You can subscribe to this list here.
| 2001 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
(1) |
Dec
(3) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2002 |
Jan
(3) |
Feb
(2) |
Mar
(8) |
Apr
(3) |
May
(6) |
Jun
(1) |
Jul
(15) |
Aug
(6) |
Sep
|
Oct
(10) |
Nov
(2) |
Dec
(4) |
| 2003 |
Jan
(1) |
Feb
(7) |
Mar
(3) |
Apr
(6) |
May
(7) |
Jun
(5) |
Jul
(5) |
Aug
(25) |
Sep
(14) |
Oct
(2) |
Nov
|
Dec
(2) |
| 2004 |
Jan
(7) |
Feb
(4) |
Mar
(12) |
Apr
(16) |
May
(43) |
Jun
(56) |
Jul
(43) |
Aug
(40) |
Sep
(66) |
Oct
(12) |
Nov
(26) |
Dec
(10) |
| 2005 |
Jan
(13) |
Feb
(33) |
Mar
(16) |
Apr
(7) |
May
(10) |
Jun
(34) |
Jul
(41) |
Aug
(8) |
Sep
(4) |
Oct
(32) |
Nov
(20) |
Dec
(25) |
| 2006 |
Jan
(30) |
Feb
(101) |
Mar
(5) |
Apr
(75) |
May
(74) |
Jun
(22) |
Jul
(6) |
Aug
(70) |
Sep
(19) |
Oct
(21) |
Nov
(31) |
Dec
(50) |
| 2007 |
Jan
(15) |
Feb
(20) |
Mar
(24) |
Apr
(33) |
May
(13) |
Jun
(18) |
Jul
(13) |
Aug
(7) |
Sep
(63) |
Oct
(68) |
Nov
(29) |
Dec
(68) |
| 2008 |
Jan
(30) |
Feb
(33) |
Mar
(30) |
Apr
(103) |
May
(78) |
Jun
(48) |
Jul
(72) |
Aug
(24) |
Sep
(62) |
Oct
(63) |
Nov
(70) |
Dec
(37) |
| 2009 |
Jan
(34) |
Feb
(35) |
Mar
(64) |
Apr
(34) |
May
(34) |
Jun
(58) |
Jul
(30) |
Aug
(30) |
Sep
(46) |
Oct
(52) |
Nov
(12) |
Dec
(23) |
| 2010 |
Jan
(121) |
Feb
(18) |
Mar
(53) |
Apr
(62) |
May
(62) |
Jun
(20) |
Jul
(33) |
Aug
(20) |
Sep
(36) |
Oct
(35) |
Nov
(44) |
Dec
(63) |
| 2011 |
Jan
(19) |
Feb
(32) |
Mar
(94) |
Apr
(41) |
May
(47) |
Jun
(25) |
Jul
(34) |
Aug
(20) |
Sep
(9) |
Oct
(41) |
Nov
(33) |
Dec
(24) |
| 2012 |
Jan
(12) |
Feb
(36) |
Mar
(48) |
Apr
(32) |
May
(20) |
Jun
(15) |
Jul
(32) |
Aug
(13) |
Sep
(33) |
Oct
(54) |
Nov
(25) |
Dec
(16) |
| 2013 |
Jan
(45) |
Feb
(39) |
Mar
(38) |
Apr
(50) |
May
(29) |
Jun
(30) |
Jul
(33) |
Aug
(12) |
Sep
(9) |
Oct
(25) |
Nov
(29) |
Dec
(20) |
| 2014 |
Jan
(25) |
Feb
(19) |
Mar
(16) |
Apr
(33) |
May
(27) |
Jun
(37) |
Jul
(29) |
Aug
(27) |
Sep
(37) |
Oct
(58) |
Nov
(109) |
Dec
(26) |
| 2015 |
Jan
(4) |
Feb
(35) |
Mar
(22) |
Apr
(35) |
May
(28) |
Jun
(20) |
Jul
(4) |
Aug
(16) |
Sep
(37) |
Oct
(13) |
Nov
(13) |
Dec
(14) |
| 2016 |
Jan
(22) |
Feb
(7) |
Mar
(23) |
Apr
(30) |
May
(10) |
Jun
(10) |
Jul
(15) |
Aug
(12) |
Sep
(22) |
Oct
(31) |
Nov
(5) |
Dec
(5) |
| 2017 |
Jan
(30) |
Feb
(25) |
Mar
(28) |
Apr
(4) |
May
(19) |
Jun
(13) |
Jul
(7) |
Aug
(1) |
Sep
(2) |
Oct
(5) |
Nov
(12) |
Dec
(2) |
| 2018 |
Jan
(7) |
Feb
|
Mar
(7) |
Apr
(2) |
May
(8) |
Jun
(18) |
Jul
(6) |
Aug
(3) |
Sep
(15) |
Oct
(33) |
Nov
(13) |
Dec
(7) |
| 2019 |
Jan
(5) |
Feb
(7) |
Mar
(30) |
Apr
(5) |
May
(4) |
Jun
(69) |
Jul
(86) |
Aug
(22) |
Sep
(6) |
Oct
(7) |
Nov
(5) |
Dec
(3) |
| 2020 |
Jan
(10) |
Feb
(12) |
Mar
(22) |
Apr
(5) |
May
(1) |
Jun
(4) |
Jul
(6) |
Aug
|
Sep
(9) |
Oct
|
Nov
|
Dec
(1) |
| 2021 |
Jan
(4) |
Feb
(11) |
Mar
(7) |
Apr
(7) |
May
|
Jun
(3) |
Jul
(10) |
Aug
(6) |
Sep
|
Oct
|
Nov
(18) |
Dec
(2) |
| 2022 |
Jan
(1) |
Feb
(1) |
Mar
|
Apr
|
May
|
Jun
(2) |
Jul
|
Aug
(4) |
Sep
|
Oct
|
Nov
|
Dec
|
| 2023 |
Jan
|
Feb
|
Mar
|
Apr
(1) |
May
(1) |
Jun
|
Jul
|
Aug
(5) |
Sep
|
Oct
|
Nov
|
Dec
|
|
From: Michael S. <mi...@st...> - 2014-11-24 19:25:03
|
Michael Postmann wrote: > In our setup we have a root CA which singed two intermediate CA's which > then sign some client and webserver certificates to be used internally and > by our clients. For reasons of security, we want to remove the root CA from > the server, as soon as the intermediate CAs are signed. The root CA will be > stored in physical safe so we have it available in case we need it again. An off-line root CA key. > So if I just remove the RootCA from "ejbca" will key verification up the > issuer chain and similar stuff be still possible? Could I later just add > the key again to EJBCA if I e.g. need to revoke the key or sign another > intermediate CA? It very much depends on what "key verification" means. (You probably mean cert validation.) Of course simple checks along the public-key cert chain will work. The tricky part is the revocation check. It depends on what your relying party software expects. E.g. issuing a CRL every few months is very easy with a temporarily actived root CA key. But if you have client software which can only do revocation checks via OCSP *and* does *not* support delegated OCSP signing keys you're lost. Ciao, Michael. |
|
From: Michael S. <mi...@st...> - 2014-11-24 19:20:41
|
Andreas Kuehne wrote: > your idea to delete the root CA is a bit suprising to me! I would agree > that's a good idea to lock away the private key of the root, preferably > on a smart card or in an encrypted file with different holders of > credential parts. > > Without the root certificate all your chain validations will fail. > Making OCSP requests for the intermediate CA is 'difficult' without > having the issuing certificate at hand ... Andreas, this reveals that you're very much into SigG signature checking. ;-) "Normal" implementations (e.g. Firefox) usually only send OCSP requests for end entities. But you could even remove the root CA key if the root CA issued a OCSP responder cert with separate key pair (OCSP delegation). Ciao, Michael. |
|
From: Samuel L. B. <sa...@pr...> - 2014-11-24 18:26:21
|
Hi, That problem was caused by the --status option which didn't accept lower-case parameters. I've committed a fix to SVN. Regards, Samuel Den 2014-11-24 18:31, Michael Ströder skrev: > HI! > > Using latest SVN revision creating an OcspKeyBinding with the command-line tool > fails (see below). > > Ciao, Michael. > > # /opt/ejbca/bin/ejbca.sh keybind create --name > "KB_OCSP_Server_1" --token "CT_OCSP1" --type OcspKeyBinding --alias > privatesignkeyalias --sigalg SHA1WithRSA --verbose --status active --cert null > SETTING: --name as KB_OCSP_Server_1 > SETTING: --token as CT_OCSP1 > SETTING: --type as OcspKeyBinding > SETTING: --alias as privatesignkeyalias > SETTING: --sigalg as SHA1WithRSA > SETTING: --status as active > SETTING: --cert as null > Exception in thread "main" java.lang.IllegalArgumentException: No enum constant > org.cesecore.keybind.InternalKeyBindingStatus.active > at java.lang.Enum.valueOf(Enum.java:236) > at > org.cesecore.keybind.InternalKeyBindingStatus.valueOf(InternalKeyBindingStatus.java:21) > at > org.ejbca.ui.cli.keybind.InternalKeyBindingCreateCommand.execute(InternalKeyBindingCreateCommand.java:116) > at > org.ejbca.ui.cli.infrastructure.command.PasswordUsingCommandBase.execute(PasswordUsingCommandBase.java:202) > at > org.ejbca.ui.cli.infrastructure.library.CommandLibrary$Branch.execute(CommandLibrary.java:276) > at > org.ejbca.ui.cli.infrastructure.library.CommandLibrary$Branch.execute(CommandLibrary.java:286) > at > org.ejbca.ui.cli.infrastructure.library.CommandLibrary.findAndExecuteCommandFromParameters(CommandLibrary.java:67) > at org.ejbca.ui.cli.EjbcaEjbCli.main(EjbcaEjbCli.java:33) > > > > ------------------------------------------------------------------------------ > Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT Server > from Actuate! Instantly Supercharge Your Business Reports and Dashboards > with Interactivity, Sharing, Native Excel Exports, App Integration & more > Get technology previously reserved for billion-dollar corporations, FREE > http://pubads.g.doubleclick.net/gampad/clk?id=157005751&iu=/4140/ostg.clktrk > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Michael S. <mi...@st...> - 2014-11-24 17:31:40
|
HI! Using latest SVN revision creating an OcspKeyBinding with the command-line tool fails (see below). Ciao, Michael. # /opt/ejbca/bin/ejbca.sh keybind create --name "KB_OCSP_Server_1" --token "CT_OCSP1" --type OcspKeyBinding --alias privatesignkeyalias --sigalg SHA1WithRSA --verbose --status active --cert null SETTING: --name as KB_OCSP_Server_1 SETTING: --token as CT_OCSP1 SETTING: --type as OcspKeyBinding SETTING: --alias as privatesignkeyalias SETTING: --sigalg as SHA1WithRSA SETTING: --status as active SETTING: --cert as null Exception in thread "main" java.lang.IllegalArgumentException: No enum constant org.cesecore.keybind.InternalKeyBindingStatus.active at java.lang.Enum.valueOf(Enum.java:236) at org.cesecore.keybind.InternalKeyBindingStatus.valueOf(InternalKeyBindingStatus.java:21) at org.ejbca.ui.cli.keybind.InternalKeyBindingCreateCommand.execute(InternalKeyBindingCreateCommand.java:116) at org.ejbca.ui.cli.infrastructure.command.PasswordUsingCommandBase.execute(PasswordUsingCommandBase.java:202) at org.ejbca.ui.cli.infrastructure.library.CommandLibrary$Branch.execute(CommandLibrary.java:276) at org.ejbca.ui.cli.infrastructure.library.CommandLibrary$Branch.execute(CommandLibrary.java:286) at org.ejbca.ui.cli.infrastructure.library.CommandLibrary.findAndExecuteCommandFromParameters(CommandLibrary.java:67) at org.ejbca.ui.cli.EjbcaEjbCli.main(EjbcaEjbCli.java:33) |
|
From: Andreas K. <ku...@tr...> - 2014-11-24 13:19:16
|
Hi Michael, your idea to delete the root CA is a bit suprising to me! I would agree that's a good idea to lock away the private key of the root, preferably on a smart card or in an encrypted file with different holders of credential parts. Without the root certificate all your chain validations will fail. Making OCSP requests for the intermediate CA is 'difficult' without having the issuing certificate at hand ... What do you want to achieve by 'deleting' the CA? Greetings, Andreas > Hi! > > In our setup we have a root CA which singed two intermediate CA's which then sign some client and webserver certificates to be used internally and by our clients. For reasons of security, we want to remove the root CA from the server, as soon as the intermediate CAs are signed. The root CA will be stored in physical safe so we have it available in case we need it again. > > So if I just remove the RootCA from "ejbca" will key verification up the issuer chain and similar stuff be still possible? Could I later just add the key again to EJBCA if I e.g. need to revoke the key or sign another intermediate CA? > > cheers > > nomike > > > > > ------------------------------------------------------------------------------ > Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT Server > from Actuate! Instantly Supercharge Your Business Reports and Dashboards > with Interactivity, Sharing, Native Excel Exports, App Integration & more > Get technology previously reserved for billion-dollar corporations, FREE > http://pubads.g.doubleclick.net/gampad/clk?id=157005751&iu=/4140/ostg.clktrk > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop -- Andreas Kühne phone: +49 177 293 24 97 mailto: ku...@tr... Trustable Ltd. Niederlassung Deutschland Ströverstr. 18 - 59427 Unna Amtsgericht Hamm HRB 5868 Directors Andreas Kühne, Heiko Veit Company UK Company No: 5218868 Registered in England and Wales |
|
From: Michael P. <M.P...@pa...> - 2014-11-24 13:05:56
|
Hi! In our setup we have a root CA which singed two intermediate CA's which then sign some client and webserver certificates to be used internally and by our clients. For reasons of security, we want to remove the root CA from the server, as soon as the intermediate CAs are signed. The root CA will be stored in physical safe so we have it available in case we need it again. So if I just remove the RootCA from "ejbca" will key verification up the issuer chain and similar stuff be still possible? Could I later just add the key again to EJBCA if I e.g. need to revoke the key or sign another intermediate CA? cheers nomike |
|
From: eilaf s. <eil...@gm...> - 2014-11-23 10:33:48
|
Could not run execute method for class ca
java.security.InvalidParameterException: Attempted to create an
AccessUserAspectData with matchValue == null
at
org.cesecore.authorization.user.AccessUserAspectData.<init>(AccessUserAspectData.java:69)
at
org.ejbca.core.ejb.authorization.ComplexAccessControlSessionBean.initializeAuthorizationModule(ComplexAccessControlSessionBean.java:188)
at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
at
sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:57)
at
sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
at java.lang.reflect.Method.invoke(Method.java:606)
at
org.jboss.as.ee.component.ManagedReferenceMethodInterceptorFactory$ManagedReferenceMethodInterceptor.processInvocation(ManagedReferenceMethodInterceptorFactory.java:72)
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
at
org.jboss.invocation.WeavedInterceptor.processInvocation(WeavedInterceptor.java:53)
at
org.jboss.as.ee.component.interceptors.UserInterceptorFactory$1.processInvocation(UserInterceptorFactory.java:36)
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
at
org.jboss.as.jpa.interceptor.SBInvocationInterceptor.processInvocation(SBInvocationInterceptor.java:47)
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
at
org.jboss.invocation.InitialInterceptor.processInvocation(InitialInterceptor.java:21)
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
at
org.jboss.invocation.ChainedInterceptor.processInvocation(ChainedInterceptor.java:61)
at
org.jboss.as.ee.component.interceptors.ComponentDispatcherInterceptor.processInvocation(ComponentDispatcherInterceptor.java:53)
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
at
org.jboss.as.ejb3.component.pool.PooledInstanceInterceptor.processInvocation(PooledInstanceInterceptor.java:51)
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
at
org.jboss.as.ejb3.tx.CMTTxInterceptor.invokeInNoTx(CMTTxInterceptor.java:211)
at
org.jboss.as.ejb3.tx.CMTTxInterceptor.supports(CMTTxInterceptor.java:363)
at
org.jboss.as.ejb3.tx.CMTTxInterceptor.processInvocation(CMTTxInterceptor.java:194)
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
at
org.jboss.as.ejb3.remote.EJBRemoteTransactionPropagatingInterceptor.processInvocation(EJBRemoteTransactionPropagatingInterceptor.java:80)
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
at
org.jboss.as.ejb3.component.interceptors.CurrentInvocationContextInterceptor.processInvocation(CurrentInvocationContextInterceptor.java:41)
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
at
org.jboss.as.ejb3.component.interceptors.LoggingInterceptor.processInvocation(LoggingInterceptor.java:59)
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
at
org.jboss.as.ee.component.NamespaceContextInterceptor.processInvocation(NamespaceContextInterceptor.java:50)
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
at
org.jboss.as.ejb3.component.interceptors.AdditionalSetupInterceptor.processInvocation(AdditionalSetupInterceptor.java:43)
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
at
org.jboss.as.ee.component.TCCLInterceptor.processInvocation(TCCLInterceptor.java:45)
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
at
org.jboss.invocation.ChainedInterceptor.processInvocation(ChainedInterceptor.java:61)
at
org.jboss.as.ee.component.ViewService$View.invoke(ViewService.java:165)
at
org.jboss.as.ejb3.remote.protocol.versionone.MethodInvocationMessageHandler.invokeMethod(MethodInvocationMessageHandler.java:302)
at
org.jboss.as.ejb3.remote.protocol.versionone.MethodInvocationMessageHandler.access$200(MethodInvocationMessageHandler.java:64)
at
org.jboss.as.ejb3.remote.protocol.versionone.MethodInvocationMessageHandler$1.run(MethodInvocationMessageHandler.java:196)
at
java.util.concurrent.Executors$RunnableAdapter.call(Executors.java:471)
at java.util.concurrent.FutureTask.run(FutureTask.java:262)
at
java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1145)
at
java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:615)
at java.lang.Thread.run(Thread.java:745)
at org.jboss.threads.JBossThread.run(JBossThread.java:122)
at ...asynchronous invocation...(Unknown Source)
at
org.jboss.ejb.client.remoting.InvocationExceptionResponseHandler$MethodInvocationExceptionResultProducer.getResult(InvocationExceptionResponseHandler.java:99)
at
org.jboss.ejb.client.EJBClientInvocationContext.getResult(EJBClientInvocationContext.java:270)
at
org.jboss.ejb.client.TransactionInterceptor.handleInvocationResult(TransactionInterceptor.java:47)
at
org.jboss.ejb.client.EJBClientInvocationContext.getResult(EJBClientInvocationContext.java:272)
at
org.jboss.ejb.client.ReceiverInterceptor.handleInvocationResult(ReceiverInterceptor.java:132)
at
org.jboss.ejb.client.EJBClientInvocationContext.getResult(EJBClientInvocationContext.java:260)
at
org.jboss.ejb.client.EJBClientInvocationContext.awaitResponse(EJBClientInvocationContext.java:399)
at
org.jboss.ejb.client.EJBInvocationHandler.doInvoke(EJBInvocationHandler.java:140)
at
org.jboss.ejb.client.EJBInvocationHandler.doInvoke(EJBInvocationHandler.java:121)
at
org.jboss.ejb.client.EJBInvocationHandler.invoke(EJBInvocationHandler.java:104)
at com.sun.proxy.$Proxy4.initializeAuthorizationModule(Unknown Source)
at
org.ejbca.ui.cli.ca.BaseCaAdminCommand.initAuthorizationModule(BaseCaAdminCommand.java:195)
at
org.ejbca.ui.cli.ca.CaImportCACertCommand.execute(CaImportCACertCommand.java:98)
at
org.ejbca.ui.cli.CliCommandHelper.executeCommand(CliCommandHelper.java:147)
at
org.ejbca.ui.cli.CliCommandHelper.searchAndRun(CliCommandHelper.java:105)
at org.ejbca.ui.cli.EjbcaEjbCli.main(EjbcaEjbCli.java:25)
--
Eilaf Hamad Elnil Mugbil
University Of Khartoum
School Of Mathematical science
|
|
From: Michael S. <mi...@st...> - 2014-11-21 12:34:36
|
pu...@fe... wrote: > you may consider to check chphermail. This is a mail gateway for > en-/decryption of smtp mails. EJBCA ca route its mails through that > gateway. Note that I've implemented a simple S/MIME encryption filter myself (used with postfix) back in 1998. Still I think it would be a nice feature because EJBCA also owns the user DB and I don't want to have passwords stored in clear in a MTA queue. Ciao, Michael. |
|
From: Tomas G. <to...@pr...> - 2014-11-21 11:48:43
|
Great pointer! To add further, there is EJBCA integration in Ciphermail (former Djigzo), and it's being used in production :-) Cheers, Tomas On 2014-11-21 12:06, pu...@fe... wrote: > Hello, > > you may consider to check chphermail. This is a mail gateway for > en-/decryption of smtp mails. EJBCA ca route its mails through that > gateway. > > Christian > > Zitat von Michael Ströder <mi...@st...>: > >> It would be really cool if EJBCA would send temporary passwords etc. >> in S/MIME >> encrypted e-mails if a recipient cert can be found in the DB. > > ------------------------ > Powered by http://ip6.li > > > ------------------------------------------------------------------------------ > Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT Server > from Actuate! Instantly Supercharge Your Business Reports and Dashboards > with Interactivity, Sharing, Native Excel Exports, App Integration & more > Get technology previously reserved for billion-dollar corporations, FREE > http://pubads.g.doubleclick.net/gampad/clk?id=157005751&iu=/4140/ostg.clktrk > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: <pu...@fe...> - 2014-11-21 11:31:59
|
Hello, you may consider to check chphermail. This is a mail gateway for en-/decryption of smtp mails. EJBCA ca route its mails through that gateway. Christian Zitat von Michael Ströder <mi...@st...>: > It would be really cool if EJBCA would send temporary passwords etc. > in S/MIME > encrypted e-mails if a recipient cert can be found in the DB. ------------------------ Powered by http://ip6.li |
|
From: Michael S. <mi...@st...> - 2014-11-20 16:57:40
|
Tomas Gustavsson wrote: > > Interesting feature. You should register it in Jira. Hmm, I can only add support requests: https://jira.primekey.se/browse/SUPPORT-324 Ciao, Michael. |
|
From: <co...@co...> - 2014-11-20 15:23:30
|
Hi,
I am trying to setup EJBCA with Luna SA. But i get error
which i cannot google. I tried both 6.1.1 and 6.2.0 client tool box. Java
version 1.7.0_71.
Policies 22 and 23 are on
Allow activation On 22
Allow auto-activation On 23
But when i enter password i get :
dist/clientToolBox/ejbcaClientToolBox.sh PKCS11HSMKeyTool generate
/usr/safenet/lunaclient/lib/libCryptoki2_64.so 2048 rsa2048_1 1 0
Using Slot Reference Type: Slot Number.
2014-11-20 15:53:51,605 INFO [org.cesecore.keys.token.p11.Pkcs11SlotLabel]
Using SUN PKCS11 provider: sun.security.pkcs11.SunPKCS11
PKCS11 Token [SunPKCS11-libCryptoki2_64.so-slot1] Password:
Command could not be executed. See log for stack trace.
2014-11-20 15:53:54,271 ERROR [org.ejbca.ui.cli.HSMKeyTool] Command
'PKCS11HSMKeyTool generate /usr/safenet/lunaclient/lib/libCryptoki2_64.so
null pkcs11 2048 rsa2048_1 1' could not be executed.
java.security.KeyStoreException: KeyStore instantiation failed
at java.security.KeyStore$Builder$2.getKeyStore(KeyStore.java:1735)
at
org.ejbca.util.keystore.KeyStoreContainerP11.getInstance(KeyStoreContainerP1
1.java:90)
at
org.ejbca.util.keystore.KeyStoreContainerP11.getInstance(KeyStoreContainerP1
1.java:61)
at
org.ejbca.util.keystore.KeyStoreContainerFactory.getInstance(KeyStoreContain
erFactory.java:43)
at org.ejbca.ui.cli.HSMKeyTool.doIt(HSMKeyTool.java:208)
at org.ejbca.ui.cli.HSMKeyTool.execute(HSMKeyTool.java:448)
at
org.ejbca.ui.cli.PKCS11HSMKeyTool.execute(PKCS11HSMKeyTool.java:47)
at
org.ejbca.ui.cli.ClientToolBox.executeIfSelected(ClientToolBox.java:40)
at org.ejbca.ui.cli.ClientToolBox.main(ClientToolBox.java:66)
Caused by: java.security.cert.CertificateException: Could not parse
certificate: java.io.IOException: Empty input
at
sun.security.provider.X509Factory.engineGenerateCertificate(X509Factory.java
:104)
at
java.security.cert.CertificateFactory.generateCertificate(CertificateFactory
.java:339)
at sun.security.pkcs11.P11KeyStore.loadCert(P11KeyStore.java:1207)
at sun.security.pkcs11.P11KeyStore.mapLabels(P11KeyStore.java:2370)
at sun.security.pkcs11.P11KeyStore.engineLoad(P11KeyStore.java:856)
at java.security.KeyStore.load(KeyStore.java:1248)
at java.security.KeyStore$Builder$2$1.run(KeyStore.java:1705)
at java.security.KeyStore$Builder$2$1.run(KeyStore.java:1686)
at java.security.AccessController.doPrivileged(Native Method)
at java.security.KeyStore$Builder$2.getKeyStore(KeyStore.java:1732)
... 8 more
Caused by: java.io.IOException: Empty input
at
sun.security.provider.X509Factory.engineGenerateCertificate(X509Factory.java
:101)
... 17 more
Can anyone point me where i could make configuration mistake ?
With kind regards,
Congo
|
|
From: Tomas G. <to...@pr...> - 2014-11-20 14:33:31
|
Interesting feature. You should register it in Jira. Cheers, Tomas On 2014-11-20 11:07, Michael Ströder wrote: > HI! > > It would be really cool if EJBCA would send temporary passwords etc. in S/MIME > encrypted e-mails if a recipient cert can be found in the DB. > > Something configurable like: > - Search recipient's S/MIME cert by CA, cert profile, EE profile combination. > - S/MIME policy opportunistic vs. mandatory > > Ciao, Michael. > > > > ------------------------------------------------------------------------------ > Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT Server > from Actuate! Instantly Supercharge Your Business Reports and Dashboards > with Interactivity, Sharing, Native Excel Exports, App Integration & more > Get technology previously reserved for billion-dollar corporations, FREE > http://pubads.g.doubleclick.net/gampad/clk?id=157005751&iu=/4140/ostg.clktrk > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Tomas G. <to...@pr...> - 2014-11-20 14:03:55
|
On 2014-11-20 11:26, Michael Ströder wrote: > HI! > > Is the parameter --keytype missing for "ejbca.sh cryptotoken generatekey"? > Or what are valid values for --keyspec? E.g. for RSA-2048. Example keyspecs are "2048, secp256r1, DSA1024, gost3410, dstu4145". Added examples for next rel. > Also the --help says --keyspec is optional but it's not. Already fixed. > > Ciao, Michael. > > > > ------------------------------------------------------------------------------ > Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT Server > from Actuate! Instantly Supercharge Your Business Reports and Dashboards > with Interactivity, Sharing, Native Excel Exports, App Integration & more > Get technology previously reserved for billion-dollar corporations, FREE > http://pubads.g.doubleclick.net/gampad/clk?id=157005751&iu=/4140/ostg.clktrk > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Michael S. <mi...@st...> - 2014-11-20 12:17:04
|
HI! It seems that ejbca.sh is so slow on my test systems because those are VMs in a KVM cluster and there's not enough entropy in /dev/random, and therefore starting a JVM hangs in gathering entropy... Also running haveged does not help since it's not real hardware. So how to enforce ejbca.sh using /dev/urandom instead? I've tried to edit ejbca.sh: exec "$JAVACMD" -Djava.security.egd=file:/dev/urandom -jar [..] But it does not help either. Nope, I don't want to directly muck with /dev/random like described in this "solution" (top on Google): http://nofluffjuststuff.com/blog/pratik_patel/2010/01/solution_futex_wait_hangs_java_on_linux__ubuntu_in_vmware_or_virtual_box Ciao, Michael. |
|
From: Michael S. <mi...@st...> - 2014-11-20 10:26:25
|
HI! Is the parameter --keytype missing for "ejbca.sh cryptotoken generatekey"? Or what are valid values for --keyspec? E.g. for RSA-2048. Also the --help says --keyspec is optional but it's not. Ciao, Michael. |
|
From: Michael S. <mi...@st...> - 2014-11-20 10:07:37
|
HI! It would be really cool if EJBCA would send temporary passwords etc. in S/MIME encrypted e-mails if a recipient cert can be found in the DB. Something configurable like: - Search recipient's S/MIME cert by CA, cert profile, EE profile combination. - S/MIME policy opportunistic vs. mandatory Ciao, Michael. |
|
From: eilaf s. <eil...@gm...> - 2014-11-20 09:28:03
|
It was running but the port 1099 was not opened. after solving the port
issue i get:
ERROR [org.jboss.ejb3.invocation] (EJB default - 8) JBAS014134: EJB
Invocation failed on component ComplexAccessControlSessionBean for method
public abstract void
org.ejbca.core.ejb.authorization.ComplexAccessControlSession.initializeAuthorizationModule(org.cesecore.authentication.tokens.AuthenticationToken,int,java.lang.String)
throws
org.cesecore.roles.RoleExistsException,org.cesecore.authorization.AuthorizationDeniedException,org.cesecore.authorization.rules.AccessRuleNotFoundException,org.cesecore.roles.RoleNotFoundException:
java.security.InvalidParameterException: Attempted to create an
AccessUserAspectData with matchValue == null
at
org.cesecore.authorization.user.AccessUserAspectData.<init>(AccessUserAspectData.java:69)
[cesecore-entity.jar:]
at
org.ejbca.core.ejb.authorization.ComplexAccessControlSessionBean.initializeAuthorizationModule(ComplexAccessControlSessionBean.java:188)
[ejbca-ejb.jar:]
at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
[rt.jar:1.7.0_65]
at
sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:57)
[rt.jar:1.7.0_65]
at
sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
[rt.jar:1.7.0_65]
at java.lang.reflect.Method.invoke(Method.java:606) [rt.jar:1.7.0_65]
at
org.jboss.as.ee.component.ManagedReferenceMethodInterceptorFactory$ManagedReferenceMethodInterceptor.processInvocation(ManagedReferenceMethodInterceptorFactory.java:72)
[jboss-as-ee-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.invocation.WeavedInterceptor.processInvocation(WeavedInterceptor.java:53)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.as.ee.component.interceptors.UserInterceptorFactory$1.processInvocation(UserInterceptorFactory.java:36)
[jboss-as-ee-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.as.jpa.interceptor.SBInvocationInterceptor.processInvocation(SBInvocationInterceptor.java:47)
[jboss-as-jpa-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.invocation.InitialInterceptor.processInvocation(InitialInterceptor.java:21)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.invocation.ChainedInterceptor.processInvocation(ChainedInterceptor.java:61)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.as.ee.component.interceptors.ComponentDispatcherInterceptor.processInvocation(ComponentDispatcherInterceptor.java:53)
[jboss-as-ee-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.as.ejb3.component.pool.PooledInstanceInterceptor.processInvocation(PooledInstanceInterceptor.java:51)
[jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.as.ejb3.tx.CMTTxInterceptor.invokeInNoTx(CMTTxInterceptor.java:211)
[jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.as.ejb3.tx.CMTTxInterceptor.supports(CMTTxInterceptor.java:363)
[jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.as.ejb3.tx.CMTTxInterceptor.processInvocation(CMTTxInterceptor.java:194)
[jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.as.ejb3.remote.EJBRemoteTransactionPropagatingInterceptor.processInvocation(EJBRemoteTransactionPropagatingInterceptor.java:80)
[jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.as.ejb3.component.interceptors.CurrentInvocationContextInterceptor.processInvocation(CurrentInvocationContextInterceptor.java:41)
[jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.as.ejb3.component.interceptors.LoggingInterceptor.processInvocation(LoggingInterceptor.java:59)
[jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.as.ee.component.NamespaceContextInterceptor.processInvocation(NamespaceContextInterceptor.java:50)
[jboss-as-ee-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.as.ejb3.component.interceptors.AdditionalSetupInterceptor.processInvocation(AdditionalSetupInterceptor.java:43)
[jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.as.ee.component.TCCLInterceptor.processInvocation(TCCLInterceptor.java:45)
[jboss-as-ee-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.invocation.ChainedInterceptor.processInvocation(ChainedInterceptor.java:61)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.as.ee.component.ViewService$View.invoke(ViewService.java:165)
[jboss-as-ee-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.as.ejb3.remote.protocol.versionone.MethodInvocationMessageHandler.invokeMethod(MethodInvocationMessageHandler.java:302)
[jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.as.ejb3.remote.protocol.versionone.MethodInvocationMessageHandler.access$200(MethodInvocationMessageHandler.java:64)
[jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.as.ejb3.remote.protocol.versionone.MethodInvocationMessageHandler$1.run(MethodInvocationMessageHandler.java:196)
[jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final]
at
java.util.concurrent.Executors$RunnableAdapter.call(Executors.java:471)
[rt.jar:1.7.0_65]
at java.util.concurrent.FutureTask.run(FutureTask.java:262)
[rt.jar:1.7.0_65]
at
java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1145)
[rt.jar:1.7.0_65]
at
java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:615)
[rt.jar:1.7.0_65]
at java.lang.Thread.run(Thread.java:745) [rt.jar:1.7.0_65]
at org.jboss.threads.JBossThread.run(JBossThread.java:122)
On Thu, Nov 20, 2014 at 11:55 AM, Tomas Gustavsson <to...@pr...>
wrote:
>
> There is no EJBCA running that you can connect to.
>
> Cheers,
> Tomas
>
> On 2014-11-20 09:49, eilaf sorkatti wrote:
> > Hi,
> >
> > I tried again the command
> > bin/ejbca.sh ca importcacert SudanCA p12/SudanCA.pem -initauthorization
> > with ejbca_ce_6_0_4 and jboss as 7 I get these exceptions:
> >
> >
> > javax.naming.CommunicationException: Could not obtain connection to any
> > of these urls: 127.0.0.1:1099 <http://127.0.0.1:1099> and discovery
> > failed with error: javax.naming.CommunicationException: Receive timed
> > out [Root exception is java.net.SocketTimeoutException: Receive timed
> > out] [Root exception is javax.naming.CommunicationException: Failed to
> > connect to server /127.0.0.1:1099 <http://127.0.0.1:1099> [Root
> > exception is javax.naming.ServiceUnavailableException: Failed to connect
> > to server /127.0.0.1:1099 <http://127.0.0.1:1099> [Root exception is
> > java.net.ConnectException: Connection refused]]]
> > at
> org.jnp.interfaces.NamingContext.checkRef(NamingContext.java:1763)
> > at org.jnp.interfaces.NamingContext.lookup(NamingContext.java:693)
> > at org.jnp.interfaces.NamingContext.lookup(NamingContext.java:686)
> > at javax.naming.InitialContext.lookup(InitialContext.java:411)
> > at
> org.ejbca.core.ejb.JndiHelper.getRemoteSession(JndiHelper.java:57)
> > at
> >
> org.ejbca.core.model.util.EjbRemoteHelper.getAdminGroupSession(EjbRemoteHelper.java:94)
> > at
> >
> org.ejbca.ui.cli.ca.BaseCaAdminCommand.initAuthorizationModule(BaseCaAdminCommand.java:161)
> > at
> >
> org.ejbca.ui.cli.ca.CaImportCACertCommand.execute(CaImportCACertCommand.java:61)
> > at org.ejbca.ui.cli.EjbcaEjbCli.executeCommand(EjbcaEjbCli.java:118)
> > at org.ejbca.ui.cli.EjbcaEjbCli.main(EjbcaEjbCli.java:80)
> > Caused by: javax.naming.CommunicationException: Failed to connect to
> > server /127.0.0.1:1099 <http://127.0.0.1:1099> [Root exception is
> > javax.naming.ServiceUnavailableException: Failed to connect to server
> > /127.0.0.1:1099 <http://127.0.0.1:1099> [Root exception is
> > java.net.ConnectException: Connection refused]]
> > at
> org.jnp.interfaces.NamingContext.getServer(NamingContext.java:335)
> > at
> org.jnp.interfaces.NamingContext.checkRef(NamingContext.java:1734)
> > ... 9 more
> > Caused by: javax.naming.ServiceUnavailableException: Failed to connect
> > to server /127.0.0.1:1099 <http://127.0.0.1:1099> [Root exception is
> > java.net.ConnectException: Connection refused]
> > at
> org.jnp.interfaces.NamingContext.getServer(NamingContext.java:305)
> > ... 10 more
> > Caused by: java.net.ConnectException: Connection refused
> > at java.net.PlainSocketImpl.socketConnect(Native Method)
> > at
> >
> java.net.AbstractPlainSocketImpl.doConnect(AbstractPlainSocketImpl.java:339)
> > at
> >
> java.net.AbstractPlainSocketImpl.connectToAddress(AbstractPlainSocketImpl.java:200)
> > at
> >
> java.net.AbstractPlainSocketImpl.connect(AbstractPlainSocketImpl.java:182)
> > at java.net.SocksSocketImpl.connect(SocksSocketImpl.java:392)
> > at java.net.Socket.connect(Socket.java:579)
> > at
> >
> org.jnp.interfaces.TimedSocketFactory.createSocket(TimedSocketFactory.java:97)
> > at
> >
> org.jnp.interfaces.TimedSocketFactory.createSocket(TimedSocketFactory.java:82)
> > at
> org.jnp.interfaces.NamingContext.getServer(NamingContext.java:301)
> > ... 10 more
> > Could not run execute method for class class
> > org.ejbca.ui.cli.ca.CaImportCACertCommand
> > java.lang.NullPointerException
> > at
> >
> org.ejbca.ui.cli.ca.BaseCaAdminCommand.initAuthorizationModule(BaseCaAdminCommand.java:161)
> > at
> >
> org.ejbca.ui.cli.ca.CaImportCACertCommand.execute(CaImportCACertCommand.java:61)
> > at org.ejbca.ui.cli.EjbcaEjbCli.executeCommand(EjbcaEjbCli.java:118)
> > at org.ejbca.ui.cli.EjbcaEjbCli.main(EjbcaEjbCli.java:80)
> >
> >
> > On Tue, Nov 18, 2014 at 1:40 PM, eilaf sorkatti <eil...@gm...
> > <mailto:eil...@gm...>> wrote:
> >
> > Hi,
> >
> >
> > I am using ejbca_4_0_9, jboss5_1_0.GA . trying to use the command
> > bin/ejbca.sh ca importcacert CA1 p12/CA1.pem -initauthorization
> > but i get the message :
> >
> >
> > javax.naming.NameNotFoundException: ejbca not bound
> > at org.jnp.server.NamingServer.getBinding(NamingServer.java:771)
> > at org.jnp.server.NamingServer.getBinding(NamingServer.java:779)
> > at org.jnp.server.NamingServer.getObject(NamingServer.java:785)
> > at org.jnp.server.NamingServer.lookup(NamingServer.java:396)
> > at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
> > at
> >
> sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:57)
> > at
> >
> sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
> > at java.lang.reflect.Method.invoke(Method.java:606)
> > at
> > sun.rmi.server.UnicastServerRef.dispatch(UnicastServerRef.java:322)
> > at sun.rmi.transport.Transport$1.run(Transport.java:177)
> > at sun.rmi.transport.Transport$1.run(Transport.java:174)
> > at java.security.AccessController.doPrivileged(Native Method)
> > at sun.rmi.transport.Transport.serviceCall(Transport.java:173)
> > at
> >
> sun.rmi.transport.tcp.TCPTransport.handleMessages(TCPTransport.java:556)
> > at
> >
> sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.run0(TCPTransport.java:811)
> > at
> >
> sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.run(TCPTransport.java:670)
> > at
> >
> java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1145)
> > at
> >
> java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:615)
> > at java.lang.Thread.run(Thread.java:745)
> > at
> >
> sun.rmi.transport.StreamRemoteCall.exceptionReceivedFromServer(StreamRemoteCall.java:275)
> > at
> >
> sun.rmi.transport.StreamRemoteCall.executeCall(StreamRemoteCall.java:252)
> > at sun.rmi.server.UnicastRef.invoke(UnicastRef.java:161)
> > at org.jnp.server.NamingServer_Stub.lookup(Unknown Source)
> > at
> org.jnp.interfaces.NamingContext.lookup(NamingContext.java:726)
> > at
> org.jnp.interfaces.NamingContext.lookup(NamingContext.java:686)
> > at javax.naming.InitialContext.lookup(InitialContext.java:411)
> > at
> > org.ejbca.core.ejb.JndiHelper.getRemoteSession(JndiHelper.java:57)
> > at
> >
> org.ejbca.core.model.util.EjbRemoteHelper.getAdminGroupSession(EjbRemoteHelper.java:94)
> > at
> >
> org.ejbca.ui.cli.ca.BaseCaAdminCommand.initAuthorizationModule(BaseCaAdminCommand.java:161)
> > at
> >
> org.ejbca.ui.cli.ca.CaImportCACertCommand.execute(CaImportCACertCommand.java:61)
> > at
> > org.ejbca.ui.cli.EjbcaEjbCli.executeCommand(EjbcaEjbCli.java:118)
> > at org.ejbca.ui.cli.EjbcaEjbCli.main(EjbcaEjbCli.java:80)
> > Could not run execute method for class class
> > org.ejbca.ui.cli.ca.CaImportCACertCommand
> > java.lang.NullPointerException
> > at
> >
> org.ejbca.ui.cli.ca.BaseCaAdminCommand.initAuthorizationModule(BaseCaAdminCommand.java:161)
> > at
> >
> org.ejbca.ui.cli.ca.CaImportCACertCommand.execute(CaImportCACertCommand.java:61)
> > at
> > org.ejbca.ui.cli.EjbcaEjbCli.executeCommand(EjbcaEjbCli.java:118)
> > at org.ejbca.ui.cli.EjbcaEjbCli.main(EjbcaEjbCli.java:80)
> >
> >
> > --
> > Eilaf Hamad Elnil Mugbil
> > University Of Khartoum
> > School Of Mathematical science
> >
> >
> >
> >
> > --
> > Eilaf Hamad Elnil Mugbil
> > University Of Khartoum
> > School Of Mathematical science
> >
> >
> >
> ------------------------------------------------------------------------------
> > Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT Server
> > from Actuate! Instantly Supercharge Your Business Reports and Dashboards
> > with Interactivity, Sharing, Native Excel Exports, App Integration & more
> > Get technology previously reserved for billion-dollar corporations, FREE
> >
> http://pubads.g.doubleclick.net/gampad/clk?id=157005751&iu=/4140/ostg.clktrk
> >
> >
> >
> > _______________________________________________
> > Ejbca-develop mailing list
> > Ejb...@li...
> > https://lists.sourceforge.net/lists/listinfo/ejbca-develop
> >
>
>
> ------------------------------------------------------------------------------
> Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT Server
> from Actuate! Instantly Supercharge Your Business Reports and Dashboards
> with Interactivity, Sharing, Native Excel Exports, App Integration & more
> Get technology previously reserved for billion-dollar corporations, FREE
>
> http://pubads.g.doubleclick.net/gampad/clk?id=157005751&iu=/4140/ostg.clktrk
> _______________________________________________
> Ejbca-develop mailing list
> Ejb...@li...
> https://lists.sourceforge.net/lists/listinfo/ejbca-develop
>
--
Eilaf Hamad Elnil Mugbil
University Of Khartoum
School Of Mathematical science
|
|
From: Tomas G. <to...@pr...> - 2014-11-20 08:55:49
|
There is no EJBCA running that you can connect to. Cheers, Tomas On 2014-11-20 09:49, eilaf sorkatti wrote: > Hi, > > I tried again the command > bin/ejbca.sh ca importcacert SudanCA p12/SudanCA.pem -initauthorization > with ejbca_ce_6_0_4 and jboss as 7 I get these exceptions: > > > javax.naming.CommunicationException: Could not obtain connection to any > of these urls: 127.0.0.1:1099 <http://127.0.0.1:1099> and discovery > failed with error: javax.naming.CommunicationException: Receive timed > out [Root exception is java.net.SocketTimeoutException: Receive timed > out] [Root exception is javax.naming.CommunicationException: Failed to > connect to server /127.0.0.1:1099 <http://127.0.0.1:1099> [Root > exception is javax.naming.ServiceUnavailableException: Failed to connect > to server /127.0.0.1:1099 <http://127.0.0.1:1099> [Root exception is > java.net.ConnectException: Connection refused]]] > at org.jnp.interfaces.NamingContext.checkRef(NamingContext.java:1763) > at org.jnp.interfaces.NamingContext.lookup(NamingContext.java:693) > at org.jnp.interfaces.NamingContext.lookup(NamingContext.java:686) > at javax.naming.InitialContext.lookup(InitialContext.java:411) > at org.ejbca.core.ejb.JndiHelper.getRemoteSession(JndiHelper.java:57) > at > org.ejbca.core.model.util.EjbRemoteHelper.getAdminGroupSession(EjbRemoteHelper.java:94) > at > org.ejbca.ui.cli.ca.BaseCaAdminCommand.initAuthorizationModule(BaseCaAdminCommand.java:161) > at > org.ejbca.ui.cli.ca.CaImportCACertCommand.execute(CaImportCACertCommand.java:61) > at org.ejbca.ui.cli.EjbcaEjbCli.executeCommand(EjbcaEjbCli.java:118) > at org.ejbca.ui.cli.EjbcaEjbCli.main(EjbcaEjbCli.java:80) > Caused by: javax.naming.CommunicationException: Failed to connect to > server /127.0.0.1:1099 <http://127.0.0.1:1099> [Root exception is > javax.naming.ServiceUnavailableException: Failed to connect to server > /127.0.0.1:1099 <http://127.0.0.1:1099> [Root exception is > java.net.ConnectException: Connection refused]] > at org.jnp.interfaces.NamingContext.getServer(NamingContext.java:335) > at org.jnp.interfaces.NamingContext.checkRef(NamingContext.java:1734) > ... 9 more > Caused by: javax.naming.ServiceUnavailableException: Failed to connect > to server /127.0.0.1:1099 <http://127.0.0.1:1099> [Root exception is > java.net.ConnectException: Connection refused] > at org.jnp.interfaces.NamingContext.getServer(NamingContext.java:305) > ... 10 more > Caused by: java.net.ConnectException: Connection refused > at java.net.PlainSocketImpl.socketConnect(Native Method) > at > java.net.AbstractPlainSocketImpl.doConnect(AbstractPlainSocketImpl.java:339) > at > java.net.AbstractPlainSocketImpl.connectToAddress(AbstractPlainSocketImpl.java:200) > at > java.net.AbstractPlainSocketImpl.connect(AbstractPlainSocketImpl.java:182) > at java.net.SocksSocketImpl.connect(SocksSocketImpl.java:392) > at java.net.Socket.connect(Socket.java:579) > at > org.jnp.interfaces.TimedSocketFactory.createSocket(TimedSocketFactory.java:97) > at > org.jnp.interfaces.TimedSocketFactory.createSocket(TimedSocketFactory.java:82) > at org.jnp.interfaces.NamingContext.getServer(NamingContext.java:301) > ... 10 more > Could not run execute method for class class > org.ejbca.ui.cli.ca.CaImportCACertCommand > java.lang.NullPointerException > at > org.ejbca.ui.cli.ca.BaseCaAdminCommand.initAuthorizationModule(BaseCaAdminCommand.java:161) > at > org.ejbca.ui.cli.ca.CaImportCACertCommand.execute(CaImportCACertCommand.java:61) > at org.ejbca.ui.cli.EjbcaEjbCli.executeCommand(EjbcaEjbCli.java:118) > at org.ejbca.ui.cli.EjbcaEjbCli.main(EjbcaEjbCli.java:80) > > > On Tue, Nov 18, 2014 at 1:40 PM, eilaf sorkatti <eil...@gm... > <mailto:eil...@gm...>> wrote: > > Hi, > > > I am using ejbca_4_0_9, jboss5_1_0.GA . trying to use the command > bin/ejbca.sh ca importcacert CA1 p12/CA1.pem -initauthorization > but i get the message : > > > javax.naming.NameNotFoundException: ejbca not bound > at org.jnp.server.NamingServer.getBinding(NamingServer.java:771) > at org.jnp.server.NamingServer.getBinding(NamingServer.java:779) > at org.jnp.server.NamingServer.getObject(NamingServer.java:785) > at org.jnp.server.NamingServer.lookup(NamingServer.java:396) > at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method) > at > sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:57) > at > sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43) > at java.lang.reflect.Method.invoke(Method.java:606) > at > sun.rmi.server.UnicastServerRef.dispatch(UnicastServerRef.java:322) > at sun.rmi.transport.Transport$1.run(Transport.java:177) > at sun.rmi.transport.Transport$1.run(Transport.java:174) > at java.security.AccessController.doPrivileged(Native Method) > at sun.rmi.transport.Transport.serviceCall(Transport.java:173) > at > sun.rmi.transport.tcp.TCPTransport.handleMessages(TCPTransport.java:556) > at > sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.run0(TCPTransport.java:811) > at > sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.run(TCPTransport.java:670) > at > java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1145) > at > java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:615) > at java.lang.Thread.run(Thread.java:745) > at > sun.rmi.transport.StreamRemoteCall.exceptionReceivedFromServer(StreamRemoteCall.java:275) > at > sun.rmi.transport.StreamRemoteCall.executeCall(StreamRemoteCall.java:252) > at sun.rmi.server.UnicastRef.invoke(UnicastRef.java:161) > at org.jnp.server.NamingServer_Stub.lookup(Unknown Source) > at org.jnp.interfaces.NamingContext.lookup(NamingContext.java:726) > at org.jnp.interfaces.NamingContext.lookup(NamingContext.java:686) > at javax.naming.InitialContext.lookup(InitialContext.java:411) > at > org.ejbca.core.ejb.JndiHelper.getRemoteSession(JndiHelper.java:57) > at > org.ejbca.core.model.util.EjbRemoteHelper.getAdminGroupSession(EjbRemoteHelper.java:94) > at > org.ejbca.ui.cli.ca.BaseCaAdminCommand.initAuthorizationModule(BaseCaAdminCommand.java:161) > at > org.ejbca.ui.cli.ca.CaImportCACertCommand.execute(CaImportCACertCommand.java:61) > at > org.ejbca.ui.cli.EjbcaEjbCli.executeCommand(EjbcaEjbCli.java:118) > at org.ejbca.ui.cli.EjbcaEjbCli.main(EjbcaEjbCli.java:80) > Could not run execute method for class class > org.ejbca.ui.cli.ca.CaImportCACertCommand > java.lang.NullPointerException > at > org.ejbca.ui.cli.ca.BaseCaAdminCommand.initAuthorizationModule(BaseCaAdminCommand.java:161) > at > org.ejbca.ui.cli.ca.CaImportCACertCommand.execute(CaImportCACertCommand.java:61) > at > org.ejbca.ui.cli.EjbcaEjbCli.executeCommand(EjbcaEjbCli.java:118) > at org.ejbca.ui.cli.EjbcaEjbCli.main(EjbcaEjbCli.java:80) > > > -- > Eilaf Hamad Elnil Mugbil > University Of Khartoum > School Of Mathematical science > > > > > -- > Eilaf Hamad Elnil Mugbil > University Of Khartoum > School Of Mathematical science > > > ------------------------------------------------------------------------------ > Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT Server > from Actuate! Instantly Supercharge Your Business Reports and Dashboards > with Interactivity, Sharing, Native Excel Exports, App Integration & more > Get technology previously reserved for billion-dollar corporations, FREE > http://pubads.g.doubleclick.net/gampad/clk?id=157005751&iu=/4140/ostg.clktrk > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: eilaf s. <eil...@gm...> - 2014-11-20 08:49:59
|
Hi,
I tried again the command
bin/ejbca.sh ca importcacert SudanCA p12/SudanCA.pem -initauthorization
with ejbca_ce_6_0_4 and jboss as 7 I get these exceptions:
javax.naming.CommunicationException: Could not obtain connection to any of
these urls: 127.0.0.1:1099 and discovery failed with error:
javax.naming.CommunicationException: Receive timed out [Root exception is
java.net.SocketTimeoutException: Receive timed out] [Root exception is
javax.naming.CommunicationException: Failed to connect to server /
127.0.0.1:1099 [Root exception is javax.naming.ServiceUnavailableException:
Failed to connect to server /127.0.0.1:1099 [Root exception is
java.net.ConnectException: Connection refused]]]
at org.jnp.interfaces.NamingContext.checkRef(NamingContext.java:1763)
at org.jnp.interfaces.NamingContext.lookup(NamingContext.java:693)
at org.jnp.interfaces.NamingContext.lookup(NamingContext.java:686)
at javax.naming.InitialContext.lookup(InitialContext.java:411)
at org.ejbca.core.ejb.JndiHelper.getRemoteSession(JndiHelper.java:57)
at
org.ejbca.core.model.util.EjbRemoteHelper.getAdminGroupSession(EjbRemoteHelper.java:94)
at
org.ejbca.ui.cli.ca.BaseCaAdminCommand.initAuthorizationModule(BaseCaAdminCommand.java:161)
at
org.ejbca.ui.cli.ca.CaImportCACertCommand.execute(CaImportCACertCommand.java:61)
at org.ejbca.ui.cli.EjbcaEjbCli.executeCommand(EjbcaEjbCli.java:118)
at org.ejbca.ui.cli.EjbcaEjbCli.main(EjbcaEjbCli.java:80)
Caused by: javax.naming.CommunicationException: Failed to connect to server
/127.0.0.1:1099 [Root exception is
javax.naming.ServiceUnavailableException: Failed to connect to server /
127.0.0.1:1099 [Root exception is java.net.ConnectException: Connection
refused]]
at org.jnp.interfaces.NamingContext.getServer(NamingContext.java:335)
at org.jnp.interfaces.NamingContext.checkRef(NamingContext.java:1734)
... 9 more
Caused by: javax.naming.ServiceUnavailableException: Failed to connect to
server /127.0.0.1:1099 [Root exception is java.net.ConnectException:
Connection refused]
at org.jnp.interfaces.NamingContext.getServer(NamingContext.java:305)
... 10 more
Caused by: java.net.ConnectException: Connection refused
at java.net.PlainSocketImpl.socketConnect(Native Method)
at
java.net.AbstractPlainSocketImpl.doConnect(AbstractPlainSocketImpl.java:339)
at
java.net.AbstractPlainSocketImpl.connectToAddress(AbstractPlainSocketImpl.java:200)
at
java.net.AbstractPlainSocketImpl.connect(AbstractPlainSocketImpl.java:182)
at java.net.SocksSocketImpl.connect(SocksSocketImpl.java:392)
at java.net.Socket.connect(Socket.java:579)
at
org.jnp.interfaces.TimedSocketFactory.createSocket(TimedSocketFactory.java:97)
at
org.jnp.interfaces.TimedSocketFactory.createSocket(TimedSocketFactory.java:82)
at org.jnp.interfaces.NamingContext.getServer(NamingContext.java:301)
... 10 more
Could not run execute method for class class
org.ejbca.ui.cli.ca.CaImportCACertCommand
java.lang.NullPointerException
at
org.ejbca.ui.cli.ca.BaseCaAdminCommand.initAuthorizationModule(BaseCaAdminCommand.java:161)
at
org.ejbca.ui.cli.ca.CaImportCACertCommand.execute(CaImportCACertCommand.java:61)
at org.ejbca.ui.cli.EjbcaEjbCli.executeCommand(EjbcaEjbCli.java:118)
at org.ejbca.ui.cli.EjbcaEjbCli.main(EjbcaEjbCli.java:80)
On Tue, Nov 18, 2014 at 1:40 PM, eilaf sorkatti <eil...@gm...>
wrote:
> Hi,
>
>
> I am using ejbca_4_0_9, jboss5_1_0.GA . trying to use the command
> bin/ejbca.sh ca importcacert CA1 p12/CA1.pem -initauthorization
> but i get the message :
>
>
> javax.naming.NameNotFoundException: ejbca not bound
> at org.jnp.server.NamingServer.getBinding(NamingServer.java:771)
> at org.jnp.server.NamingServer.getBinding(NamingServer.java:779)
> at org.jnp.server.NamingServer.getObject(NamingServer.java:785)
> at org.jnp.server.NamingServer.lookup(NamingServer.java:396)
> at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
> at
> sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:57)
> at
> sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
> at java.lang.reflect.Method.invoke(Method.java:606)
> at sun.rmi.server.UnicastServerRef.dispatch(UnicastServerRef.java:322)
> at sun.rmi.transport.Transport$1.run(Transport.java:177)
> at sun.rmi.transport.Transport$1.run(Transport.java:174)
> at java.security.AccessController.doPrivileged(Native Method)
> at sun.rmi.transport.Transport.serviceCall(Transport.java:173)
> at
> sun.rmi.transport.tcp.TCPTransport.handleMessages(TCPTransport.java:556)
> at
> sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.run0(TCPTransport.java:811)
> at
> sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.run(TCPTransport.java:670)
> at
> java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1145)
> at
> java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:615)
> at java.lang.Thread.run(Thread.java:745)
> at
> sun.rmi.transport.StreamRemoteCall.exceptionReceivedFromServer(StreamRemoteCall.java:275)
> at
> sun.rmi.transport.StreamRemoteCall.executeCall(StreamRemoteCall.java:252)
> at sun.rmi.server.UnicastRef.invoke(UnicastRef.java:161)
> at org.jnp.server.NamingServer_Stub.lookup(Unknown Source)
> at org.jnp.interfaces.NamingContext.lookup(NamingContext.java:726)
> at org.jnp.interfaces.NamingContext.lookup(NamingContext.java:686)
> at javax.naming.InitialContext.lookup(InitialContext.java:411)
> at org.ejbca.core.ejb.JndiHelper.getRemoteSession(JndiHelper.java:57)
> at
> org.ejbca.core.model.util.EjbRemoteHelper.getAdminGroupSession(EjbRemoteHelper.java:94)
> at
> org.ejbca.ui.cli.ca.BaseCaAdminCommand.initAuthorizationModule(BaseCaAdminCommand.java:161)
> at
> org.ejbca.ui.cli.ca.CaImportCACertCommand.execute(CaImportCACertCommand.java:61)
> at org.ejbca.ui.cli.EjbcaEjbCli.executeCommand(EjbcaEjbCli.java:118)
> at org.ejbca.ui.cli.EjbcaEjbCli.main(EjbcaEjbCli.java:80)
> Could not run execute method for class class
> org.ejbca.ui.cli.ca.CaImportCACertCommand
> java.lang.NullPointerException
> at
> org.ejbca.ui.cli.ca.BaseCaAdminCommand.initAuthorizationModule(BaseCaAdminCommand.java:161)
> at
> org.ejbca.ui.cli.ca.CaImportCACertCommand.execute(CaImportCACertCommand.java:61)
> at org.ejbca.ui.cli.EjbcaEjbCli.executeCommand(EjbcaEjbCli.java:118)
> at org.ejbca.ui.cli.EjbcaEjbCli.main(EjbcaEjbCli.java:80)
>
>
> --
> Eilaf Hamad Elnil Mugbil
> University Of Khartoum
> School Of Mathematical science
>
--
Eilaf Hamad Elnil Mugbil
University Of Khartoum
School Of Mathematical science
|
|
From: Michael S. <mi...@st...> - 2014-11-18 15:57:50
|
Branko Majic <br...@ma...> wrote > Michael Ströder <mi...@st...> wrote: > > Maybe it's a dumb question. But looking at the architecture [1] it's not > > clear to me which protocol is used by the CA to publish data to an external > > OCSP responder. > > Publishing is done directly to an OCSP database. Yes, got it working in the mean-time. Can I configure multiple OCSP connections in va-publisher.properties? Or is everybody using the DB's own replication? Is the use of client certs for DB connections supported? Ciao, Michael. |
|
From: Branko M. <br...@ma...> - 2014-11-18 15:49:21
|
On Tue, 18 Nov 2014 09:43:29 +0100 Michael Ströder <mi...@st...> wrote: > HI! > > Maybe it's a dumb question. But looking at the architecture [1] it's not clear > to me which protocol is used by the CA to publish data to an external OCSP > responder. > > Ciao, Michael. > > [1] http://www.ejbca.org/docs/architecture.html > Publishing is done directly to an OCSP database. Best regards -- Branko Majic Jabber: br...@ma... Please use only Free formats when sending attachments to me. Бранко Мајић Џабер: br...@ma... Молим вас да додатке шаљете искључиво у слободним форматима. |
|
From: Andreas K. <ku...@tr...> - 2014-11-18 11:49:24
|
Hi Tomas, > How are you remote controling the GUI? Sounds cool. GUI-remoting is not really cool ... At the wire level even a fency web page is just an HTTP endpoint and with a POST you can push your stuff into the system ... I use a simple XSL stylesheet to extract relevant information ( e.g. JSF view state) from a page and merge it with the target data. Post the request ... an a new CA is born ;-) > We'll introduce new features as the business cases and needs arise. No > immediate plans for other upload functionality. OK, so no major redesign in the pipeline, currently ... > In Enterprise edition there is a separate tool for dumping and importing > a whole installation (except keys) for easily moving from say acceptance > environment to production. Ah, interesting! That's an important feature I was missing ever since! My current focus is to set up a complex test CA for an OASIS DSS test bed. This has to be open sourced so the enterprise edition is not an option. But I'll keep it in mind for other occasions! Greetings, Andreas -- Andreas Kühne phone: +49 177 293 24 97 mailto: ku...@tr... Trustable Ltd. Niederlassung Deutschland Ströverstr. 18 - 59427 Unna Amtsgericht Hamm HRB 5868 Directors Andreas Kühne, Heiko Veit Company UK Company No: 5218868 Registered in England and Wales |
|
From: eilaf s. <eil...@gm...> - 2014-11-18 10:41:05
|
Hi,
I am using ejbca_4_0_9, jboss5_1_0.GA . trying to use the command
bin/ejbca.sh ca importcacert CA1 p12/CA1.pem -initauthorization
but i get the message :
javax.naming.NameNotFoundException: ejbca not bound
at org.jnp.server.NamingServer.getBinding(NamingServer.java:771)
at org.jnp.server.NamingServer.getBinding(NamingServer.java:779)
at org.jnp.server.NamingServer.getObject(NamingServer.java:785)
at org.jnp.server.NamingServer.lookup(NamingServer.java:396)
at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
at
sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:57)
at
sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
at java.lang.reflect.Method.invoke(Method.java:606)
at sun.rmi.server.UnicastServerRef.dispatch(UnicastServerRef.java:322)
at sun.rmi.transport.Transport$1.run(Transport.java:177)
at sun.rmi.transport.Transport$1.run(Transport.java:174)
at java.security.AccessController.doPrivileged(Native Method)
at sun.rmi.transport.Transport.serviceCall(Transport.java:173)
at
sun.rmi.transport.tcp.TCPTransport.handleMessages(TCPTransport.java:556)
at
sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.run0(TCPTransport.java:811)
at
sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.run(TCPTransport.java:670)
at
java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1145)
at
java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:615)
at java.lang.Thread.run(Thread.java:745)
at
sun.rmi.transport.StreamRemoteCall.exceptionReceivedFromServer(StreamRemoteCall.java:275)
at
sun.rmi.transport.StreamRemoteCall.executeCall(StreamRemoteCall.java:252)
at sun.rmi.server.UnicastRef.invoke(UnicastRef.java:161)
at org.jnp.server.NamingServer_Stub.lookup(Unknown Source)
at org.jnp.interfaces.NamingContext.lookup(NamingContext.java:726)
at org.jnp.interfaces.NamingContext.lookup(NamingContext.java:686)
at javax.naming.InitialContext.lookup(InitialContext.java:411)
at org.ejbca.core.ejb.JndiHelper.getRemoteSession(JndiHelper.java:57)
at
org.ejbca.core.model.util.EjbRemoteHelper.getAdminGroupSession(EjbRemoteHelper.java:94)
at
org.ejbca.ui.cli.ca.BaseCaAdminCommand.initAuthorizationModule(BaseCaAdminCommand.java:161)
at
org.ejbca.ui.cli.ca.CaImportCACertCommand.execute(CaImportCACertCommand.java:61)
at org.ejbca.ui.cli.EjbcaEjbCli.executeCommand(EjbcaEjbCli.java:118)
at org.ejbca.ui.cli.EjbcaEjbCli.main(EjbcaEjbCli.java:80)
Could not run execute method for class class
org.ejbca.ui.cli.ca.CaImportCACertCommand
java.lang.NullPointerException
at
org.ejbca.ui.cli.ca.BaseCaAdminCommand.initAuthorizationModule(BaseCaAdminCommand.java:161)
at
org.ejbca.ui.cli.ca.CaImportCACertCommand.execute(CaImportCACertCommand.java:61)
at org.ejbca.ui.cli.EjbcaEjbCli.executeCommand(EjbcaEjbCli.java:118)
at org.ejbca.ui.cli.EjbcaEjbCli.main(EjbcaEjbCli.java:80)
--
Eilaf Hamad Elnil Mugbil
University Of Khartoum
School Of Mathematical science
|
|
From: BARINDER P. S. <pal...@gm...> - 2014-11-18 09:08:40
|
Thanks Michael and Tomas, yes the url was wrong But now i am getting the following error on the client side ejbca@ejbca:~/cmpforopenssl-code-766/src/openssl-client$ ./cmpclient --server localhost --port 8080 --path ejbca/publicweb/cmp/vmware --srvcert ManagementCA.cacert.pem --ir --user vmware --password vmware --newclcert user1.der --newkey user_key.pem --subject "CN=vmware,C=SC" INFO: Reading DER Certificate from File ManagementCA.cacert.pem SUCCESS: BIO_new INFO: Unable to read certificate in DER format, trying PEM... INFO: Reading PEM Certificate from File ManagementCA.cacert.pem SUCCESS: BIO_new INFO: Using existing key file "user_key.pem" INFO: Reading Public Key from File user_key.pem INFO: the passphrase is ""... SUCCESS: Reading PKEY INFO: Sending Initialization Request ERROR: received no initial Client Certificate. FILE cmpclient.c, LINE 394 140725023463072:error:3209608B:CMP routines:CMP_doInitialRequestSeq:pkibody error:cmp_ses.c:381:bodytype=23, error="PKIStatus: rejection, PKIFailureInfo: badMessageCheck: Could not extract password from CRMF request using the RegTokenPwd authentication module" ejbca@ejbca:~/cmpforopenssl-code-766/src/openssl-client$ and the following error on the EJBCA VM server logs 15:48:59,073 INFO [org.ejbca.ui.web.protocol.CmpServlet] (http--0.0.0.0-8080-1) CMP message received from: 127.0.0.1, for CMP alias: vmware 15:48:59,136 INFO [org.ejbca.core.protocol.cmp.CrmfMessageHandler] (http--0.0.0.0-8080-1) Could not extract password from CRMF request using the RegTokenPwd authentication module 15:48:59,157 INFO [org.ejbca.ui.web.protocol.CmpServlet] (http--0.0.0.0-8080-1) Sent a CMP response to: 127.0.0.1, process time 84. I am getting no clue what is wrong, please suggest Thanks Barinder On Tue, Nov 18, 2014 at 1:52 PM, Michael Ströder <mi...@st...> wrote: > Which version of EJBCA are you using? > > BARINDER PAL SINGH wrote: > > ejbca@ejbca:~/cmpforopenssl-code-766/src/openssl-client$ ./cmpclient > > --server localhost --port 8080 --path ejbca/public/cmp > > Are you sure that the value for --path is correct? I can see this path > value > mentioned at the example on this page but it might be outdated: > http://blog.ejbca.org/2014/01/using-cmp-with-cmp-for-openssl-tool-to.html > > In my working example I have: > > --path ejbca/publicweb/cmp/CMP_Server > > where "ejbca/publicweb/" is the base URL of the public web interface and > "CMP_Server" is the CMP configuration alias. > > In case you're using 6.x see also: > http://blog.ejbca.org/2013/09/whats-new-in-ejbca-6-part-2-cmp-aliases.html > > Ciao, Michael. > > > > ------------------------------------------------------------------------------ > Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT Server > from Actuate! Instantly Supercharge Your Business Reports and Dashboards > with Interactivity, Sharing, Native Excel Exports, App Integration & more > Get technology previously reserved for billion-dollar corporations, FREE > > http://pubads.g.doubleclick.net/gampad/clk?id=157005751&iu=/4140/ostg.clktrk > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > |