You can subscribe to this list here.
| 2001 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
(1) |
Dec
(3) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2002 |
Jan
(3) |
Feb
(2) |
Mar
(8) |
Apr
(3) |
May
(6) |
Jun
(1) |
Jul
(15) |
Aug
(6) |
Sep
|
Oct
(10) |
Nov
(2) |
Dec
(4) |
| 2003 |
Jan
(1) |
Feb
(7) |
Mar
(3) |
Apr
(6) |
May
(7) |
Jun
(5) |
Jul
(5) |
Aug
(25) |
Sep
(14) |
Oct
(2) |
Nov
|
Dec
(2) |
| 2004 |
Jan
(7) |
Feb
(4) |
Mar
(12) |
Apr
(16) |
May
(43) |
Jun
(56) |
Jul
(43) |
Aug
(40) |
Sep
(66) |
Oct
(12) |
Nov
(26) |
Dec
(10) |
| 2005 |
Jan
(13) |
Feb
(33) |
Mar
(16) |
Apr
(7) |
May
(10) |
Jun
(34) |
Jul
(41) |
Aug
(8) |
Sep
(4) |
Oct
(32) |
Nov
(20) |
Dec
(25) |
| 2006 |
Jan
(30) |
Feb
(101) |
Mar
(5) |
Apr
(75) |
May
(74) |
Jun
(22) |
Jul
(6) |
Aug
(70) |
Sep
(19) |
Oct
(21) |
Nov
(31) |
Dec
(50) |
| 2007 |
Jan
(15) |
Feb
(20) |
Mar
(24) |
Apr
(33) |
May
(13) |
Jun
(18) |
Jul
(13) |
Aug
(7) |
Sep
(63) |
Oct
(68) |
Nov
(29) |
Dec
(68) |
| 2008 |
Jan
(30) |
Feb
(33) |
Mar
(30) |
Apr
(103) |
May
(78) |
Jun
(48) |
Jul
(72) |
Aug
(24) |
Sep
(62) |
Oct
(63) |
Nov
(70) |
Dec
(37) |
| 2009 |
Jan
(34) |
Feb
(35) |
Mar
(64) |
Apr
(34) |
May
(34) |
Jun
(58) |
Jul
(30) |
Aug
(30) |
Sep
(46) |
Oct
(52) |
Nov
(12) |
Dec
(23) |
| 2010 |
Jan
(121) |
Feb
(18) |
Mar
(53) |
Apr
(62) |
May
(62) |
Jun
(20) |
Jul
(33) |
Aug
(20) |
Sep
(36) |
Oct
(35) |
Nov
(44) |
Dec
(63) |
| 2011 |
Jan
(19) |
Feb
(32) |
Mar
(94) |
Apr
(41) |
May
(47) |
Jun
(25) |
Jul
(34) |
Aug
(20) |
Sep
(9) |
Oct
(41) |
Nov
(33) |
Dec
(24) |
| 2012 |
Jan
(12) |
Feb
(36) |
Mar
(48) |
Apr
(32) |
May
(20) |
Jun
(15) |
Jul
(32) |
Aug
(13) |
Sep
(33) |
Oct
(54) |
Nov
(25) |
Dec
(16) |
| 2013 |
Jan
(45) |
Feb
(39) |
Mar
(38) |
Apr
(50) |
May
(29) |
Jun
(30) |
Jul
(33) |
Aug
(12) |
Sep
(9) |
Oct
(25) |
Nov
(29) |
Dec
(20) |
| 2014 |
Jan
(25) |
Feb
(19) |
Mar
(16) |
Apr
(33) |
May
(27) |
Jun
(37) |
Jul
(29) |
Aug
(27) |
Sep
(37) |
Oct
(58) |
Nov
(109) |
Dec
(26) |
| 2015 |
Jan
(4) |
Feb
(35) |
Mar
(22) |
Apr
(35) |
May
(28) |
Jun
(20) |
Jul
(4) |
Aug
(16) |
Sep
(37) |
Oct
(13) |
Nov
(13) |
Dec
(14) |
| 2016 |
Jan
(22) |
Feb
(7) |
Mar
(23) |
Apr
(30) |
May
(10) |
Jun
(10) |
Jul
(15) |
Aug
(12) |
Sep
(22) |
Oct
(31) |
Nov
(5) |
Dec
(5) |
| 2017 |
Jan
(30) |
Feb
(25) |
Mar
(28) |
Apr
(4) |
May
(19) |
Jun
(13) |
Jul
(7) |
Aug
(1) |
Sep
(2) |
Oct
(5) |
Nov
(12) |
Dec
(2) |
| 2018 |
Jan
(7) |
Feb
|
Mar
(7) |
Apr
(2) |
May
(8) |
Jun
(18) |
Jul
(6) |
Aug
(3) |
Sep
(15) |
Oct
(33) |
Nov
(13) |
Dec
(7) |
| 2019 |
Jan
(5) |
Feb
(7) |
Mar
(30) |
Apr
(5) |
May
(4) |
Jun
(69) |
Jul
(86) |
Aug
(22) |
Sep
(6) |
Oct
(7) |
Nov
(5) |
Dec
(3) |
| 2020 |
Jan
(10) |
Feb
(12) |
Mar
(22) |
Apr
(5) |
May
(1) |
Jun
(4) |
Jul
(6) |
Aug
|
Sep
(9) |
Oct
|
Nov
|
Dec
(1) |
| 2021 |
Jan
(4) |
Feb
(11) |
Mar
(7) |
Apr
(7) |
May
|
Jun
(3) |
Jul
(10) |
Aug
(6) |
Sep
|
Oct
|
Nov
(18) |
Dec
(2) |
| 2022 |
Jan
(1) |
Feb
(1) |
Mar
|
Apr
|
May
|
Jun
(2) |
Jul
|
Aug
(4) |
Sep
|
Oct
|
Nov
|
Dec
|
| 2023 |
Jan
|
Feb
|
Mar
|
Apr
(1) |
May
(1) |
Jun
|
Jul
|
Aug
(5) |
Sep
|
Oct
|
Nov
|
Dec
|
|
From: Tomas G. <to...@pr...> - 2014-12-22 10:23:57
|
Hi,
Thanks, which version of EJBCA did you make the patch against? 6.2.0?
Regards,
Tomas
On 2014-12-22 10:10, fra...@in... wrote:
> Hi all,
>
> I did modification to string to X500Name conversion for DN creation.
> My patch rewrite stringToBcX500Name and supports MultiRDN features in order
> to complains National rules in DN generation.
> It can generate DN using + syntax for MultiRDN and maintains ordering
> features. Additional + chars in DN names can be written using
> the standard \+ syntax. Current ordering feature take account for the first
> attribute in MultiRDN attribute.
> MultiRDN content respects RFC ASN1 SET ordering rules.
> Attached a modified version of CertTools.java for MultiRDN.
>
> For example
> "DN=200590 + givenName=Enrico Maria + serialNumber=IT:MEZCAL86T16H523D +
> surname=Ciaffi,O=Test1,C=IT,O=Test
>
> Results in
> "SURNAME=Ciaffi+DN=200590+GIVENNAME=Enrico
> Maria+SN=IT:MEZCAL86T16H523D,O=Test1,O=Test,C=IT"
>
> 0 30 125: SEQUENCE {
> 2 31 11: SET {
> 4 30 9: SEQUENCE {
> 6 06 3: OBJECT IDENTIFIER countryName (2 5 4 6)
> 11 13 2: PrintableString 'IT'
> : }
> : }
> 15 31 13: SET {
> 17 30 11: SEQUENCE {
> 19 06 3: OBJECT IDENTIFIER organizationName (2 5 4 10)
> 24 0C 4: UTF8String 'Test'
> : }
> : }
> 30 31 14: SET {
> 32 30 12: SEQUENCE {
> 34 06 3: OBJECT IDENTIFIER organizationName (2 5 4 10)
> 39 0C 5: UTF8String 'Test1'
> : }
> : }
> 46 31 79: SET {
> 48 30 13: SEQUENCE {
> 50 06 3: OBJECT IDENTIFIER surname (2 5 4 4)
> 55 0C 6: UTF8String 'Ciaffi'
> : }
> 63 30 13: SEQUENCE {
> 65 06 3: OBJECT IDENTIFIER dnQualifier (2 5 4 46)
> 70 13 6: PrintableString '200590'
> : }
> 78 30 19: SEQUENCE {
> 80 06 3: OBJECT IDENTIFIER givenName (2 5 4 42)
> 85 0C 12: UTF8String 'Enrico Maria'
> : }
> 99 30 26: SEQUENCE {
> 101 06 3: OBJECT IDENTIFIER serialNumber (2 5 4 5)
> 106 13 19: PrintableString 'IT:MEZCAL86T16H523D'
> : }
> : }
> : }
>
> I hope this contribution can be added to EjbCA for missing MultiRDN feature.
> I test this patch in Italian Qualified Certification Authorities and CNS
> certificate generation.
>
> Regards,
>
> Francesco Petruzzi
> Innovery S.p.A.
> fra...@in...
>
>
> ---
> Questa e-mail è stata controllata per individuare virus con Avast antivirus.
> http://www.avast.com
>
>
>
> ------------------------------------------------------------------------------
> Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT Server
> from Actuate! Instantly Supercharge Your Business Reports and Dashboards
> with Interactivity, Sharing, Native Excel Exports, App Integration & more
> Get technology previously reserved for billion-dollar corporations, FREE
> http://pubads.g.doubleclick.net/gampad/clk?id=164703151&iu=/4140/ostg.clktrk
>
>
>
> _______________________________________________
> Ejbca-develop mailing list
> Ejb...@li...
> https://lists.sourceforge.net/lists/listinfo/ejbca-develop
>
|
|
From: <fra...@in...> - 2014-12-22 10:04:54
|
Hi all,
I did modification to string to X500Name conversion for DN creation.
My patch rewrite stringToBcX500Name and supports MultiRDN features in order
to complains National rules in DN generation.
It can generate DN using + syntax for MultiRDN and maintains ordering
features. Additional + chars in DN names can be written using
the standard \+ syntax. Current ordering feature take account for the first
attribute in MultiRDN attribute.
MultiRDN content respects RFC ASN1 SET ordering rules.
Attached a modified version of CertTools.java for MultiRDN.
For example
"DN=200590 + givenName=Enrico Maria + serialNumber=IT:MEZCAL86T16H523D +
surname=Ciaffi,O=Test1,C=IT,O=Test
Results in
"SURNAME=Ciaffi+DN=200590+GIVENNAME=Enrico
Maria+SN=IT:MEZCAL86T16H523D,O=Test1,O=Test,C=IT"
0 30 125: SEQUENCE {
2 31 11: SET {
4 30 9: SEQUENCE {
6 06 3: OBJECT IDENTIFIER countryName (2 5 4 6)
11 13 2: PrintableString 'IT'
: }
: }
15 31 13: SET {
17 30 11: SEQUENCE {
19 06 3: OBJECT IDENTIFIER organizationName (2 5 4 10)
24 0C 4: UTF8String 'Test'
: }
: }
30 31 14: SET {
32 30 12: SEQUENCE {
34 06 3: OBJECT IDENTIFIER organizationName (2 5 4 10)
39 0C 5: UTF8String 'Test1'
: }
: }
46 31 79: SET {
48 30 13: SEQUENCE {
50 06 3: OBJECT IDENTIFIER surname (2 5 4 4)
55 0C 6: UTF8String 'Ciaffi'
: }
63 30 13: SEQUENCE {
65 06 3: OBJECT IDENTIFIER dnQualifier (2 5 4 46)
70 13 6: PrintableString '200590'
: }
78 30 19: SEQUENCE {
80 06 3: OBJECT IDENTIFIER givenName (2 5 4 42)
85 0C 12: UTF8String 'Enrico Maria'
: }
99 30 26: SEQUENCE {
101 06 3: OBJECT IDENTIFIER serialNumber (2 5 4 5)
106 13 19: PrintableString 'IT:MEZCAL86T16H523D'
: }
: }
: }
I hope this contribution can be added to EjbCA for missing MultiRDN feature.
I test this patch in Italian Qualified Certification Authorities and CNS
certificate generation.
Regards,
Francesco Petruzzi
Innovery S.p.A.
fra...@in...
---
Questa e-mail è stata controllata per individuare virus con Avast antivirus.
http://www.avast.com
|
|
From: Тимур <tim...@gm...> - 2014-12-18 14:27:52
|
Thank you a lot, Michael. All is clear. 2014-12-18 20:17 GMT+06:00 Michael Ströder <mi...@st...>: > > Тимур wrote: > > Could you please to gve me a reference how to set up CRL automatic update > > service > > in EJBCA 6.2.0 ? > > http://www.ejbca.org/docs/adminguide.html#CRL%20generation > > Ciao, Michael. > > > > ------------------------------------------------------------------------------ > Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT Server > from Actuate! Instantly Supercharge Your Business Reports and Dashboards > with Interactivity, Sharing, Native Excel Exports, App Integration & more > Get technology previously reserved for billion-dollar corporations, FREE > > http://pubads.g.doubleclick.net/gampad/clk?id=164703151&iu=/4140/ostg.clktrk > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > |
|
From: Michael S. <mi...@st...> - 2014-12-18 14:17:34
|
Тимур wrote: > Could you please to gve me a reference how to set up CRL automatic update > service > in EJBCA 6.2.0 ? http://www.ejbca.org/docs/adminguide.html#CRL%20generation Ciao, Michael. |
|
From: Тимур <tim...@gm...> - 2014-12-18 13:55:41
|
Thanks to all who found a minute to answer me ! Yes , I fixed :) CRL status manually. Could you please to gve me a reference how to set up CRL automatic update service in EJBCA 6.2.0 ? Thank you a lot, Timur 2014-12-18 19:10 GMT+06:00 Michael Ströder <mi...@st...>: > > Тимур wrote: > > I have successfully installed and configured EJBCA 6.2.0 (r19221) based > on > > RHEL 5.7 / Java 7u45 / Oracle 10g R2 and all works fine, no errors. > > Then two new users' CAs named "testca.bta.kz" and "Default CA" were > created > > (also without errors) - all work fine. Only question is why in > > certificate authorities home page some CAs have their CRL status marked > by > > yellow warning triangle "CRL status: Expired" ? How to fix CRL ? > > Could you please to see attached screenshots and config of my EJBCA > > instance ? > > You probably did not set up a CRLUpdate service for those CAs yet. > > Ciao, Michael. > > > > ------------------------------------------------------------------------------ > Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT Server > from Actuate! Instantly Supercharge Your Business Reports and Dashboards > with Interactivity, Sharing, Native Excel Exports, App Integration & more > Get technology previously reserved for billion-dollar corporations, FREE > > http://pubads.g.doubleclick.net/gampad/clk?id=164703151&iu=/4140/ostg.clktrk > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > |
|
From: Pavel B. <byc...@ht...> - 2014-12-18 13:24:24
|
Hi Timur, You can update CRL manually or set up CRL Updater service in services Best regards, Pavel On 18.12.2014 15:02, Тимур wrote: > Hello, dears ! > > I have successfully installed and configured EJBCA 6.2.0 (r19221) > based on RHEL 5.7 / Java 7u45 / Oracle 10g R2 and all works fine, no > errors. > Then two new users' CAs named "testca.bta.kz <http://testca.bta.kz>" > and "Default CA" were created (also without errors) - all work fine. > Only question is why in certificate authorities home page some CAs > have their CRL status marked by yellow warning triangle "CRL status: > Expired" ? How to fix CRL ? > Could you please to see attached screenshots and config of my EJBCA > instance ? > > Thank you a lot, > Timur > > > ------------------------------------------------------------------------------ > Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT Server > from Actuate! Instantly Supercharge Your Business Reports and Dashboards > with Interactivity, Sharing, Native Excel Exports, App Integration & more > Get technology previously reserved for billion-dollar corporations, FREE > http://pubads.g.doubleclick.net/gampad/clk?id=164703151&iu=/4140/ostg.clktrk > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Michael S. <mi...@st...> - 2014-12-18 13:23:33
|
Тимур wrote: > I have successfully installed and configured EJBCA 6.2.0 (r19221) based on > RHEL 5.7 / Java 7u45 / Oracle 10g R2 and all works fine, no errors. > Then two new users' CAs named "testca.bta.kz" and "Default CA" were created > (also without errors) - all work fine. Only question is why in > certificate authorities home page some CAs have their CRL status marked by > yellow warning triangle "CRL status: Expired" ? How to fix CRL ? > Could you please to see attached screenshots and config of my EJBCA > instance ? You probably did not set up a CRLUpdate service for those CAs yet. Ciao, Michael. |
|
From: Manuel D. <ma...@de...> - 2014-12-18 13:19:28
|
Hej Timur, according to the "CRL Expire Period" configured in your CA (default 1 day) the CRL (Certificate Revokation List) expires after one day, even if there is no change to the CA / no certificate is revoked. You can "fix" this by clicking "Create CRL" for that CA in "CA Structure & CRLs". does that answer your question ? best regards, Manuel On Thu, Dec 18, 2014 at 2:02 PM, Тимур <tim...@gm...> wrote: > Hello, dears ! > > I have successfully installed and configured EJBCA 6.2.0 (r19221) based on > RHEL 5.7 / Java 7u45 / Oracle 10g R2 and all works fine, no errors. > Then two new users' CAs named "testca.bta.kz" and "Default CA" were created > (also without errors) - all work fine. Only question is why in certificate > authorities home page some CAs have their CRL status marked by yellow > warning triangle "CRL status: Expired" ? How to fix CRL ? > Could you please to see attached screenshots and config of my EJBCA instance > ? > > Thank you a lot, > Timur > > ------------------------------------------------------------------------------ > Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT Server > from Actuate! Instantly Supercharge Your Business Reports and Dashboards > with Interactivity, Sharing, Native Excel Exports, App Integration & more > Get technology previously reserved for billion-dollar corporations, FREE > http://pubads.g.doubleclick.net/gampad/clk?id=164703151&iu=/4140/ostg.clktrk > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Тимур <tim...@gm...> - 2014-12-18 13:02:54
|
Hello, dears ! I have successfully installed and configured EJBCA 6.2.0 (r19221) based on RHEL 5.7 / Java 7u45 / Oracle 10g R2 and all works fine, no errors. Then two new users' CAs named "testca.bta.kz" and "Default CA" were created (also without errors) - all work fine. Only question is why in certificate authorities home page some CAs have their CRL status marked by yellow warning triangle "CRL status: Expired" ? How to fix CRL ? Could you please to see attached screenshots and config of my EJBCA instance ? Thank you a lot, Timur |
|
From: Michael S. <mi...@st...> - 2014-12-09 16:36:02
|
Michael Postmann wrote: > I'm not sure in which format the key is: > ---SNIP--- > root@server /tmp # cat defaultKey.pem :( > -----BEGIN PUBLIC KEY----- > MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAjth4dOk72dVII56T/EJ0 > tmC11daQtJynfmrxcV0gDrxfd/6qTTlNY9jwcAo/C/q/5Cvon2nn7URILmDrlibv > BiHS0ScHtA4OEj6y7pXil7Go59aO8n/qgr7NCGSYIEUVDa+6bCACTOISsEgzO6/L > MUzNcSMHA4mI7DgQeffGBWrEsB9TlOHxBCnF3cqQ9aFGzp6Foewv4kk/iVff/eZm > xKUk4OMTWgQadIQC/fpj0VyKAeppwwogJahV3GP6CPiALVPbiOvfBxMr6Pem1Udw > NcNQSZ4ihgDDdIXbFXyqDjMoKQgF0D5PHUEOIfmZ08cgk9qULUK3OwBhgOwmCIPQ > GQIDAQAB > -----END PUBLIC KEY----- > root@server /tmp # openssl x509 -in defaultKey.pem -inform PEM -out defaultKey.crt -outform DER > unable to load certificate The BEGIN line indicates that this is a raw public key file and not a X.509 certificate. Ciao, Michael. |
|
From: Michael P. <M.P...@pa...> - 2014-12-09 16:05:21
|
I'm not sure in which format the key is: ---SNIP--- root@server /tmp # cat defaultKey.pem :( -----BEGIN PUBLIC KEY----- MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAjth4dOk72dVII56T/EJ0 tmC11daQtJynfmrxcV0gDrxfd/6qTTlNY9jwcAo/C/q/5Cvon2nn7URILmDrlibv BiHS0ScHtA4OEj6y7pXil7Go59aO8n/qgr7NCGSYIEUVDa+6bCACTOISsEgzO6/L MUzNcSMHA4mI7DgQeffGBWrEsB9TlOHxBCnF3cqQ9aFGzp6Foewv4kk/iVff/eZm xKUk4OMTWgQadIQC/fpj0VyKAeppwwogJahV3GP6CPiALVPbiOvfBxMr6Pem1Udw NcNQSZ4ihgDDdIXbFXyqDjMoKQgF0D5PHUEOIfmZ08cgk9qULUK3OwBhgOwmCIPQ GQIDAQAB -----END PUBLIC KEY----- root@server /tmp # openssl x509 -in defaultKey.pem -inform PEM -out defaultKey.crt -outform DER unable to load certificate 140050112972616:error:0906D06C:PEM routines:PEM_read_bio:no start line:pem_lib.c:703:Expecting: TRUSTED CERTIFICATE 1 root@server /tmp # openssl x509 -in defaultKey.pem -inform DER -out defaultKey.crt -outform DER :( unable to load certificate 139951552452424:error:0D0680A8:asn1 encoding routines:ASN1_CHECK_TLEN:wrong tag:tasn_dec.c:1319: 139951552452424:error:0D07803A:asn1 encoding routines:ASN1_ITEM_EX_D2I:nested asn1 error:tasn_dec.c:381:Type=X509 ---SNAP--- Any suggestions? cheers nomike -----Ursprüngliche Nachricht----- Von: Tomas Gustavsson [mailto:to...@pr...] Gesendet: Dienstag, 9. Dezember 2014 15:55 An: ejb...@li... Betreff: Re: [Ejbca-develop] Adding admin user certificates It's just that keytool needs the certificate in DER format, not PEM. There is also the command "ant javatruststore" in EJBCA. /Tomas On 2014-12-09 15:43, Michael Postmann wrote: > Thanks for the suggestion. > > However I'm not able to import the CA-Certificate into the truststore. > The SubCA was created in EJBCA. > > I opened the corresponding crypto token and downloaded the public key aliased "defaultKey" and got a file in ".pem" format. > I transferred this file back to the server and tried to import it using keytool, but only got an error message: > > ---SNIP--- > # keytool -import -trustcacerts -file /tmp/defaultKey.pem -keystore > p12/truststore.jks -storepass changeit -alias pkiadminuserca keytool > error: java.lang.Exception: Input not an X.509 certificate > ---SNAP--- > > I do not have to import the private key of the SubCA into the truststore, do I? > > cheers > nomike > > -----Ursprüngliche Nachricht----- > Von: Tomas Gustavsson [mailto:to...@pr...] > Gesendet: Dienstag, 9. Dezember 2014 14:45 > An: ejb...@li... > Betreff: Re: [Ejbca-develop] Adding admin user certificates > > You need to update the JBoss truststore to trust new CA certificates. > > http://ejbca.org/docs/userguide.html#Administrators%20issued%20by%20ex > ternal%20CAs > > Regards, > Tomas > ----- > Save time and money with an Enterprise support subscription. Please see www.primekey.se for more information. > http://www.primekey.se/Products/EJBCA+PKI/ > http://www.primekey.se/Services/Support/ > > On 2014-12-09 14:23, Michael Postmann wrote: >> Hi! >> >> I've created a new internal RootCA for our company and a SubCA for >> issuing SSL Client certificates for accessing the EJBCA admin panel >> which will be provided to the individual users. >> >> I've created one such test certificate and imported it into my local >> Firefox keystore. When I now try to access the EJBCA-Admin GUI, >> Firefox asks me which certificate I'd like to use. However it only >> offers the "SuperAmin" certificate and not the one I've just created. >> >> Does EJBCA somehow tell the Browser to only ask the user for a >> limited set of certificates (e.g. signed by a specific CA)? Is this configurable? >> >> cheers >> >> nomike >> >> >> >> --------------------------------------------------------------------- >> - >> -------- Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT >> Server from Actuate! Instantly Supercharge Your Business Reports and >> Dashboards with Interactivity, Sharing, Native Excel Exports, App >> Integration & more Get technology previously reserved for >> billion-dollar corporations, FREE >> http://pubads.g.doubleclick.net/gampad/clk?id=164703151&iu=/4140/ostg. >> clktrk >> >> >> >> _______________________________________________ >> Ejbca-develop mailing list >> Ejb...@li... >> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >> > > ---------------------------------------------------------------------- > -------- Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT > Server from Actuate! Instantly Supercharge Your Business Reports and > Dashboards with Interactivity, Sharing, Native Excel Exports, App > Integration & more Get technology previously reserved for > billion-dollar corporations, FREE > http://pubads.g.doubleclick.net/gampad/clk?id=164703151&iu=/4140/ostg. > clktrk _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > ---------------------------------------------------------------------- > -------- Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT > Server from Actuate! Instantly Supercharge Your Business Reports and > Dashboards with Interactivity, Sharing, Native Excel Exports, App > Integration & more Get technology previously reserved for > billion-dollar corporations, FREE > http://pubads.g.doubleclick.net/gampad/clk?id=164703151&iu=/4140/ostg. > clktrk _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > ------------------------------------------------------------------------------ Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT Server from Actuate! Instantly Supercharge Your Business Reports and Dashboards with Interactivity, Sharing, Native Excel Exports, App Integration & more Get technology previously reserved for billion-dollar corporations, FREE http://pubads.g.doubleclick.net/gampad/clk?id=164703151&iu=/4140/ostg.clktrk _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Tomas G. <to...@pr...> - 2014-12-09 14:54:48
|
It's just that keytool needs the certificate in DER format, not PEM. There is also the command "ant javatruststore" in EJBCA. /Tomas On 2014-12-09 15:43, Michael Postmann wrote: > Thanks for the suggestion. > > However I'm not able to import the CA-Certificate into the truststore. > The SubCA was created in EJBCA. > > I opened the corresponding crypto token and downloaded the public key aliased "defaultKey" and got a file in ".pem" format. > I transferred this file back to the server and tried to import it using keytool, but only got an error message: > > ---SNIP--- > # keytool -import -trustcacerts -file /tmp/defaultKey.pem -keystore p12/truststore.jks -storepass changeit -alias pkiadminuserca > keytool error: java.lang.Exception: Input not an X.509 certificate > ---SNAP--- > > I do not have to import the private key of the SubCA into the truststore, do I? > > cheers > nomike > > -----Ursprüngliche Nachricht----- > Von: Tomas Gustavsson [mailto:to...@pr...] > Gesendet: Dienstag, 9. Dezember 2014 14:45 > An: ejb...@li... > Betreff: Re: [Ejbca-develop] Adding admin user certificates > > You need to update the JBoss truststore to trust new CA certificates. > > http://ejbca.org/docs/userguide.html#Administrators%20issued%20by%20external%20CAs > > Regards, > Tomas > ----- > Save time and money with an Enterprise support subscription. Please see www.primekey.se for more information. > http://www.primekey.se/Products/EJBCA+PKI/ > http://www.primekey.se/Services/Support/ > > On 2014-12-09 14:23, Michael Postmann wrote: >> Hi! >> >> I've created a new internal RootCA for our company and a SubCA for >> issuing SSL Client certificates for accessing the EJBCA admin panel >> which will be provided to the individual users. >> >> I've created one such test certificate and imported it into my local >> Firefox keystore. When I now try to access the EJBCA-Admin GUI, >> Firefox asks me which certificate I'd like to use. However it only >> offers the "SuperAmin" certificate and not the one I've just created. >> >> Does EJBCA somehow tell the Browser to only ask the user for a limited >> set of certificates (e.g. signed by a specific CA)? Is this configurable? >> >> cheers >> >> nomike >> >> >> >> ---------------------------------------------------------------------- >> -------- Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT >> Server from Actuate! Instantly Supercharge Your Business Reports and >> Dashboards with Interactivity, Sharing, Native Excel Exports, App >> Integration & more Get technology previously reserved for >> billion-dollar corporations, FREE >> http://pubads.g.doubleclick.net/gampad/clk?id=164703151&iu=/4140/ostg. >> clktrk >> >> >> >> _______________________________________________ >> Ejbca-develop mailing list >> Ejb...@li... >> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >> > > ------------------------------------------------------------------------------ > Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT Server from Actuate! Instantly Supercharge Your Business Reports and Dashboards with Interactivity, Sharing, Native Excel Exports, App Integration & more Get technology previously reserved for billion-dollar corporations, FREE http://pubads.g.doubleclick.net/gampad/clk?id=164703151&iu=/4140/ostg.clktrk > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > ------------------------------------------------------------------------------ > Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT Server > from Actuate! Instantly Supercharge Your Business Reports and Dashboards > with Interactivity, Sharing, Native Excel Exports, App Integration & more > Get technology previously reserved for billion-dollar corporations, FREE > http://pubads.g.doubleclick.net/gampad/clk?id=164703151&iu=/4140/ostg.clktrk > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Michael S. <mi...@st...> - 2014-12-09 14:54:38
|
Michael Postmann wrote: > Thanks for the suggestion. > > However I'm not able to import the CA-Certificate into the truststore. > The SubCA was created in EJBCA. > > I opened the corresponding crypto token and downloaded the public key aliased "defaultKey" and got a file in ".pem" format. > I transferred this file back to the server and tried to import it using keytool, but only got an error message: > > ---SNIP--- > # keytool -import -trustcacerts -file /tmp/defaultKey.pem -keystore p12/truststore.jks -storepass changeit -alias pkiadminuserca > keytool error: java.lang.Exception: Input not an X.509 certificate > ---SNAP--- For the browser to present a client cert for selection by the user it has to build the full chain against one of the client cert trust anchors sent by the server. You can observe what the server sends as client cert CA trust anchors by running openssl s_client -connect server.example.com:8443 So you have to: 1. Make sure that truststore.jks contains the root CA needed to validate the client cert. 2. You browser knows the root CA needed to validate the client cert as trusted and knows the sub CA cert (imported without trust flags). > I do not have to import the private key of the SubCA into the truststore, > do I? truststore.jks should not contain private keys! And tomcat.jks just contains the server's private key. Ciao, Michael. |
|
From: Michael P. <M.P...@pa...> - 2014-12-09 14:44:01
|
Thanks for the suggestion. However I'm not able to import the CA-Certificate into the truststore. The SubCA was created in EJBCA. I opened the corresponding crypto token and downloaded the public key aliased "defaultKey" and got a file in ".pem" format. I transferred this file back to the server and tried to import it using keytool, but only got an error message: ---SNIP--- # keytool -import -trustcacerts -file /tmp/defaultKey.pem -keystore p12/truststore.jks -storepass changeit -alias pkiadminuserca keytool error: java.lang.Exception: Input not an X.509 certificate ---SNAP--- I do not have to import the private key of the SubCA into the truststore, do I? cheers nomike -----Ursprüngliche Nachricht----- Von: Tomas Gustavsson [mailto:to...@pr...] Gesendet: Dienstag, 9. Dezember 2014 14:45 An: ejb...@li... Betreff: Re: [Ejbca-develop] Adding admin user certificates You need to update the JBoss truststore to trust new CA certificates. http://ejbca.org/docs/userguide.html#Administrators%20issued%20by%20external%20CAs Regards, Tomas ----- Save time and money with an Enterprise support subscription. Please see www.primekey.se for more information. http://www.primekey.se/Products/EJBCA+PKI/ http://www.primekey.se/Services/Support/ On 2014-12-09 14:23, Michael Postmann wrote: > Hi! > > I've created a new internal RootCA for our company and a SubCA for > issuing SSL Client certificates for accessing the EJBCA admin panel > which will be provided to the individual users. > > I've created one such test certificate and imported it into my local > Firefox keystore. When I now try to access the EJBCA-Admin GUI, > Firefox asks me which certificate I'd like to use. However it only > offers the "SuperAmin" certificate and not the one I've just created. > > Does EJBCA somehow tell the Browser to only ask the user for a limited > set of certificates (e.g. signed by a specific CA)? Is this configurable? > > cheers > > nomike > > > > ---------------------------------------------------------------------- > -------- Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT > Server from Actuate! Instantly Supercharge Your Business Reports and > Dashboards with Interactivity, Sharing, Native Excel Exports, App > Integration & more Get technology previously reserved for > billion-dollar corporations, FREE > http://pubads.g.doubleclick.net/gampad/clk?id=164703151&iu=/4140/ostg. > clktrk > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > ------------------------------------------------------------------------------ Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT Server from Actuate! Instantly Supercharge Your Business Reports and Dashboards with Interactivity, Sharing, Native Excel Exports, App Integration & more Get technology previously reserved for billion-dollar corporations, FREE http://pubads.g.doubleclick.net/gampad/clk?id=164703151&iu=/4140/ostg.clktrk _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Tomas G. <to...@pr...> - 2014-12-09 13:45:14
|
You need to update the JBoss truststore to trust new CA certificates. http://ejbca.org/docs/userguide.html#Administrators%20issued%20by%20external%20CAs Regards, Tomas ----- Save time and money with an Enterprise support subscription. Please see www.primekey.se for more information. http://www.primekey.se/Products/EJBCA+PKI/ http://www.primekey.se/Services/Support/ On 2014-12-09 14:23, Michael Postmann wrote: > Hi! > > I’ve created a new internal RootCA for our company and a SubCA for > issuing SSL Client certificates for accessing the EJBCA admin panel > which will be provided to the individual users. > > I’ve created one such test certificate and imported it into my local > Firefox keystore. When I now try to access the EJBCA-Admin GUI, Firefox > asks me which certificate I’d like to use. However it only offers the > “SuperAmin” certificate and not the one I’ve just created. > > Does EJBCA somehow tell the Browser to only ask the user for a limited > set of certificates (e.g. signed by a specific CA)? Is this configurable? > > cheers > > nomike > > > > ------------------------------------------------------------------------------ > Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT Server > from Actuate! Instantly Supercharge Your Business Reports and Dashboards > with Interactivity, Sharing, Native Excel Exports, App Integration & more > Get technology previously reserved for billion-dollar corporations, FREE > http://pubads.g.doubleclick.net/gampad/clk?id=164703151&iu=/4140/ostg.clktrk > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Michael P. <M.P...@pa...> - 2014-12-09 13:23:35
|
Hi! I've created a new internal RootCA for our company and a SubCA for issuing SSL Client certificates for accessing the EJBCA admin panel which will be provided to the individual users. I've created one such test certificate and imported it into my local Firefox keystore. When I now try to access the EJBCA-Admin GUI, Firefox asks me which certificate I'd like to use. However it only offers the "SuperAmin" certificate and not the one I've just created. Does EJBCA somehow tell the Browser to only ask the user for a limited set of certificates (e.g. signed by a specific CA)? Is this configurable? cheers nomike |
|
From: Liliana C. <lil...@bu...> - 2014-12-04 21:17:23
|
Thank you for your response Michael. Does it mean that the Username must be localhost ? ________________________________________ De : Michael Ströder [mi...@st...] Envoyé : jeudi 4 décembre 2014 19:46 À : ejb...@li... Objet : Re: [Ejbca-develop] I need to modify httpserver.hostname after ejbca installation Liliana Cabalantti wrote: > How can I do this ? > > The server certificate was generated during 'ant install', with default values (CN=localhost,O=EJBCA Sample,C=SE). > > Today, the appliance is connected to a network and has its own IP address. > > I tried the following, without success: > > 1. Change /etc/hostname to newhost > 2. Modify /etc/hosts > 3. Create a new end entity with CN=newhost. I also tried with the IP address > 4. Create a keystore (newhost) > 5. cp p12/newhost.jks /opt/jboss/jboss-as-7.1.1.Final/standalone/configuration/keystore/keystore.jks > 6. mv p12/newhost.jks tomcat.jks > 7. ant web-configure > 8. ant deploy-keystore > 9. Restart JBoss. > > Result: JBoss does nor start correctly: JBoss cannot alter mysql 'jboss'@'localhost' user for table 'AccessRulesData' and 'AdminEntityData'. Make sure the cert in p12/tomcat.jks matches one CA in p12/truststore.jks and the cert/key alias of the server key in p12/tomcat.jks matches the hostname in httpserver.hostname. Ciao, Michael. |
|
From: Michael S. <mi...@st...> - 2014-12-04 18:46:57
|
Liliana Cabalantti wrote: > How can I do this ? > > The server certificate was generated during 'ant install', with default values (CN=localhost,O=EJBCA Sample,C=SE). > > Today, the appliance is connected to a network and has its own IP address. > > I tried the following, without success: > > 1. Change /etc/hostname to newhost > 2. Modify /etc/hosts > 3. Create a new end entity with CN=newhost. I also tried with the IP address > 4. Create a keystore (newhost) > 5. cp p12/newhost.jks /opt/jboss/jboss-as-7.1.1.Final/standalone/configuration/keystore/keystore.jks > 6. mv p12/newhost.jks tomcat.jks > 7. ant web-configure > 8. ant deploy-keystore > 9. Restart JBoss. > > Result: JBoss does nor start correctly: JBoss cannot alter mysql 'jboss'@'localhost' user for table 'AccessRulesData' and 'AdminEntityData'. Make sure the cert in p12/tomcat.jks matches one CA in p12/truststore.jks and the cert/key alias of the server key in p12/tomcat.jks matches the hostname in httpserver.hostname. Ciao, Michael. |
|
From: Liliana C. <lil...@bu...> - 2014-12-04 17:25:27
|
Hi, How can I do this ? The server certificate was generated during 'ant install', with default values (CN=localhost,O=EJBCA Sample,C=SE). Today, the appliance is connected to a network and has its own IP address. I tried the following, without success: 1. Change /etc/hostname to newhost 2. Modify /etc/hosts 3. Create a new end entity with CN=newhost. I also tried with the IP address 4. Create a keystore (newhost) 5. cp p12/newhost.jks /opt/jboss/jboss-as-7.1.1.Final/standalone/configuration/keystore/keystore.jks 6. mv p12/newhost.jks tomcat.jks 7. ant web-configure 8. ant deploy-keystore 9. Restart JBoss. Result: JBoss does nor start correctly: JBoss cannot alter mysql 'jboss'@'localhost' user for table 'AccessRulesData' and 'AdminEntityData'. Do you have any ideas ? Thanks in advance, Liliana Cabalantti Bull, Architect of an Open World(tm) BSS/TrustWay Tél : +33 1 30 80 63 95 Fax : +33 1 30 80 63 40 lil...@bu... -----Message d'origine----- De : Tomas Gustavsson [mailto:to...@pr...] Envoyé : lundi 3 novembre 2014 15:04 À : ejb...@li... Objet : Re: [Ejbca-develop] I need to modify httpserver.hostname after ejbca installation Hi, yes hostname can be changed. Issued TLS certificates needs to be updated/renewed when hostnames change in order to not have browser warnings. Regards, Tomas ********** PrimeKey Solutions AB Anderstorpsvägen 16, 171 54 Solna, Sweden Mob: +46 (0)707421096 Internet: www.primekey.se<http://www.primekey.se> Twitter: twitter.com/primekeyPKI ********** On 2014-11-03 09:57, Liliana Cabalantti wrote: > Hello, > > I'm working with ejbca_ce_6_0_3 and jboss-as-7.1.1.Final. > > I'm setting up a PKI in a HSM appliance using > httpserver.hostname=localhost. Once the PKI will be operational, the > appliance will be integrated to a network. I'd like to know if > httpserver.hostname can be modified so that the CAs, RAs already > generated are still available. > > Thanks for your help. > > Best regards, > > Liliana Cabalantti > > Bull, Architect of an Open World(tm) > > BSS/TrustWay > > Tél : +33 1 30 80 63 95 > > Fax : +33 1 30 80 63 40 > > lil...@bu...<mailto:lil...@bu...> <mailto:lil...@bu...> > > BULL_logo > > > > ---------------------------------------------------------------------- > -------- > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li...<mailto:Ejb...@li...> > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > ------------------------------------------------------------------------------ _______________________________________________ Ejbca-develop mailing list Ejb...@li...<mailto:Ejb...@li...> https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Tomas G. <to...@pr...> - 2014-12-03 17:19:58
|
Yes that should be it. I was actually thinking about the server log as well, so you can see if there is anything on the server side that is slow. But the client is good first of course. Regards, Tomas On 2014-12-03 17:55, Michael Ströder wrote: > Tomas Gustavsson <to...@pr...> wrote >> Enable trace logging > > How? > > For ejbca.sh I'm looking here: > /dist/ejbca-ejb-cli/log4j.xml > /src/java/log4j.properties > > Are those the right files to tweak ejbca.sh console output? > > Ciao, Michael. > > |
|
From: Michael S. <mi...@st...> - 2014-12-03 16:55:42
|
Tomas Gustavsson <to...@pr...> wrote > Enable trace logging How? For ejbca.sh I'm looking here: /dist/ejbca-ejb-cli/log4j.xml /src/java/log4j.properties Are those the right files to tweak ejbca.sh console output? Ciao, Michael. |
|
From: Tomas G. <to...@pr...> - 2014-12-03 16:38:24
|
Enable trace logging and check in the server.log if there are any strange pauses. Also apply recommended database indexes from doc/sql-scripts. Cheers, TOmas On 2014-12-03 17:21, Michael Ströder wrote: > HI! > > How can I trace what's going on within ejbca.sh? > > I'm still looking why it's so slow in my setup. > > Ciao, Michael. > > > > ------------------------------------------------------------------------------ > Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT Server > from Actuate! Instantly Supercharge Your Business Reports and Dashboards > with Interactivity, Sharing, Native Excel Exports, App Integration & more > Get technology previously reserved for billion-dollar corporations, FREE > http://pubads.g.doubleclick.net/gampad/clk?id=164703151&iu=/4140/ostg.clktrk > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Michael S. <mi...@st...> - 2014-12-03 16:22:02
|
HI! How can I trace what's going on within ejbca.sh? I'm still looking why it's so slow in my setup. Ciao, Michael. |
|
From: Eilaf E. <eil...@ho...> - 2014-12-02 05:50:36
|
Sorry i meant it worked fine previously on ejbca 6.0.4 no 6.0.2, From: eil...@ho... To: ejb...@li... Subject: RE: [Ejbca-develop] error generating keys using clientToolBox Date: Tue, 2 Dec 2014 09:42:38 +0400 Hi, Tried adding -password thePIN to the command but still it's not working, although everything was working fine in ejbca 6.0.2 with jdk6. > From: ma...@de... > Date: Sun, 30 Nov 2014 14:31:44 +0100 > To: ejb...@li... > Subject: Re: [Ejbca-develop] error generating keys using clientToolBox > > Hi, > > On Sun, Nov 30, 2014 at 6:18 AM, Eilaf Essam <eil...@ho...> wrote: > > Hi, i used this command : > > ./ejbcaClientToolBox.sh PKCS11HSMKeyTool generate > > /root/Utimaco/libcs_pkcs11_R2.so 1024 signKey 0 > > > > slot 0 is already initialized and with so pin and user pin. > > I recommend you try adding the user PIN to the tool with "-password thePIN" > > ~manuel > > ------------------------------------------------------------------------------ > Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT Server > from Actuate! Instantly Supercharge Your Business Reports and Dashboards > with Interactivity, Sharing, Native Excel Exports, App Integration & more > Get technology previously reserved for billion-dollar corporations, FREE > http://pubads.g.doubleclick.net/gampad/clk?id=157005751&iu=/4140/ostg.clktrk > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Eilaf E. <eil...@ho...> - 2014-12-02 05:42:45
|
Hi, Tried adding -password thePIN to the command but still it's not working, although everything was working fine in ejbca 6.0.2 with jdk6. > From: ma...@de... > Date: Sun, 30 Nov 2014 14:31:44 +0100 > To: ejb...@li... > Subject: Re: [Ejbca-develop] error generating keys using clientToolBox > > Hi, > > On Sun, Nov 30, 2014 at 6:18 AM, Eilaf Essam <eil...@ho...> wrote: > > Hi, i used this command : > > ./ejbcaClientToolBox.sh PKCS11HSMKeyTool generate > > /root/Utimaco/libcs_pkcs11_R2.so 1024 signKey 0 > > > > slot 0 is already initialized and with so pin and user pin. > > I recommend you try adding the user PIN to the tool with "-password thePIN" > > ~manuel > > ------------------------------------------------------------------------------ > Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT Server > from Actuate! Instantly Supercharge Your Business Reports and Dashboards > with Interactivity, Sharing, Native Excel Exports, App Integration & more > Get technology previously reserved for billion-dollar corporations, FREE > http://pubads.g.doubleclick.net/gampad/clk?id=157005751&iu=/4140/ostg.clktrk > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop |