You can subscribe to this list here.
| 2001 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
(1) |
Dec
(3) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2002 |
Jan
(3) |
Feb
(2) |
Mar
(8) |
Apr
(3) |
May
(6) |
Jun
(1) |
Jul
(15) |
Aug
(6) |
Sep
|
Oct
(10) |
Nov
(2) |
Dec
(4) |
| 2003 |
Jan
(1) |
Feb
(7) |
Mar
(3) |
Apr
(6) |
May
(7) |
Jun
(5) |
Jul
(5) |
Aug
(25) |
Sep
(14) |
Oct
(2) |
Nov
|
Dec
(2) |
| 2004 |
Jan
(7) |
Feb
(4) |
Mar
(12) |
Apr
(16) |
May
(43) |
Jun
(56) |
Jul
(43) |
Aug
(40) |
Sep
(66) |
Oct
(12) |
Nov
(26) |
Dec
(10) |
| 2005 |
Jan
(13) |
Feb
(33) |
Mar
(16) |
Apr
(7) |
May
(10) |
Jun
(34) |
Jul
(41) |
Aug
(8) |
Sep
(4) |
Oct
(32) |
Nov
(20) |
Dec
(25) |
| 2006 |
Jan
(30) |
Feb
(101) |
Mar
(5) |
Apr
(75) |
May
(74) |
Jun
(22) |
Jul
(6) |
Aug
(70) |
Sep
(19) |
Oct
(21) |
Nov
(31) |
Dec
(50) |
| 2007 |
Jan
(15) |
Feb
(20) |
Mar
(24) |
Apr
(33) |
May
(13) |
Jun
(18) |
Jul
(13) |
Aug
(7) |
Sep
(63) |
Oct
(68) |
Nov
(29) |
Dec
(68) |
| 2008 |
Jan
(30) |
Feb
(33) |
Mar
(30) |
Apr
(103) |
May
(78) |
Jun
(48) |
Jul
(72) |
Aug
(24) |
Sep
(62) |
Oct
(63) |
Nov
(70) |
Dec
(37) |
| 2009 |
Jan
(34) |
Feb
(35) |
Mar
(64) |
Apr
(34) |
May
(34) |
Jun
(58) |
Jul
(30) |
Aug
(30) |
Sep
(46) |
Oct
(52) |
Nov
(12) |
Dec
(23) |
| 2010 |
Jan
(121) |
Feb
(18) |
Mar
(53) |
Apr
(62) |
May
(62) |
Jun
(20) |
Jul
(33) |
Aug
(20) |
Sep
(36) |
Oct
(35) |
Nov
(44) |
Dec
(63) |
| 2011 |
Jan
(19) |
Feb
(32) |
Mar
(94) |
Apr
(41) |
May
(47) |
Jun
(25) |
Jul
(34) |
Aug
(20) |
Sep
(9) |
Oct
(41) |
Nov
(33) |
Dec
(24) |
| 2012 |
Jan
(12) |
Feb
(36) |
Mar
(48) |
Apr
(32) |
May
(20) |
Jun
(15) |
Jul
(32) |
Aug
(13) |
Sep
(33) |
Oct
(54) |
Nov
(25) |
Dec
(16) |
| 2013 |
Jan
(45) |
Feb
(39) |
Mar
(38) |
Apr
(50) |
May
(29) |
Jun
(30) |
Jul
(33) |
Aug
(12) |
Sep
(9) |
Oct
(25) |
Nov
(29) |
Dec
(20) |
| 2014 |
Jan
(25) |
Feb
(19) |
Mar
(16) |
Apr
(33) |
May
(27) |
Jun
(37) |
Jul
(29) |
Aug
(27) |
Sep
(37) |
Oct
(58) |
Nov
(109) |
Dec
(26) |
| 2015 |
Jan
(4) |
Feb
(35) |
Mar
(22) |
Apr
(35) |
May
(28) |
Jun
(20) |
Jul
(4) |
Aug
(16) |
Sep
(37) |
Oct
(13) |
Nov
(13) |
Dec
(14) |
| 2016 |
Jan
(22) |
Feb
(7) |
Mar
(23) |
Apr
(30) |
May
(10) |
Jun
(10) |
Jul
(15) |
Aug
(12) |
Sep
(22) |
Oct
(31) |
Nov
(5) |
Dec
(5) |
| 2017 |
Jan
(30) |
Feb
(25) |
Mar
(28) |
Apr
(4) |
May
(19) |
Jun
(13) |
Jul
(7) |
Aug
(1) |
Sep
(2) |
Oct
(5) |
Nov
(12) |
Dec
(2) |
| 2018 |
Jan
(7) |
Feb
|
Mar
(7) |
Apr
(2) |
May
(8) |
Jun
(18) |
Jul
(6) |
Aug
(3) |
Sep
(15) |
Oct
(33) |
Nov
(13) |
Dec
(7) |
| 2019 |
Jan
(5) |
Feb
(7) |
Mar
(30) |
Apr
(5) |
May
(4) |
Jun
(69) |
Jul
(86) |
Aug
(22) |
Sep
(6) |
Oct
(7) |
Nov
(5) |
Dec
(3) |
| 2020 |
Jan
(10) |
Feb
(12) |
Mar
(22) |
Apr
(5) |
May
(1) |
Jun
(4) |
Jul
(6) |
Aug
|
Sep
(9) |
Oct
|
Nov
|
Dec
(1) |
| 2021 |
Jan
(4) |
Feb
(11) |
Mar
(7) |
Apr
(7) |
May
|
Jun
(3) |
Jul
(10) |
Aug
(6) |
Sep
|
Oct
|
Nov
(18) |
Dec
(2) |
| 2022 |
Jan
(1) |
Feb
(1) |
Mar
|
Apr
|
May
|
Jun
(2) |
Jul
|
Aug
(4) |
Sep
|
Oct
|
Nov
|
Dec
|
| 2023 |
Jan
|
Feb
|
Mar
|
Apr
(1) |
May
(1) |
Jun
|
Jul
|
Aug
(5) |
Sep
|
Oct
|
Nov
|
Dec
|
|
From: Michael S. <mi...@st...> - 2014-11-18 08:43:43
|
HI! Maybe it's a dumb question. But looking at the architecture [1] it's not clear to me which protocol is used by the CA to publish data to an external OCSP responder. Ciao, Michael. [1] http://www.ejbca.org/docs/architecture.html |
|
From: Tomas G. <to...@pr...> - 2014-11-18 08:35:17
|
Hi, If there are any people in Sweden on this list, here is a nice (free) event that will be held next week in Stockholm. EJBCA will be mentioned, and talks will be in English. Regards, Tomas -------- Forwarded Message -------- Subject: [Foss-sthlm-announce] Påminnelse Techday by Init 2014 den 27:e november Date: Tue, 18 Nov 2014 09:26:42 +0100 From: Claes Jakobsson <cl...@su...> To: FOSS-folk i Stockholm <fos...@co...> CC: fos...@co... Hej, en liten påminnelse om Techday by Init 2014 nästa torsdag den 27:e. Nu är talarlistan på plats och i år har vi: Universal 2nd Factor (U2F) - Simon Josefsson, Yubico Spiralbunden säkerhet - Patrik Järnefelt, Blocket AB & Daniel Gustafsson, SCM Ventures AB PKI, an enabler of business - Tomas Gustavsson, Primekey Securing web based applications in PostgreSQL - Magnus Hagander, Redpill Linpro Network Segmentation: When information security is a business and technology enabler - Fredrik Söderblom, XPD Securing your system with AppArmor & SELinux - SUSE Security Team Incident response and forensic investigations is always a challenge - Robert Malmgren, ROMAB/sysctl Varnish Security Firewall - Kacper Wysocki, Redpill Linpro Antalet platser är begränsat men det finns ännu gott om plats kvar. Anmälan via Meetup på http://www.meetup.com/Techday-by-Init/events/214720932/ /Claes |
|
From: Michael S. <mi...@st...> - 2014-11-18 08:22:22
|
Which version of EJBCA are you using? BARINDER PAL SINGH wrote: > ejbca@ejbca:~/cmpforopenssl-code-766/src/openssl-client$ ./cmpclient > --server localhost --port 8080 --path ejbca/public/cmp Are you sure that the value for --path is correct? I can see this path value mentioned at the example on this page but it might be outdated: http://blog.ejbca.org/2014/01/using-cmp-with-cmp-for-openssl-tool-to.html In my working example I have: --path ejbca/publicweb/cmp/CMP_Server where "ejbca/publicweb/" is the base URL of the public web interface and "CMP_Server" is the CMP configuration alias. In case you're using 6.x see also: http://blog.ejbca.org/2013/09/whats-new-in-ejbca-6-part-2-cmp-aliases.html Ciao, Michael. |
|
From: Tomas G. <to...@pr...> - 2014-11-18 08:16:45
|
You should check what errors you have on the server side. See http://ejbca.org/docs/adminguide.html#Troubleshooting Regards, Tomas --- Save time and money with an Enterprise support subscription. Please see www.primekey.se for more information. http://www.primekey.se/Products/EJBCA+PKI/ http://www.primekey.se/Services/Support/ On 2014-11-18 09:10, BARINDER PAL SINGH wrote: > Hello, > > I am using the CMP client patch for OPENSSL and trying to get the > certificate from the EJBCA VM deployed on the server > > I have configured the following things > > > Pre-registered client with password authentication > > * Download the CA certificate to the client(downloaded the existing > ManagementCA certificate and have put this CA certificate in the > location where CMP client code is compiled) > * Add a new end entity in EJBCA(added an end entity with the username > name: vmware and password:vmware) > * Run the command > > ejbca@ejbca:~/cmpforopenssl-code-766/src/openssl-client$ ./cmpclient > --server localhost --port 8080 --path ejbca/public/cmp --srvcert > ManagementCA.cacert.pem --ir --user vmware --password vmware --newclcert > user1.der --newkey user_key.pem --subject "CN=vmware,C=SC" > > But i am getting the following error > > ejbca@ejbca:~/cmpforopenssl-code-766/src/openssl-client$ ./cmpclient > --server localhost --port 8080 --path ejbca/public/cmp --srvcert > ManagementCA.cacert.pem --ir --user vmware --password vmware --newclcert > user1.der --newkey user_key.pem --subject "CN=vmware,C=SC" > INFO: Reading DER Certificate from File ManagementCA.cacert.pem > SUCCESS: BIO_new > INFO: Unable to read certificate in DER format, trying PEM... > INFO: Reading PEM Certificate from File ManagementCA.cacert.pem > SUCCESS: BIO_new > INFO: Using existing key file "user_key.pem" > INFO: Reading Public Key from File user_key.pem > INFO: the passphrase is ""... > SUCCESS: Reading PKEY > INFO: Sending Initialization Request > ERROR: received no initial Client Certificate. FILE cmpclient.c, LINE 394 > 139753323554464:error:3209D07F:CMP > routines:CMP_PKIMESSAGE_http_perform:invalid content type:cmp_http.c:906: > 139753323554464:error:32096083:CMP routines:CMP_doInitialRequestSeq:ip > not received:cmp_ses.c:373: > > > > Also i have configured the following configuration > The above requires a CMP alias in EJBCA with the following > configuration:(cmp alias with the name vmware) > > * Client mode > * HMAC > <http://en.wikipedia.org/wiki/Hash-based_message_authentication_code> authentication > module > * CN as extract username component > > Can you please suggest what might be wrong in the above configuration. > > Thanks in Advance > Barinder > > > ------------------------------------------------------------------------------ > Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT Server > from Actuate! Instantly Supercharge Your Business Reports and Dashboards > with Interactivity, Sharing, Native Excel Exports, App Integration & more > Get technology previously reserved for billion-dollar corporations, FREE > http://pubads.g.doubleclick.net/gampad/clk?id=157005751&iu=/4140/ostg.clktrk > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Tomas G. <to...@pr...> - 2014-11-18 08:14:29
|
Hi, How are you remote controling the GUI? Sounds cool. We'll introduce new features as the business cases and needs arise. No immediate plans for other upload functionality. In Enterprise edition there is a separate tool for dumping and importing a whole installation (except keys) for easily moving from say acceptance environment to production. Cheers, Tomas On 2014-11-17 15:56, Andreas Kuehne wrote: > Hi folks, > > as I can see in the recent version of ejbca you are using a new style of > GUI implementation. This new approach makes it a bit harder for me to > 'remote control' the GUI. But I'm happy to see that you introduced a > 'bulk upload' of certificate profiles. That's very handy! Do you plan to > introduce such an upload functionality for the other administration > aspects, too? > > Greetings, > > Andreas > |
|
From: BARINDER P. S. <pal...@gm...> - 2014-11-18 08:11:02
|
Hello, I am using the CMP client patch for OPENSSL and trying to get the certificate from the EJBCA VM deployed on the server I have configured the following things Pre-registered client with password authentication - Download the CA certificate to the client(downloaded the existing ManagementCA certificate and have put this CA certificate in the location where CMP client code is compiled) - Add a new end entity in EJBCA(added an end entity with the username name: vmware and password:vmware) - Run the command ejbca@ejbca:~/cmpforopenssl-code-766/src/openssl-client$ ./cmpclient --server localhost --port 8080 --path ejbca/public/cmp --srvcert ManagementCA.cacert.pem --ir --user vmware --password vmware --newclcert user1.der --newkey user_key.pem --subject "CN=vmware,C=SC" But i am getting the following error ejbca@ejbca:~/cmpforopenssl-code-766/src/openssl-client$ ./cmpclient --server localhost --port 8080 --path ejbca/public/cmp --srvcert ManagementCA.cacert.pem --ir --user vmware --password vmware --newclcert user1.der --newkey user_key.pem --subject "CN=vmware,C=SC" INFO: Reading DER Certificate from File ManagementCA.cacert.pem SUCCESS: BIO_new INFO: Unable to read certificate in DER format, trying PEM... INFO: Reading PEM Certificate from File ManagementCA.cacert.pem SUCCESS: BIO_new INFO: Using existing key file "user_key.pem" INFO: Reading Public Key from File user_key.pem INFO: the passphrase is ""... SUCCESS: Reading PKEY INFO: Sending Initialization Request ERROR: received no initial Client Certificate. FILE cmpclient.c, LINE 394 139753323554464:error:3209D07F:CMP routines:CMP_PKIMESSAGE_http_perform:invalid content type:cmp_http.c:906: 139753323554464:error:32096083:CMP routines:CMP_doInitialRequestSeq:ip not received:cmp_ses.c:373: Also i have configured the following configuration The above requires a CMP alias in EJBCA with the following configuration:(cmp alias with the name vmware) - Client mode - HMAC <http://en.wikipedia.org/wiki/Hash-based_message_authentication_code> authentication module - CN as extract username component Can you please suggest what might be wrong in the above configuration. Thanks in Advance Barinder |
|
From: Michael S. <mi...@st...> - 2014-11-17 15:18:13
|
Michael Ströder wrote: > It seems something was removed from SVN recently. > [..] > java.io.FileNotFoundException: /opt/ejbca/modules/externalra-scep/build.xml (No > such file or directory) Seems this has been re-added in revision 20256. Ciao, Michael. |
|
From: Andreas K. <ku...@tr...> - 2014-11-17 15:05:48
|
Hi folks, as I can see in the recent version of ejbca you are using a new style of GUI implementation. This new approach makes it a bit harder for me to 'remote control' the GUI. But I'm happy to see that you introduced a 'bulk upload' of certificate profiles. That's very handy! Do you plan to introduce such an upload functionality for the other administration aspects, too? Greetings, Andreas -- Andreas Kühne phone: +49 177 293 24 97 mailto: ku...@tr... Trustable Ltd. Niederlassung Deutschland Ströverstr. 18 - 59427 Unna Amtsgericht Hamm HRB 5868 Directors Andreas Kühne, Heiko Veit Company UK Company No: 5218868 Registered in England and Wales |
|
From: Liliana C. <lil...@bu...> - 2014-11-17 14:36:15
|
Hi Tomas, I've verified the operation creating an end entity and user certificate, and there is no problem. Even if the RA sees "No publishers defined" in his Home page, the user certificates is published to the publisher defined in the certificate profile. Best regards, Liliana Cabalantti Bull, Architect of an Open WorldT BSS/TrustWay Tél : +33 1 30 80 63 95 Fax : +33 1 30 80 63 40 lil...@bu... -----Message d'origine----- De : Tomas Gustavsson [mailto:to...@pr...] Envoyé : vendredi 14 novembre 2014 10:18 À : Liliana Cabalantti Objet : Re: RE : [Ejbca-develop] RA in charge of creating end entities for user certificate and Publisher Hi Liliana, I have no immediate idea without looking into the code, or testing myself. It can be hard to get answers to questions that requires anyone to spend time on digging, especially for old versions of EJBCA. If BUll got a support contract there would be immediate SLA of course :-) Kind regards, Tomas ********** PrimeKey Solutions AB Anderstorpsvägen 16, 171 54 Solna, Sweden Mob: +46 (0)707421096 Internet: www.primekey.se Twitter: twitter.com/primekeyPKI ********** On 2014-11-13 16:33, Liliana Cabalantti wrote: > Yes, I know. Any ideas about my problem ? > > Best regards, > > Liliana Cabalantti > Bull, Architect of an Open WorldT > BSS/TrustWay > Tél : +33 1 30 80 63 95 > Fax : +33 1 30 80 63 40 > lil...@bu... > > > -----Message d'origine----- > De : Tomas Gustavsson [mailto:to...@pr...] Envoyé : jeudi 13 > novembre 2014 07:50 À : Liliana Cabalantti Objet : Re: RE : > [Ejbca-develop] RA in charge of creating end entities for user > certificate and Publisher > > > Ah cool. We've been talking to him. > > Cheers, > Tomas > > On 2014-11-13 07:27, Liliana Cabalantti wrote: >> Yes, we both work in TrustWay BU. >> >> Best regards, >> ________________________________________ >> De : Tomas Gustavsson [to...@pr...] Date d'envoi : mercredi 12 >> novembre 2014 23:27 À : Liliana Cabalantti Objet : Re: >> [Ejbca-develop] RA in charge of creating end entities for user >> certificate and Publisher >> >> Hi Liliana, >> >> Just a question, since you are working at Bull. Do you know Max Tu-Ba >> at Bull? >> >> Kind Regards, >> Tomas Gustavsson >> ********** >> PrimeKey Solutions AB >> Anderstorpsvägen 16, 171 54 Solna, Sweden >> Mob: +46 (0)707421096 >> Internet: www.primekey.se >> Twitter: twitter.com/primekeyPKI >> ********** >> On 2014-11-12 10:55, Liliana Cabalantti wrote: >>> Hello, >>> >>> I'm working with ejbca_ce_6_0_3 and jboss-as-7.1.1.Final. I'll try >>> to better explain my problem. >>> >>> I've created a RA Administrator in charge of creation end entities >>> for user certificates with the following Access Rules: >>> >>> ·Authorized CAs : MedusaUserCA >>> >>> ·End entity Profiles: User End Entity Profile >>> >>> User End Entity Profile is defined as follows: >>> >>> ·Default Certificate Profile: User Cert Profile >>> >>> ·Available Profiles: User Cert Profile >>> >>> ·Default CA : MedusaUserCA >>> >>> ·Available Cas : MedusaUserCA >>> >>> User Cert Profile is defined as follows: >>> >>> ·Available CAs: MedusaUserCA >>> >>> ·Publishers: MyPublisher >>> >>> I created an end entity and user certificate for the RA. >>> >>> When I connect to adminweb with the RA credentials, I obtain: >>> >>> *Why "No publishers defined" ?* >>> >>> Thanks for your help. >>> >>> Best regards, >>> >>> Liliana Cabalantti >>> >>> Bull, Architect of an Open WorldT >>> >>> BSS/TrustWay >>> >>> Tél : +33 1 30 80 63 95 >>> >>> Fax : +33 1 30 80 63 40 >>> >>> lil...@bu... <mailto:lil...@bu...> >>> >>> BULL_logo >>> >>> >>> >>> -------------------------------------------------------------------- >>> - >>> --------- Comprehensive Server Monitoring with Site24x7. >>> Monitor 10 servers for $9/Month. >>> Get alerted through email, SMS, voice calls or mobile push notifications. >>> Take corrective actions from your mobile device. >>> http://pubads.g.doubleclick.net/gampad/clk?id=154624111&iu=/4140/ost >>> g >>> .clktrk >>> >>> >>> >>> _______________________________________________ >>> Ejbca-develop mailing list >>> Ejb...@li... >>> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >>> |
|
From: Andreas K. <ku...@tr...> - 2014-11-17 13:11:51
|
Hi Michael, maybe this is just a side effect ... I'm unable to access the repo 'https://svn.cesecore.eu/svn/ejbca/trunk/' at all ... Greetings, Andreas > HI! > > It seems something was removed from SVN recently. > > Even ant clean does not work with fresh svn checkout (see below). > It works with older checkout. :-/ > > Ciao, Michael. > > BUILD FAILED > /opt/ejbca/build.xml:43: The following error occurred while executing this > line: > /opt/ejbca/modules/build.xml:64: The following error occurred while executing > this line: > java.io.FileNotFoundException: /opt/ejbca/modules/externalra-scep/build.xml (No > such file or directory) > at java.io.FileInputStream.open(Native Method) > at java.io.FileInputStream.<init>(FileInputStream.java:146) > at org.apache.tools.ant.helper.ProjectHelper2.parse(ProjectHelper2.java:278) > at org.apache.tools.ant.helper.ProjectHelper2.parse(ProjectHelper2.java:178) > at org.apache.tools.ant.ProjectHelper.configureProject(ProjectHelper.java:82) > at org.apache.tools.ant.taskdefs.Ant.execute(Ant.java:393) > at org.apache.tools.ant.UnknownElement.execute(UnknownElement.java:291) > at sun.reflect.GeneratedMethodAccessor4.invoke(Unknown Source) > at > sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43) > at java.lang.reflect.Method.invoke(Method.java:606) > at org.apache.tools.ant.dispatch.DispatchUtils.execute(DispatchUtils.java:106) > at org.apache.tools.ant.Task.perform(Task.java:348) > at org.apache.tools.ant.Target.execute(Target.java:390) > at org.apache.tools.ant.Target.performTasks(Target.java:411) > at org.apache.tools.ant.Project.executeSortedTargets(Project.java:1399) > at > org.apache.tools.ant.helper.SingleCheckExecutor.executeTargets(SingleCheckExecutor.java:38) > at org.apache.tools.ant.Project.executeTargets(Project.java:1251) > at org.apache.tools.ant.taskdefs.Ant.execute(Ant.java:442) > at org.apache.tools.ant.UnknownElement.execute(UnknownElement.java:291) > at sun.reflect.GeneratedMethodAccessor4.invoke(Unknown Source) > at > sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43) > at java.lang.reflect.Method.invoke(Method.java:606) > at org.apache.tools.ant.dispatch.DispatchUtils.execute(DispatchUtils.java:106) > at org.apache.tools.ant.Task.perform(Task.java:348) > at org.apache.tools.ant.Target.execute(Target.java:390) > at org.apache.tools.ant.Target.performTasks(Target.java:411) > at org.apache.tools.ant.Project.executeSortedTargets(Project.java:1399) > at org.apache.tools.ant.Project.executeTarget(Project.java:1368) > at > org.apache.tools.ant.helper.DefaultExecutor.executeTargets(DefaultExecutor.java:41) > at org.apache.tools.ant.Project.executeTargets(Project.java:1251) > at org.apache.tools.ant.Main.runBuild(Main.java:809) > at org.apache.tools.ant.Main.startAnt(Main.java:217) > at org.apache.tools.ant.launch.Launcher.run(Launcher.java:280) > at org.apache.tools.ant.launch.Launcher.main(Launcher.java:109) > > Total time: 2 seconds > > > > ------------------------------------------------------------------------------ > Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT Server > from Actuate! Instantly Supercharge Your Business Reports and Dashboards > with Interactivity, Sharing, Native Excel Exports, App Integration & more > Get technology previously reserved for billion-dollar corporations, FREE > http://pubads.g.doubleclick.net/gampad/clk?id=157005751&iu=/4140/ostg.clktrk > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > -- Andreas Kühne phone: +49 177 293 24 97 mailto: ku...@tr... Trustable Ltd. Niederlassung Deutschland Ströverstr. 18 - 59427 Unna Amtsgericht Hamm HRB 5868 Directors Andreas Kühne, Heiko Veit Company UK Company No: 5218868 Registered in England and Wales |
|
From: Michael S. <mi...@st...> - 2014-11-17 12:45:15
|
HI! It seems something was removed from SVN recently. Even ant clean does not work with fresh svn checkout (see below). It works with older checkout. :-/ Ciao, Michael. BUILD FAILED /opt/ejbca/build.xml:43: The following error occurred while executing this line: /opt/ejbca/modules/build.xml:64: The following error occurred while executing this line: java.io.FileNotFoundException: /opt/ejbca/modules/externalra-scep/build.xml (No such file or directory) at java.io.FileInputStream.open(Native Method) at java.io.FileInputStream.<init>(FileInputStream.java:146) at org.apache.tools.ant.helper.ProjectHelper2.parse(ProjectHelper2.java:278) at org.apache.tools.ant.helper.ProjectHelper2.parse(ProjectHelper2.java:178) at org.apache.tools.ant.ProjectHelper.configureProject(ProjectHelper.java:82) at org.apache.tools.ant.taskdefs.Ant.execute(Ant.java:393) at org.apache.tools.ant.UnknownElement.execute(UnknownElement.java:291) at sun.reflect.GeneratedMethodAccessor4.invoke(Unknown Source) at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43) at java.lang.reflect.Method.invoke(Method.java:606) at org.apache.tools.ant.dispatch.DispatchUtils.execute(DispatchUtils.java:106) at org.apache.tools.ant.Task.perform(Task.java:348) at org.apache.tools.ant.Target.execute(Target.java:390) at org.apache.tools.ant.Target.performTasks(Target.java:411) at org.apache.tools.ant.Project.executeSortedTargets(Project.java:1399) at org.apache.tools.ant.helper.SingleCheckExecutor.executeTargets(SingleCheckExecutor.java:38) at org.apache.tools.ant.Project.executeTargets(Project.java:1251) at org.apache.tools.ant.taskdefs.Ant.execute(Ant.java:442) at org.apache.tools.ant.UnknownElement.execute(UnknownElement.java:291) at sun.reflect.GeneratedMethodAccessor4.invoke(Unknown Source) at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43) at java.lang.reflect.Method.invoke(Method.java:606) at org.apache.tools.ant.dispatch.DispatchUtils.execute(DispatchUtils.java:106) at org.apache.tools.ant.Task.perform(Task.java:348) at org.apache.tools.ant.Target.execute(Target.java:390) at org.apache.tools.ant.Target.performTasks(Target.java:411) at org.apache.tools.ant.Project.executeSortedTargets(Project.java:1399) at org.apache.tools.ant.Project.executeTarget(Project.java:1368) at org.apache.tools.ant.helper.DefaultExecutor.executeTargets(DefaultExecutor.java:41) at org.apache.tools.ant.Project.executeTargets(Project.java:1251) at org.apache.tools.ant.Main.runBuild(Main.java:809) at org.apache.tools.ant.Main.startAnt(Main.java:217) at org.apache.tools.ant.launch.Launcher.run(Launcher.java:280) at org.apache.tools.ant.launch.Launcher.main(Launcher.java:109) Total time: 2 seconds |
|
From: Tomas G. <to...@pr...> - 2014-11-15 06:49:12
|
I think Firefox is more concerned about usability than the openvpn client :). If you let the user select expired certificates, which will not be accepted by the server, the support organization risks getting lots of calls from users making the wrong choice. Ie they have a new certificate, but tries to select an old one for authentication The user friendliness and support issue is another aspect of the whole puzzle. Cheers, Tomas On November 15, 2014 12:08:37 AM CET, Hans Witvliet <hw...@a-...> wrote: >Thanks Tomas, > >If it was an optional feature on the client, yes. >but afaics this if forced upon my by firefox, no choice.... > >And if you lay the responsibility with the client,what is the purpose >of >checking it on the server side (devils advocate) > >I mean, when connecting to an ssl webserver, you are given lots of >choices whether or not to accept risky exceptions, like untrustworthy >CA's. (are you sure etc etc) >These are possible exceptions on others certificates. >You should not accept them, but you have the choice, so you could. > >And there should be no exception for an expired certificate of my own? > >Strange, not? > >It make we wonder whether openvpn is an exception in it forgivenness, >or firefox an exception is being so strict..... > >Hans > > >On Fri, 2014-11-14 at 19:55 +0100, Tomas Gustavsson wrote: >> My spontaneous opinion would definitely be B), where the expired >> certificate is not accepted. A new card have to be issued. >> >> No risk of configuring wrongly on the server side. >> >> Cheers, >> Tomas >> >> On 2014-11-13 23:33, Hans Witvliet wrote: >> > Dear all, >> > >> > >> > Last week I was in a discussion about the acceptance of >certificates. >> > >> > As you all here have a solid experience with certificates, and >whether >> > or not one should accept one, i would like to know about your >P.O.V. >> > >> > The situation is as following: >> > If you have a certificate that is neither expired nor revoked it is >> > obvious that one should be able to use it for client-authentication >> > >> > But in this case something went wrong during issuing [they should >have >> > been using ejbca instead of some vague proprietary system], and the >> > validity-period was set to three months instead of three years.... >Often >> > you see that the cert gets revoked automatically, but not in this >case. >> > >> > a) If i use such certificate for openvpn, the client does not care, >but >> > it is up to the server-side to decide whether it will accept the >> > connection or not. >> > >> > b) if i use such certificate for https, i noticed that the client >(in >> > this case firefox) bluntly refuse to try to start the connection, >> > because the validity date has expired. >> > >> > Both parties know & trust each other, but the cert can not be >re-issued >> > (the best solution) because it is glued inside a smartcard. >> > >> > So what is the proper behavior? >> > Situation A) where the server decide what to accept or not, or B) >where >> > the decision is taken out of their hands? >> > >> > I am curios about the opinion of a "trusted third party" ;-) >> > >> > Hans >> > >> > >------------------------------------------------------------------------------ >> > Comprehensive Server Monitoring with Site24x7. >> > Monitor 10 servers for $9/Month. >> > Get alerted through email, SMS, voice calls or mobile push >notifications. >> > Take corrective actions from your mobile device. >> > >http://pubads.g.doubleclick.net/gampad/clk?id=154624111&iu=/4140/ostg.clktrk >> > _______________________________________________ >> > Ejbca-develop mailing list >> > Ejb...@li... >> > https://lists.sourceforge.net/lists/listinfo/ejbca-develop >> > >> >> >------------------------------------------------------------------------------ >> Comprehensive Server Monitoring with Site24x7. >> Monitor 10 servers for $9/Month. >> Get alerted through email, SMS, voice calls or mobile push >notifications. >> Take corrective actions from your mobile device. >> >http://pubads.g.doubleclick.net/gampad/clk?id=154624111&iu=/4140/ostg.clktrk >> _______________________________________________ >> Ejbca-develop mailing list >> Ejb...@li... >> https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > >------------------------------------------------------------------------------ >Comprehensive Server Monitoring with Site24x7. >Monitor 10 servers for $9/Month. >Get alerted through email, SMS, voice calls or mobile push >notifications. >Take corrective actions from your mobile device. >http://pubads.g.doubleclick.net/gampad/clk?id=154624111&iu=/4140/ostg.clktrk >_______________________________________________ >Ejbca-develop mailing list >Ejb...@li... >https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Hans W. <hw...@a-...> - 2014-11-14 23:08:47
|
Thanks Tomas, If it was an optional feature on the client, yes. but afaics this if forced upon my by firefox, no choice.... And if you lay the responsibility with the client,what is the purpose of checking it on the server side (devils advocate) I mean, when connecting to an ssl webserver, you are given lots of choices whether or not to accept risky exceptions, like untrustworthy CA's. (are you sure etc etc) These are possible exceptions on others certificates. You should not accept them, but you have the choice, so you could. And there should be no exception for an expired certificate of my own? Strange, not? It make we wonder whether openvpn is an exception in it forgivenness, or firefox an exception is being so strict..... Hans On Fri, 2014-11-14 at 19:55 +0100, Tomas Gustavsson wrote: > My spontaneous opinion would definitely be B), where the expired > certificate is not accepted. A new card have to be issued. > > No risk of configuring wrongly on the server side. > > Cheers, > Tomas > > On 2014-11-13 23:33, Hans Witvliet wrote: > > Dear all, > > > > > > Last week I was in a discussion about the acceptance of certificates. > > > > As you all here have a solid experience with certificates, and whether > > or not one should accept one, i would like to know about your P.O.V. > > > > The situation is as following: > > If you have a certificate that is neither expired nor revoked it is > > obvious that one should be able to use it for client-authentication > > > > But in this case something went wrong during issuing [they should have > > been using ejbca instead of some vague proprietary system], and the > > validity-period was set to three months instead of three years.... Often > > you see that the cert gets revoked automatically, but not in this case. > > > > a) If i use such certificate for openvpn, the client does not care, but > > it is up to the server-side to decide whether it will accept the > > connection or not. > > > > b) if i use such certificate for https, i noticed that the client (in > > this case firefox) bluntly refuse to try to start the connection, > > because the validity date has expired. > > > > Both parties know & trust each other, but the cert can not be re-issued > > (the best solution) because it is glued inside a smartcard. > > > > So what is the proper behavior? > > Situation A) where the server decide what to accept or not, or B) where > > the decision is taken out of their hands? > > > > I am curios about the opinion of a "trusted third party" ;-) > > > > Hans > > > > ------------------------------------------------------------------------------ > > Comprehensive Server Monitoring with Site24x7. > > Monitor 10 servers for $9/Month. > > Get alerted through email, SMS, voice calls or mobile push notifications. > > Take corrective actions from your mobile device. > > http://pubads.g.doubleclick.net/gampad/clk?id=154624111&iu=/4140/ostg.clktrk > > _______________________________________________ > > Ejbca-develop mailing list > > Ejb...@li... > > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > ------------------------------------------------------------------------------ > Comprehensive Server Monitoring with Site24x7. > Monitor 10 servers for $9/Month. > Get alerted through email, SMS, voice calls or mobile push notifications. > Take corrective actions from your mobile device. > http://pubads.g.doubleclick.net/gampad/clk?id=154624111&iu=/4140/ostg.clktrk > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Tomas G. <to...@pr...> - 2014-11-14 18:55:21
|
My spontaneous opinion would definitely be B), where the expired certificate is not accepted. A new card have to be issued. No risk of configuring wrongly on the server side. Cheers, Tomas On 2014-11-13 23:33, Hans Witvliet wrote: > Dear all, > > > Last week I was in a discussion about the acceptance of certificates. > > As you all here have a solid experience with certificates, and whether > or not one should accept one, i would like to know about your P.O.V. > > The situation is as following: > If you have a certificate that is neither expired nor revoked it is > obvious that one should be able to use it for client-authentication > > But in this case something went wrong during issuing [they should have > been using ejbca instead of some vague proprietary system], and the > validity-period was set to three months instead of three years.... Often > you see that the cert gets revoked automatically, but not in this case. > > a) If i use such certificate for openvpn, the client does not care, but > it is up to the server-side to decide whether it will accept the > connection or not. > > b) if i use such certificate for https, i noticed that the client (in > this case firefox) bluntly refuse to try to start the connection, > because the validity date has expired. > > Both parties know & trust each other, but the cert can not be re-issued > (the best solution) because it is glued inside a smartcard. > > So what is the proper behavior? > Situation A) where the server decide what to accept or not, or B) where > the decision is taken out of their hands? > > I am curios about the opinion of a "trusted third party" ;-) > > Hans > > ------------------------------------------------------------------------------ > Comprehensive Server Monitoring with Site24x7. > Monitor 10 servers for $9/Month. > Get alerted through email, SMS, voice calls or mobile push notifications. > Take corrective actions from your mobile device. > http://pubads.g.doubleclick.net/gampad/clk?id=154624111&iu=/4140/ostg.clktrk > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Tomas G. <to...@pr...> - 2014-11-14 09:09:33
|
Since the VM comes with a management CA pre-installed, anyone with a Superadmin from one VM can be superadmin in your VM. That makes it unsuitable fro production, from a security perspective. You can tweak this of course, and block default superadmin etc. But it all depends on what security requirements you have on your CA. If they are high, it is not suitable. Regards, Tomas ----- Save time and money with an Enterprise support subscription. Please see www.primekey.se for more information. http://www.primekey.se/Products/EJBCA+PKI/ http://www.primekey.se/Services/Support/ On 2014-11-12 21:14, Roberto Carna wrote: > Dear, I've been using Tinyca for a pair of years but I now I want to > use a more robust CA software like ejbca that let me sign the > certificates with SHA-2 as minimum. > > As the ejbca installation is very hard to me, I'd want to install the > virtual machine version in my vmware platform, and my question is > this: > > Is the EJBCA VM version suitable for a production environment ? Is it > possible to adjust any parameter to use as I said ? > > Thanks a lot, > > Roberto > > ------------------------------------------------------------------------------ > Comprehensive Server Monitoring with Site24x7. > Monitor 10 servers for $9/Month. > Get alerted through email, SMS, voice calls or mobile push notifications. > Take corrective actions from your mobile device. > http://pubads.g.doubleclick.net/gampad/clk?id=154624111&iu=/4140/ostg.clktrk > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Hans W. <hw...@a-...> - 2014-11-13 22:49:09
|
Dear all, Last week I was in a discussion about the acceptance of certificates. As you all here have a solid experience with certificates, and whether or not one should accept one, i would like to know about your P.O.V. The situation is as following: If you have a certificate that is neither expired nor revoked it is obvious that one should be able to use it for client-authentication But in this case something went wrong during issuing [they should have been using ejbca instead of some vague proprietary system], and the validity-period was set to three months instead of three years.... Often you see that the cert gets revoked automatically, but not in this case. a) If i use such certificate for openvpn, the client does not care, but it is up to the server-side to decide whether it will accept the connection or not. b) if i use such certificate for https, i noticed that the client (in this case firefox) bluntly refuse to try to start the connection, because the validity date has expired. Both parties know & trust each other, but the cert can not be re-issued (the best solution) because it is glued inside a smartcard. So what is the proper behavior? Situation A) where the server decide what to accept or not, or B) where the decision is taken out of their hands? I am curios about the opinion of a "trusted third party" ;-) Hans |
|
From: eilaf s. <eil...@gm...> - 2014-11-13 07:43:52
|
Ok, For example When I try to add an administrator from the adminstration EJBCA web the following exception Report appears to me: HTTP Status 500 - ------------------------------ *type* Exception report *message* *description* *The server encountered an internal error () that prevented it from fulfilling this request.* *exception* javax.servlet.ServletException: viewId:/administratorprivileges/editadminentities.jsf - View /administratorprivileges/editadminentities.jsf could not be restored. javax.faces.webapp.FacesServlet.service(FacesServlet.java:270) org.apache.myfaces.webapp.filter.ExtensionsFilter.doFilter(ExtensionsFilter.java:147) org.ejbca.ui.web.admin.ProxiedAuthenticationFilter.doFilter(ProxiedAuthenticationFilter.java:109) *root cause* javax.faces.application.ViewExpiredException: viewId:/administratorprivileges/editadminentities.jsf - View /administratorprivileges/editadminentities.jsf could not be restored. com.sun.faces.lifecycle.RestoreViewPhase.execute(RestoreViewPhase.java:189) com.sun.faces.lifecycle.Phase.doPhase(Phase.java:100) com.sun.faces.lifecycle.RestoreViewPhase.doPhase(RestoreViewPhase.java:102) com.sun.faces.lifecycle.LifecycleImpl.execute(LifecycleImpl.java:118) javax.faces.webapp.FacesServlet.service(FacesServlet.java:265) org.apache.myfaces.webapp.filter.ExtensionsFilter.doFilter(ExtensionsFilter.java:147) org.ejbca.ui.web.admin.ProxiedAuthenticationFilter.doFilter(ProxiedAuthenticationFilter.java:109) *note* *The full stack trace of the root cause is available in the JBoss Web/7.0.13.Final logs.* ------------------------------ JBoss Web/7.0.13.Final My Question Is : If I Use CESeCore Library , Instead of this Exception Report Can I get another simple message clarify What cause this exception? Hopefully that you get my question!. Regards. On Wed, Nov 5, 2014 at 1:29 AM, Branko Majic <br...@ma...> wrote: > On Tue, 4 Nov 2014 08:44:50 +0300 > eilaf sorkatti <eil...@gm...> wrote: > > > Hi, > > > > I am asking about the Errors pages appears on EJBCA public web due to > some > > mistakes that happens by the one who want to generate certificates. These > > errors are not specify the type of mistake happens. > > I found this product on PrimeKey Jira https://www.cesecore.eu/ , Is this > > product solve this problem? > > > > It's a bit hard to understand your question. Could you try > rephrasing/explaining in more details what you mean? > > As for CESeCore, it is a library heavily relied upon by the EJBCA and > SignServer. > > Best regards > > -- > Branko Majic > Jabber: br...@ma... > Please use only Free formats when sending attachments to me. > > Бранко Мајић > Џабер: br...@ma... > Молим вас да додатке шаљете искључиво у слободним форматима. > > > ------------------------------------------------------------------------------ > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > -- Eilaf Hamad Elnil Mugbil University Of Khartoum School Of Mathematical science |
|
From: Roberto C. <rob...@gm...> - 2014-11-12 20:14:17
|
Dear, I've been using Tinyca for a pair of years but I now I want to use a more robust CA software like ejbca that let me sign the certificates with SHA-2 as minimum. As the ejbca installation is very hard to me, I'd want to install the virtual machine version in my vmware platform, and my question is this: Is the EJBCA VM version suitable for a production environment ? Is it possible to adjust any parameter to use as I said ? Thanks a lot, Roberto |
|
From: Michael S. <mi...@st...> - 2014-11-12 13:46:33
|
Tomas Gustavsson wrote: > An ra admin can issue certificates for the CAs and profiles he have access to, not others. Sorry for nitpicking here: The problem is that if CAs and/or end entity profiles of the RA admin's cert and the new cert differ you have to give at least view rights to the RA admin's CA and EE profile. Ciao, Michael. |
|
From: Liliana C. <lil...@bu...> - 2014-11-12 09:56:13
|
Hello, I'm working with ejbca_ce_6_0_3 and jboss-as-7.1.1.Final. I'll try to better explain my problem. I've created a RA Administrator in charge of creation end entities for user certificates with the following Access Rules: · Authorized CAs : MedusaUserCA · End entity Profiles: User End Entity Profile User End Entity Profile is defined as follows: · Default Certificate Profile: User Cert Profile · Available Profiles: User Cert Profile · Default CA : MedusaUserCA · Available Cas : MedusaUserCA User Cert Profile is defined as follows: · Available CAs: MedusaUserCA · Publishers: MyPublisher I created an end entity and user certificate for the RA. When I connect to adminweb with the RA credentials, I obtain: [cid:image002.png@01CFFE67.3CCCB910] Why "No publishers defined" ? Thanks for your help. Best regards, Liliana Cabalantti Bull, Architect of an Open World(tm) BSS/TrustWay Tél : +33 1 30 80 63 95 Fax : +33 1 30 80 63 40 lil...@bu...<mailto:lil...@bu...> [BULL_logo] |
|
From: eilaf s. <eil...@gm...> - 2014-11-12 09:28:28
|
No one of these happened i think! , I put the module on :
/jboss-eap-6.3/modules/
system/layers/base/org/mariadb/main , it contains:
<?xml version"1.0" encoding="UTF-8"?>
<module xmlns="urn:jboss:module:1.0" name="org.mariadb">
<resources>
<resource-root path="mariadb-java-client-1.1.5.jar"/>
</resources>
<dependencies>
<module name="javax.api"/>
<module name="javax.transaction.api"/>
</dependencies>
</module>
The command is :
/subsystem=datasources/jdbc-driver=org.mariadb.jdbc.Driver:add(driver-
name=org.mariadb.jdbc.Driver,driver-module-name=org.mariadb,driver-xa-datasource-class-name=org.mariadb.jdbc.MySQLDataSource)
The jar file on the same directory, I login to the system as Root.
On Wed, Nov 12, 2014 at 12:27 PM, eilaf sorkatti <eil...@gm...>
wrote:
>
> ---------- Forwarded message ----------
> From: eilaf sorkatti <eil...@gm...>
> Date: Wed, Nov 5, 2014 at 2:50 PM
> Subject: Re: [Ejbca-develop] Failed Registering mariadb module on Jboss
> EAP 6.2.0
> To: Tomas Gustavsson <to...@pr...>
>
>
> No one of these happened i think! , I put the module on :
> /jboss-eap-6.3/modules/system/layers/base/org/mariadb/main , it contains:
>
> <?xml version"1.0" encoding="UTF-8"?>
> <module xmlns="urn:jboss:module:1.0" name="org.mariadb">
> <resources>
> <resource-root path="mariadb-java-client-1.1.5.jar"/>
> </resources>
> <dependencies>
> <module name="javax.api"/>
> <module name="javax.transaction.api"/>
> </dependencies>
> </module>
> The command is :
> /subsystem=datasources/jdbc-driver=org.mariadb.jdbc.Driver:add(driver-
> name=org.mariadb.jdbc.Driver,driver-module-name=org.mariadb,driver-xa-datasource-class-name=org.mariadb.jdbc.MySQLDataSource)
>
>
> The jar file on the same directory, I login to the system as Root.
>
>
> On Wed, Nov 5, 2014 at 2:31 PM, Tomas Gustavsson <to...@pr...>
> wrote:
>
>> Seems there is some mismatch between your module.xml and the command you
>> run, or the module.xml is in the wrong place or can not be read.
>>
>> Cheers,
>> Tomas
>>
>> eilaf sorkatti <eil...@gm...> skrev: (5 november 2014 12:12:35
>> CET)
>> >Hello all,
>> >
>> >Thank you Tomas for your reply. This is what appear when enable
>> >debugging:
>> >
>> >14:09:33,587 DEBUG [org.jboss.as.controller.management-operation]
>> >(management-handler-thread - 4) JBAS014616: Operation ("add") failed -
>> >address: ([
>> > ("subsystem" => "datasources"),
>> > ("jdbc-driver" => "org.mariadb.jdbc.Driver")
>> >]) - failure description: "JBAS010441: Failed to load module for driver
>> >[org.mariadb]"
>> >14:09:54,499 DEBUG [org.apache.catalina.session]
>> >(ContainerBackgroundProcessor[StandardEngine[jboss.web]]) Start expire
>> >sessions StandardManager at 1415185794499 sessioncount 0
>> >
>> >
>> >
>> >On Mon, Nov 3, 2014 at 4:41 PM, Tomas Gustavsson <to...@pr...>
>> >wrote:
>> >
>> >>
>> >> This one seems to works for me with module.xml in:
>> >> jboss-eap-6.2/modules/system/layers/base/org/mariadb/main
>> >>
>> >> <?xml version="1.0" encoding="UTF-8"?>
>> >> <module xmlns="urn:jboss:module:1.0" name="org.mariadb">
>> >> <resources>
>> >> <resource-root path="mariadb-java-client-1.1.5.jar"/>
>> >> </resources>
>> >> <dependencies>
>> >> <module name="javax.api"/>
>> >> <module name="javax.transaction.api"/>
>> >> </dependencies>
>> >> </module>
>> >>
>> >>
>> >>
>>
>> >/subsystem=datasources/jdbc-driver=org.mariadb.jdbc.Driver:add(driver-name=org.mariadb.jdbc.Driver,driver-module-name=org.mariadb,driver-xa-datasource-class-name=org.mariadb.jdbc.MySQLDataSource)
>> >>
>> >>
>> >> You need to analyze your server.lgo to see why JBoss does not like
>> >your
>> >> driver. Perhaps you have written with root privileges?
>> >>
>> >> Cheers,
>> >> Tomas
>> >>
>> >> On 2014-11-03 07:08, eilaf sorkatti wrote:
>> >> > There is no need to edit standalone.xml am i right?, Here is my
>> >details
>> >> > "I was wrong am using JBOSS EAP 6.3":
>> >> > I put module.xml on
>> >> > /root/pki/jboss-eap-6.3/modules/system/layers/base/org/mariadb/main
>> >, it
>> >> > contains:
>> >> >
>> >> > <?xml version"1.0" encoding="UTF-8"?>
>> >> > <module xmlns="urn:jboss:module:1.0" name="org.mariadb">
>> >> > <resources>
>> >> > <resource-root path="mariadb-java-client-1.1.5.jar"/>
>> >> > </resources>
>> >> > <dependencies>
>> >> > <module name="javax.api"/>
>> >> > <module name="javax.transaction.api"/>
>> >> > </dependencies>
>> >> > </module>
>> >> >
>> >> > I put the connector on the same directory. I run ./jboss-cli.sh
>> >> > then write the command
>> >> > /subsystem=datasources/jdbc-
>> >> > driver=org.mariadb.jdbc.
>> >> >
>> >>
>>
>> >Driver:add(driver-name=org.mariadb.jdbc.Driver,driver-module-name=org.mariadb,driver-xa-datasource-class-name=org.mariadb.jdbc.MySQLDataSource)
>> >> >
>> >> > Then I get that error!!!
>> >> >
>> >> > On Sun, Nov 2, 2014 at 1:58 PM, eilaf sorkatti
>> ><eil...@gm...
>> >> > <mailto:eil...@gm...>> wrote:
>> >> >
>> >> > sorry the urn:jboss:module:1.0
>> >> >
>> >> > On Sun, Nov 2, 2014 at 1:58 PM, eilaf sorkatti
>> >> > <eil...@gm... <mailto:eil...@gm...>> wrote:
>> >> >
>> >> > There is no need to edit standalone.xml am i right?, Here
>> >is my
>> >> > details "I was wrong am using JBOSS EAP 6.3":
>> >> > I put module.xml on
>> >> >
>> >> /root/pki/jboss-eap-6.3/modules/system/layers/base/org/mariadb/main
>> >> > , it contains:
>> >> >
>> >> > <?xml version"1.0" encoding="UTF-8"?>
>> >> > <module xmlns="urn:jboss:module:1.9" name="org.mariadb">
>> >> > <resources>
>> >> > <resource-root path="mariadb-java-client-1.1.5.jar"/>
>> >> > </resources>
>> >> > <dependencies>
>> >> > <module name="javax.api"/>
>> >> > <module name="javax.transaction.api"/>
>> >> > </dependencies>
>> >> > </module>
>> >> >
>> >> > I put the connector on the same directory. I run
>> >./jboss-cli.sh
>> >> > then write the command
>> >> > /subsystem=datasources/jdbc-driver=org.mariadb.jdbc.
>> >> >
>> >>
>>
>> >Driver:add(driver-name=org.mariadb.jdbc.Driver,driver-module-name=org.mariadb,driver-xa-datasource-class-name=org.mariadb.jdbc.MySQLDataSource)
>> >> >
>> >> > Then I get that error!!!
>> >> >
>> >> >
>> >> > On Sun, Nov 2, 2014 at 12:38 PM, EJBCA Support
>> >> > <ejb...@pr...
>> ><mailto:ejb...@pr...>>
>> >> > wrote:
>> >> >
>> >> >
>> >> > Seems there is something wrong in your file, or you are
>> >not
>> >> > matching the
>> >> > driver version in module.xml with the jar file you are
>> >> > placing there.
>> >> >
>> >> > You have to give full details of what you do in order
>> >to
>> >> > figure out what
>> >> > is wrong.
>> >> >
>> >> > (it works for me ;-))
>> >> >
>> >> > Cheers,
>> >> > Tomas
>> >> >
>> >> > On 2014-11-02 06:48, eilaf sorkatti wrote:
>> >> > >
>> >> > > Hi,
>> >> > > Am using JBOSS EAP 6.2.0, I Create the JDBC module
>> >> > configuration file
>> >> > > module.xml. when I try to register driver for
>> >mariaDB i
>> >> get:
>> >> > > /subsystem=datasources/jdbc-
>> >> > >
>> >> >
>> >>
>>
>> >driver=org.mariadb.jdbc.Driver:add(driver-name=org.mariadb.jdbc.Driver,driver-module-name=org.mariadb,driver-xa-datasource-class-name=org.mariadb.jdbc.MySQLDataSource)
>> >> > > {
>> >> > > "outcome" => "failed",
>> >> > > "failure-description" => "JBAS010441: Failed to
>> >load
>> >> > module for
>> >> > > driver [org.mariadb]",
>> >> > > "rolled-back" => true
>> >> > > }
>> >> > >
>> >> > > --
>> >> > > Eilaf Hamad Elnil Mugbil
>> >> > > University Of Khartoum
>> >> > > School Of Mathematical science
>> >> > >
>> >> > >
>> >> > >
>> >> >
>> >>
>>
>> >------------------------------------------------------------------------------
>> >> > >
>> >> > >
>> >> > >
>> >> > > _______________________________________________
>> >> > > Ejbca-develop mailing list
>> >> > > Ejb...@li...
>> >> > <mailto:Ejb...@li...>
>> >> > >
>> >> https://lists.sourceforge.net/lists/listinfo/ejbca-develop
>> >> > >
>> >> >
>> >> >
>> >> >
>> >> >
>> >>
>>
>> >------------------------------------------------------------------------------
>> >> > _______________________________________________
>> >> > Ejbca-develop mailing list
>> >> > Ejb...@li...
>> >> > <mailto:Ejb...@li...>
>> >> >
>> >https://lists.sourceforge.net/lists/listinfo/ejbca-develop
>> >> >
>> >> >
>> >> >
>> >> >
>> >> > --
>> >> > Eilaf Hamad Elnil Mugbil
>> >> > University Of Khartoum
>> >> > School Of Mathematical science
>> >> >
>> >> >
>> >> >
>> >> >
>> >> > --
>> >> > Eilaf Hamad Elnil Mugbil
>> >> > University Of Khartoum
>> >> > School Of Mathematical science
>> >> >
>> >> >
>> >> >
>> >> >
>> >> > --
>> >> > Eilaf Hamad Elnil Mugbil
>> >> > University Of Khartoum
>> >> > School Of Mathematical science
>> >> >
>> >> >
>> >> >
>> >>
>>
>> >------------------------------------------------------------------------------
>> >> >
>> >> >
>> >> >
>> >> > _______________________________________________
>> >> > Ejbca-develop mailing list
>> >> > Ejb...@li...
>> >> > https://lists.sourceforge.net/lists/listinfo/ejbca-develop
>> >> >
>> >>
>> >>
>> >>
>>
>> >------------------------------------------------------------------------------
>> >> _______________________________________________
>> >> Ejbca-develop mailing list
>> >> Ejb...@li...
>> >> https://lists.sourceforge.net/lists/listinfo/ejbca-develop
>> >>
>>
>>
>
>
> --
> Eilaf Hamad Elnil Mugbil
> University Of Khartoum
> School Of Mathematical science
>
>
>
> --
> Eilaf Hamad Elnil Mugbil
> University Of Khartoum
> School Of Mathematical science
>
--
Eilaf Hamad Elnil Mugbil
University Of Khartoum
School Of Mathematical science
|
|
From: eilaf s. <eil...@gm...> - 2014-11-12 09:28:07
|
---------- Forwarded message ----------
From: eilaf sorkatti <eil...@gm...>
Date: Wed, Nov 5, 2014 at 2:50 PM
Subject: Re: [Ejbca-develop] Failed Registering mariadb module on Jboss EAP
6.2.0
To: Tomas Gustavsson <to...@pr...>
No one of these happened i think! , I put the module on :
/jboss-eap-6.3/modules/system/layers/base/org/mariadb/main , it contains:
<?xml version"1.0" encoding="UTF-8"?>
<module xmlns="urn:jboss:module:1.0" name="org.mariadb">
<resources>
<resource-root path="mariadb-java-client-1.1.5.jar"/>
</resources>
<dependencies>
<module name="javax.api"/>
<module name="javax.transaction.api"/>
</dependencies>
</module>
The command is :
/subsystem=datasources/jdbc-driver=org.mariadb.jdbc.Driver:add(driver-
name=org.mariadb.jdbc.Driver,driver-module-name=org.mariadb,driver-xa-datasource-class-name=org.mariadb.jdbc.MySQLDataSource)
The jar file on the same directory, I login to the system as Root.
On Wed, Nov 5, 2014 at 2:31 PM, Tomas Gustavsson <to...@pr...> wrote:
> Seems there is some mismatch between your module.xml and the command you
> run, or the module.xml is in the wrong place or can not be read.
>
> Cheers,
> Tomas
>
> eilaf sorkatti <eil...@gm...> skrev: (5 november 2014 12:12:35
> CET)
> >Hello all,
> >
> >Thank you Tomas for your reply. This is what appear when enable
> >debugging:
> >
> >14:09:33,587 DEBUG [org.jboss.as.controller.management-operation]
> >(management-handler-thread - 4) JBAS014616: Operation ("add") failed -
> >address: ([
> > ("subsystem" => "datasources"),
> > ("jdbc-driver" => "org.mariadb.jdbc.Driver")
> >]) - failure description: "JBAS010441: Failed to load module for driver
> >[org.mariadb]"
> >14:09:54,499 DEBUG [org.apache.catalina.session]
> >(ContainerBackgroundProcessor[StandardEngine[jboss.web]]) Start expire
> >sessions StandardManager at 1415185794499 sessioncount 0
> >
> >
> >
> >On Mon, Nov 3, 2014 at 4:41 PM, Tomas Gustavsson <to...@pr...>
> >wrote:
> >
> >>
> >> This one seems to works for me with module.xml in:
> >> jboss-eap-6.2/modules/system/layers/base/org/mariadb/main
> >>
> >> <?xml version="1.0" encoding="UTF-8"?>
> >> <module xmlns="urn:jboss:module:1.0" name="org.mariadb">
> >> <resources>
> >> <resource-root path="mariadb-java-client-1.1.5.jar"/>
> >> </resources>
> >> <dependencies>
> >> <module name="javax.api"/>
> >> <module name="javax.transaction.api"/>
> >> </dependencies>
> >> </module>
> >>
> >>
> >>
>
> >/subsystem=datasources/jdbc-driver=org.mariadb.jdbc.Driver:add(driver-name=org.mariadb.jdbc.Driver,driver-module-name=org.mariadb,driver-xa-datasource-class-name=org.mariadb.jdbc.MySQLDataSource)
> >>
> >>
> >> You need to analyze your server.lgo to see why JBoss does not like
> >your
> >> driver. Perhaps you have written with root privileges?
> >>
> >> Cheers,
> >> Tomas
> >>
> >> On 2014-11-03 07:08, eilaf sorkatti wrote:
> >> > There is no need to edit standalone.xml am i right?, Here is my
> >details
> >> > "I was wrong am using JBOSS EAP 6.3":
> >> > I put module.xml on
> >> > /root/pki/jboss-eap-6.3/modules/system/layers/base/org/mariadb/main
> >, it
> >> > contains:
> >> >
> >> > <?xml version"1.0" encoding="UTF-8"?>
> >> > <module xmlns="urn:jboss:module:1.0" name="org.mariadb">
> >> > <resources>
> >> > <resource-root path="mariadb-java-client-1.1.5.jar"/>
> >> > </resources>
> >> > <dependencies>
> >> > <module name="javax.api"/>
> >> > <module name="javax.transaction.api"/>
> >> > </dependencies>
> >> > </module>
> >> >
> >> > I put the connector on the same directory. I run ./jboss-cli.sh
> >> > then write the command
> >> > /subsystem=datasources/jdbc-
> >> > driver=org.mariadb.jdbc.
> >> >
> >>
>
> >Driver:add(driver-name=org.mariadb.jdbc.Driver,driver-module-name=org.mariadb,driver-xa-datasource-class-name=org.mariadb.jdbc.MySQLDataSource)
> >> >
> >> > Then I get that error!!!
> >> >
> >> > On Sun, Nov 2, 2014 at 1:58 PM, eilaf sorkatti
> ><eil...@gm...
> >> > <mailto:eil...@gm...>> wrote:
> >> >
> >> > sorry the urn:jboss:module:1.0
> >> >
> >> > On Sun, Nov 2, 2014 at 1:58 PM, eilaf sorkatti
> >> > <eil...@gm... <mailto:eil...@gm...>> wrote:
> >> >
> >> > There is no need to edit standalone.xml am i right?, Here
> >is my
> >> > details "I was wrong am using JBOSS EAP 6.3":
> >> > I put module.xml on
> >> >
> >> /root/pki/jboss-eap-6.3/modules/system/layers/base/org/mariadb/main
> >> > , it contains:
> >> >
> >> > <?xml version"1.0" encoding="UTF-8"?>
> >> > <module xmlns="urn:jboss:module:1.9" name="org.mariadb">
> >> > <resources>
> >> > <resource-root path="mariadb-java-client-1.1.5.jar"/>
> >> > </resources>
> >> > <dependencies>
> >> > <module name="javax.api"/>
> >> > <module name="javax.transaction.api"/>
> >> > </dependencies>
> >> > </module>
> >> >
> >> > I put the connector on the same directory. I run
> >./jboss-cli.sh
> >> > then write the command
> >> > /subsystem=datasources/jdbc-driver=org.mariadb.jdbc.
> >> >
> >>
>
> >Driver:add(driver-name=org.mariadb.jdbc.Driver,driver-module-name=org.mariadb,driver-xa-datasource-class-name=org.mariadb.jdbc.MySQLDataSource)
> >> >
> >> > Then I get that error!!!
> >> >
> >> >
> >> > On Sun, Nov 2, 2014 at 12:38 PM, EJBCA Support
> >> > <ejb...@pr...
> ><mailto:ejb...@pr...>>
> >> > wrote:
> >> >
> >> >
> >> > Seems there is something wrong in your file, or you are
> >not
> >> > matching the
> >> > driver version in module.xml with the jar file you are
> >> > placing there.
> >> >
> >> > You have to give full details of what you do in order
> >to
> >> > figure out what
> >> > is wrong.
> >> >
> >> > (it works for me ;-))
> >> >
> >> > Cheers,
> >> > Tomas
> >> >
> >> > On 2014-11-02 06:48, eilaf sorkatti wrote:
> >> > >
> >> > > Hi,
> >> > > Am using JBOSS EAP 6.2.0, I Create the JDBC module
> >> > configuration file
> >> > > module.xml. when I try to register driver for
> >mariaDB i
> >> get:
> >> > > /subsystem=datasources/jdbc-
> >> > >
> >> >
> >>
>
> >driver=org.mariadb.jdbc.Driver:add(driver-name=org.mariadb.jdbc.Driver,driver-module-name=org.mariadb,driver-xa-datasource-class-name=org.mariadb.jdbc.MySQLDataSource)
> >> > > {
> >> > > "outcome" => "failed",
> >> > > "failure-description" => "JBAS010441: Failed to
> >load
> >> > module for
> >> > > driver [org.mariadb]",
> >> > > "rolled-back" => true
> >> > > }
> >> > >
> >> > > --
> >> > > Eilaf Hamad Elnil Mugbil
> >> > > University Of Khartoum
> >> > > School Of Mathematical science
> >> > >
> >> > >
> >> > >
> >> >
> >>
>
> >------------------------------------------------------------------------------
> >> > >
> >> > >
> >> > >
> >> > > _______________________________________________
> >> > > Ejbca-develop mailing list
> >> > > Ejb...@li...
> >> > <mailto:Ejb...@li...>
> >> > >
> >> https://lists.sourceforge.net/lists/listinfo/ejbca-develop
> >> > >
> >> >
> >> >
> >> >
> >> >
> >>
>
> >------------------------------------------------------------------------------
> >> > _______________________________________________
> >> > Ejbca-develop mailing list
> >> > Ejb...@li...
> >> > <mailto:Ejb...@li...>
> >> >
> >https://lists.sourceforge.net/lists/listinfo/ejbca-develop
> >> >
> >> >
> >> >
> >> >
> >> > --
> >> > Eilaf Hamad Elnil Mugbil
> >> > University Of Khartoum
> >> > School Of Mathematical science
> >> >
> >> >
> >> >
> >> >
> >> > --
> >> > Eilaf Hamad Elnil Mugbil
> >> > University Of Khartoum
> >> > School Of Mathematical science
> >> >
> >> >
> >> >
> >> >
> >> > --
> >> > Eilaf Hamad Elnil Mugbil
> >> > University Of Khartoum
> >> > School Of Mathematical science
> >> >
> >> >
> >> >
> >>
>
> >------------------------------------------------------------------------------
> >> >
> >> >
> >> >
> >> > _______________________________________________
> >> > Ejbca-develop mailing list
> >> > Ejb...@li...
> >> > https://lists.sourceforge.net/lists/listinfo/ejbca-develop
> >> >
> >>
> >>
> >>
>
> >------------------------------------------------------------------------------
> >> _______________________________________________
> >> Ejbca-develop mailing list
> >> Ejb...@li...
> >> https://lists.sourceforge.net/lists/listinfo/ejbca-develop
> >>
>
>
--
Eilaf Hamad Elnil Mugbil
University Of Khartoum
School Of Mathematical science
--
Eilaf Hamad Elnil Mugbil
University Of Khartoum
School Of Mathematical science
|
|
From: Tomas G. <to...@pr...> - 2014-11-12 07:55:44
|
Waiting for more remake of this "feature" I updated the docs for the
next release.
*** Use LDAP DN order ***
In a certificate the order of the DN components (CN,O,C etc) can be put
in different order, in the binary encoded certificate.
last-to-first, forward (historically called LDAP DN Order in
EJBCA): CN=Common Name, O=Organization, C=Country
first-to-last, reverse order: C=Country, O=Organization, CN=Common name
When using string representation of DNs, the actual order is commonly
not displayed, but the tool used will display in the order it sees fit
which might be the reverse of the real, binary, order. In order to see
the real, binary, order an asn1 parsing tool, like OpenSSL, can be used.
In practice DN order can be important as comparisons is often done using
string comparisons, where the string value may be depending on the order
or not.
The most common order is first-to-last (i.e. C,O,CN), but for historical
reasons EJBCA uses last-to-first (CN,O,C). Some applications do require
first-to-last order however and therefore EJBCA gives you the choice
(named as 'non LDAP DN order'). There are two places in EJBCA where this
can be configured:
In the Certificate profile (Edit certificate profiles)
In the CA configuration (Edit Certificate Authorities)
The relationship between the settings is that they are both evaluated in
a logical AND expression. This means that if both are true the DN will
have last-to-first (LDAP) DN order, but if any one of them is false the
DN will have X.500 order.
For some references see RFC2253 and RFC4514
Cheers,
Tomas
On 2014-10-15 23:32, Michael Ströder wrote:
> Tomas Gustavsson wrote:
>> Of course EJBCA is not caring about the string representation of DNs,
>
> Not true! (not meant as offense)
>
> If you accept an input field or config file value with a DN (like EJBCA does
> in various places) you're definitely in the business of dealing with string
> representation of DNs!
>
> Let's pick an example from your docs:
>
> http://www.ejbca.org/docs/userguide.html#Name%20Constraints
>
> C=SE,O=Company
> Matches against the beginning of the Subject DN. The certificates must
> not use LDAP DN order, which is enabled by default!
>
> Can you see the confusion introduced?
>
>> Anyhow, to summarize your suggestion it is to "uncheck" the checkbox by
>> default, and remove the option.
>
> Yepp.
>
>> Providing only one possible asn.1
>> encoding, which in your view is the correct one?
>
> You simply have to preserve the RDNSequence order in whatever data structure
> you keep or convert the DN at a given time. ;-)
>
> Ciao, Michael.
>
>
>
> ------------------------------------------------------------------------------
> Comprehensive Server Monitoring with Site24x7.
> Monitor 10 servers for $9/Month.
> Get alerted through email, SMS, voice calls or mobile push notifications.
> Take corrective actions from your mobile device.
> http://p.sf.net/sfu/Zoho
>
>
>
> _______________________________________________
> Ejbca-develop mailing list
> Ejb...@li...
> https://lists.sourceforge.net/lists/listinfo/ejbca-develop
>
|
|
From: Michael S. <mi...@st...> - 2014-11-11 14:38:54
|
HI! I'd like to let admins submit CSRs for server certs including the PKCS#10 CSR data. After that an RA admin should approve the request (checking that the server admin who submitted the CSR is authorized to do so) and the CA should issue the cert informing the user via e-mail notification to pick it up. Is that possible? Tested with approval settings in the cert profile like this: [x] Add/Edit End Entity [ ] Key Recovery [ ] Revocation [ ] CA Service Activation But then "ejbcaClientToolBox.sh EjbcaWsRaCli generatenewuser" does not submit the PKCS#10 data. Just the user is added after approving it. Ciao, Michael. |
|
From: Tomas G. <to...@pr...> - 2014-11-11 12:04:39
|
An ra admin can issue certificates for the CAs and profiles he have access to, not others. "Michael Ströder" <mi...@st...> skrev: (11 november 2014 10:00:01 CET) >Tomas Gustavsson wrote: >> One important thing in profiles are how "available CAs" and >"available >> profiles" are selected. An administrator does not have access to a >> profile if he/she does not have access to all selected "available" >CAs >> and profiles. > >Now the interesting question is what "have access" really means (see my >own >follow-up). Obviously the RA admin of another sub CA should not be able >to let >the admin CA issue arbitrary certs. > >Ciao, Michael. > > > >------------------------------------------------------------------------ > >------------------------------------------------------------------------------ >Comprehensive Server Monitoring with Site24x7. >Monitor 10 servers for $9/Month. >Get alerted through email, SMS, voice calls or mobile push >notifications. >Take corrective actions from your mobile device. >http://pubads.g.doubleclick.net/gampad/clk?id=154624111&iu=/4140/ostg.clktrk > >------------------------------------------------------------------------ > >_______________________________________________ >Ejbca-develop mailing list >Ejb...@li... >https://lists.sourceforge.net/lists/listinfo/ejbca-develop |