kth.se/utbildning/grukth/exjobb/rapportlistor/2010/rapporter10/eklund_johan_10047.pdf) > . Is something 'workflow engine alike' available? > > Greetings, > > Andreas > |
|
From: Andreas K. <ku...@tr...> - 2015-03-17 11:23:08
|
Hi Folks, I'm looking for a flexible workflow engine for flexible definition and easy integration of the RA part. There once was this paper from Johan Eklund (http://www.nada.kth.se/utbildning/grukth/exjobb/rapportlistor/2010/rapporter10/eklund_johan_10047.pdf) . Is something 'workflow engine alike' available? Greetings, Andreas -- Andreas Kühne phone: +49 177 293 24 97 mailto: ku...@tr... Trustable Ltd. Niederlassung Deutschland Ströverstr. 18 - 59427 Unna Amtsgericht Hamm HRB 5868 Directors Andreas Kühne, Heiko Veit Company UK Company No: 5218868 Registered in England and Wales |
|
From: Tomas G. <to...@pr...> - 2015-03-16 08:50:48
|
Hi, Yes you can do it. Take a look at the "override" settings in certificate profiles, and CA configuration. Should be some documentation links in there as well. Cheers, Tomas ----- Save time and money with an Enterprise support subscription. Please see www.primekey.se for more information. http://www.primekey.se/Products/EJBCA+PKI/ http://www.primekey.se/Services/Support/ On 2015-03-13 18:53, William Roberts wrote: > EJBCA folks, > > I am new to the world of CA's, so bear with me please. > > Current Problem: > Microsoft CA has 4 registry keys that can be set to templates. Thus when > a CSR comes in, one of 4 possible templates is used. This level of > granularity does not suit me. Thus I am interested in using EJBCA for > this solution. > See: > http://social.technet.microsoft.com/wiki/contents/articles/9063.network-device-enrollment-service-ndes-in-active-directory-certificate-services-ad-cs.aspx > > What I need to do: > Via some remote interface, like SCEP but doesn't have to be, upload a > CSR and have all the fields honored. For instance, a snippet of my CSR: > > --- snippet from CSR dump with openssl --- > Requested Extensions: > X509v3 Key Usage: critical > Digital Signature > X509v3 Extended Key Usage: > TLS Web Client Authentication, scardLogin, Any Extended > Key Usage > X509v3 Certificate Policies: > Policy: 2.16.840.1.101.3.2.1.3.13 > > Is their a way to configure EJBCA for this support, and any doc links > are much appreciated. Thank you. > > > -- > Respectfully, > > William C Roberts > > > > ------------------------------------------------------------------------------ > Dive into the World of Parallel Programming The Go Parallel Website, sponsored > by Intel and developed in partnership with Slashdot Media, is your hub for all > things parallel software development, from weekly thought leadership blogs to > news, videos, case studies, tutorials and more. Take a look and join the > conversation now. http://goparallel.sourceforge.net/ > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: William R. <bil...@gm...> - 2015-03-13 17:53:19
|
EJBCA folks, I am new to the world of CA's, so bear with me please. Current Problem: Microsoft CA has 4 registry keys that can be set to templates. Thus when a CSR comes in, one of 4 possible templates is used. This level of granularity does not suit me. Thus I am interested in using EJBCA for this solution. See: http://social.technet.microsoft.com/wiki/contents/articles/9063.network-device-enrollment-service-ndes-in-active-directory-certificate-services-ad-cs.aspx What I need to do: Via some remote interface, like SCEP but doesn't have to be, upload a CSR and have all the fields honored. For instance, a snippet of my CSR: --- snippet from CSR dump with openssl --- Requested Extensions: X509v3 Key Usage: critical Digital Signature X509v3 Extended Key Usage: TLS Web Client Authentication, scardLogin, Any Extended Key Usage X509v3 Certificate Policies: Policy: 2.16.840.1.101.3.2.1.3.13 Is their a way to configure EJBCA for this support, and any doc links are much appreciated. Thank you. -- Respectfully, William C Roberts |
|
From: Tomas G. <to...@pr...> - 2015-03-11 16:59:10
|
Hi currently it is not possible to do this through the CLI. Internal APIs have the possibility of course, but it is not included in the CLI commands. Cheers, Tomas PS: PrimeKey has some Enterprise tools to do this, but it's not available freely. On 2015-03-11 16:05, Tomasz Rakowski wrote: > Hi, > > Is there a way to create Publishers from cli ? > > I'm trying to automate ejbca installation process in our environment > and would love to instantiate few publishers along the way. > > Regards > > > ------------------------------------------------------------------------------ > Dive into the World of Parallel Programming The Go Parallel Website, sponsored > by Intel and developed in partnership with Slashdot Media, is your hub for all > things parallel software development, from weekly thought leadership blogs to > news, videos, case studies, tutorials and more. Take a look and join the > conversation now. http://goparallel.sourceforge.net/ > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |