You can subscribe to this list here.
| 2001 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
(1) |
Dec
(3) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2002 |
Jan
(3) |
Feb
(2) |
Mar
(8) |
Apr
(3) |
May
(6) |
Jun
(1) |
Jul
(15) |
Aug
(6) |
Sep
|
Oct
(10) |
Nov
(2) |
Dec
(4) |
| 2003 |
Jan
(1) |
Feb
(7) |
Mar
(3) |
Apr
(6) |
May
(7) |
Jun
(5) |
Jul
(5) |
Aug
(25) |
Sep
(14) |
Oct
(2) |
Nov
|
Dec
(2) |
| 2004 |
Jan
(7) |
Feb
(4) |
Mar
(12) |
Apr
(16) |
May
(43) |
Jun
(56) |
Jul
(43) |
Aug
(40) |
Sep
(66) |
Oct
(12) |
Nov
(26) |
Dec
(10) |
| 2005 |
Jan
(13) |
Feb
(33) |
Mar
(16) |
Apr
(7) |
May
(10) |
Jun
(34) |
Jul
(41) |
Aug
(8) |
Sep
(4) |
Oct
(32) |
Nov
(20) |
Dec
(25) |
| 2006 |
Jan
(30) |
Feb
(101) |
Mar
(5) |
Apr
(75) |
May
(74) |
Jun
(22) |
Jul
(6) |
Aug
(70) |
Sep
(19) |
Oct
(21) |
Nov
(31) |
Dec
(50) |
| 2007 |
Jan
(15) |
Feb
(20) |
Mar
(24) |
Apr
(33) |
May
(13) |
Jun
(18) |
Jul
(13) |
Aug
(7) |
Sep
(63) |
Oct
(68) |
Nov
(29) |
Dec
(68) |
| 2008 |
Jan
(30) |
Feb
(33) |
Mar
(30) |
Apr
(103) |
May
(78) |
Jun
(48) |
Jul
(72) |
Aug
(24) |
Sep
(62) |
Oct
(63) |
Nov
(70) |
Dec
(37) |
| 2009 |
Jan
(34) |
Feb
(35) |
Mar
(64) |
Apr
(34) |
May
(34) |
Jun
(58) |
Jul
(30) |
Aug
(30) |
Sep
(46) |
Oct
(52) |
Nov
(12) |
Dec
(23) |
| 2010 |
Jan
(121) |
Feb
(18) |
Mar
(53) |
Apr
(62) |
May
(62) |
Jun
(20) |
Jul
(33) |
Aug
(20) |
Sep
(36) |
Oct
(35) |
Nov
(44) |
Dec
(63) |
| 2011 |
Jan
(19) |
Feb
(32) |
Mar
(94) |
Apr
(41) |
May
(47) |
Jun
(25) |
Jul
(34) |
Aug
(20) |
Sep
(9) |
Oct
(41) |
Nov
(33) |
Dec
(24) |
| 2012 |
Jan
(12) |
Feb
(36) |
Mar
(48) |
Apr
(32) |
May
(20) |
Jun
(15) |
Jul
(32) |
Aug
(13) |
Sep
(33) |
Oct
(54) |
Nov
(25) |
Dec
(16) |
| 2013 |
Jan
(45) |
Feb
(39) |
Mar
(38) |
Apr
(50) |
May
(29) |
Jun
(30) |
Jul
(33) |
Aug
(12) |
Sep
(9) |
Oct
(25) |
Nov
(29) |
Dec
(20) |
| 2014 |
Jan
(25) |
Feb
(19) |
Mar
(16) |
Apr
(33) |
May
(27) |
Jun
(37) |
Jul
(29) |
Aug
(27) |
Sep
(37) |
Oct
(58) |
Nov
(109) |
Dec
(26) |
| 2015 |
Jan
(4) |
Feb
(35) |
Mar
(22) |
Apr
(35) |
May
(28) |
Jun
(20) |
Jul
(4) |
Aug
(16) |
Sep
(37) |
Oct
(13) |
Nov
(13) |
Dec
(14) |
| 2016 |
Jan
(22) |
Feb
(7) |
Mar
(23) |
Apr
(30) |
May
(10) |
Jun
(10) |
Jul
(15) |
Aug
(12) |
Sep
(22) |
Oct
(31) |
Nov
(5) |
Dec
(5) |
| 2017 |
Jan
(30) |
Feb
(25) |
Mar
(28) |
Apr
(4) |
May
(19) |
Jun
(13) |
Jul
(7) |
Aug
(1) |
Sep
(2) |
Oct
(5) |
Nov
(12) |
Dec
(2) |
| 2018 |
Jan
(7) |
Feb
|
Mar
(7) |
Apr
(2) |
May
(8) |
Jun
(18) |
Jul
(6) |
Aug
(3) |
Sep
(15) |
Oct
(33) |
Nov
(13) |
Dec
(7) |
| 2019 |
Jan
(5) |
Feb
(7) |
Mar
(30) |
Apr
(5) |
May
(4) |
Jun
(69) |
Jul
(86) |
Aug
(22) |
Sep
(6) |
Oct
(7) |
Nov
(5) |
Dec
(3) |
| 2020 |
Jan
(10) |
Feb
(12) |
Mar
(22) |
Apr
(5) |
May
(1) |
Jun
(4) |
Jul
(6) |
Aug
|
Sep
(9) |
Oct
|
Nov
|
Dec
(1) |
| 2021 |
Jan
(4) |
Feb
(11) |
Mar
(7) |
Apr
(7) |
May
|
Jun
(3) |
Jul
(10) |
Aug
(6) |
Sep
|
Oct
|
Nov
(18) |
Dec
(2) |
| 2022 |
Jan
(1) |
Feb
(1) |
Mar
|
Apr
|
May
|
Jun
(2) |
Jul
|
Aug
(4) |
Sep
|
Oct
|
Nov
|
Dec
|
| 2023 |
Jan
|
Feb
|
Mar
|
Apr
(1) |
May
(1) |
Jun
|
Jul
|
Aug
(5) |
Sep
|
Oct
|
Nov
|
Dec
|
|
From: Daniel F. <da...@di...> - 2014-10-15 09:23:13
|
Hi, We have a EJBCA installation with around 300 users running for around 5y. I am facing right now a problem I'm just unable to solve. Some of our users are able to generate a new identity even after the status changed to 40 (Generated) and no administrator changed it to 10(NEW). The logs show this behaviour is triggered by the "RA user" automatically for unknown reasons. For example http://pastebin.com/DDugx1QN Any idea? Thanks. -- ----------------------------------- Daniel Franganillo Corrales ----------------------------------- e-mail: da...@di... ----------------------------------- CriptoLab. Despacho 6305. Facultad de Informática. Campus de Montegancedo S/N Universidad Politécnica de Madrid. Boadilla del Monte. Madrid (Spain) Teléfono - 91 336 (3673) ----------------------------------- |
|
From: Michael S. <mi...@st...> - 2014-10-15 08:21:41
|
Tomas Gustavsson wrote:
>
> What do you mean it is wrong?
If you enable "LDAP DN order" the order is actually reversed. When displaying
the certs with OpenSSL subject and issuer are *not* LDAP DN order. Please
check yourself with
openssl x509 -nameopt rfc2253
^^^^^^^^^^^^^^^^
(If you don't use this -nameopt value you get some obscure OpenSSL internal
string representation which is definitely *not* LDAP DN order although in
recent versions separated by comma.)
I'd suggest to completely drop this flawed configuration option.
> Can you suggest some new help text?
1. There is no such thing as a X.500 DN string representation. The only
well-defined string representation for distinguished names is RFC 4514
(formerly RFC 2253) which defines what you call "LDAP DN order".
BTW: Obviously the ASN.1 string type gets lost with this representation.
=> IMO if generating strings of DNs this RFC 4514 representation should be
*always* used
2. And this help text is plain wrong:
"In theory the order of the DN should not matter, because comparisons between
DNs should be done on the RDN level."
It is confusing and in contradiction to
http://tools.ietf.org/html/rfc5280#section-7.1
[..] Two distinguished names DN1 and DN2 match if they
have the same number of RDNs, for each RDN in DN1 there is a matching
RDN in DN2, and the matching RDNs appear in the same order in both
DNs.
Note the words "same order" herein.
Also in some protocols DN matching is even done by strictly comparing the DER
encoding of the DNs to avoid having to deal with compability issues of the
different ASN.1 string types.
Ciao, Michael.
|
|
From: Tomas G. <to...@pr...> - 2014-10-15 08:06:57
|
What do you mean it is wrong? Can you suggest some new help text? Cheers, Tomas On 2014-10-13 15:39, Michael Ströder wrote: > HI! > > Besides the misleading help text the option "LDAP DN order" in certificates > profiles still is wrong. > > My recommendation is currently to uncheck the option to get the right order. > You always have to check with openssl x509 -name rfc2253 to get this displayed > right by OpenSSL. > > Ciao, Michael. > > > > ------------------------------------------------------------------------------ > Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer > Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports > Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper > Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer > http://p.sf.net/sfu/Zoho > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Tomas G. <to...@pr...> - 2014-10-13 16:10:27
|
The current working is that patch releases is only Enterprise (it does cost resources). Main releases will be Community and everything goes into future main releases of course. Cheers, Tomas On 2014-10-13 15:31, Michael Ströder wrote: > On Mon, 13 Oct 2014 15:20:43 +0200 Tomas Gustavsson <to...@pr...> wrote >> Ok, then it is the referenced issue. >> >> 6.2.3 is Enterprise only. > > Does that mean that the community edition won't receive any fixes? > > Ciao, Michael. > > |
|
From: Samuel L. B. <sa...@pr...> - 2014-10-13 13:49:17
|
Hi, > What's the valid input format for field "Certificate Policy Id" in adminweb? > > I got a exception traceback with this message for input value 42.42.42.42: > > "string 42.42.42.42 not an OID" That's in fact not a valid OID. All OIDs start with either 0, 1 or 2. See this list: http://oid-info.com/cgi-bin/display?tree=1 Regards, Samuel |
|
From: Michael S. <mi...@st...> - 2014-10-13 13:39:27
|
HI! Besides the misleading help text the option "LDAP DN order" in certificates profiles still is wrong. My recommendation is currently to uncheck the option to get the right order. You always have to check with openssl x509 -name rfc2253 to get this displayed right by OpenSSL. Ciao, Michael. |
|
From: Michael S. <mi...@st...> - 2014-10-13 13:36:03
|
HI! What's the valid input format for field "Certificate Policy Id" in adminweb? I got a exception traceback with this message for input value 42.42.42.42: "string 42.42.42.42 not an OID" Ciao, Michael. |
|
From: Michael S. <mi...@st...> - 2014-10-13 13:31:51
|
On Mon, 13 Oct 2014 15:20:43 +0200 Tomas Gustavsson <to...@pr...> wrote > Ok, then it is the referenced issue. > > 6.2.3 is Enterprise only. Does that mean that the community edition won't receive any fixes? Ciao, Michael. |
|
From: Tomas G. <to...@pr...> - 2014-10-13 13:20:52
|
Ok, then it is the referenced issue. 6.2.3 is Enterprise only. Regards, Tomas On 2014-10-13 15:16, Michael Ströder wrote: > On Mon, 13 Oct 2014 15:07:33 +0200 Tomas Gustavsson <to...@pr...> wrote >> You are using a subjectAltName subset for the Root CA? > > No, But I've checked "Subset of Subject DN" -> "Restrict". > > 6.2.3 is enterprise-only? > > Ciao, Michael. > > |
|
From: Michael S. <mi...@st...> - 2014-10-13 13:16:19
|
On Mon, 13 Oct 2014 15:07:33 +0200 Tomas Gustavsson <to...@pr...> wrote > You are using a subjectAltName subset for the Root CA? No, But I've checked "Subset of Subject DN" -> "Restrict". 6.2.3 is enterprise-only? Ciao, Michael. |
|
From: Tomas G. <to...@pr...> - 2014-10-13 13:07:50
|
You are using a subjectAltName subset for the Root CA? There was an issue like this fixed in 6.2.3. https://jira.primekey.se/browse/ECA-3760 I'm not sure if it still remains for subjectAltName as well though, so I created an issue to verify it. https://jira.primekey.se/browse/ECA-3852 Cheers, Tomas On 2014-10-13 14:09, Michael Ströder wrote: > HI! > > ejbca 6.2 up and running and I've created a RSA 4096 softkey. > > However when I'm trying to generate a self-signed root CA cert based on custom > certificate profile with adminweb UI I get the following message (see more log > lines attached below): > > An exception has occurred. > java.lang.ClassCastException: java.lang.String cannot be cast to > java.lang.Integer > > Any help is appreciated. > > Ciao, Michael. > > ---------------------------- snip --------------------------- > 14:03:01,431 INFO [org.ejbca.core.ejb.ca.caadmin.CAAdminSessionBean] > (http--0.0.0.0-8443-1) Creating an X509 CA: CA_Test-RootCA-01 > 14:03:01,575 INFO [org.cesecore.audit.impl.log4j.Log4jDevice] > (http--0.0.0.0-8443-1) 2014-10-13 > 14:03:01+02:00;ACCESS_CONTROL;SUCCESS;ACCESSCONTROL;CORE;CN=SuperAdmin,O=Test-EJBCA,C=DE;;;;resource0=/ca_functionality/add_ca;resource1=/cryptotoken/use/875412134 > 14:03:01,629 INFO [org.cesecore.audit.impl.log4j.Log4jDevice] > (http--0.0.0.0-8443-1) 2014-10-13 > 14:03:01+02:00;CA_CREATION;SUCCESS;CA;CORE;CN=SuperAdmin,O=Test-EJBCA,C=DE;-377994287;;;msg=CA > with id -377994287 and name CA_Test-RootCA-01 added, status: 1. > ;tokenproperties={defaultKey=privatesignkeyalias, > certSignKey=privatesignkeyalias, > crlSignKey=privatesignkeyalias};tokensequence=00000 > 14:03:01,652 INFO [org.cesecore.audit.impl.log4j.Log4jDevice] > (http--0.0.0.0-8443-1) 2014-10-13 > 14:03:01+02:00;CA_CREATION;FAILURE;CA;CORE;CN=SuperAdmin,O=Test-EJBCA,C=DE;-377994287;;;msg=Could > not create CA CA_Test-RootCA-01.;error=java.lang.String cannot be cast to > java.lang.Integer > 14:03:01,668 ERROR [org.jboss.ejb3.invocation] (http--0.0.0.0-8443-1) > JBAS014134: EJB Invocation failed on component CAAdminSessionBean for method > public abstract void > org.ejbca.core.ejb.ca.caadmin.CAAdminSession.createCA(org.cesecore.authentication.tokens.AuthenticationToken,org.cesecore.certificates.ca.CAInfo) > throws > org.cesecore.certificates.ca.CAExistsException,org.cesecore.authorization.AuthorizationDeniedException,org.cesecore.keys.token.CryptoTokenOfflineException,org.cesecore.certificates.ca.InvalidAlgorithmException: > javax.ejb.EJBException: java.lang.ClassCastException: java.lang.String cannot > be cast to java.lang.Integer > at > org.ejbca.core.ejb.ca.caadmin.CAAdminSessionBean.createCertificateChain(CAAdminSessionBean.java:820) > [ejbca-ejb.jar:] > at > org.ejbca.core.ejb.ca.caadmin.CAAdminSessionBean.createCA(CAAdminSessionBean.java:701) > [ejbca-ejb.jar:] > at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method) > [rt.jar:1.7.0_65] > at > sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:57) > [rt.jar:1.7.0_65] > at > sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43) > [rt.jar:1.7.0_65] > at java.lang.reflect.Method.invoke(Method.java:606) [rt.jar:1.7.0_65] > at > org.jboss.as.ee.component.ManagedReferenceMethodInterceptorFactory$ManagedReferenceMethodInterceptor.processInvocation(ManagedReferenceMethodInterceptorFactory.java:72) > [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] > at > org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) > [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at > org.jboss.invocation.WeavedInterceptor.processInvocation(WeavedInterceptor.java:53) > [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at > org.jboss.as.ee.component.interceptors.UserInterceptorFactory$1.processInvocation(UserInterceptorFactory.java:36) > [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] > at > org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) > [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at > org.jboss.as.jpa.interceptor.SBInvocationInterceptor.processInvocation(SBInvocationInterceptor.java:47) > [jboss-as-jpa-7.1.1.Final.jar:7.1.1.Final] > at > org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) > [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at > org.jboss.invocation.InitialInterceptor.processInvocation(InitialInterceptor.java:21) > [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at > org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) > [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at > org.jboss.invocation.ChainedInterceptor.processInvocation(ChainedInterceptor.java:61) > [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at > org.jboss.as.ee.component.interceptors.ComponentDispatcherInterceptor.processInvocation(ComponentDispatcherInterceptor.java:53) > [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] > at > org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) > [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at > org.jboss.as.ejb3.component.pool.PooledInstanceInterceptor.processInvocation(PooledInstanceInterceptor.java:51) > [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final] > at > org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) > [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at > org.jboss.as.ejb3.tx.CMTTxInterceptor.invokeInOurTx(CMTTxInterceptor.java:228) > [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final] > at org.jboss.as.ejb3.tx.CMTTxInterceptor.required(CMTTxInterceptor.java:304) > [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final] > at > org.jboss.as.ejb3.tx.CMTTxInterceptor.processInvocation(CMTTxInterceptor.java:190) > [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final] > at > org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) > [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at > org.jboss.as.ejb3.component.interceptors.CurrentInvocationContextInterceptor.processInvocation(CurrentInvocationContextInterceptor.java:41) > [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final] > at > org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) > [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at > org.jboss.as.ejb3.component.interceptors.LoggingInterceptor.processInvocation(LoggingInterceptor.java:59) > [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final] > at > org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) > [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at > org.jboss.as.ee.component.NamespaceContextInterceptor.processInvocation(NamespaceContextInterceptor.java:50) > [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] > at > org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) > [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at > org.jboss.as.ejb3.component.interceptors.AdditionalSetupInterceptor.processInvocation(AdditionalSetupInterceptor.java:32) > [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final] > at > org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) > [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at > org.jboss.as.ee.component.TCCLInterceptor.processInvocation(TCCLInterceptor.java:45) > [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] > at > org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) > [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at > org.jboss.invocation.ChainedInterceptor.processInvocation(ChainedInterceptor.java:61) > [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at org.jboss.as.ee.component.ViewService$View.invoke(ViewService.java:165) > [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] > at > org.jboss.as.ee.component.ViewDescription$1.processInvocation(ViewDescription.java:173) > [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] > at > org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) > [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at > org.jboss.invocation.ChainedInterceptor.processInvocation(ChainedInterceptor.java:61) > [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at > org.jboss.as.ee.component.ProxyInvocationHandler.invoke(ProxyInvocationHandler.java:72) > [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] > at org.ejbca.core.ejb.ca.caadmin.CAAdminSessionLocal$$$view30.createCA(Unknown > Source) [ejbca-interface.jar:] > at > org.ejbca.ui.web.admin.cainterface.CADataHandler.createCA(CADataHandler.java:114) > at > org.ejbca.ui.web.admin.cainterface.CAInterfaceBean.actionCreateCaMakeRequestInternal(CAInterfaceBean.java:771) > at > org.ejbca.ui.web.admin.cainterface.CAInterfaceBean.actionCreateCaMakeRequest(CAInterfaceBean.java:576) > at org.apache.jsp.ca.editcas.editcas_jsp._jspService(editcas_jsp.java:492) > at org.apache.jasper.runtime.HttpJspBase.service(HttpJspBase.java:70) > at javax.servlet.http.HttpServlet.service(HttpServlet.java:847) > [jboss-servlet-api_3.0_spec-1.0.0.Final.jar:1.0.0.Final] > at > org.apache.jasper.servlet.JspServletWrapper.service(JspServletWrapper.java:369) > at org.apache.jasper.servlet.JspServlet.serviceJspFile(JspServlet.java:326) > at org.apache.jasper.servlet.JspServlet.service(JspServlet.java:253) > at javax.servlet.http.HttpServlet.service(HttpServlet.java:847) > [jboss-servlet-api_3.0_spec-1.0.0.Final.jar:1.0.0.Final] > at > org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:329) > at > org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:248) > at > org.owasp.filters.ContentSecurityPolicyFilter.doFilter(ContentSecurityPolicyFilter.java:198) > [ejbca-common-web.jar:EJBCA 6.2.0 (r19221)] > at > org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:280) > at > org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:248) > at org.owasp.filters.ClickjackFilter.doFilter(ClickjackFilter.java:36) > [ejbca-common-web.jar:EJBCA 6.2.0 (r19221)] > at > org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:280) > at > org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:248) > at > org.ejbca.ui.web.admin.ProxiedAuthenticationFilter.doFilter(ProxiedAuthenticationFilter.java:109) > at > org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:280) > at > org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:248) > at > org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:275) > at > org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:161) > at > org.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:397) > at > org.jboss.as.jpa.interceptor.WebNonTxEmCloserValve.invoke(WebNonTxEmCloserValve.java:50) > [jboss-as-jpa-7.1.1.Final.jar:7.1.1.Final] > at > org.jboss.as.web.security.SecurityContextAssociationValve.invoke(SecurityContextAssociationValve.java:153) > at > org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:155) > at > org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:102) > at > org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:109) > at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:368) > at org.apache.coyote.http11.Http11Processor.process(Http11Processor.java:877) > at > org.apache.coyote.http11.Http11Protocol$Http11ConnectionHandler.process(Http11Protocol.java:671) > at org.apache.tomcat.util.net.JIoEndpoint$Worker.run(JIoEndpoint.java:930) > at java.lang.Thread.run(Thread.java:745) [rt.jar:1.7.0_65] > Caused by: java.lang.ClassCastException: java.lang.String cannot be cast to > java.lang.Integer > at > org.cesecore.certificates.certificateprofile.CertificateProfile.constructUserData(CertificateProfile.java:1302) > [cesecore-common.jar:] > at > org.cesecore.certificates.certificateprofile.CertificateProfile.createSubjectDNSubSet(CertificateProfile.java:1246) > [cesecore-common.jar:] > at org.cesecore.certificates.ca.X509CA.generateCertificate(X509CA.java:703) > [cesecore-common.jar:] > at org.cesecore.certificates.ca.X509CA.generateCertificate(X509CA.java:631) > [cesecore-common.jar:] > at org.cesecore.certificates.ca.CA.generateCertificate(CA.java:764) > [cesecore-common.jar:] > at org.cesecore.certificates.ca.CA.generateCertificate(CA.java:723) > [cesecore-common.jar:] > at > org.ejbca.core.ejb.ca.caadmin.CAAdminSessionBean.createCertificateChain(CAAdminSessionBean.java:797) > [ejbca-ejb.jar:] > ... 74 more > > 14:03:01,784 ERROR [errorpage.jsp] (http--0.0.0.0-8443-1) > java.lang.ClassCastException: java.lang.String cannot be cast to > java.lang.Integer: javax.ejb.EJBException: java.lang.ClassCastException: > java.lang.String cannot be cast to java.lang.Integer > at > org.ejbca.core.ejb.ca.caadmin.CAAdminSessionBean.createCertificateChain(CAAdminSessionBean.java:820) > [ejbca-ejb.jar:] > at > org.ejbca.core.ejb.ca.caadmin.CAAdminSessionBean.createCA(CAAdminSessionBean.java:701) > [ejbca-ejb.jar:] > at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method) > [rt.jar:1.7.0_65] > at > sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:57) > [rt.jar:1.7.0_65] > at > sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43) > [rt.jar:1.7.0_65] > at java.lang.reflect.Method.invoke(Method.java:606) [rt.jar:1.7.0_65] > at > org.jboss.as.ee.component.ManagedReferenceMethodInterceptorFactory$ManagedReferenceMethodInterceptor.processInvocation(ManagedReferenceMethodInterceptorFactory.java:72) > [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] > at > org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) > [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at > org.jboss.invocation.WeavedInterceptor.processInvocation(WeavedInterceptor.java:53) > [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at > org.jboss.as.ee.component.interceptors.UserInterceptorFactory$1.processInvocation(UserInterceptorFactory.java:36) > [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] > at > org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) > [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at > org.jboss.as.jpa.interceptor.SBInvocationInterceptor.processInvocation(SBInvocationInterceptor.java:47) > [jboss-as-jpa-7.1.1.Final.jar:7.1.1.Final] > at > org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) > [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at > org.jboss.invocation.InitialInterceptor.processInvocation(InitialInterceptor.java:21) > [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at > org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) > [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at > org.jboss.invocation.ChainedInterceptor.processInvocation(ChainedInterceptor.java:61) > [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at > org.jboss.as.ee.component.interceptors.ComponentDispatcherInterceptor.processInvocation(ComponentDispatcherInterceptor.java:53) > [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] > at > org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) > [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at > org.jboss.as.ejb3.component.pool.PooledInstanceInterceptor.processInvocation(PooledInstanceInterceptor.java:51) > [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final] > at > org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) > [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at > org.jboss.as.ejb3.tx.CMTTxInterceptor.invokeInOurTx(CMTTxInterceptor.java:228) > [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final] > at org.jboss.as.ejb3.tx.CMTTxInterceptor.required(CMTTxInterceptor.java:304) > [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final] > at > org.jboss.as.ejb3.tx.CMTTxInterceptor.processInvocation(CMTTxInterceptor.java:190) > [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final] > at > org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) > [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at > org.jboss.as.ejb3.component.interceptors.CurrentInvocationContextInterceptor.processInvocation(CurrentInvocationContextInterceptor.java:41) > [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final] > at > org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) > [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at > org.jboss.as.ejb3.component.interceptors.LoggingInterceptor.processInvocation(LoggingInterceptor.java:59) > [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final] > at > org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) > [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at > org.jboss.as.ee.component.NamespaceContextInterceptor.processInvocation(NamespaceContextInterceptor.java:50) > [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] > at > org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) > [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at > org.jboss.as.ejb3.component.interceptors.AdditionalSetupInterceptor.processInvocation(AdditionalSetupInterceptor.java:32) > [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final] > at > org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) > [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at > org.jboss.as.ee.component.TCCLInterceptor.processInvocation(TCCLInterceptor.java:45) > [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] > at > org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) > [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at > org.jboss.invocation.ChainedInterceptor.processInvocation(ChainedInterceptor.java:61) > [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at org.jboss.as.ee.component.ViewService$View.invoke(ViewService.java:165) > [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] > at > org.jboss.as.ee.component.ViewDescription$1.processInvocation(ViewDescription.java:173) > [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] > at > org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) > [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at > org.jboss.invocation.ChainedInterceptor.processInvocation(ChainedInterceptor.java:61) > [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at > org.jboss.as.ee.component.ProxyInvocationHandler.invoke(ProxyInvocationHandler.java:72) > [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] > at org.ejbca.core.ejb.ca.caadmin.CAAdminSessionLocal$$$view30.createCA(Unknown > Source) [ejbca-interface.jar:] > at > org.ejbca.ui.web.admin.cainterface.CADataHandler.createCA(CADataHandler.java:114) > [classes:] > at > org.ejbca.ui.web.admin.cainterface.CAInterfaceBean.actionCreateCaMakeRequestInternal(CAInterfaceBean.java:771) > [classes:] > at > org.ejbca.ui.web.admin.cainterface.CAInterfaceBean.actionCreateCaMakeRequest(CAInterfaceBean.java:576) > [classes:] > at org.apache.jsp.ca.editcas.editcas_jsp._jspService(editcas_jsp.java:492) > at org.apache.jasper.runtime.HttpJspBase.service(HttpJspBase.java:70) > [jbossweb-7.0.13.Final.jar:] > at javax.servlet.http.HttpServlet.service(HttpServlet.java:847) > [jboss-servlet-api_3.0_spec-1.0.0.Final.jar:1.0.0.Final] > at > org.apache.jasper.servlet.JspServletWrapper.service(JspServletWrapper.java:369) > [jbossweb-7.0.13.Final.jar:] > at org.apache.jasper.servlet.JspServlet.serviceJspFile(JspServlet.java:326) > [jbossweb-7.0.13.Final.jar:] > at org.apache.jasper.servlet.JspServlet.service(JspServlet.java:253) > [jbossweb-7.0.13.Final.jar:] > at javax.servlet.http.HttpServlet.service(HttpServlet.java:847) > [jboss-servlet-api_3.0_spec-1.0.0.Final.jar:1.0.0.Final] > at > org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:329) > [jbossweb-7.0.13.Final.jar:] > at > org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:248) > [jbossweb-7.0.13.Final.jar:] > at > org.owasp.filters.ContentSecurityPolicyFilter.doFilter(ContentSecurityPolicyFilter.java:198) > [ejbca-common-web.jar:EJBCA 6.2.0 (r19221)] > at > org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:280) > [jbossweb-7.0.13.Final.jar:] > at > org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:248) > [jbossweb-7.0.13.Final.jar:] > at org.owasp.filters.ClickjackFilter.doFilter(ClickjackFilter.java:36) > [ejbca-common-web.jar:EJBCA 6.2.0 (r19221)] > at > org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:280) > [jbossweb-7.0.13.Final.jar:] > at > org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:248) > [jbossweb-7.0.13.Final.jar:] > at > org.ejbca.ui.web.admin.ProxiedAuthenticationFilter.doFilter(ProxiedAuthenticationFilter.java:109) > [classes:] > at > org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:280) > [jbossweb-7.0.13.Final.jar:] > at > org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:248) > [jbossweb-7.0.13.Final.jar:] > at > org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:275) > [jbossweb-7.0.13.Final.jar:] > at > org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:161) > [jbossweb-7.0.13.Final.jar:] > at > org.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:397) > [jbossweb-7.0.13.Final.jar:] > at > org.jboss.as.jpa.interceptor.WebNonTxEmCloserValve.invoke(WebNonTxEmCloserValve.java:50) > [jboss-as-jpa-7.1.1.Final.jar:7.1.1.Final] > at > org.jboss.as.web.security.SecurityContextAssociationValve.invoke(SecurityContextAssociationValve.java:153) > [jboss-as-web-7.1.1.Final.jar:7.1.1.Final] > at > org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:155) > [jbossweb-7.0.13.Final.jar:] > at > org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:102) > [jbossweb-7.0.13.Final.jar:] > at > org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:109) > [jbossweb-7.0.13.Final.jar:] > at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:368) > [jbossweb-7.0.13.Final.jar:] > at org.apache.coyote.http11.Http11Processor.process(Http11Processor.java:877) > [jbossweb-7.0.13.Final.jar:] > at > org.apache.coyote.http11.Http11Protocol$Http11ConnectionHandler.process(Http11Protocol.java:671) > [jbossweb-7.0.13.Final.jar:] > at org.apache.tomcat.util.net.JIoEndpoint$Worker.run(JIoEndpoint.java:930) > [jbossweb-7.0.13.Final.jar:] > at java.lang.Thread.run(Thread.java:745) [rt.jar:1.7.0_65] > Caused by: java.lang.ClassCastException: java.lang.String cannot be cast to > java.lang.Integer > at > org.cesecore.certificates.certificateprofile.CertificateProfile.constructUserData(CertificateProfile.java:1302) > [cesecore-common.jar:] > at > org.cesecore.certificates.certificateprofile.CertificateProfile.createSubjectDNSubSet(CertificateProfile.java:1246) > [cesecore-common.jar:] > at org.cesecore.certificates.ca.X509CA.generateCertificate(X509CA.java:703) > [cesecore-common.jar:] > at org.cesecore.certificates.ca.X509CA.generateCertificate(X509CA.java:631) > [cesecore-common.jar:] > at org.cesecore.certificates.ca.CA.generateCertificate(CA.java:764) > [cesecore-common.jar:] > at org.cesecore.certificates.ca.CA.generateCertificate(CA.java:723) > [cesecore-common.jar:] > at > org.ejbca.core.ejb.ca.caadmin.CAAdminSessionBean.createCertificateChain(CAAdminSessionBean.java:797) > [ejbca-ejb.jar:] > ... 74 more > > 14:04:50,135 INFO [org.cesecore.keys.token.SoftCryptoToken] (EJB default - 9) > Activated Crypto Token with id -1720728161. > > > > ------------------------------------------------------------------------------ > Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer > Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports > Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper > Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer > http://p.sf.net/sfu/Zoho > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Michael S. <mi...@st...> - 2014-10-13 12:10:20
|
HI!
ejbca 6.2 up and running and I've created a RSA 4096 softkey.
However when I'm trying to generate a self-signed root CA cert based on custom
certificate profile with adminweb UI I get the following message (see more log
lines attached below):
An exception has occurred.
java.lang.ClassCastException: java.lang.String cannot be cast to
java.lang.Integer
Any help is appreciated.
Ciao, Michael.
---------------------------- snip ---------------------------
14:03:01,431 INFO [org.ejbca.core.ejb.ca.caadmin.CAAdminSessionBean]
(http--0.0.0.0-8443-1) Creating an X509 CA: CA_Test-RootCA-01
14:03:01,575 INFO [org.cesecore.audit.impl.log4j.Log4jDevice]
(http--0.0.0.0-8443-1) 2014-10-13
14:03:01+02:00;ACCESS_CONTROL;SUCCESS;ACCESSCONTROL;CORE;CN=SuperAdmin,O=Test-EJBCA,C=DE;;;;resource0=/ca_functionality/add_ca;resource1=/cryptotoken/use/875412134
14:03:01,629 INFO [org.cesecore.audit.impl.log4j.Log4jDevice]
(http--0.0.0.0-8443-1) 2014-10-13
14:03:01+02:00;CA_CREATION;SUCCESS;CA;CORE;CN=SuperAdmin,O=Test-EJBCA,C=DE;-377994287;;;msg=CA
with id -377994287 and name CA_Test-RootCA-01 added, status: 1.
;tokenproperties={defaultKey=privatesignkeyalias,
certSignKey=privatesignkeyalias,
crlSignKey=privatesignkeyalias};tokensequence=00000
14:03:01,652 INFO [org.cesecore.audit.impl.log4j.Log4jDevice]
(http--0.0.0.0-8443-1) 2014-10-13
14:03:01+02:00;CA_CREATION;FAILURE;CA;CORE;CN=SuperAdmin,O=Test-EJBCA,C=DE;-377994287;;;msg=Could
not create CA CA_Test-RootCA-01.;error=java.lang.String cannot be cast to
java.lang.Integer
14:03:01,668 ERROR [org.jboss.ejb3.invocation] (http--0.0.0.0-8443-1)
JBAS014134: EJB Invocation failed on component CAAdminSessionBean for method
public abstract void
org.ejbca.core.ejb.ca.caadmin.CAAdminSession.createCA(org.cesecore.authentication.tokens.AuthenticationToken,org.cesecore.certificates.ca.CAInfo)
throws
org.cesecore.certificates.ca.CAExistsException,org.cesecore.authorization.AuthorizationDeniedException,org.cesecore.keys.token.CryptoTokenOfflineException,org.cesecore.certificates.ca.InvalidAlgorithmException:
javax.ejb.EJBException: java.lang.ClassCastException: java.lang.String cannot
be cast to java.lang.Integer
at
org.ejbca.core.ejb.ca.caadmin.CAAdminSessionBean.createCertificateChain(CAAdminSessionBean.java:820)
[ejbca-ejb.jar:]
at
org.ejbca.core.ejb.ca.caadmin.CAAdminSessionBean.createCA(CAAdminSessionBean.java:701)
[ejbca-ejb.jar:]
at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
[rt.jar:1.7.0_65]
at
sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:57)
[rt.jar:1.7.0_65]
at
sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
[rt.jar:1.7.0_65]
at java.lang.reflect.Method.invoke(Method.java:606) [rt.jar:1.7.0_65]
at
org.jboss.as.ee.component.ManagedReferenceMethodInterceptorFactory$ManagedReferenceMethodInterceptor.processInvocation(ManagedReferenceMethodInterceptorFactory.java:72)
[jboss-as-ee-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.invocation.WeavedInterceptor.processInvocation(WeavedInterceptor.java:53)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.as.ee.component.interceptors.UserInterceptorFactory$1.processInvocation(UserInterceptorFactory.java:36)
[jboss-as-ee-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.as.jpa.interceptor.SBInvocationInterceptor.processInvocation(SBInvocationInterceptor.java:47)
[jboss-as-jpa-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.invocation.InitialInterceptor.processInvocation(InitialInterceptor.java:21)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.invocation.ChainedInterceptor.processInvocation(ChainedInterceptor.java:61)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.as.ee.component.interceptors.ComponentDispatcherInterceptor.processInvocation(ComponentDispatcherInterceptor.java:53)
[jboss-as-ee-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.as.ejb3.component.pool.PooledInstanceInterceptor.processInvocation(PooledInstanceInterceptor.java:51)
[jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.as.ejb3.tx.CMTTxInterceptor.invokeInOurTx(CMTTxInterceptor.java:228)
[jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final]
at org.jboss.as.ejb3.tx.CMTTxInterceptor.required(CMTTxInterceptor.java:304)
[jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.as.ejb3.tx.CMTTxInterceptor.processInvocation(CMTTxInterceptor.java:190)
[jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.as.ejb3.component.interceptors.CurrentInvocationContextInterceptor.processInvocation(CurrentInvocationContextInterceptor.java:41)
[jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.as.ejb3.component.interceptors.LoggingInterceptor.processInvocation(LoggingInterceptor.java:59)
[jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.as.ee.component.NamespaceContextInterceptor.processInvocation(NamespaceContextInterceptor.java:50)
[jboss-as-ee-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.as.ejb3.component.interceptors.AdditionalSetupInterceptor.processInvocation(AdditionalSetupInterceptor.java:32)
[jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.as.ee.component.TCCLInterceptor.processInvocation(TCCLInterceptor.java:45)
[jboss-as-ee-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.invocation.ChainedInterceptor.processInvocation(ChainedInterceptor.java:61)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at org.jboss.as.ee.component.ViewService$View.invoke(ViewService.java:165)
[jboss-as-ee-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.as.ee.component.ViewDescription$1.processInvocation(ViewDescription.java:173)
[jboss-as-ee-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.invocation.ChainedInterceptor.processInvocation(ChainedInterceptor.java:61)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.as.ee.component.ProxyInvocationHandler.invoke(ProxyInvocationHandler.java:72)
[jboss-as-ee-7.1.1.Final.jar:7.1.1.Final]
at org.ejbca.core.ejb.ca.caadmin.CAAdminSessionLocal$$$view30.createCA(Unknown
Source) [ejbca-interface.jar:]
at
org.ejbca.ui.web.admin.cainterface.CADataHandler.createCA(CADataHandler.java:114)
at
org.ejbca.ui.web.admin.cainterface.CAInterfaceBean.actionCreateCaMakeRequestInternal(CAInterfaceBean.java:771)
at
org.ejbca.ui.web.admin.cainterface.CAInterfaceBean.actionCreateCaMakeRequest(CAInterfaceBean.java:576)
at org.apache.jsp.ca.editcas.editcas_jsp._jspService(editcas_jsp.java:492)
at org.apache.jasper.runtime.HttpJspBase.service(HttpJspBase.java:70)
at javax.servlet.http.HttpServlet.service(HttpServlet.java:847)
[jboss-servlet-api_3.0_spec-1.0.0.Final.jar:1.0.0.Final]
at
org.apache.jasper.servlet.JspServletWrapper.service(JspServletWrapper.java:369)
at org.apache.jasper.servlet.JspServlet.serviceJspFile(JspServlet.java:326)
at org.apache.jasper.servlet.JspServlet.service(JspServlet.java:253)
at javax.servlet.http.HttpServlet.service(HttpServlet.java:847)
[jboss-servlet-api_3.0_spec-1.0.0.Final.jar:1.0.0.Final]
at
org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:329)
at
org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:248)
at
org.owasp.filters.ContentSecurityPolicyFilter.doFilter(ContentSecurityPolicyFilter.java:198)
[ejbca-common-web.jar:EJBCA 6.2.0 (r19221)]
at
org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:280)
at
org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:248)
at org.owasp.filters.ClickjackFilter.doFilter(ClickjackFilter.java:36)
[ejbca-common-web.jar:EJBCA 6.2.0 (r19221)]
at
org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:280)
at
org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:248)
at
org.ejbca.ui.web.admin.ProxiedAuthenticationFilter.doFilter(ProxiedAuthenticationFilter.java:109)
at
org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:280)
at
org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:248)
at
org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:275)
at
org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:161)
at
org.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:397)
at
org.jboss.as.jpa.interceptor.WebNonTxEmCloserValve.invoke(WebNonTxEmCloserValve.java:50)
[jboss-as-jpa-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.as.web.security.SecurityContextAssociationValve.invoke(SecurityContextAssociationValve.java:153)
at
org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:155)
at
org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:102)
at
org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:109)
at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:368)
at org.apache.coyote.http11.Http11Processor.process(Http11Processor.java:877)
at
org.apache.coyote.http11.Http11Protocol$Http11ConnectionHandler.process(Http11Protocol.java:671)
at org.apache.tomcat.util.net.JIoEndpoint$Worker.run(JIoEndpoint.java:930)
at java.lang.Thread.run(Thread.java:745) [rt.jar:1.7.0_65]
Caused by: java.lang.ClassCastException: java.lang.String cannot be cast to
java.lang.Integer
at
org.cesecore.certificates.certificateprofile.CertificateProfile.constructUserData(CertificateProfile.java:1302)
[cesecore-common.jar:]
at
org.cesecore.certificates.certificateprofile.CertificateProfile.createSubjectDNSubSet(CertificateProfile.java:1246)
[cesecore-common.jar:]
at org.cesecore.certificates.ca.X509CA.generateCertificate(X509CA.java:703)
[cesecore-common.jar:]
at org.cesecore.certificates.ca.X509CA.generateCertificate(X509CA.java:631)
[cesecore-common.jar:]
at org.cesecore.certificates.ca.CA.generateCertificate(CA.java:764)
[cesecore-common.jar:]
at org.cesecore.certificates.ca.CA.generateCertificate(CA.java:723)
[cesecore-common.jar:]
at
org.ejbca.core.ejb.ca.caadmin.CAAdminSessionBean.createCertificateChain(CAAdminSessionBean.java:797)
[ejbca-ejb.jar:]
... 74 more
14:03:01,784 ERROR [errorpage.jsp] (http--0.0.0.0-8443-1)
java.lang.ClassCastException: java.lang.String cannot be cast to
java.lang.Integer: javax.ejb.EJBException: java.lang.ClassCastException:
java.lang.String cannot be cast to java.lang.Integer
at
org.ejbca.core.ejb.ca.caadmin.CAAdminSessionBean.createCertificateChain(CAAdminSessionBean.java:820)
[ejbca-ejb.jar:]
at
org.ejbca.core.ejb.ca.caadmin.CAAdminSessionBean.createCA(CAAdminSessionBean.java:701)
[ejbca-ejb.jar:]
at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
[rt.jar:1.7.0_65]
at
sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:57)
[rt.jar:1.7.0_65]
at
sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
[rt.jar:1.7.0_65]
at java.lang.reflect.Method.invoke(Method.java:606) [rt.jar:1.7.0_65]
at
org.jboss.as.ee.component.ManagedReferenceMethodInterceptorFactory$ManagedReferenceMethodInterceptor.processInvocation(ManagedReferenceMethodInterceptorFactory.java:72)
[jboss-as-ee-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.invocation.WeavedInterceptor.processInvocation(WeavedInterceptor.java:53)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.as.ee.component.interceptors.UserInterceptorFactory$1.processInvocation(UserInterceptorFactory.java:36)
[jboss-as-ee-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.as.jpa.interceptor.SBInvocationInterceptor.processInvocation(SBInvocationInterceptor.java:47)
[jboss-as-jpa-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.invocation.InitialInterceptor.processInvocation(InitialInterceptor.java:21)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.invocation.ChainedInterceptor.processInvocation(ChainedInterceptor.java:61)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.as.ee.component.interceptors.ComponentDispatcherInterceptor.processInvocation(ComponentDispatcherInterceptor.java:53)
[jboss-as-ee-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.as.ejb3.component.pool.PooledInstanceInterceptor.processInvocation(PooledInstanceInterceptor.java:51)
[jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.as.ejb3.tx.CMTTxInterceptor.invokeInOurTx(CMTTxInterceptor.java:228)
[jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final]
at org.jboss.as.ejb3.tx.CMTTxInterceptor.required(CMTTxInterceptor.java:304)
[jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.as.ejb3.tx.CMTTxInterceptor.processInvocation(CMTTxInterceptor.java:190)
[jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.as.ejb3.component.interceptors.CurrentInvocationContextInterceptor.processInvocation(CurrentInvocationContextInterceptor.java:41)
[jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.as.ejb3.component.interceptors.LoggingInterceptor.processInvocation(LoggingInterceptor.java:59)
[jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.as.ee.component.NamespaceContextInterceptor.processInvocation(NamespaceContextInterceptor.java:50)
[jboss-as-ee-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.as.ejb3.component.interceptors.AdditionalSetupInterceptor.processInvocation(AdditionalSetupInterceptor.java:32)
[jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.as.ee.component.TCCLInterceptor.processInvocation(TCCLInterceptor.java:45)
[jboss-as-ee-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.invocation.ChainedInterceptor.processInvocation(ChainedInterceptor.java:61)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at org.jboss.as.ee.component.ViewService$View.invoke(ViewService.java:165)
[jboss-as-ee-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.as.ee.component.ViewDescription$1.processInvocation(ViewDescription.java:173)
[jboss-as-ee-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.invocation.ChainedInterceptor.processInvocation(ChainedInterceptor.java:61)
[jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at
org.jboss.as.ee.component.ProxyInvocationHandler.invoke(ProxyInvocationHandler.java:72)
[jboss-as-ee-7.1.1.Final.jar:7.1.1.Final]
at org.ejbca.core.ejb.ca.caadmin.CAAdminSessionLocal$$$view30.createCA(Unknown
Source) [ejbca-interface.jar:]
at
org.ejbca.ui.web.admin.cainterface.CADataHandler.createCA(CADataHandler.java:114)
[classes:]
at
org.ejbca.ui.web.admin.cainterface.CAInterfaceBean.actionCreateCaMakeRequestInternal(CAInterfaceBean.java:771)
[classes:]
at
org.ejbca.ui.web.admin.cainterface.CAInterfaceBean.actionCreateCaMakeRequest(CAInterfaceBean.java:576)
[classes:]
at org.apache.jsp.ca.editcas.editcas_jsp._jspService(editcas_jsp.java:492)
at org.apache.jasper.runtime.HttpJspBase.service(HttpJspBase.java:70)
[jbossweb-7.0.13.Final.jar:]
at javax.servlet.http.HttpServlet.service(HttpServlet.java:847)
[jboss-servlet-api_3.0_spec-1.0.0.Final.jar:1.0.0.Final]
at
org.apache.jasper.servlet.JspServletWrapper.service(JspServletWrapper.java:369)
[jbossweb-7.0.13.Final.jar:]
at org.apache.jasper.servlet.JspServlet.serviceJspFile(JspServlet.java:326)
[jbossweb-7.0.13.Final.jar:]
at org.apache.jasper.servlet.JspServlet.service(JspServlet.java:253)
[jbossweb-7.0.13.Final.jar:]
at javax.servlet.http.HttpServlet.service(HttpServlet.java:847)
[jboss-servlet-api_3.0_spec-1.0.0.Final.jar:1.0.0.Final]
at
org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:329)
[jbossweb-7.0.13.Final.jar:]
at
org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:248)
[jbossweb-7.0.13.Final.jar:]
at
org.owasp.filters.ContentSecurityPolicyFilter.doFilter(ContentSecurityPolicyFilter.java:198)
[ejbca-common-web.jar:EJBCA 6.2.0 (r19221)]
at
org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:280)
[jbossweb-7.0.13.Final.jar:]
at
org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:248)
[jbossweb-7.0.13.Final.jar:]
at org.owasp.filters.ClickjackFilter.doFilter(ClickjackFilter.java:36)
[ejbca-common-web.jar:EJBCA 6.2.0 (r19221)]
at
org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:280)
[jbossweb-7.0.13.Final.jar:]
at
org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:248)
[jbossweb-7.0.13.Final.jar:]
at
org.ejbca.ui.web.admin.ProxiedAuthenticationFilter.doFilter(ProxiedAuthenticationFilter.java:109)
[classes:]
at
org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:280)
[jbossweb-7.0.13.Final.jar:]
at
org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:248)
[jbossweb-7.0.13.Final.jar:]
at
org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:275)
[jbossweb-7.0.13.Final.jar:]
at
org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:161)
[jbossweb-7.0.13.Final.jar:]
at
org.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:397)
[jbossweb-7.0.13.Final.jar:]
at
org.jboss.as.jpa.interceptor.WebNonTxEmCloserValve.invoke(WebNonTxEmCloserValve.java:50)
[jboss-as-jpa-7.1.1.Final.jar:7.1.1.Final]
at
org.jboss.as.web.security.SecurityContextAssociationValve.invoke(SecurityContextAssociationValve.java:153)
[jboss-as-web-7.1.1.Final.jar:7.1.1.Final]
at
org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:155)
[jbossweb-7.0.13.Final.jar:]
at
org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:102)
[jbossweb-7.0.13.Final.jar:]
at
org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:109)
[jbossweb-7.0.13.Final.jar:]
at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:368)
[jbossweb-7.0.13.Final.jar:]
at org.apache.coyote.http11.Http11Processor.process(Http11Processor.java:877)
[jbossweb-7.0.13.Final.jar:]
at
org.apache.coyote.http11.Http11Protocol$Http11ConnectionHandler.process(Http11Protocol.java:671)
[jbossweb-7.0.13.Final.jar:]
at org.apache.tomcat.util.net.JIoEndpoint$Worker.run(JIoEndpoint.java:930)
[jbossweb-7.0.13.Final.jar:]
at java.lang.Thread.run(Thread.java:745) [rt.jar:1.7.0_65]
Caused by: java.lang.ClassCastException: java.lang.String cannot be cast to
java.lang.Integer
at
org.cesecore.certificates.certificateprofile.CertificateProfile.constructUserData(CertificateProfile.java:1302)
[cesecore-common.jar:]
at
org.cesecore.certificates.certificateprofile.CertificateProfile.createSubjectDNSubSet(CertificateProfile.java:1246)
[cesecore-common.jar:]
at org.cesecore.certificates.ca.X509CA.generateCertificate(X509CA.java:703)
[cesecore-common.jar:]
at org.cesecore.certificates.ca.X509CA.generateCertificate(X509CA.java:631)
[cesecore-common.jar:]
at org.cesecore.certificates.ca.CA.generateCertificate(CA.java:764)
[cesecore-common.jar:]
at org.cesecore.certificates.ca.CA.generateCertificate(CA.java:723)
[cesecore-common.jar:]
at
org.ejbca.core.ejb.ca.caadmin.CAAdminSessionBean.createCertificateChain(CAAdminSessionBean.java:797)
[ejbca-ejb.jar:]
... 74 more
14:04:50,135 INFO [org.cesecore.keys.token.SoftCryptoToken] (EJB default - 9)
Activated Crypto Token with id -1720728161.
|
|
From: Michael S. <mi...@st...> - 2014-10-10 15:19:14
|
Tomas Gustavsson wrote: > How about version of ant? Hmmpf, that was it. Upgrading ant helped. Thanks. How about adding a check to build.xml for ant version? Ciao, Michael. |
|
From: Andreas K. <ku...@tr...> - 2014-10-10 11:11:24
|
Hi Michael, is your ant version recent enough? Greetings, Andreas > HI! > > I've managed to install EJBCA 6.2 on one system. But I'm banging my head > against the wall to find out why it fails on another system (CentOS 6.5, > openjdk 1.7) > > BUILD FAILED > /opt/ejbca_ce_6_2_0/build.xml:649: The following error occurred while executing > this line: > /opt/ejbca_ce_6_2_0/bin/jboss.xml:443: The following error occurred while > executing this line: > /opt/ejbca_ce_6_2_0/bin/jboss.xml:568: Problem: failed to create task or type > local > Cause: The name is undefined. > Action: Check the spelling. > Action: Check that any custom tasks/types have been declared. > Action: Check that any <presetdef>/<macrodef> declarations have taken place. > > Any hint where to look? > > Ciao, Michael. > > > > ------------------------------------------------------------------------------ > Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer > Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS Reports > Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper > Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer > http://pubads.g.doubleclick.net/gampad/clk?id=154622311&iu=/4140/ostg.clktrk > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > -- Andreas Kühne phone: +49 177 293 24 97 mailto: ku...@tr... Trustable Ltd. Niederlassung Deutschland Ströverstr. 18 - 59427 Unna Amtsgericht Hamm HRB 5868 Directors Andreas Kühne, Heiko Veit Company UK Company No: 5218868 Registered in England and Wales |
|
From: Tomas G. <to...@pr...> - 2014-10-10 11:03:54
|
How about version of ant? Cheers, Tomas "Michael Ströder" <mi...@st...> skrev: (10 oktober 2014 12:21:10 CEST) >HI! > >I've managed to install EJBCA 6.2 on one system. But I'm banging my >head >against the wall to find out why it fails on another system (CentOS >6.5, >openjdk 1.7) > >BUILD FAILED >/opt/ejbca_ce_6_2_0/build.xml:649: The following error occurred while >executing >this line: >/opt/ejbca_ce_6_2_0/bin/jboss.xml:443: The following error occurred >while >executing this line: >/opt/ejbca_ce_6_2_0/bin/jboss.xml:568: Problem: failed to create task >or type >local >Cause: The name is undefined. >Action: Check the spelling. >Action: Check that any custom tasks/types have been declared. >Action: Check that any <presetdef>/<macrodef> declarations have taken >place. > >Any hint where to look? > >Ciao, Michael. > > > >------------------------------------------------------------------------------ >Meet PCI DSS 3.0 Compliance Requirements with EventLog Analyzer >Achieve PCI DSS 3.0 Compliant Status with Out-of-the-box PCI DSS >Reports >Are you Audit-Ready for PCI DSS 3.0 Compliance? Download White paper >Comply to PCI DSS 3.0 Requirement 10 and 11.5 with EventLog Analyzer >http://pubads.g.doubleclick.net/gampad/clk?id=154622311&iu=/4140/ostg.clktrk >_______________________________________________ >Ejbca-develop mailing list >Ejb...@li... >https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Michael S. <mi...@st...> - 2014-10-10 10:39:43
|
HI! I've managed to install EJBCA 6.2 on one system. But I'm banging my head against the wall to find out why it fails on another system (CentOS 6.5, openjdk 1.7) BUILD FAILED /opt/ejbca_ce_6_2_0/build.xml:649: The following error occurred while executing this line: /opt/ejbca_ce_6_2_0/bin/jboss.xml:443: The following error occurred while executing this line: /opt/ejbca_ce_6_2_0/bin/jboss.xml:568: Problem: failed to create task or type local Cause: The name is undefined. Action: Check the spelling. Action: Check that any custom tasks/types have been declared. Action: Check that any <presetdef>/<macrodef> declarations have taken place. Any hint where to look? Ciao, Michael. |
|
From: John M. <joh...@gm...> - 2014-09-26 10:41:48
|
Hello, I am using the External RA service ( http://www.ejbca.org/docs/externalra.html). I want to add extra information for an end entity, like social security number or other private information that should not appear on the certificates issued for the entity. The problem is that the *EditUserRequest*(long requestId, String username, String subjectDN, String subjectAltName, String email, String subjectDirectoryAttributes, String endEntityProfileName, String certificateProfileName, String cAName, String password, int status, int type, String tokenname, String hardtokenissuername) doesn't have a field to set the extended information. When inspecting the code for the *EditUserRequestProcessor -> MessageProcessr:* protected EndEntityInformation >> generateEndEntityInformation(AuthenticationToken admin, ExtRARequest >> submessage) throws ClassCastException, EjbcaException, >> CADoesntExistsException, AuthorizationDeniedException { > > String dirAttributes = submessage.getSubjectDirectoryAttributes(); > > ExtendedInformation ext = null; > > if (dirAttributes != null) { > > ext = new ExtendedInformation(); > > ext.setSubjectDirectoryAttributes(dirAttributes); > > } > > return new EndEntityInformation(submessage.getUsername(), > > submessage.getSubjectDN(), > > getCAId(admin,submessage.getCAName()), > > submessage.getSubjectAltName(), > > submessage.getEmail(), > > EndEntityConstants.STATUS_INPROCESS, > > new EndEntityType(EndEntityTypes.ENDUSER), > > getEndEntityProfileId(admin, >> submessage.getEndEntityProfileName()), > > >> getCertificateProfileId(submessage.getCertificateProfileName()), > > null, > > null, > > SecConst.TOKEN_SOFT_BROWSERGEN, > > 0, > > ext); > > } > > As you can see only the subjectDirAttributes are added to the extendedinformation. Is there a way to save the information on the ejbca database ? The solution I am working on right now, is to create another table on the RA database, where the Message table is located, where I put extra information for the UserData table in the EJBCA databasse. |
|
From: Randy Yu <yu...@ec...> - 2014-09-22 02:42:42
|
Thanks Tomas. Sorry I was also testing EJBCA 4.x as we have been troubleshooting with both version 4 and 6 as a responder to version 3 instances. My question previously applied to using a 4.0.16 instance. Also are there any caveats that are known from using version 4 and 6 as responders to version 3 production CA instances? ________________________________________ From: Tomas Gustavsson [to...@pr...] Sent: Friday, September 19, 2014 12:31 PM To: ejb...@li...; Randy Yu Subject: Re: [Ejbca-develop] EJBCA ocsp verification error In EJBCA 6 there is no ocsp keys directory, you create a crypto token, issue a csr to the CA, and import the issued certificate. Cheers, Tomas On 19 september 2014 16:53:14 CEST, Randy Yu <yu...@ec...> wrote: >Thanks Tomas. > >If we are using a Luna HSM hard token, I believe we have to create a >PKCS11 key as the PKCS12 is only for soft tokens? Also, when >attempting to create a PKCS11 key for the specific CA, we issue the >following command but are unsure how to retrieve the actual key to >store in the ocsp keys directory. > >./ejbcaClientToolBox.sh PKCS11HSMKeyTool generate >/usr/lunasa/lib/libCryptoki2.so 2048 test 1 > > >-----Original Message----- >From: Tomas Gustavsson [mailto:to...@pr...] >Sent: September-11-14 10:35 AM >To: ejb...@li... >Subject: Re: [Ejbca-develop] EJBCA ocsp verification error > > >If you want to set up an OCSP responder, separate from the CA you need >an OCSP Signer private key and certificate. > >Cheers, >Tomas > >On 2014-09-11 16:01, Randy Yu wrote: >> Some more information to add to this. The CA we import to the EJBCA >6 instance is a public key from a hard token signed CA. With the >public key imported to EJBCA 6, would the issuer name hash be carried >over or is this a possible reason why it is unable to be found? >> >> Also with this EJBCA 6 ocsp responder instance we are trying to >setup, we are trying to use this same imported CA to do the CRL >download service, we are unable to complete the "polulating the ocsp >responder database" steps since the CDP editing option is unavailable: >> >> Admin GUI -> Certification Authorities -> "Edit CA" for the imported >> CA -> Configure an external CDP where the CA makes its CRLs available > >> (must begin with "http://") >> >> Thanks. >> -----Original Message----- >> From: Randy Yu [mailto:yu...@ec...] >> Sent: September-09-14 11:04 AM >> To: ejb...@li... >> Subject: Re: [Ejbca-develop] EJBCA ocsp verification error >> >> Thanks Branko. >> >> The error differs when using OpenSSL ocsp command: >> >> 22:47:24,929 INFO >[org.cesecore.certificates.ocsp.OcspResponseGeneratorSessionBean] >(http--0.0.0.0-8080-3) Received OCSP request for certificate with >serNo: 4391e01e01561076, and issuerNameHash: >1381ab5168453c9d28d2288f76020542ac6f556c. Client ip a.a.a.a. >> 22:47:24,945 INFO >[org.cesecore.certificates.ocsp.OcspResponseGeneratorSessionBean] >(http--0.0.0.0-8080-3) Unable to find CA certificate by issuer name >hash: 1381ab5168453c9d28d2288f76020542ac6f556c, using the default >responder to send 'UnknownStatus'. >> >> This occurs even if I provide the subca.pem with the -issuer switch. >> >> -----Original Message----- >> From: Branko Majic [mailto:br...@ma...] >> Sent: September-08-14 1:26 PM >> To: ejb...@li... >> Subject: Re: [Ejbca-develop] EJBCA ocsp verification error >> >> On September 8, 2014 6:43:43 PM CEST, Randy Yu <yu...@ec...> >wrote: >>> Here is the ocsp request from OpenSSL in base64 format. I'm not >sure >>> how to achieve the same thing with CertUtil as I don't see an option > >>> like OpenSSL has -reqout switch. >>> >>> Thanks. >>> >> >> Hm... Do you get the same error when using the OpenSSL ocsp tool? >That is a tool that I commonly use for testing our installations, and >it usually works flawlessly (both EJBCA and the tool). >> -- >> Branko Majic >> Jabber: br...@ma... >> Please use only Free formats when sending attachments to me. >> >> Бранко Мајић >> Џабер: br...@ma... >> Молим вас да додатке шаљете искључиво у слободним форматима. >> >> >---------------------------------------------------------------------- >> -------- >> Want excitement? >> Manually upgrade your production database. >> When you want reliability, choose Perforce Perforce version control. >Predictably reliable. >> >http://pubads.g.doubleclick.net/gampad/clk?id=157508191&iu=/4140/ostg. >> clktrk _______________________________________________ >> Ejbca-develop mailing list >> Ejb...@li... >> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >> >---------------------------------------------------------------------- >> -------- >> Want excitement? >> Manually upgrade your production database. >> When you want reliability, choose Perforce. >> Perforce version control. Predictably reliable. >> >http://pubads.g.doubleclick.net/gampad/clk?id=157508191&iu=/4140/ostg. >> clktrk _______________________________________________ >> Ejbca-develop mailing list >> Ejb...@li... >> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >> >---------------------------------------------------------------------- >> -------- >> Want excitement? >> Manually upgrade your production database. >> When you want reliability, choose Perforce Perforce version control. >> Predictably reliable. >> >http://pubads.g.doubleclick.net/gampad/clk?id=157508191&iu=/4140/ostg. >> clktrk _______________________________________________ >> Ejbca-develop mailing list >> Ejb...@li... >> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >> > >------------------------------------------------------------------------------ >Want excitement? >Manually upgrade your production database. >When you want reliability, choose Perforce Perforce version control. >Predictably reliable. >http://pubads.g.doubleclick.net/gampad/clk?id=157508191&iu=/4140/ostg.clktrk >_______________________________________________ >Ejbca-develop mailing list >Ejb...@li... >https://lists.sourceforge.net/lists/listinfo/ejbca-develop >------------------------------------------------------------------------------ >Slashdot TV. Video for Nerds. Stuff that Matters. >http://pubads.g.doubleclick.net/gampad/clk?id=160591471&iu=/4140/ostg.clktrk >_______________________________________________ >Ejbca-develop mailing list >Ejb...@li... >https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Tomas G. <to...@pr...> - 2014-09-19 16:32:07
|
In EJBCA 6 there is no ocsp keys directory, you create a crypto token, issue a csr to the CA, and import the issued certificate. Cheers, Tomas On 19 september 2014 16:53:14 CEST, Randy Yu <yu...@ec...> wrote: >Thanks Tomas. > >If we are using a Luna HSM hard token, I believe we have to create a >PKCS11 key as the PKCS12 is only for soft tokens? Also, when >attempting to create a PKCS11 key for the specific CA, we issue the >following command but are unsure how to retrieve the actual key to >store in the ocsp keys directory. > >./ejbcaClientToolBox.sh PKCS11HSMKeyTool generate >/usr/lunasa/lib/libCryptoki2.so 2048 test 1 > > >-----Original Message----- >From: Tomas Gustavsson [mailto:to...@pr...] >Sent: September-11-14 10:35 AM >To: ejb...@li... >Subject: Re: [Ejbca-develop] EJBCA ocsp verification error > > >If you want to set up an OCSP responder, separate from the CA you need >an OCSP Signer private key and certificate. > >Cheers, >Tomas > >On 2014-09-11 16:01, Randy Yu wrote: >> Some more information to add to this. The CA we import to the EJBCA >6 instance is a public key from a hard token signed CA. With the >public key imported to EJBCA 6, would the issuer name hash be carried >over or is this a possible reason why it is unable to be found? >> >> Also with this EJBCA 6 ocsp responder instance we are trying to >setup, we are trying to use this same imported CA to do the CRL >download service, we are unable to complete the "polulating the ocsp >responder database" steps since the CDP editing option is unavailable: >> >> Admin GUI -> Certification Authorities -> "Edit CA" for the imported >> CA -> Configure an external CDP where the CA makes its CRLs available > >> (must begin with "http://") >> >> Thanks. >> -----Original Message----- >> From: Randy Yu [mailto:yu...@ec...] >> Sent: September-09-14 11:04 AM >> To: ejb...@li... >> Subject: Re: [Ejbca-develop] EJBCA ocsp verification error >> >> Thanks Branko. >> >> The error differs when using OpenSSL ocsp command: >> >> 22:47:24,929 INFO >[org.cesecore.certificates.ocsp.OcspResponseGeneratorSessionBean] >(http--0.0.0.0-8080-3) Received OCSP request for certificate with >serNo: 4391e01e01561076, and issuerNameHash: >1381ab5168453c9d28d2288f76020542ac6f556c. Client ip a.a.a.a. >> 22:47:24,945 INFO >[org.cesecore.certificates.ocsp.OcspResponseGeneratorSessionBean] >(http--0.0.0.0-8080-3) Unable to find CA certificate by issuer name >hash: 1381ab5168453c9d28d2288f76020542ac6f556c, using the default >responder to send 'UnknownStatus'. >> >> This occurs even if I provide the subca.pem with the -issuer switch. >> >> -----Original Message----- >> From: Branko Majic [mailto:br...@ma...] >> Sent: September-08-14 1:26 PM >> To: ejb...@li... >> Subject: Re: [Ejbca-develop] EJBCA ocsp verification error >> >> On September 8, 2014 6:43:43 PM CEST, Randy Yu <yu...@ec...> >wrote: >>> Here is the ocsp request from OpenSSL in base64 format. I'm not >sure >>> how to achieve the same thing with CertUtil as I don't see an option > >>> like OpenSSL has -reqout switch. >>> >>> Thanks. >>> >> >> Hm... Do you get the same error when using the OpenSSL ocsp tool? >That is a tool that I commonly use for testing our installations, and >it usually works flawlessly (both EJBCA and the tool). >> -- >> Branko Majic >> Jabber: br...@ma... >> Please use only Free formats when sending attachments to me. >> >> Бранко Мајић >> Џабер: br...@ma... >> Молим вас да додатке шаљете искључиво у слободним форматима. >> >> >---------------------------------------------------------------------- >> -------- >> Want excitement? >> Manually upgrade your production database. >> When you want reliability, choose Perforce Perforce version control. >Predictably reliable. >> >http://pubads.g.doubleclick.net/gampad/clk?id=157508191&iu=/4140/ostg. >> clktrk _______________________________________________ >> Ejbca-develop mailing list >> Ejb...@li... >> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >> >---------------------------------------------------------------------- >> -------- >> Want excitement? >> Manually upgrade your production database. >> When you want reliability, choose Perforce. >> Perforce version control. Predictably reliable. >> >http://pubads.g.doubleclick.net/gampad/clk?id=157508191&iu=/4140/ostg. >> clktrk _______________________________________________ >> Ejbca-develop mailing list >> Ejb...@li... >> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >> >---------------------------------------------------------------------- >> -------- >> Want excitement? >> Manually upgrade your production database. >> When you want reliability, choose Perforce Perforce version control. >> Predictably reliable. >> >http://pubads.g.doubleclick.net/gampad/clk?id=157508191&iu=/4140/ostg. >> clktrk _______________________________________________ >> Ejbca-develop mailing list >> Ejb...@li... >> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >> > >------------------------------------------------------------------------------ >Want excitement? >Manually upgrade your production database. >When you want reliability, choose Perforce Perforce version control. >Predictably reliable. >http://pubads.g.doubleclick.net/gampad/clk?id=157508191&iu=/4140/ostg.clktrk >_______________________________________________ >Ejbca-develop mailing list >Ejb...@li... >https://lists.sourceforge.net/lists/listinfo/ejbca-develop >------------------------------------------------------------------------------ >Slashdot TV. Video for Nerds. Stuff that Matters. >http://pubads.g.doubleclick.net/gampad/clk?id=160591471&iu=/4140/ostg.clktrk >_______________________________________________ >Ejbca-develop mailing list >Ejb...@li... >https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Randy Yu <yu...@ec...> - 2014-09-19 14:53:45
|
Thanks Tomas. If we are using a Luna HSM hard token, I believe we have to create a PKCS11 key as the PKCS12 is only for soft tokens? Also, when attempting to create a PKCS11 key for the specific CA, we issue the following command but are unsure how to retrieve the actual key to store in the ocsp keys directory. ./ejbcaClientToolBox.sh PKCS11HSMKeyTool generate /usr/lunasa/lib/libCryptoki2.so 2048 test 1 -----Original Message----- From: Tomas Gustavsson [mailto:to...@pr...] Sent: September-11-14 10:35 AM To: ejb...@li... Subject: Re: [Ejbca-develop] EJBCA ocsp verification error If you want to set up an OCSP responder, separate from the CA you need an OCSP Signer private key and certificate. Cheers, Tomas On 2014-09-11 16:01, Randy Yu wrote: > Some more information to add to this. The CA we import to the EJBCA 6 instance is a public key from a hard token signed CA. With the public key imported to EJBCA 6, would the issuer name hash be carried over or is this a possible reason why it is unable to be found? > > Also with this EJBCA 6 ocsp responder instance we are trying to setup, we are trying to use this same imported CA to do the CRL download service, we are unable to complete the "polulating the ocsp responder database" steps since the CDP editing option is unavailable: > > Admin GUI -> Certification Authorities -> "Edit CA" for the imported > CA -> Configure an external CDP where the CA makes its CRLs available > (must begin with "http://") > > Thanks. > -----Original Message----- > From: Randy Yu [mailto:yu...@ec...] > Sent: September-09-14 11:04 AM > To: ejb...@li... > Subject: Re: [Ejbca-develop] EJBCA ocsp verification error > > Thanks Branko. > > The error differs when using OpenSSL ocsp command: > > 22:47:24,929 INFO [org.cesecore.certificates.ocsp.OcspResponseGeneratorSessionBean] (http--0.0.0.0-8080-3) Received OCSP request for certificate with serNo: 4391e01e01561076, and issuerNameHash: 1381ab5168453c9d28d2288f76020542ac6f556c. Client ip a.a.a.a. > 22:47:24,945 INFO [org.cesecore.certificates.ocsp.OcspResponseGeneratorSessionBean] (http--0.0.0.0-8080-3) Unable to find CA certificate by issuer name hash: 1381ab5168453c9d28d2288f76020542ac6f556c, using the default responder to send 'UnknownStatus'. > > This occurs even if I provide the subca.pem with the -issuer switch. > > -----Original Message----- > From: Branko Majic [mailto:br...@ma...] > Sent: September-08-14 1:26 PM > To: ejb...@li... > Subject: Re: [Ejbca-develop] EJBCA ocsp verification error > > On September 8, 2014 6:43:43 PM CEST, Randy Yu <yu...@ec...> wrote: >> Here is the ocsp request from OpenSSL in base64 format. I'm not sure >> how to achieve the same thing with CertUtil as I don't see an option >> like OpenSSL has -reqout switch. >> >> Thanks. >> > > Hm... Do you get the same error when using the OpenSSL ocsp tool? That is a tool that I commonly use for testing our installations, and it usually works flawlessly (both EJBCA and the tool). > -- > Branko Majic > Jabber: br...@ma... > Please use only Free formats when sending attachments to me. > > Бранко Мајић > Џабер: br...@ma... > Молим вас да додатке шаљете искључиво у слободним форматима. > > ---------------------------------------------------------------------- > -------- > Want excitement? > Manually upgrade your production database. > When you want reliability, choose Perforce Perforce version control. Predictably reliable. > http://pubads.g.doubleclick.net/gampad/clk?id=157508191&iu=/4140/ostg. > clktrk _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > ---------------------------------------------------------------------- > -------- > Want excitement? > Manually upgrade your production database. > When you want reliability, choose Perforce. > Perforce version control. Predictably reliable. > http://pubads.g.doubleclick.net/gampad/clk?id=157508191&iu=/4140/ostg. > clktrk _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > ---------------------------------------------------------------------- > -------- > Want excitement? > Manually upgrade your production database. > When you want reliability, choose Perforce Perforce version control. > Predictably reliable. > http://pubads.g.doubleclick.net/gampad/clk?id=157508191&iu=/4140/ostg. > clktrk _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > ------------------------------------------------------------------------------ Want excitement? Manually upgrade your production database. When you want reliability, choose Perforce Perforce version control. Predictably reliable. http://pubads.g.doubleclick.net/gampad/clk?id=157508191&iu=/4140/ostg.clktrk _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Pavel B. <byc...@ht...> - 2014-09-19 14:51:04
|
Tomas, Thanks for the reply. I hope that this issue will be fixed not only in an enterprise edition but in a community edition too. Best regards, Pavel -------- Original Message -------- *Subject: *Re: [Ejbca-develop] Certificate Policies duplication issue *From: *Tomas Gustavsson <to...@pr...> *To: *ejb...@li... *Date: *19.09.2014 13:59 > Hmm, this looks very strange. Will take a look at it. > > https://jira.primekey.se/browse/ECA-3779 > > Cheers, > Tomas > > On 2014-09-19 11:53, Pavel Bychykhin wrote: >> Hello Everyone, >> My EJBCA ver. 6.2.0 >> I tried to set Certificate Policies in Certificate Profile and found >> that this is impossible to set up different policies for different profiles. >> Once I've added a policy in a profile all other profiles shows the same >> info. >> CA issuer URI in Authority Information Access demonstrates the same >> behavior: once issuer is added to some profile it is being displayed in >> all profiles. >> Is there any way to solve the issue? >> Thanks in advance. >> > ------------------------------------------------------------------------------ > Slashdot TV. Video for Nerds. Stuff that Matters. > http://pubads.g.doubleclick.net/gampad/clk?id=160591471&iu=/4140/ostg.clktrk > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Tomas G. <to...@pr...> - 2014-09-19 10:59:26
|
Hmm, this looks very strange. Will take a look at it. https://jira.primekey.se/browse/ECA-3779 Cheers, Tomas On 2014-09-19 11:53, Pavel Bychykhin wrote: > Hello Everyone, > My EJBCA ver. 6.2.0 > I tried to set Certificate Policies in Certificate Profile and found > that this is impossible to set up different policies for different profiles. > Once I've added a policy in a profile all other profiles shows the same > info. > CA issuer URI in Authority Information Access demonstrates the same > behavior: once issuer is added to some profile it is being displayed in > all profiles. > Is there any way to solve the issue? > Thanks in advance. > |
|
From: Pavel B. <byc...@ht...> - 2014-09-19 09:53:43
|
Hello Everyone, My EJBCA ver. 6.2.0 I tried to set Certificate Policies in Certificate Profile and found that this is impossible to set up different policies for different profiles. Once I've added a policy in a profile all other profiles shows the same info. CA issuer URI in Authority Information Access demonstrates the same behavior: once issuer is added to some profile it is being displayed in all profiles. Is there any way to solve the issue? Thanks in advance. -- Best regards, Pavel |
|
From: Ebtehal H. <h.e...@ya...> - 2014-09-17 11:03:40
|
Thanks Tomas it was sloved ________________________________ From: Tomas Gustavsson <to...@pr...> To: ejb...@li... Sent: Wednesday, 17 September 2014, 3:05:49 Subject: Re: [Ejbca-develop] Stress Test You need to uncheck "enforce unique public keys" for the CA. Cheers, Tomas On 2014-09-17 08:38, Ebtehal Hassan wrote: > Hello, > I want make stress test for CA in EJBCA v. 6.2.0 but it can be issued > just 1 certificate & after that the JBOSS was get some error > the command to stress test > Now the stress test show some result: > > > Server@ca2:/opt/ejbca/dist/clientToolBox$ ./ejbcaClientToolBox.sh > EjbcaWsRaCli stress AdminCA > Test client started, tail info and error files in this directory for output. > Statistic will be written to standard output each 10 second. > The test was started at Thu Sep 14 20:03:33 CEST 2011.008332292 > A test key for each thread is generated. This could take some time if > you have specified many threads and long keys. > Total # of successfully performed tests: 1 > Total # of failed tests: 30 > # of tests completed each second: 0.1 > # of tests completed each second in last period: 0.1 > Relative average time for different tasks (all should sum up to 1): > Relative time spent registring new users: 0.4267 > Relative time spent signing certificates: 0.0395 > Time spent with test client work: 0.5338 > Absolute extremes: > Min time for job 'Relative time spent registring new users' (ms): 114 > (Thu Sep 14 20:03:42 CEST 2011) > Max time per job 'Relative time spent registring new users' (ms): 186 > (Thu Sep 14 20:03:33 CEST 2011) > Min time for job 'Relative time spent signing certificates' (ms): 395 > (Thu Sep 14 20:03:34 CEST 2011) > Max time per job 'Relative time spent signing certificates' (ms): 395 > (Thu Sep 14 20:03:34 CEST 2011) > > > In th JBOSS log i see this: > Thu Sep 14 20:04:01 CEST 2011 : Command failure. Class > 'org.ejbca.core.protocol.ws.client.StressTestCommand.Pkcs10RequestCommand' > with this job data: Username 'WSTESTUSER-5377453774162515311' with > password 'foo123'. > org.ejbca.core.protocol.ws.client.gen.EjbcaException_Exception: User > 'WSTESTUSER-5377453774162515311' is not allowed to use same key as the > user(s) 'WSTESTUSER8587251972754523283' is/are using. > at > sun.reflect.GeneratedConstructorAccessor42.newInstance(Unknown Source) > at > sun.reflect.DelegatingConstructorAccessorImpl.newInstance(DelegatingConstructorAccessorImpl.java:45) > at java.lang.reflect.Constructor.newInstance(Constructor.java:532) > at > com.sun.xml.internal.ws.fault.SOAPFaultBuilder.createException(SOAPFaultBuilder.java:130) > at > com.sun.xml.internal.ws.client.sei.SyncMethodHandler.invoke(SyncMethodHandler.java:108) > at > com.sun.xml.internal.ws.client.sei.SyncMethodHandler.invoke(SyncMethodHandler.java:78) > at > com.sun.xml.internal.ws.client.sei.SEIStub.invoke(SEIStub.java:107) > at $Proxy27.pkcs10Request(Unknown Source) > > > > Please help me to solve the problem > > > Best Regards; > Ebtehal Hassan > > > ------------------------------------------------------------------------------ > Want excitement? > Manually upgrade your production database. > When you want reliability, choose Perforce > Perforce version control. Predictably reliable. > http://pubads.g.doubleclick.net/gampad/clk?id=157508191&iu=/4140/ostg.clktrk > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > ------------------------------------------------------------------------------ Want excitement? Manually upgrade your production database. When you want reliability, choose Perforce Perforce version control. Predictably reliable. http://pubads.g.doubleclick.net/gampad/clk?id=157508191&iu=/4140/ostg.clktrk _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Tomas G. <to...@pr...> - 2014-09-17 07:06:00
|
You need to uncheck "enforce unique public keys" for the CA. Cheers, Tomas On 2014-09-17 08:38, Ebtehal Hassan wrote: > Hello, > I want make stress test for CA in EJBCA v. 6.2.0 but it can be issued > just 1 certificate & after that the JBOSS was get some error > the command to stress test > Now the stress test show some result: > > > Server@ca2:/opt/ejbca/dist/clientToolBox$ ./ejbcaClientToolBox.sh > EjbcaWsRaCli stress AdminCA > Test client started, tail info and error files in this directory for output. > Statistic will be written to standard output each 10 second. > The test was started at Thu Sep 14 20:03:33 CEST 2011.008332292 > A test key for each thread is generated. This could take some time if > you have specified many threads and long keys. > Total # of successfully performed tests: 1 > Total # of failed tests: 30 > # of tests completed each second: 0.1 > # of tests completed each second in last period: 0.1 > Relative average time for different tasks (all should sum up to 1): > Relative time spent registring new users: 0.4267 > Relative time spent signing certificates: 0.0395 > Time spent with test client work: 0.5338 > Absolute extremes: > Min time for job 'Relative time spent registring new users' (ms): 114 > (Thu Sep 14 20:03:42 CEST 2011) > Max time per job 'Relative time spent registring new users' (ms): 186 > (Thu Sep 14 20:03:33 CEST 2011) > Min time for job 'Relative time spent signing certificates' (ms): 395 > (Thu Sep 14 20:03:34 CEST 2011) > Max time per job 'Relative time spent signing certificates' (ms): 395 > (Thu Sep 14 20:03:34 CEST 2011) > > > In th JBOSS log i see this: > Thu Sep 14 20:04:01 CEST 2011 : Command failure. Class > 'org.ejbca.core.protocol.ws.client.StressTestCommand.Pkcs10RequestCommand' > with this job data: Username 'WSTESTUSER-5377453774162515311' with > password 'foo123'. > org.ejbca.core.protocol.ws.client.gen.EjbcaException_Exception: User > 'WSTESTUSER-5377453774162515311' is not allowed to use same key as the > user(s) 'WSTESTUSER8587251972754523283' is/are using. > at > sun.reflect.GeneratedConstructorAccessor42.newInstance(Unknown Source) > at > sun.reflect.DelegatingConstructorAccessorImpl.newInstance(DelegatingConstructorAccessorImpl.java:45) > at java.lang.reflect.Constructor.newInstance(Constructor.java:532) > at > com.sun.xml.internal.ws.fault.SOAPFaultBuilder.createException(SOAPFaultBuilder.java:130) > at > com.sun.xml.internal.ws.client.sei.SyncMethodHandler.invoke(SyncMethodHandler.java:108) > at > com.sun.xml.internal.ws.client.sei.SyncMethodHandler.invoke(SyncMethodHandler.java:78) > at > com.sun.xml.internal.ws.client.sei.SEIStub.invoke(SEIStub.java:107) > at $Proxy27.pkcs10Request(Unknown Source) > > > > Please help me to solve the problem > > > Best Regards; > Ebtehal Hassan > > > ------------------------------------------------------------------------------ > Want excitement? > Manually upgrade your production database. > When you want reliability, choose Perforce > Perforce version control. Predictably reliable. > http://pubads.g.doubleclick.net/gampad/clk?id=157508191&iu=/4140/ostg.clktrk > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |