You can subscribe to this list here.
| 2001 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
(1) |
Dec
(3) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2002 |
Jan
(3) |
Feb
(2) |
Mar
(8) |
Apr
(3) |
May
(6) |
Jun
(1) |
Jul
(15) |
Aug
(6) |
Sep
|
Oct
(10) |
Nov
(2) |
Dec
(4) |
| 2003 |
Jan
(1) |
Feb
(7) |
Mar
(3) |
Apr
(6) |
May
(7) |
Jun
(5) |
Jul
(5) |
Aug
(25) |
Sep
(14) |
Oct
(2) |
Nov
|
Dec
(2) |
| 2004 |
Jan
(7) |
Feb
(4) |
Mar
(12) |
Apr
(16) |
May
(43) |
Jun
(56) |
Jul
(43) |
Aug
(40) |
Sep
(66) |
Oct
(12) |
Nov
(26) |
Dec
(10) |
| 2005 |
Jan
(13) |
Feb
(33) |
Mar
(16) |
Apr
(7) |
May
(10) |
Jun
(34) |
Jul
(41) |
Aug
(8) |
Sep
(4) |
Oct
(32) |
Nov
(20) |
Dec
(25) |
| 2006 |
Jan
(30) |
Feb
(101) |
Mar
(5) |
Apr
(75) |
May
(74) |
Jun
(22) |
Jul
(6) |
Aug
(70) |
Sep
(19) |
Oct
(21) |
Nov
(31) |
Dec
(50) |
| 2007 |
Jan
(15) |
Feb
(20) |
Mar
(24) |
Apr
(33) |
May
(13) |
Jun
(18) |
Jul
(13) |
Aug
(7) |
Sep
(63) |
Oct
(68) |
Nov
(29) |
Dec
(68) |
| 2008 |
Jan
(30) |
Feb
(33) |
Mar
(30) |
Apr
(103) |
May
(78) |
Jun
(48) |
Jul
(72) |
Aug
(24) |
Sep
(62) |
Oct
(63) |
Nov
(70) |
Dec
(37) |
| 2009 |
Jan
(34) |
Feb
(35) |
Mar
(64) |
Apr
(34) |
May
(34) |
Jun
(58) |
Jul
(30) |
Aug
(30) |
Sep
(46) |
Oct
(52) |
Nov
(12) |
Dec
(23) |
| 2010 |
Jan
(121) |
Feb
(18) |
Mar
(53) |
Apr
(62) |
May
(62) |
Jun
(20) |
Jul
(33) |
Aug
(20) |
Sep
(36) |
Oct
(35) |
Nov
(44) |
Dec
(63) |
| 2011 |
Jan
(19) |
Feb
(32) |
Mar
(94) |
Apr
(41) |
May
(47) |
Jun
(25) |
Jul
(34) |
Aug
(20) |
Sep
(9) |
Oct
(41) |
Nov
(33) |
Dec
(24) |
| 2012 |
Jan
(12) |
Feb
(36) |
Mar
(48) |
Apr
(32) |
May
(20) |
Jun
(15) |
Jul
(32) |
Aug
(13) |
Sep
(33) |
Oct
(54) |
Nov
(25) |
Dec
(16) |
| 2013 |
Jan
(45) |
Feb
(39) |
Mar
(38) |
Apr
(50) |
May
(29) |
Jun
(30) |
Jul
(33) |
Aug
(12) |
Sep
(9) |
Oct
(25) |
Nov
(29) |
Dec
(20) |
| 2014 |
Jan
(25) |
Feb
(19) |
Mar
(16) |
Apr
(33) |
May
(27) |
Jun
(37) |
Jul
(29) |
Aug
(27) |
Sep
(37) |
Oct
(58) |
Nov
(109) |
Dec
(26) |
| 2015 |
Jan
(4) |
Feb
(35) |
Mar
(22) |
Apr
(35) |
May
(28) |
Jun
(20) |
Jul
(4) |
Aug
(16) |
Sep
(37) |
Oct
(13) |
Nov
(13) |
Dec
(14) |
| 2016 |
Jan
(22) |
Feb
(7) |
Mar
(23) |
Apr
(30) |
May
(10) |
Jun
(10) |
Jul
(15) |
Aug
(12) |
Sep
(22) |
Oct
(31) |
Nov
(5) |
Dec
(5) |
| 2017 |
Jan
(30) |
Feb
(25) |
Mar
(28) |
Apr
(4) |
May
(19) |
Jun
(13) |
Jul
(7) |
Aug
(1) |
Sep
(2) |
Oct
(5) |
Nov
(12) |
Dec
(2) |
| 2018 |
Jan
(7) |
Feb
|
Mar
(7) |
Apr
(2) |
May
(8) |
Jun
(18) |
Jul
(6) |
Aug
(3) |
Sep
(15) |
Oct
(33) |
Nov
(13) |
Dec
(7) |
| 2019 |
Jan
(5) |
Feb
(7) |
Mar
(30) |
Apr
(5) |
May
(4) |
Jun
(69) |
Jul
(86) |
Aug
(22) |
Sep
(6) |
Oct
(7) |
Nov
(5) |
Dec
(3) |
| 2020 |
Jan
(10) |
Feb
(12) |
Mar
(22) |
Apr
(5) |
May
(1) |
Jun
(4) |
Jul
(6) |
Aug
|
Sep
(9) |
Oct
|
Nov
|
Dec
(1) |
| 2021 |
Jan
(4) |
Feb
(11) |
Mar
(7) |
Apr
(7) |
May
|
Jun
(3) |
Jul
(10) |
Aug
(6) |
Sep
|
Oct
|
Nov
(18) |
Dec
(2) |
| 2022 |
Jan
(1) |
Feb
(1) |
Mar
|
Apr
|
May
|
Jun
(2) |
Jul
|
Aug
(4) |
Sep
|
Oct
|
Nov
|
Dec
|
| 2023 |
Jan
|
Feb
|
Mar
|
Apr
(1) |
May
(1) |
Jun
|
Jul
|
Aug
(5) |
Sep
|
Oct
|
Nov
|
Dec
|
|
From: Ebtehal H. <h.e...@ya...> - 2014-09-17 06:40:54
|
Hello,
I want make stress test for CA in EJBCA v. 6.2.0 but it can be issued just 1 certificate & after that the JBOSS was get some error
the command to stress test
Now the stress test show some result:
Server@ca2:/opt/ejbca/dist/clientToolBox$ ./ejbcaClientToolBox.sh EjbcaWsRaCli stress AdminCA
Test client started, tail info and error files in this directory for output.
Statistic will be written to standard output each 10 second.
The test was started at Thu Sep 14 20:03:33 CEST 2011.008332292
A test key for each thread is generated. This could take some time if you have specified many threads and long keys.
Total # of successfully performed tests: 1
Total # of failed tests: 30
# of tests completed each second: 0.1
# of tests completed each second in last period: 0.1
Relative average time for different tasks (all should sum up to 1):
Relative time spent registring new users: 0.4267
Relative time spent signing certificates: 0.0395
Time spent with test client work: 0.5338
Absolute extremes:
Min time for job 'Relative time spent registring new users' (ms): 114 (Thu Sep 14 20:03:42 CEST 2011)
Max time per job 'Relative time spent registring new users' (ms): 186 (Thu Sep 14 20:03:33 CEST 2011)
Min time for job 'Relative time spent signing certificates' (ms): 395 (Thu Sep 14 20:03:34 CEST 2011)
Max time per job 'Relative time spent signing certificates' (ms): 395 (Thu Sep 14 20:03:34 CEST 2011)
In th JBOSS log i see this:
Thu Sep 14 20:04:01 CEST 2011 : Command failure. Class
'org.ejbca.core.protocol.ws.client.StressTestCommand.Pkcs10RequestCommand' with this job data: Username 'WSTESTUSER-5377453774162515311' with
password 'foo123'.
org.ejbca.core.protocol.ws.client.gen.EjbcaException_Exception: User
'WSTESTUSER-5377453774162515311' is not allowed to use same key as the
user(s) 'WSTESTUSER8587251972754523283' is/are using.
at sun.reflect.GeneratedConstructorAccessor42.newInstance(Unknown Source)
at sun.reflect.DelegatingConstructorAccessorImpl.newInstance(DelegatingConstructorAccessorImpl.java:45)
at java.lang.reflect.Constructor.newInstance(Constructor.java:532)
at com.sun.xml.internal.ws.fault.SOAPFaultBuilder.createException(SOAPFaultBuilder.java:130)
at com.sun.xml.internal.ws.client.sei.SyncMethodHandler.invoke(SyncMethodHandler.java:108)
at com.sun.xml.internal.ws.client.sei.SyncMethodHandler.invoke(SyncMethodHandler.java:78)
at com.sun.xml.internal.ws.client.sei.SEIStub.invoke(SEIStub.java:107)
at $Proxy27.pkcs10Request(Unknown Source)
Please help me to solve the problem
Best Regards;
Ebtehal Hassan
|
|
From: Tomas G. <to...@pr...> - 2014-09-11 14:34:44
|
If you want to set up an OCSP responder, separate from the CA you need an OCSP Signer private key and certificate. Cheers, Tomas On 2014-09-11 16:01, Randy Yu wrote: > Some more information to add to this. The CA we import to the EJBCA 6 instance is a public key from a hard token signed CA. With the public key imported to EJBCA 6, would the issuer name hash be carried over or is this a possible reason why it is unable to be found? > > Also with this EJBCA 6 ocsp responder instance we are trying to setup, we are trying to use this same imported CA to do the CRL download service, we are unable to complete the "polulating the ocsp responder database" steps since the CDP editing option is unavailable: > > Admin GUI -> Certification Authorities -> "Edit CA" for the imported CA -> Configure an external CDP where the CA makes its CRLs available (must begin with "http://") > > Thanks. > -----Original Message----- > From: Randy Yu [mailto:yu...@ec...] > Sent: September-09-14 11:04 AM > To: ejb...@li... > Subject: Re: [Ejbca-develop] EJBCA ocsp verification error > > Thanks Branko. > > The error differs when using OpenSSL ocsp command: > > 22:47:24,929 INFO [org.cesecore.certificates.ocsp.OcspResponseGeneratorSessionBean] (http--0.0.0.0-8080-3) Received OCSP request for certificate with serNo: 4391e01e01561076, and issuerNameHash: 1381ab5168453c9d28d2288f76020542ac6f556c. Client ip a.a.a.a. > 22:47:24,945 INFO [org.cesecore.certificates.ocsp.OcspResponseGeneratorSessionBean] (http--0.0.0.0-8080-3) Unable to find CA certificate by issuer name hash: 1381ab5168453c9d28d2288f76020542ac6f556c, using the default responder to send 'UnknownStatus'. > > This occurs even if I provide the subca.pem with the -issuer switch. > > -----Original Message----- > From: Branko Majic [mailto:br...@ma...] > Sent: September-08-14 1:26 PM > To: ejb...@li... > Subject: Re: [Ejbca-develop] EJBCA ocsp verification error > > On September 8, 2014 6:43:43 PM CEST, Randy Yu <yu...@ec...> wrote: >> Here is the ocsp request from OpenSSL in base64 format. I'm not sure >> how to achieve the same thing with CertUtil as I don't see an option >> like OpenSSL has -reqout switch. >> >> Thanks. >> > > Hm... Do you get the same error when using the OpenSSL ocsp tool? That is a tool that I commonly use for testing our installations, and it usually works flawlessly (both EJBCA and the tool). > -- > Branko Majic > Jabber: br...@ma... > Please use only Free formats when sending attachments to me. > > Бранко Мајић > Џабер: br...@ma... > Молим вас да додатке шаљете искључиво у слободним форматима. > > ------------------------------------------------------------------------------ > Want excitement? > Manually upgrade your production database. > When you want reliability, choose Perforce Perforce version control. Predictably reliable. > http://pubads.g.doubleclick.net/gampad/clk?id=157508191&iu=/4140/ostg.clktrk > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > ------------------------------------------------------------------------------ > Want excitement? > Manually upgrade your production database. > When you want reliability, choose Perforce. > Perforce version control. Predictably reliable. > http://pubads.g.doubleclick.net/gampad/clk?id=157508191&iu=/4140/ostg.clktrk > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > ------------------------------------------------------------------------------ > Want excitement? > Manually upgrade your production database. > When you want reliability, choose Perforce > Perforce version control. Predictably reliable. > http://pubads.g.doubleclick.net/gampad/clk?id=157508191&iu=/4140/ostg.clktrk > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Randy Yu <yu...@ec...> - 2014-09-11 14:22:17
|
Some more information to add to this. The CA we import to the EJBCA 6 instance is a public key from a hard token signed CA. With the public key imported to EJBCA 6, would the issuer name hash be carried over or is this a possible reason why it is unable to be found? Also with this EJBCA 6 ocsp responder instance we are trying to setup, we are trying to use this same imported CA to do the CRL download service, we are unable to complete the "polulating the ocsp responder database" steps since the CDP editing option is unavailable: Admin GUI -> Certification Authorities -> "Edit CA" for the imported CA -> Configure an external CDP where the CA makes its CRLs available (must begin with "http://") Thanks. -----Original Message----- From: Randy Yu [mailto:yu...@ec...] Sent: September-09-14 11:04 AM To: ejb...@li... Subject: Re: [Ejbca-develop] EJBCA ocsp verification error Thanks Branko. The error differs when using OpenSSL ocsp command: 22:47:24,929 INFO [org.cesecore.certificates.ocsp.OcspResponseGeneratorSessionBean] (http--0.0.0.0-8080-3) Received OCSP request for certificate with serNo: 4391e01e01561076, and issuerNameHash: 1381ab5168453c9d28d2288f76020542ac6f556c. Client ip a.a.a.a. 22:47:24,945 INFO [org.cesecore.certificates.ocsp.OcspResponseGeneratorSessionBean] (http--0.0.0.0-8080-3) Unable to find CA certificate by issuer name hash: 1381ab5168453c9d28d2288f76020542ac6f556c, using the default responder to send 'UnknownStatus'. This occurs even if I provide the subca.pem with the -issuer switch. -----Original Message----- From: Branko Majic [mailto:br...@ma...] Sent: September-08-14 1:26 PM To: ejb...@li... Subject: Re: [Ejbca-develop] EJBCA ocsp verification error On September 8, 2014 6:43:43 PM CEST, Randy Yu <yu...@ec...> wrote: >Here is the ocsp request from OpenSSL in base64 format. I'm not sure >how to achieve the same thing with CertUtil as I don't see an option >like OpenSSL has -reqout switch. > >Thanks. > Hm... Do you get the same error when using the OpenSSL ocsp tool? That is a tool that I commonly use for testing our installations, and it usually works flawlessly (both EJBCA and the tool). -- Branko Majic Jabber: br...@ma... Please use only Free formats when sending attachments to me. Бранко Мајић Џабер: br...@ma... Молим вас да додатке шаљете искључиво у слободним форматима. ------------------------------------------------------------------------------ Want excitement? Manually upgrade your production database. When you want reliability, choose Perforce Perforce version control. Predictably reliable. http://pubads.g.doubleclick.net/gampad/clk?id=157508191&iu=/4140/ostg.clktrk _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop ------------------------------------------------------------------------------ Want excitement? Manually upgrade your production database. When you want reliability, choose Perforce. Perforce version control. Predictably reliable. http://pubads.g.doubleclick.net/gampad/clk?id=157508191&iu=/4140/ostg.clktrk _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Tomas G. <to...@pr...> - 2014-09-10 13:15:46
|
Of-topic but could be interesting. The eID Conference in Budapest on the 13-14 October will feature PKI and EJBCA experts on-site. - Meet PKI Experts, from several companies, who have made successful PKI deployments. - Meet EJBCA core developers. - Learn new things regarding eID and ePassports. https://eid-epass.org/ Cheers, Tomas |
|
From: Sudhir K. <ya...@ao...> - 2014-09-10 09:42:35
|
<div id="AOLMsgPart_2_680ca8c9-eeaf-470b-aea4-d013469dd986">Dear All, Going to set up external ocsp responders. Well this ocsp will respond only those certificate which has been issued by perticular CA. I have .cer file of that perticular CA and ocsp signing certificat in .p12 format. Can you somebody help me about setting of profile to get ocsp rresponde working. Please help me Sudhir Kumar <div> <div>ya...@ao... </div></div> </div> |
|
From: Randy Yu <yu...@ec...> - 2014-09-09 15:04:30
|
Thanks Branko. The error differs when using OpenSSL ocsp command: 22:47:24,929 INFO [org.cesecore.certificates.ocsp.OcspResponseGeneratorSessionBean] (http--0.0.0.0-8080-3) Received OCSP request for certificate with serNo: 4391e01e01561076, and issuerNameHash: 1381ab5168453c9d28d2288f76020542ac6f556c. Client ip a.a.a.a. 22:47:24,945 INFO [org.cesecore.certificates.ocsp.OcspResponseGeneratorSessionBean] (http--0.0.0.0-8080-3) Unable to find CA certificate by issuer name hash: 1381ab5168453c9d28d2288f76020542ac6f556c, using the default responder to send 'UnknownStatus'. This occurs even if I provide the subca.pem with the -issuer switch. -----Original Message----- From: Branko Majic [mailto:br...@ma...] Sent: September-08-14 1:26 PM To: ejb...@li... Subject: Re: [Ejbca-develop] EJBCA ocsp verification error On September 8, 2014 6:43:43 PM CEST, Randy Yu <yu...@ec...> wrote: >Here is the ocsp request from OpenSSL in base64 format. I'm not sure >how to achieve the same thing with CertUtil as I don't see an option >like OpenSSL has -reqout switch. > >Thanks. > Hm... Do you get the same error when using the OpenSSL ocsp tool? That is a tool that I commonly use for testing our installations, and it usually works flawlessly (both EJBCA and the tool). -- Branko Majic Jabber: br...@ma... Please use only Free formats when sending attachments to me. Бранко Мајић Џабер: br...@ma... Молим вас да додатке шаљете искључиво у слободним форматима. ------------------------------------------------------------------------------ Want excitement? Manually upgrade your production database. When you want reliability, choose Perforce Perforce version control. Predictably reliable. http://pubads.g.doubleclick.net/gampad/clk?id=157508191&iu=/4140/ostg.clktrk _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Branko M. <br...@ma...> - 2014-09-08 17:25:49
|
On September 8, 2014 6:43:43 PM CEST, Randy Yu <yu...@ec...> wrote: >Here is the ocsp request from OpenSSL in base64 format. I'm not sure >how to achieve the same thing with CertUtil as I don't see an option >like OpenSSL has -reqout switch. > >Thanks. > Hm... Do you get the same error when using the OpenSSL ocsp tool? That is a tool that I commonly use for testing our installations, and it usually works flawlessly (both EJBCA and the tool). -- Branko Majic Jabber: br...@ma... Please use only Free formats when sending attachments to me. Бранко Мајић Џабер: br...@ma... Молим вас да додатке шаљете искључиво у слободним форматима. |
|
From: Randy Yu <yu...@ec...> - 2014-09-08 16:44:03
|
Here is the ocsp request from OpenSSL in base64 format. I'm not sure how to achieve the same thing with CertUtil as I don't see an option like OpenSSL has -reqout switch. Thanks. -----Original Message----- From: Tomas Gustavsson [mailto:to...@pr...] Sent: September-08-14 2:28 AM To: ejb...@li... Subject: Re: [Ejbca-develop] EJBCA ocsp verification error The binary, or base64 encoded ocsp request in itself. And details how it was generated. /Tomas On 2014-09-08 05:16, Randy Yu wrote: > Thanks Tomas, > > For the process of extracting an OCSP request, what sort of details are necessary? Would you need the test certificates that I am using or other details? > > Thanks. > ________________________________________ > From: Tomas Gustavsson [to...@pr...] > Sent: Sunday, September 07, 2014 1:53 AM > To: ejb...@li... > Subject: Re: [Ejbca-develop] EJBCA ocsp verification error > > These errors seem to be totally different things. > > For the first user, I'd recommend trying a new version of EJBCA. > Digging into old 3.x is probably not something anyone want to do. > > For you Randy, it seems your OCSP request is missing issuerKeyHash > and/or issuerNameHash. If you can extract an OCSP request we can take > a look at it. > > Cheers, > Tomas > > On 2014-09-05 21:57, Randy Yu wrote: >> I have also tried a similar verification against EJBCA 6.2 VM with importing my CA. I am using the Windows CertUtil application to verify against my OCSP server. The following error occurs on the EJBCA server.log. Any tips are appreciated: >> >> 20:27:10,129 ERROR [org.jboss.ejb3.invocation] (http--0.0.0.0-8080-3) JBAS014134: EJB Invocation failed on component OcspResponseGeneratorSessionBean for method public abstract org.cesecore.certificates.ocsp.OcspResponseInformation org.cesecore.certificates.ocsp.OcspResponseGeneratorSession.getOcspResponse(byte[],java.security.cert.X509Certificate[],java.lang.String,java.lang.String,java.lang.StringBuffer,org.cesecore.certificates.ocsp.logging.AuditLogger,org.cesecore.certificates.ocsp.logging.TransactionLogger) throws org.cesecore.certificates.ocsp.exception.MalformedRequestException,java.io.IOException,org.bouncycastle.cert.ocsp.OCSPException: java.lang.NumberFormatException: Zero length BigInteger >> at java.math.BigInteger.<init>(BigInteger.java:190) [rt.jar:1.7.0_51] >> at org.cesecore.certificates.ocsp.cache.OcspSigningCache.getCacheIdFromCertificateID(OcspSigningCache.java:136) [cesecore-ejb-interface.jar:] >> at org.cesecore.certificates.ocsp.cache.OcspSigningCache.getEntry(OcspSigningCache.java:47) [cesecore-ejb-interface.jar:] >> at org.cesecore.certificates.ocsp.OcspResponseGeneratorSessionBean.translateRequestFromByteArray(OcspResponseGeneratorSessionBean.java:612) [cesecore-ejb.jar:] >> at org.cesecore.certificates.ocsp.OcspResponseGeneratorSessionBean.getOcspResponse(OcspResponseGeneratorSessionBean.java:865) [cesecore-ejb.jar:] >> at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method) [rt.jar:1.7.0_51] >> at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:57) [rt.jar:1.7.0_51] >> at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43) [rt.jar:1.7.0_51] >> at java.lang.reflect.Method.invoke(Method.java:606) [rt.jar:1.7.0_51] >> at org.jboss.as.ee.component.ManagedReferenceMethodInterceptorFactory$ManagedReferenceMethodInterceptor.processInvocation(ManagedReferenceMethodInterceptorFactory.java:72) [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] >> at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] >> at org.jboss.invocation.WeavedInterceptor.processInvocation(WeavedInterceptor.java:53) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] >> at org.jboss.as.ee.component.interceptors.UserInterceptorFactory$1.processInvocation(UserInterceptorFactory.java:36) [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] >> at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] >> at org.jboss.as.jpa.interceptor.SBInvocationInterceptor.processInvocation(SBInvocationInterceptor.java:47) [jboss-as-jpa-7.1.1.Final.jar:7.1.1.Final] >> at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] >> at org.jboss.invocation.InitialInterceptor.processInvocation(InitialInterceptor.java:21) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] >> at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] >> at org.jboss.invocation.ChainedInterceptor.processInvocation(ChainedInterceptor.java:61) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] >> at org.jboss.as.ee.component.interceptors.ComponentDispatcherInterceptor.processInvocation(ComponentDispatcherInterceptor.java:53) [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] >> at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] >> at org.jboss.as.ejb3.component.pool.PooledInstanceInterceptor.processInvocation(PooledInstanceInterceptor.java:51) [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final] >> at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] >> at org.jboss.as.ejb3.tx.CMTTxInterceptor.invokeInNoTx(CMTTxInterceptor.java:211) [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final] >> at org.jboss.as.ejb3.tx.CMTTxInterceptor.supports(CMTTxInterceptor.java:363) [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final] >> at org.jboss.as.ejb3.tx.CMTTxInterceptor.processInvocation(CMTTxInterceptor.java:194) [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final] >> at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] >> at org.jboss.as.ejb3.component.interceptors.CurrentInvocationContextInterceptor.processInvocation(CurrentInvocationContextInterceptor.java:41) [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final] >> at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] >> at org.jboss.as.ejb3.component.interceptors.LoggingInterceptor.processInvocation(LoggingInterceptor.java:59) [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final] >> at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] >> at org.jboss.as.ee.component.NamespaceContextInterceptor.processInvocation(NamespaceContextInterceptor.java:50) [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] >> at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] >> at org.jboss.as.ejb3.component.interceptors.AdditionalSetupInterceptor.processInvocation(AdditionalSetupInterceptor.java:32) [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final] >> at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] >> at org.jboss.as.ee.component.TCCLInterceptor.processInvocation(TCCLInterceptor.java:45) [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] >> at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] >> at org.jboss.invocation.ChainedInterceptor.processInvocation(ChainedInterceptor.java:61) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] >> at org.jboss.as.ee.component.ViewService$View.invoke(ViewService.java:165) [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] >> at org.jboss.as.ee.component.ViewDescription$1.processInvocation(ViewDescription.java:173) [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] >> at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] >> at org.jboss.invocation.ChainedInterceptor.processInvocation(ChainedInterceptor.java:61) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] >> at org.jboss.as.ee.component.ProxyInvocationHandler.invoke(ProxyInvocationHandler.java:72) [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] >> at org.cesecore.certificates.ocsp.OcspResponseGeneratorSessionLocal$$$view13.getOcspResponse(Unknown Source) [cesecore-ejb-interface.jar:] >> at org.ejbca.ui.web.protocol.OCSPServlet.processOcspRequest(OCSPServlet.java:239) >> at org.ejbca.ui.web.protocol.OCSPServlet.doPost(OCSPServlet.java:181) >> at javax.servlet.http.HttpServlet.service(HttpServlet.java:754) [jboss-servlet-api_3.0_spec-1.0.0.Final.jar:1.0.0.Final] >> at javax.servlet.http.HttpServlet.service(HttpServlet.java:847) [jboss-servlet-api_3.0_spec-1.0.0.Final.jar:1.0.0.Final] >> at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:329) >> at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:248) >> at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:275) >> at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:161) >> at org.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:397) >> at org.jboss.as.jpa.interceptor.WebNonTxEmCloserValve.invoke(WebNonTxEmCloserValve.java:50) [jboss-as-jpa-7.1.1.Final.jar:7.1.1.Final] >> at org.jboss.as.web.security.SecurityContextAssociationValve.invoke(SecurityContextAssociationValve.java:153) >> at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:155) >> at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:102) >> at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:109) >> at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:368) >> at org.apache.coyote.http11.Http11Processor.process(Http11Processor.java:877) >> at org.apache.coyote.http11.Http11Protocol$Http11ConnectionHandler.process(Http11Protocol.java:671) >> at org.apache.tomcat.util.net.JIoEndpoint$Worker.run(JIoEndpoint.java:930) >> at java.lang.Thread.run(Thread.java:744) [rt.jar:1.7.0_51] >> >> -- >> Randy Yu >> 416-226-8615 | www.echoworx.com >> >> >> -----Original Message----- >> From: Randy Yu [mailto:yu...@ec...] >> Sent: September-02-14 4:05 PM >> To: ejb...@li... >> Subject: [Ejbca-develop] EJBCA ocsp verification error >> >> When using the ejbca.sh ocsp cmd for OCSP verification, I am seeing the following error with an early version 3.x EJBCA. Any comments/recommendations for what could be causing this? >> >> 2014-09-02 19:09:22,009 DEBUG [org.ejbca.util.CertTools] >getCertfromByteArray: >> 2014-09-02 19:09:22,009 DEBUG [org.ejbca.util.CertTools] <getCertfromByteArray: >> 2014-09-02 19:09:22,009 DEBUG [org.ejbca.util.CertTools] >getCertfromByteArray: >> 2014-09-02 19:09:22,009 DEBUG [org.ejbca.util.CertTools] <getCertfromByteArray: >> 2014-09-02 19:09:22,037 ERROR [org.jboss.ejb.plugins.LogInterceptor] RuntimeException in method: public abstract org.ejbca.core.model.ca.caadmin.extendedcaservices.ExtendedCAServiceResponse org.ejbca.core.ejb.ca.sign.ISignSessionLocal.extendedService(org.ejbca.core.model.log.Admin,int,org.ejbca.core.model.ca.caadmin.extendedcaservices.ExtendedCAServiceRequest) throws org.ejbca.core.model.ca.caadmin.extendedcaservices.ExtendedCAServiceRequestException,org.ejbca.core.model.ca.caadmin.extendedcaservices.IllegalExtendedCAServiceRequestException,org.ejbca.core.model.ca.caadmin.extendedcaservices.ExtendedCAServiceNotActiveException,org.ejbca.core.model.ca.caadmin.CADoesntExistsException: >> java.lang.IllegalArgumentException: unknown signing algorithm specified >> at org.bouncycastle.ocsp.BasicOCSPRespGenerator.generate(Unknown Source) >> at org.bouncycastle.ocsp.BasicOCSPRespGenerator.generate(Unknown Source) >> at org.ejbca.core.model.ca.caadmin.X509CA.extendedService(X509CA.java:629) >> at org.ejbca.core.ejb.ca.sign.RSASignSessionBean.extendedService(RSASignSessionBean.java:1377) >> at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method) >> at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:39) >> at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:25) >> at java.lang.reflect.Method.invoke(Method.java:592) >> at org.jboss.invocation.Invocation.performCall(Invocation.java:345) >> at org.jboss.ejb.StatelessSessionContainer$ContainerInterceptor.invoke(StatelessSessionContainer.java:214) >> at org.jboss.resource.connectionmanager.CachedConnectionInterceptor.invoke(CachedConnectionInterceptor.java:185) >> at org.jboss.ejb.plugins.StatelessSessionInstanceInterceptor.invoke(StatelessSessionInstanceInterceptor.java:113) >> at org.jboss.webservice.server.ServiceEndpointInterceptor.invoke(ServiceEndpointInterceptor.java:51) >> at org.jboss.ejb.plugins.CallValidationInterceptor.invoke(CallValidationInterceptor.java:48) >> at org.jboss.ejb.plugins.AbstractTxInterceptor.invokeNext(AbstractTxInterceptor.java:105) >> at org.jboss.ejb.plugins.TxInterceptorCMT.runWithTransactions(TxInterceptorCMT.java:313) >> at org.jboss.ejb.plugins.TxInterceptorCMT.invoke(TxInterceptorCMT.java:146) >> at org.jboss.ejb.plugins.SecurityInterceptor.invoke(SecurityInterceptor.java:122) >> at org.jboss.ejb.plugins.LogInterceptor.invoke(LogInterceptor.java:192) >> at org.jboss.ejb.plugins.ProxyFactoryFinderInterceptor.invoke(ProxyFactoryFinderInterceptor.java:122) >> at org.jboss.ejb.SessionContainer.internalInvoke(SessionContainer.java:624) >> at org.jboss.ejb.Container.invoke(Container.java:870) >> at org.jboss.ejb.plugins.local.BaseLocalProxyFactory.invoke(BaseLocalProxyFactory.java:413) >> at org.jboss.ejb.plugins.local.StatelessSessionProxy.invoke(StatelessSessionProxy.java:82) >> at $Proxy194.extendedService(Unknown Source) >> at org.ejbca.ui.web.protocol.OCSPServlet.extendedService(OCSPServlet.java:106) >> at org.ejbca.ui.web.protocol.OCSPServletBase.signOCSPResponse(OCSPServletBase.java:313) >> at org.ejbca.ui.web.protocol.OCSPServletBase.service(OCSPServletBase.java:662) >> at org.ejbca.ui.web.protocol.OCSPServletBase.doPost(OCSPServletBase.java:439) >> at javax.servlet.http.HttpServlet.service(HttpServlet.java:717) >> at javax.servlet.http.HttpServlet.service(HttpServlet.java:810) >> at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:237) >> at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:157) >> at org.jboss.web.tomcat.filters.ReplyHeaderFilter.doFilter(ReplyHeaderFilter.java:75) >> at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:186) >> at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:157) >> at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:214) >> at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104) >> at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520) >> at org.apache.catalina.core.StandardContextValve.invokeInternal(StandardContextValve.java:198) >> at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:152) >> at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104) >> at org.jboss.web.tomcat.security.CustomPrincipalValve.invoke(CustomPrincipalValve.java:66) >> at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102) >> at org.jboss.web.tomcat.security.SecurityAssociationValve.invoke(SecurityAssociationValve.java:150) >> at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102) >> at org.jboss.web.tomcat.security.JaccContextValve.invoke(JaccContextValve.java:54) >> at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102) >> at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520) >> at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:137) >> at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104) >> at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:118) >> at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102) >> at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520) >> at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:109) >> at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104) >> at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520) >> at org.apache.catalina.core.ContainerBase.invoke(ContainerBase.java:929) >> at org.apache.coyote.tomcat5.CoyoteAdapter.service(CoyoteAdapter.java:160) >> at org.apache.coyote.http11.Http11Processor.process(Http11Processor.java:799) >> at org.apache.coyote.http11.Http11Protocol$Http11ConnectionHandler.processConnection(Http11Protocol.java:705) >> at org.apache.tomcat.util.net.TcpWorkerThread.runIt(PoolTcpEndpoint.java:577) >> at org.apache.tomcat.util.threads.ThreadPool$ControlRunnable.run(ThreadPool.java:683) >> at java.lang.Thread.run(Thread.java:595) >> 2014-09-02 19:09:22,041 ERROR [org.ejbca.ui.web.protocol.OCSPServletBase] Unable to handle OCSP request. >> javax.ejb.EJBException: RuntimeException; CausedByException is: >> unknown signing algorithm specified >> at org.jboss.ejb.plugins.LogInterceptor.handleException(LogInterceptor.java:382) >> at org.jboss.ejb.plugins.LogInterceptor.invoke(LogInterceptor.java:196) >> at org.jboss.ejb.plugins.ProxyFactoryFinderInterceptor.invoke(ProxyFactoryFinderInterceptor.java:122) >> at org.jboss.ejb.SessionContainer.internalInvoke(SessionContainer.java:624) >> at org.jboss.ejb.Container.invoke(Container.java:870) >> at org.jboss.ejb.plugins.local.BaseLocalProxyFactory.invoke(BaseLocalProxyFactory.java:413) >> at org.jboss.ejb.plugins.local.StatelessSessionProxy.invoke(StatelessSessionProxy.java:82) >> at $Proxy194.extendedService(Unknown Source) >> at org.ejbca.ui.web.protocol.OCSPServlet.extendedService(OCSPServlet.java:106) >> at org.ejbca.ui.web.protocol.OCSPServletBase.signOCSPResponse(OCSPServletBase.java:313) >> at org.ejbca.ui.web.protocol.OCSPServletBase.service(OCSPServletBase.java:662) >> at org.ejbca.ui.web.protocol.OCSPServletBase.doPost(OCSPServletBase.java:439) >> at javax.servlet.http.HttpServlet.service(HttpServlet.java:717) >> at javax.servlet.http.HttpServlet.service(HttpServlet.java:810) >> at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:237) >> at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:157) >> at org.jboss.web.tomcat.filters.ReplyHeaderFilter.doFilter(ReplyHeaderFilter.java:75) >> at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:186) >> at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:157) >> at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:214) >> at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104) >> at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520) >> at org.apache.catalina.core.StandardContextValve.invokeInternal(StandardContextValve.java:198) >> at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:152) >> at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104) >> at org.jboss.web.tomcat.security.CustomPrincipalValve.invoke(CustomPrincipalValve.java:66) >> at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102) >> at org.jboss.web.tomcat.security.SecurityAssociationValve.invoke(SecurityAssociationValve.java:150) >> at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102) >> at org.jboss.web.tomcat.security.JaccContextValve.invoke(JaccContextValve.java:54) >> at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102) >> at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520) >> at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:137) >> at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104) >> at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:118) >> at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102) >> at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520) >> at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:109) >> at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104) >> at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520) >> at org.apache.catalina.core.ContainerBase.invoke(ContainerBase.java:929) >> at org.apache.coyote.tomcat5.CoyoteAdapter.service(CoyoteAdapter.java:160) >> at org.apache.coyote.http11.Http11Processor.process(Http11Processor.java:799) >> at org.apache.coyote.http11.Http11Protocol$Http11ConnectionHandler.processConnection(Http11Protocol.java:705) >> at org.apache.tomcat.util.net.TcpWorkerThread.runIt(PoolTcpEndpoint.java:577) >> at org.apache.tomcat.util.threads.ThreadPool$ControlRunnable.run(ThreadPool.java:683) >> at java.lang.Thread.run(Thread.java:595) >> >> Randy >> >> --------------------------------------------------------------------- >> --------- >> Slashdot TV. >> Video for Nerds. Stuff that matters. >> http://tv.slashdot.org/ >> _______________________________________________ >> Ejbca-develop mailing list >> Ejb...@li... >> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >> >> --------------------------------------------------------------------- >> --------- >> Slashdot TV. >> Video for Nerds. Stuff that matters. >> http://tv.slashdot.org/ >> _______________________________________________ >> Ejbca-develop mailing list >> Ejb...@li... >> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >> > > ---------------------------------------------------------------------- > -------- > Slashdot TV. > Video for Nerds. Stuff that matters. > http://tv.slashdot.org/ > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > ---------------------------------------------------------------------- > -------- > Want excitement? > Manually upgrade your production database. > When you want reliability, choose Perforce Perforce version control. > Predictably reliable. > http://pubads.g.doubleclick.net/gampad/clk?id=157508191&iu=/4140/ostg. > clktrk _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > ------------------------------------------------------------------------------ Want excitement? Manually upgrade your production database. When you want reliability, choose Perforce Perforce version control. Predictably reliable. http://pubads.g.doubleclick.net/gampad/clk?id=157508191&iu=/4140/ostg.clktrk _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Tomas G. <to...@pr...> - 2014-09-08 11:32:08
|
Thanks! Added for EJBCA 6.3. See https://jira.primekey.se/browse/ECA-3753. Cheers, Tomas On 2014-09-05 16:41, Andreas Schwier wrote: > In a manual install (configure, make, make install) it ends up in > > /usr/local/lib > > On Ubuntu 64 and Debian it's located in > > /usr/lib/x86_64-linux-gnu > > On Ubuntu 32 and Debian it's in > > /usr/lib/i386-linux-gnu > > On Windows in ends up in > > c:\Windows\system32 > > On 09/05/2014 04:04 PM, Tomas Gustavsson wrote: >> Very cool. Absolutely, what are the paths to the p11 library on different platforms? >> >> Cheers, >> Tomas >> >> >> On 5 september 2014 15:13:19 CEST, Andreas Schwier <and...@ca...> wrote: >>> Hi Tomas, >>> >>> we've done some tests to integrate the SmartCard-HSM as crypto token >>> via >>> OpenSC [1]. >>> >>> Would it be possible to add OpenSC as one of the default PKCS#11 >>> provider in EJBCA ? >>> >>> Kind regards, >>> >>> Andreas >>> >>> >>> [1] >>> http://www.smartcard-hsm.com/2014/09/05/Accessing_your_SmartCard-HSM_from_EJBCA.html >>> >>> >>> -- >>> >>> --------- CardContact Software & System Consulting >>> |.##> <##.| Andreas Schwier >>> |# #| Schülerweg 38 >>> |# #| 32429 Minden, Germany >>> |'##> <##'| Phone +49 571 56149 >>> --------- http://www.cardcontact.de >>> http://www.tscons.de >>> http://www.openscdp.org >>> http://www.smartcard-hsm.com >>> >>> >>> ------------------------------------------------------------------------------ >>> Slashdot TV. >>> Video for Nerds. Stuff that matters. >>> http://tv.slashdot.org/ >>> _______________________________________________ >>> Ejbca-develop mailing list >>> Ejb...@li... >>> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >> > > |
|
From: Tomas G. <to...@pr...> - 2014-09-08 06:28:23
|
The binary, or base64 encoded ocsp request in itself. And details how it was generated. /Tomas On 2014-09-08 05:16, Randy Yu wrote: > Thanks Tomas, > > For the process of extracting an OCSP request, what sort of details are necessary? Would you need the test certificates that I am using or other details? > > Thanks. > ________________________________________ > From: Tomas Gustavsson [to...@pr...] > Sent: Sunday, September 07, 2014 1:53 AM > To: ejb...@li... > Subject: Re: [Ejbca-develop] EJBCA ocsp verification error > > These errors seem to be totally different things. > > For the first user, I'd recommend trying a new version of EJBCA. Digging > into old 3.x is probably not something anyone want to do. > > For you Randy, it seems your OCSP request is missing issuerKeyHash > and/or issuerNameHash. If you can extract an OCSP request we can take a > look at it. > > Cheers, > Tomas > > On 2014-09-05 21:57, Randy Yu wrote: >> I have also tried a similar verification against EJBCA 6.2 VM with importing my CA. I am using the Windows CertUtil application to verify against my OCSP server. The following error occurs on the EJBCA server.log. Any tips are appreciated: >> >> 20:27:10,129 ERROR [org.jboss.ejb3.invocation] (http--0.0.0.0-8080-3) JBAS014134: EJB Invocation failed on component OcspResponseGeneratorSessionBean for method public abstract org.cesecore.certificates.ocsp.OcspResponseInformation org.cesecore.certificates.ocsp.OcspResponseGeneratorSession.getOcspResponse(byte[],java.security.cert.X509Certificate[],java.lang.String,java.lang.String,java.lang.StringBuffer,org.cesecore.certificates.ocsp.logging.AuditLogger,org.cesecore.certificates.ocsp.logging.TransactionLogger) throws org.cesecore.certificates.ocsp.exception.MalformedRequestException,java.io.IOException,org.bouncycastle.cert.ocsp.OCSPException: java.lang.NumberFormatException: Zero length BigInteger >> at java.math.BigInteger.<init>(BigInteger.java:190) [rt.jar:1.7.0_51] >> at org.cesecore.certificates.ocsp.cache.OcspSigningCache.getCacheIdFromCertificateID(OcspSigningCache.java:136) [cesecore-ejb-interface.jar:] >> at org.cesecore.certificates.ocsp.cache.OcspSigningCache.getEntry(OcspSigningCache.java:47) [cesecore-ejb-interface.jar:] >> at org.cesecore.certificates.ocsp.OcspResponseGeneratorSessionBean.translateRequestFromByteArray(OcspResponseGeneratorSessionBean.java:612) [cesecore-ejb.jar:] >> at org.cesecore.certificates.ocsp.OcspResponseGeneratorSessionBean.getOcspResponse(OcspResponseGeneratorSessionBean.java:865) [cesecore-ejb.jar:] >> at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method) [rt.jar:1.7.0_51] >> at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:57) [rt.jar:1.7.0_51] >> at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43) [rt.jar:1.7.0_51] >> at java.lang.reflect.Method.invoke(Method.java:606) [rt.jar:1.7.0_51] >> at org.jboss.as.ee.component.ManagedReferenceMethodInterceptorFactory$ManagedReferenceMethodInterceptor.processInvocation(ManagedReferenceMethodInterceptorFactory.java:72) [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] >> at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] >> at org.jboss.invocation.WeavedInterceptor.processInvocation(WeavedInterceptor.java:53) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] >> at org.jboss.as.ee.component.interceptors.UserInterceptorFactory$1.processInvocation(UserInterceptorFactory.java:36) [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] >> at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] >> at org.jboss.as.jpa.interceptor.SBInvocationInterceptor.processInvocation(SBInvocationInterceptor.java:47) [jboss-as-jpa-7.1.1.Final.jar:7.1.1.Final] >> at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] >> at org.jboss.invocation.InitialInterceptor.processInvocation(InitialInterceptor.java:21) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] >> at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] >> at org.jboss.invocation.ChainedInterceptor.processInvocation(ChainedInterceptor.java:61) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] >> at org.jboss.as.ee.component.interceptors.ComponentDispatcherInterceptor.processInvocation(ComponentDispatcherInterceptor.java:53) [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] >> at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] >> at org.jboss.as.ejb3.component.pool.PooledInstanceInterceptor.processInvocation(PooledInstanceInterceptor.java:51) [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final] >> at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] >> at org.jboss.as.ejb3.tx.CMTTxInterceptor.invokeInNoTx(CMTTxInterceptor.java:211) [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final] >> at org.jboss.as.ejb3.tx.CMTTxInterceptor.supports(CMTTxInterceptor.java:363) [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final] >> at org.jboss.as.ejb3.tx.CMTTxInterceptor.processInvocation(CMTTxInterceptor.java:194) [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final] >> at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] >> at org.jboss.as.ejb3.component.interceptors.CurrentInvocationContextInterceptor.processInvocation(CurrentInvocationContextInterceptor.java:41) [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final] >> at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] >> at org.jboss.as.ejb3.component.interceptors.LoggingInterceptor.processInvocation(LoggingInterceptor.java:59) [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final] >> at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] >> at org.jboss.as.ee.component.NamespaceContextInterceptor.processInvocation(NamespaceContextInterceptor.java:50) [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] >> at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] >> at org.jboss.as.ejb3.component.interceptors.AdditionalSetupInterceptor.processInvocation(AdditionalSetupInterceptor.java:32) [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final] >> at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] >> at org.jboss.as.ee.component.TCCLInterceptor.processInvocation(TCCLInterceptor.java:45) [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] >> at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] >> at org.jboss.invocation.ChainedInterceptor.processInvocation(ChainedInterceptor.java:61) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] >> at org.jboss.as.ee.component.ViewService$View.invoke(ViewService.java:165) [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] >> at org.jboss.as.ee.component.ViewDescription$1.processInvocation(ViewDescription.java:173) [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] >> at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] >> at org.jboss.invocation.ChainedInterceptor.processInvocation(ChainedInterceptor.java:61) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] >> at org.jboss.as.ee.component.ProxyInvocationHandler.invoke(ProxyInvocationHandler.java:72) [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] >> at org.cesecore.certificates.ocsp.OcspResponseGeneratorSessionLocal$$$view13.getOcspResponse(Unknown Source) [cesecore-ejb-interface.jar:] >> at org.ejbca.ui.web.protocol.OCSPServlet.processOcspRequest(OCSPServlet.java:239) >> at org.ejbca.ui.web.protocol.OCSPServlet.doPost(OCSPServlet.java:181) >> at javax.servlet.http.HttpServlet.service(HttpServlet.java:754) [jboss-servlet-api_3.0_spec-1.0.0.Final.jar:1.0.0.Final] >> at javax.servlet.http.HttpServlet.service(HttpServlet.java:847) [jboss-servlet-api_3.0_spec-1.0.0.Final.jar:1.0.0.Final] >> at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:329) >> at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:248) >> at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:275) >> at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:161) >> at org.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:397) >> at org.jboss.as.jpa.interceptor.WebNonTxEmCloserValve.invoke(WebNonTxEmCloserValve.java:50) [jboss-as-jpa-7.1.1.Final.jar:7.1.1.Final] >> at org.jboss.as.web.security.SecurityContextAssociationValve.invoke(SecurityContextAssociationValve.java:153) >> at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:155) >> at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:102) >> at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:109) >> at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:368) >> at org.apache.coyote.http11.Http11Processor.process(Http11Processor.java:877) >> at org.apache.coyote.http11.Http11Protocol$Http11ConnectionHandler.process(Http11Protocol.java:671) >> at org.apache.tomcat.util.net.JIoEndpoint$Worker.run(JIoEndpoint.java:930) >> at java.lang.Thread.run(Thread.java:744) [rt.jar:1.7.0_51] >> >> -- >> Randy Yu >> 416-226-8615 | www.echoworx.com >> >> >> -----Original Message----- >> From: Randy Yu [mailto:yu...@ec...] >> Sent: September-02-14 4:05 PM >> To: ejb...@li... >> Subject: [Ejbca-develop] EJBCA ocsp verification error >> >> When using the ejbca.sh ocsp cmd for OCSP verification, I am seeing the following error with an early version 3.x EJBCA. Any comments/recommendations for what could be causing this? >> >> 2014-09-02 19:09:22,009 DEBUG [org.ejbca.util.CertTools] >getCertfromByteArray: >> 2014-09-02 19:09:22,009 DEBUG [org.ejbca.util.CertTools] <getCertfromByteArray: >> 2014-09-02 19:09:22,009 DEBUG [org.ejbca.util.CertTools] >getCertfromByteArray: >> 2014-09-02 19:09:22,009 DEBUG [org.ejbca.util.CertTools] <getCertfromByteArray: >> 2014-09-02 19:09:22,037 ERROR [org.jboss.ejb.plugins.LogInterceptor] RuntimeException in method: public abstract org.ejbca.core.model.ca.caadmin.extendedcaservices.ExtendedCAServiceResponse org.ejbca.core.ejb.ca.sign.ISignSessionLocal.extendedService(org.ejbca.core.model.log.Admin,int,org.ejbca.core.model.ca.caadmin.extendedcaservices.ExtendedCAServiceRequest) throws org.ejbca.core.model.ca.caadmin.extendedcaservices.ExtendedCAServiceRequestException,org.ejbca.core.model.ca.caadmin.extendedcaservices.IllegalExtendedCAServiceRequestException,org.ejbca.core.model.ca.caadmin.extendedcaservices.ExtendedCAServiceNotActiveException,org.ejbca.core.model.ca.caadmin.CADoesntExistsException: >> java.lang.IllegalArgumentException: unknown signing algorithm specified >> at org.bouncycastle.ocsp.BasicOCSPRespGenerator.generate(Unknown Source) >> at org.bouncycastle.ocsp.BasicOCSPRespGenerator.generate(Unknown Source) >> at org.ejbca.core.model.ca.caadmin.X509CA.extendedService(X509CA.java:629) >> at org.ejbca.core.ejb.ca.sign.RSASignSessionBean.extendedService(RSASignSessionBean.java:1377) >> at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method) >> at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:39) >> at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:25) >> at java.lang.reflect.Method.invoke(Method.java:592) >> at org.jboss.invocation.Invocation.performCall(Invocation.java:345) >> at org.jboss.ejb.StatelessSessionContainer$ContainerInterceptor.invoke(StatelessSessionContainer.java:214) >> at org.jboss.resource.connectionmanager.CachedConnectionInterceptor.invoke(CachedConnectionInterceptor.java:185) >> at org.jboss.ejb.plugins.StatelessSessionInstanceInterceptor.invoke(StatelessSessionInstanceInterceptor.java:113) >> at org.jboss.webservice.server.ServiceEndpointInterceptor.invoke(ServiceEndpointInterceptor.java:51) >> at org.jboss.ejb.plugins.CallValidationInterceptor.invoke(CallValidationInterceptor.java:48) >> at org.jboss.ejb.plugins.AbstractTxInterceptor.invokeNext(AbstractTxInterceptor.java:105) >> at org.jboss.ejb.plugins.TxInterceptorCMT.runWithTransactions(TxInterceptorCMT.java:313) >> at org.jboss.ejb.plugins.TxInterceptorCMT.invoke(TxInterceptorCMT.java:146) >> at org.jboss.ejb.plugins.SecurityInterceptor.invoke(SecurityInterceptor.java:122) >> at org.jboss.ejb.plugins.LogInterceptor.invoke(LogInterceptor.java:192) >> at org.jboss.ejb.plugins.ProxyFactoryFinderInterceptor.invoke(ProxyFactoryFinderInterceptor.java:122) >> at org.jboss.ejb.SessionContainer.internalInvoke(SessionContainer.java:624) >> at org.jboss.ejb.Container.invoke(Container.java:870) >> at org.jboss.ejb.plugins.local.BaseLocalProxyFactory.invoke(BaseLocalProxyFactory.java:413) >> at org.jboss.ejb.plugins.local.StatelessSessionProxy.invoke(StatelessSessionProxy.java:82) >> at $Proxy194.extendedService(Unknown Source) >> at org.ejbca.ui.web.protocol.OCSPServlet.extendedService(OCSPServlet.java:106) >> at org.ejbca.ui.web.protocol.OCSPServletBase.signOCSPResponse(OCSPServletBase.java:313) >> at org.ejbca.ui.web.protocol.OCSPServletBase.service(OCSPServletBase.java:662) >> at org.ejbca.ui.web.protocol.OCSPServletBase.doPost(OCSPServletBase.java:439) >> at javax.servlet.http.HttpServlet.service(HttpServlet.java:717) >> at javax.servlet.http.HttpServlet.service(HttpServlet.java:810) >> at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:237) >> at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:157) >> at org.jboss.web.tomcat.filters.ReplyHeaderFilter.doFilter(ReplyHeaderFilter.java:75) >> at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:186) >> at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:157) >> at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:214) >> at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104) >> at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520) >> at org.apache.catalina.core.StandardContextValve.invokeInternal(StandardContextValve.java:198) >> at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:152) >> at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104) >> at org.jboss.web.tomcat.security.CustomPrincipalValve.invoke(CustomPrincipalValve.java:66) >> at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102) >> at org.jboss.web.tomcat.security.SecurityAssociationValve.invoke(SecurityAssociationValve.java:150) >> at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102) >> at org.jboss.web.tomcat.security.JaccContextValve.invoke(JaccContextValve.java:54) >> at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102) >> at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520) >> at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:137) >> at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104) >> at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:118) >> at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102) >> at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520) >> at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:109) >> at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104) >> at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520) >> at org.apache.catalina.core.ContainerBase.invoke(ContainerBase.java:929) >> at org.apache.coyote.tomcat5.CoyoteAdapter.service(CoyoteAdapter.java:160) >> at org.apache.coyote.http11.Http11Processor.process(Http11Processor.java:799) >> at org.apache.coyote.http11.Http11Protocol$Http11ConnectionHandler.processConnection(Http11Protocol.java:705) >> at org.apache.tomcat.util.net.TcpWorkerThread.runIt(PoolTcpEndpoint.java:577) >> at org.apache.tomcat.util.threads.ThreadPool$ControlRunnable.run(ThreadPool.java:683) >> at java.lang.Thread.run(Thread.java:595) >> 2014-09-02 19:09:22,041 ERROR [org.ejbca.ui.web.protocol.OCSPServletBase] Unable to handle OCSP request. >> javax.ejb.EJBException: RuntimeException; CausedByException is: >> unknown signing algorithm specified >> at org.jboss.ejb.plugins.LogInterceptor.handleException(LogInterceptor.java:382) >> at org.jboss.ejb.plugins.LogInterceptor.invoke(LogInterceptor.java:196) >> at org.jboss.ejb.plugins.ProxyFactoryFinderInterceptor.invoke(ProxyFactoryFinderInterceptor.java:122) >> at org.jboss.ejb.SessionContainer.internalInvoke(SessionContainer.java:624) >> at org.jboss.ejb.Container.invoke(Container.java:870) >> at org.jboss.ejb.plugins.local.BaseLocalProxyFactory.invoke(BaseLocalProxyFactory.java:413) >> at org.jboss.ejb.plugins.local.StatelessSessionProxy.invoke(StatelessSessionProxy.java:82) >> at $Proxy194.extendedService(Unknown Source) >> at org.ejbca.ui.web.protocol.OCSPServlet.extendedService(OCSPServlet.java:106) >> at org.ejbca.ui.web.protocol.OCSPServletBase.signOCSPResponse(OCSPServletBase.java:313) >> at org.ejbca.ui.web.protocol.OCSPServletBase.service(OCSPServletBase.java:662) >> at org.ejbca.ui.web.protocol.OCSPServletBase.doPost(OCSPServletBase.java:439) >> at javax.servlet.http.HttpServlet.service(HttpServlet.java:717) >> at javax.servlet.http.HttpServlet.service(HttpServlet.java:810) >> at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:237) >> at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:157) >> at org.jboss.web.tomcat.filters.ReplyHeaderFilter.doFilter(ReplyHeaderFilter.java:75) >> at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:186) >> at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:157) >> at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:214) >> at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104) >> at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520) >> at org.apache.catalina.core.StandardContextValve.invokeInternal(StandardContextValve.java:198) >> at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:152) >> at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104) >> at org.jboss.web.tomcat.security.CustomPrincipalValve.invoke(CustomPrincipalValve.java:66) >> at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102) >> at org.jboss.web.tomcat.security.SecurityAssociationValve.invoke(SecurityAssociationValve.java:150) >> at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102) >> at org.jboss.web.tomcat.security.JaccContextValve.invoke(JaccContextValve.java:54) >> at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102) >> at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520) >> at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:137) >> at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104) >> at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:118) >> at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102) >> at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520) >> at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:109) >> at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104) >> at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520) >> at org.apache.catalina.core.ContainerBase.invoke(ContainerBase.java:929) >> at org.apache.coyote.tomcat5.CoyoteAdapter.service(CoyoteAdapter.java:160) >> at org.apache.coyote.http11.Http11Processor.process(Http11Processor.java:799) >> at org.apache.coyote.http11.Http11Protocol$Http11ConnectionHandler.processConnection(Http11Protocol.java:705) >> at org.apache.tomcat.util.net.TcpWorkerThread.runIt(PoolTcpEndpoint.java:577) >> at org.apache.tomcat.util.threads.ThreadPool$ControlRunnable.run(ThreadPool.java:683) >> at java.lang.Thread.run(Thread.java:595) >> >> Randy >> >> ------------------------------------------------------------------------------ >> Slashdot TV. >> Video for Nerds. Stuff that matters. >> http://tv.slashdot.org/ >> _______________________________________________ >> Ejbca-develop mailing list >> Ejb...@li... >> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >> >> ------------------------------------------------------------------------------ >> Slashdot TV. >> Video for Nerds. Stuff that matters. >> http://tv.slashdot.org/ >> _______________________________________________ >> Ejbca-develop mailing list >> Ejb...@li... >> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >> > > ------------------------------------------------------------------------------ > Slashdot TV. > Video for Nerds. Stuff that matters. > http://tv.slashdot.org/ > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > ------------------------------------------------------------------------------ > Want excitement? > Manually upgrade your production database. > When you want reliability, choose Perforce > Perforce version control. Predictably reliable. > http://pubads.g.doubleclick.net/gampad/clk?id=157508191&iu=/4140/ostg.clktrk > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Randy Yu <yu...@ec...> - 2014-09-08 03:36:28
|
Thanks Tomas, For the process of extracting an OCSP request, what sort of details are necessary? Would you need the test certificates that I am using or other details? Thanks. ________________________________________ From: Tomas Gustavsson [to...@pr...] Sent: Sunday, September 07, 2014 1:53 AM To: ejb...@li... Subject: Re: [Ejbca-develop] EJBCA ocsp verification error These errors seem to be totally different things. For the first user, I'd recommend trying a new version of EJBCA. Digging into old 3.x is probably not something anyone want to do. For you Randy, it seems your OCSP request is missing issuerKeyHash and/or issuerNameHash. If you can extract an OCSP request we can take a look at it. Cheers, Tomas On 2014-09-05 21:57, Randy Yu wrote: > I have also tried a similar verification against EJBCA 6.2 VM with importing my CA. I am using the Windows CertUtil application to verify against my OCSP server. The following error occurs on the EJBCA server.log. Any tips are appreciated: > > 20:27:10,129 ERROR [org.jboss.ejb3.invocation] (http--0.0.0.0-8080-3) JBAS014134: EJB Invocation failed on component OcspResponseGeneratorSessionBean for method public abstract org.cesecore.certificates.ocsp.OcspResponseInformation org.cesecore.certificates.ocsp.OcspResponseGeneratorSession.getOcspResponse(byte[],java.security.cert.X509Certificate[],java.lang.String,java.lang.String,java.lang.StringBuffer,org.cesecore.certificates.ocsp.logging.AuditLogger,org.cesecore.certificates.ocsp.logging.TransactionLogger) throws org.cesecore.certificates.ocsp.exception.MalformedRequestException,java.io.IOException,org.bouncycastle.cert.ocsp.OCSPException: java.lang.NumberFormatException: Zero length BigInteger > at java.math.BigInteger.<init>(BigInteger.java:190) [rt.jar:1.7.0_51] > at org.cesecore.certificates.ocsp.cache.OcspSigningCache.getCacheIdFromCertificateID(OcspSigningCache.java:136) [cesecore-ejb-interface.jar:] > at org.cesecore.certificates.ocsp.cache.OcspSigningCache.getEntry(OcspSigningCache.java:47) [cesecore-ejb-interface.jar:] > at org.cesecore.certificates.ocsp.OcspResponseGeneratorSessionBean.translateRequestFromByteArray(OcspResponseGeneratorSessionBean.java:612) [cesecore-ejb.jar:] > at org.cesecore.certificates.ocsp.OcspResponseGeneratorSessionBean.getOcspResponse(OcspResponseGeneratorSessionBean.java:865) [cesecore-ejb.jar:] > at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method) [rt.jar:1.7.0_51] > at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:57) [rt.jar:1.7.0_51] > at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43) [rt.jar:1.7.0_51] > at java.lang.reflect.Method.invoke(Method.java:606) [rt.jar:1.7.0_51] > at org.jboss.as.ee.component.ManagedReferenceMethodInterceptorFactory$ManagedReferenceMethodInterceptor.processInvocation(ManagedReferenceMethodInterceptorFactory.java:72) [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] > at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at org.jboss.invocation.WeavedInterceptor.processInvocation(WeavedInterceptor.java:53) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at org.jboss.as.ee.component.interceptors.UserInterceptorFactory$1.processInvocation(UserInterceptorFactory.java:36) [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] > at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at org.jboss.as.jpa.interceptor.SBInvocationInterceptor.processInvocation(SBInvocationInterceptor.java:47) [jboss-as-jpa-7.1.1.Final.jar:7.1.1.Final] > at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at org.jboss.invocation.InitialInterceptor.processInvocation(InitialInterceptor.java:21) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at org.jboss.invocation.ChainedInterceptor.processInvocation(ChainedInterceptor.java:61) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at org.jboss.as.ee.component.interceptors.ComponentDispatcherInterceptor.processInvocation(ComponentDispatcherInterceptor.java:53) [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] > at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at org.jboss.as.ejb3.component.pool.PooledInstanceInterceptor.processInvocation(PooledInstanceInterceptor.java:51) [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final] > at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at org.jboss.as.ejb3.tx.CMTTxInterceptor.invokeInNoTx(CMTTxInterceptor.java:211) [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final] > at org.jboss.as.ejb3.tx.CMTTxInterceptor.supports(CMTTxInterceptor.java:363) [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final] > at org.jboss.as.ejb3.tx.CMTTxInterceptor.processInvocation(CMTTxInterceptor.java:194) [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final] > at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at org.jboss.as.ejb3.component.interceptors.CurrentInvocationContextInterceptor.processInvocation(CurrentInvocationContextInterceptor.java:41) [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final] > at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at org.jboss.as.ejb3.component.interceptors.LoggingInterceptor.processInvocation(LoggingInterceptor.java:59) [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final] > at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at org.jboss.as.ee.component.NamespaceContextInterceptor.processInvocation(NamespaceContextInterceptor.java:50) [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] > at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at org.jboss.as.ejb3.component.interceptors.AdditionalSetupInterceptor.processInvocation(AdditionalSetupInterceptor.java:32) [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final] > at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at org.jboss.as.ee.component.TCCLInterceptor.processInvocation(TCCLInterceptor.java:45) [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] > at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at org.jboss.invocation.ChainedInterceptor.processInvocation(ChainedInterceptor.java:61) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at org.jboss.as.ee.component.ViewService$View.invoke(ViewService.java:165) [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] > at org.jboss.as.ee.component.ViewDescription$1.processInvocation(ViewDescription.java:173) [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] > at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at org.jboss.invocation.ChainedInterceptor.processInvocation(ChainedInterceptor.java:61) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at org.jboss.as.ee.component.ProxyInvocationHandler.invoke(ProxyInvocationHandler.java:72) [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] > at org.cesecore.certificates.ocsp.OcspResponseGeneratorSessionLocal$$$view13.getOcspResponse(Unknown Source) [cesecore-ejb-interface.jar:] > at org.ejbca.ui.web.protocol.OCSPServlet.processOcspRequest(OCSPServlet.java:239) > at org.ejbca.ui.web.protocol.OCSPServlet.doPost(OCSPServlet.java:181) > at javax.servlet.http.HttpServlet.service(HttpServlet.java:754) [jboss-servlet-api_3.0_spec-1.0.0.Final.jar:1.0.0.Final] > at javax.servlet.http.HttpServlet.service(HttpServlet.java:847) [jboss-servlet-api_3.0_spec-1.0.0.Final.jar:1.0.0.Final] > at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:329) > at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:248) > at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:275) > at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:161) > at org.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:397) > at org.jboss.as.jpa.interceptor.WebNonTxEmCloserValve.invoke(WebNonTxEmCloserValve.java:50) [jboss-as-jpa-7.1.1.Final.jar:7.1.1.Final] > at org.jboss.as.web.security.SecurityContextAssociationValve.invoke(SecurityContextAssociationValve.java:153) > at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:155) > at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:102) > at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:109) > at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:368) > at org.apache.coyote.http11.Http11Processor.process(Http11Processor.java:877) > at org.apache.coyote.http11.Http11Protocol$Http11ConnectionHandler.process(Http11Protocol.java:671) > at org.apache.tomcat.util.net.JIoEndpoint$Worker.run(JIoEndpoint.java:930) > at java.lang.Thread.run(Thread.java:744) [rt.jar:1.7.0_51] > > -- > Randy Yu > 416-226-8615 | www.echoworx.com > > > -----Original Message----- > From: Randy Yu [mailto:yu...@ec...] > Sent: September-02-14 4:05 PM > To: ejb...@li... > Subject: [Ejbca-develop] EJBCA ocsp verification error > > When using the ejbca.sh ocsp cmd for OCSP verification, I am seeing the following error with an early version 3.x EJBCA. Any comments/recommendations for what could be causing this? > > 2014-09-02 19:09:22,009 DEBUG [org.ejbca.util.CertTools] >getCertfromByteArray: > 2014-09-02 19:09:22,009 DEBUG [org.ejbca.util.CertTools] <getCertfromByteArray: > 2014-09-02 19:09:22,009 DEBUG [org.ejbca.util.CertTools] >getCertfromByteArray: > 2014-09-02 19:09:22,009 DEBUG [org.ejbca.util.CertTools] <getCertfromByteArray: > 2014-09-02 19:09:22,037 ERROR [org.jboss.ejb.plugins.LogInterceptor] RuntimeException in method: public abstract org.ejbca.core.model.ca.caadmin.extendedcaservices.ExtendedCAServiceResponse org.ejbca.core.ejb.ca.sign.ISignSessionLocal.extendedService(org.ejbca.core.model.log.Admin,int,org.ejbca.core.model.ca.caadmin.extendedcaservices.ExtendedCAServiceRequest) throws org.ejbca.core.model.ca.caadmin.extendedcaservices.ExtendedCAServiceRequestException,org.ejbca.core.model.ca.caadmin.extendedcaservices.IllegalExtendedCAServiceRequestException,org.ejbca.core.model.ca.caadmin.extendedcaservices.ExtendedCAServiceNotActiveException,org.ejbca.core.model.ca.caadmin.CADoesntExistsException: > java.lang.IllegalArgumentException: unknown signing algorithm specified > at org.bouncycastle.ocsp.BasicOCSPRespGenerator.generate(Unknown Source) > at org.bouncycastle.ocsp.BasicOCSPRespGenerator.generate(Unknown Source) > at org.ejbca.core.model.ca.caadmin.X509CA.extendedService(X509CA.java:629) > at org.ejbca.core.ejb.ca.sign.RSASignSessionBean.extendedService(RSASignSessionBean.java:1377) > at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method) > at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:39) > at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:25) > at java.lang.reflect.Method.invoke(Method.java:592) > at org.jboss.invocation.Invocation.performCall(Invocation.java:345) > at org.jboss.ejb.StatelessSessionContainer$ContainerInterceptor.invoke(StatelessSessionContainer.java:214) > at org.jboss.resource.connectionmanager.CachedConnectionInterceptor.invoke(CachedConnectionInterceptor.java:185) > at org.jboss.ejb.plugins.StatelessSessionInstanceInterceptor.invoke(StatelessSessionInstanceInterceptor.java:113) > at org.jboss.webservice.server.ServiceEndpointInterceptor.invoke(ServiceEndpointInterceptor.java:51) > at org.jboss.ejb.plugins.CallValidationInterceptor.invoke(CallValidationInterceptor.java:48) > at org.jboss.ejb.plugins.AbstractTxInterceptor.invokeNext(AbstractTxInterceptor.java:105) > at org.jboss.ejb.plugins.TxInterceptorCMT.runWithTransactions(TxInterceptorCMT.java:313) > at org.jboss.ejb.plugins.TxInterceptorCMT.invoke(TxInterceptorCMT.java:146) > at org.jboss.ejb.plugins.SecurityInterceptor.invoke(SecurityInterceptor.java:122) > at org.jboss.ejb.plugins.LogInterceptor.invoke(LogInterceptor.java:192) > at org.jboss.ejb.plugins.ProxyFactoryFinderInterceptor.invoke(ProxyFactoryFinderInterceptor.java:122) > at org.jboss.ejb.SessionContainer.internalInvoke(SessionContainer.java:624) > at org.jboss.ejb.Container.invoke(Container.java:870) > at org.jboss.ejb.plugins.local.BaseLocalProxyFactory.invoke(BaseLocalProxyFactory.java:413) > at org.jboss.ejb.plugins.local.StatelessSessionProxy.invoke(StatelessSessionProxy.java:82) > at $Proxy194.extendedService(Unknown Source) > at org.ejbca.ui.web.protocol.OCSPServlet.extendedService(OCSPServlet.java:106) > at org.ejbca.ui.web.protocol.OCSPServletBase.signOCSPResponse(OCSPServletBase.java:313) > at org.ejbca.ui.web.protocol.OCSPServletBase.service(OCSPServletBase.java:662) > at org.ejbca.ui.web.protocol.OCSPServletBase.doPost(OCSPServletBase.java:439) > at javax.servlet.http.HttpServlet.service(HttpServlet.java:717) > at javax.servlet.http.HttpServlet.service(HttpServlet.java:810) > at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:237) > at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:157) > at org.jboss.web.tomcat.filters.ReplyHeaderFilter.doFilter(ReplyHeaderFilter.java:75) > at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:186) > at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:157) > at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:214) > at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104) > at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520) > at org.apache.catalina.core.StandardContextValve.invokeInternal(StandardContextValve.java:198) > at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:152) > at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104) > at org.jboss.web.tomcat.security.CustomPrincipalValve.invoke(CustomPrincipalValve.java:66) > at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102) > at org.jboss.web.tomcat.security.SecurityAssociationValve.invoke(SecurityAssociationValve.java:150) > at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102) > at org.jboss.web.tomcat.security.JaccContextValve.invoke(JaccContextValve.java:54) > at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102) > at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520) > at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:137) > at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104) > at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:118) > at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102) > at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520) > at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:109) > at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104) > at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520) > at org.apache.catalina.core.ContainerBase.invoke(ContainerBase.java:929) > at org.apache.coyote.tomcat5.CoyoteAdapter.service(CoyoteAdapter.java:160) > at org.apache.coyote.http11.Http11Processor.process(Http11Processor.java:799) > at org.apache.coyote.http11.Http11Protocol$Http11ConnectionHandler.processConnection(Http11Protocol.java:705) > at org.apache.tomcat.util.net.TcpWorkerThread.runIt(PoolTcpEndpoint.java:577) > at org.apache.tomcat.util.threads.ThreadPool$ControlRunnable.run(ThreadPool.java:683) > at java.lang.Thread.run(Thread.java:595) > 2014-09-02 19:09:22,041 ERROR [org.ejbca.ui.web.protocol.OCSPServletBase] Unable to handle OCSP request. > javax.ejb.EJBException: RuntimeException; CausedByException is: > unknown signing algorithm specified > at org.jboss.ejb.plugins.LogInterceptor.handleException(LogInterceptor.java:382) > at org.jboss.ejb.plugins.LogInterceptor.invoke(LogInterceptor.java:196) > at org.jboss.ejb.plugins.ProxyFactoryFinderInterceptor.invoke(ProxyFactoryFinderInterceptor.java:122) > at org.jboss.ejb.SessionContainer.internalInvoke(SessionContainer.java:624) > at org.jboss.ejb.Container.invoke(Container.java:870) > at org.jboss.ejb.plugins.local.BaseLocalProxyFactory.invoke(BaseLocalProxyFactory.java:413) > at org.jboss.ejb.plugins.local.StatelessSessionProxy.invoke(StatelessSessionProxy.java:82) > at $Proxy194.extendedService(Unknown Source) > at org.ejbca.ui.web.protocol.OCSPServlet.extendedService(OCSPServlet.java:106) > at org.ejbca.ui.web.protocol.OCSPServletBase.signOCSPResponse(OCSPServletBase.java:313) > at org.ejbca.ui.web.protocol.OCSPServletBase.service(OCSPServletBase.java:662) > at org.ejbca.ui.web.protocol.OCSPServletBase.doPost(OCSPServletBase.java:439) > at javax.servlet.http.HttpServlet.service(HttpServlet.java:717) > at javax.servlet.http.HttpServlet.service(HttpServlet.java:810) > at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:237) > at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:157) > at org.jboss.web.tomcat.filters.ReplyHeaderFilter.doFilter(ReplyHeaderFilter.java:75) > at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:186) > at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:157) > at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:214) > at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104) > at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520) > at org.apache.catalina.core.StandardContextValve.invokeInternal(StandardContextValve.java:198) > at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:152) > at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104) > at org.jboss.web.tomcat.security.CustomPrincipalValve.invoke(CustomPrincipalValve.java:66) > at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102) > at org.jboss.web.tomcat.security.SecurityAssociationValve.invoke(SecurityAssociationValve.java:150) > at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102) > at org.jboss.web.tomcat.security.JaccContextValve.invoke(JaccContextValve.java:54) > at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102) > at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520) > at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:137) > at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104) > at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:118) > at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102) > at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520) > at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:109) > at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104) > at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520) > at org.apache.catalina.core.ContainerBase.invoke(ContainerBase.java:929) > at org.apache.coyote.tomcat5.CoyoteAdapter.service(CoyoteAdapter.java:160) > at org.apache.coyote.http11.Http11Processor.process(Http11Processor.java:799) > at org.apache.coyote.http11.Http11Protocol$Http11ConnectionHandler.processConnection(Http11Protocol.java:705) > at org.apache.tomcat.util.net.TcpWorkerThread.runIt(PoolTcpEndpoint.java:577) > at org.apache.tomcat.util.threads.ThreadPool$ControlRunnable.run(ThreadPool.java:683) > at java.lang.Thread.run(Thread.java:595) > > Randy > > ------------------------------------------------------------------------------ > Slashdot TV. > Video for Nerds. Stuff that matters. > http://tv.slashdot.org/ > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > ------------------------------------------------------------------------------ > Slashdot TV. > Video for Nerds. Stuff that matters. > http://tv.slashdot.org/ > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > ------------------------------------------------------------------------------ Slashdot TV. Video for Nerds. Stuff that matters. http://tv.slashdot.org/ _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Tomas G. <to...@pr...> - 2014-09-07 05:55:14
|
> For you Randy, it seems your OCSP request is missing issuerKeyHash
> and/or issuerNameHash. If you can extract an OCSP request we can take a
> look at it.
Which would make it a malformed request according to RFC2560.
CertID ::= SEQUENCE {
hashAlgorithm AlgorithmIdentifier,
issuerNameHash OCTET STRING, -- Hash of Issuer's DN
issuerKeyHash OCTET STRING, -- Hash of Issuers public key
serialNumber CertificateSerialNumber }
Cheers,
Tomas
On 2014-09-07 07:53, Tomas Gustavsson wrote:
>
> These errors seem to be totally different things.
>
> For the first user, I'd recommend trying a new version of EJBCA. Digging
> into old 3.x is probably not something anyone want to do.
>
> For you Randy, it seems your OCSP request is missing issuerKeyHash
> and/or issuerNameHash. If you can extract an OCSP request we can take a
> look at it.
>
> Cheers,
> Tomas
>
> On 2014-09-05 21:57, Randy Yu wrote:
>> I have also tried a similar verification against EJBCA 6.2 VM with
>> importing my CA. I am using the Windows CertUtil application to
>> verify against my OCSP server. The following error occurs on the
>> EJBCA server.log. Any tips are appreciated:
>>
>> 20:27:10,129 ERROR [org.jboss.ejb3.invocation] (http--0.0.0.0-8080-3)
>> JBAS014134: EJB Invocation failed on component
>> OcspResponseGeneratorSessionBean for method public abstract
>> org.cesecore.certificates.ocsp.OcspResponseInformation
>> org.cesecore.certificates.ocsp.OcspResponseGeneratorSession.getOcspResponse(byte[],java.security.cert.X509Certificate[],java.lang.String,java.lang.String,java.lang.StringBuffer,org.cesecore.certificates.ocsp.logging.AuditLogger,org.cesecore.certificates.ocsp.logging.TransactionLogger)
>> throws
>> org.cesecore.certificates.ocsp.exception.MalformedRequestException,java.io.IOException,org.bouncycastle.cert.ocsp.OCSPException:
>> java.lang.NumberFormatException: Zero length BigInteger
>> at java.math.BigInteger.<init>(BigInteger.java:190)
>> [rt.jar:1.7.0_51]
>> at
>> org.cesecore.certificates.ocsp.cache.OcspSigningCache.getCacheIdFromCertificateID(OcspSigningCache.java:136)
>> [cesecore-ejb-interface.jar:]
>> at
>> org.cesecore.certificates.ocsp.cache.OcspSigningCache.getEntry(OcspSigningCache.java:47)
>> [cesecore-ejb-interface.jar:]
>> at
>> org.cesecore.certificates.ocsp.OcspResponseGeneratorSessionBean.translateRequestFromByteArray(OcspResponseGeneratorSessionBean.java:612)
>> [cesecore-ejb.jar:]
>> at
>> org.cesecore.certificates.ocsp.OcspResponseGeneratorSessionBean.getOcspResponse(OcspResponseGeneratorSessionBean.java:865)
>> [cesecore-ejb.jar:]
>> at sun.reflect.NativeMethodAccessorImpl.invoke0(Native
>> Method) [rt.jar:1.7.0_51]
>> at
>> sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:57)
>> [rt.jar:1.7.0_51]
>> at
>> sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
>> [rt.jar:1.7.0_51]
>> at java.lang.reflect.Method.invoke(Method.java:606)
>> [rt.jar:1.7.0_51]
>> at
>> org.jboss.as.ee.component.ManagedReferenceMethodInterceptorFactory$ManagedReferenceMethodInterceptor.processInvocation(ManagedReferenceMethodInterceptorFactory.java:72)
>> [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final]
>> at
>> org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
>> [jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
>> at
>> org.jboss.invocation.WeavedInterceptor.processInvocation(WeavedInterceptor.java:53)
>> [jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
>> at
>> org.jboss.as.ee.component.interceptors.UserInterceptorFactory$1.processInvocation(UserInterceptorFactory.java:36)
>> [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final]
>> at
>> org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
>> [jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
>> at
>> org.jboss.as.jpa.interceptor.SBInvocationInterceptor.processInvocation(SBInvocationInterceptor.java:47)
>> [jboss-as-jpa-7.1.1.Final.jar:7.1.1.Final]
>> at
>> org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
>> [jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
>> at
>> org.jboss.invocation.InitialInterceptor.processInvocation(InitialInterceptor.java:21)
>> [jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
>> at
>> org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
>> [jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
>> at
>> org.jboss.invocation.ChainedInterceptor.processInvocation(ChainedInterceptor.java:61)
>> [jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
>> at
>> org.jboss.as.ee.component.interceptors.ComponentDispatcherInterceptor.processInvocation(ComponentDispatcherInterceptor.java:53)
>> [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final]
>> at
>> org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
>> [jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
>> at
>> org.jboss.as.ejb3.component.pool.PooledInstanceInterceptor.processInvocation(PooledInstanceInterceptor.java:51)
>> [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final]
>> at
>> org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
>> [jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
>> at
>> org.jboss.as.ejb3.tx.CMTTxInterceptor.invokeInNoTx(CMTTxInterceptor.java:211)
>> [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final]
>> at
>> org.jboss.as.ejb3.tx.CMTTxInterceptor.supports(CMTTxInterceptor.java:363)
>> [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final]
>> at
>> org.jboss.as.ejb3.tx.CMTTxInterceptor.processInvocation(CMTTxInterceptor.java:194)
>> [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final]
>> at
>> org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
>> [jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
>> at
>> org.jboss.as.ejb3.component.interceptors.CurrentInvocationContextInterceptor.processInvocation(CurrentInvocationContextInterceptor.java:41)
>> [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final]
>> at
>> org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
>> [jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
>> at
>> org.jboss.as.ejb3.component.interceptors.LoggingInterceptor.processInvocation(LoggingInterceptor.java:59)
>> [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final]
>> at
>> org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
>> [jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
>> at
>> org.jboss.as.ee.component.NamespaceContextInterceptor.processInvocation(NamespaceContextInterceptor.java:50)
>> [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final]
>> at
>> org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
>> [jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
>> at
>> org.jboss.as.ejb3.component.interceptors.AdditionalSetupInterceptor.processInvocation(AdditionalSetupInterceptor.java:32)
>> [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final]
>> at
>> org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
>> [jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
>> at
>> org.jboss.as.ee.component.TCCLInterceptor.processInvocation(TCCLInterceptor.java:45)
>> [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final]
>> at
>> org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
>> [jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
>> at
>> org.jboss.invocation.ChainedInterceptor.processInvocation(ChainedInterceptor.java:61)
>> [jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
>> at
>> org.jboss.as.ee.component.ViewService$View.invoke(ViewService.java:165) [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final]
>>
>> at
>> org.jboss.as.ee.component.ViewDescription$1.processInvocation(ViewDescription.java:173)
>> [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final]
>> at
>> org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288)
>> [jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
>> at
>> org.jboss.invocation.ChainedInterceptor.processInvocation(ChainedInterceptor.java:61)
>> [jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
>> at
>> org.jboss.as.ee.component.ProxyInvocationHandler.invoke(ProxyInvocationHandler.java:72)
>> [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final]
>> at
>> org.cesecore.certificates.ocsp.OcspResponseGeneratorSessionLocal$$$view13.getOcspResponse(Unknown
>> Source) [cesecore-ejb-interface.jar:]
>> at
>> org.ejbca.ui.web.protocol.OCSPServlet.processOcspRequest(OCSPServlet.java:239)
>>
>> at
>> org.ejbca.ui.web.protocol.OCSPServlet.doPost(OCSPServlet.java:181)
>> at
>> javax.servlet.http.HttpServlet.service(HttpServlet.java:754)
>> [jboss-servlet-api_3.0_spec-1.0.0.Final.jar:1.0.0.Final]
>> at
>> javax.servlet.http.HttpServlet.service(HttpServlet.java:847)
>> [jboss-servlet-api_3.0_spec-1.0.0.Final.jar:1.0.0.Final]
>> at
>> org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:329)
>>
>> at
>> org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:248)
>>
>> at
>> org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:275)
>>
>> at
>> org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:161)
>>
>> at
>> org.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:397)
>>
>> at
>> org.jboss.as.jpa.interceptor.WebNonTxEmCloserValve.invoke(WebNonTxEmCloserValve.java:50)
>> [jboss-as-jpa-7.1.1.Final.jar:7.1.1.Final]
>> at
>> org.jboss.as.web.security.SecurityContextAssociationValve.invoke(SecurityContextAssociationValve.java:153)
>>
>> at
>> org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:155)
>>
>> at
>> org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:102)
>>
>> at
>> org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:109)
>>
>> at
>> org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:368)
>>
>> at
>> org.apache.coyote.http11.Http11Processor.process(Http11Processor.java:877)
>>
>> at
>> org.apache.coyote.http11.Http11Protocol$Http11ConnectionHandler.process(Http11Protocol.java:671)
>>
>> at
>> org.apache.tomcat.util.net.JIoEndpoint$Worker.run(JIoEndpoint.java:930)
>> at java.lang.Thread.run(Thread.java:744) [rt.jar:1.7.0_51]
>>
>> --
>> Randy Yu
>> 416-226-8615 | www.echoworx.com
>>
>>
>> -----Original Message-----
>> From: Randy Yu [mailto:yu...@ec...]
>> Sent: September-02-14 4:05 PM
>> To: ejb...@li...
>> Subject: [Ejbca-develop] EJBCA ocsp verification error
>>
>> When using the ejbca.sh ocsp cmd for OCSP verification, I am seeing
>> the following error with an early version 3.x EJBCA. Any
>> comments/recommendations for what could be causing this?
>>
>> 2014-09-02 19:09:22,009 DEBUG [org.ejbca.util.CertTools]
>> >getCertfromByteArray:
>> 2014-09-02 19:09:22,009 DEBUG [org.ejbca.util.CertTools]
>> <getCertfromByteArray:
>> 2014-09-02 19:09:22,009 DEBUG [org.ejbca.util.CertTools]
>> >getCertfromByteArray:
>> 2014-09-02 19:09:22,009 DEBUG [org.ejbca.util.CertTools]
>> <getCertfromByteArray:
>> 2014-09-02 19:09:22,037 ERROR [org.jboss.ejb.plugins.LogInterceptor]
>> RuntimeException in method: public abstract
>> org.ejbca.core.model.ca.caadmin.extendedcaservices.ExtendedCAServiceResponse
>> org.ejbca.core.ejb.ca.sign.ISignSessionLocal.extendedService(org.ejbca.core.model.log.Admin,int,org.ejbca.core.model.ca.caadmin.extendedcaservices.ExtendedCAServiceRequest)
>> throws
>> org.ejbca.core.model.ca.caadmin.extendedcaservices.ExtendedCAServiceRequestException,org.ejbca.core.model.ca.caadmin.extendedcaservices.IllegalExtendedCAServiceRequestException,org.ejbca.core.model.ca.caadmin.extendedcaservices.ExtendedCAServiceNotActiveException,org.ejbca.core.model.ca.caadmin.CADoesntExistsException:
>>
>> java.lang.IllegalArgumentException: unknown signing algorithm specified
>> at
>> org.bouncycastle.ocsp.BasicOCSPRespGenerator.generate(Unknown Source)
>> at
>> org.bouncycastle.ocsp.BasicOCSPRespGenerator.generate(Unknown Source)
>> at
>> org.ejbca.core.model.ca.caadmin.X509CA.extendedService(X509CA.java:629)
>> at
>> org.ejbca.core.ejb.ca.sign.RSASignSessionBean.extendedService(RSASignSessionBean.java:1377)
>>
>> at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
>> at
>> sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:39)
>>
>> at
>> sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:25)
>>
>> at java.lang.reflect.Method.invoke(Method.java:592)
>> at
>> org.jboss.invocation.Invocation.performCall(Invocation.java:345)
>> at
>> org.jboss.ejb.StatelessSessionContainer$ContainerInterceptor.invoke(StatelessSessionContainer.java:214)
>>
>> at
>> org.jboss.resource.connectionmanager.CachedConnectionInterceptor.invoke(CachedConnectionInterceptor.java:185)
>>
>> at
>> org.jboss.ejb.plugins.StatelessSessionInstanceInterceptor.invoke(StatelessSessionInstanceInterceptor.java:113)
>>
>> at
>> org.jboss.webservice.server.ServiceEndpointInterceptor.invoke(ServiceEndpointInterceptor.java:51)
>>
>> at
>> org.jboss.ejb.plugins.CallValidationInterceptor.invoke(CallValidationInterceptor.java:48)
>>
>> at
>> org.jboss.ejb.plugins.AbstractTxInterceptor.invokeNext(AbstractTxInterceptor.java:105)
>>
>> at
>> org.jboss.ejb.plugins.TxInterceptorCMT.runWithTransactions(TxInterceptorCMT.java:313)
>>
>> at
>> org.jboss.ejb.plugins.TxInterceptorCMT.invoke(TxInterceptorCMT.java:146)
>> at
>> org.jboss.ejb.plugins.SecurityInterceptor.invoke(SecurityInterceptor.java:122)
>>
>> at
>> org.jboss.ejb.plugins.LogInterceptor.invoke(LogInterceptor.java:192)
>> at
>> org.jboss.ejb.plugins.ProxyFactoryFinderInterceptor.invoke(ProxyFactoryFinderInterceptor.java:122)
>>
>> at
>> org.jboss.ejb.SessionContainer.internalInvoke(SessionContainer.java:624)
>> at org.jboss.ejb.Container.invoke(Container.java:870)
>> at
>> org.jboss.ejb.plugins.local.BaseLocalProxyFactory.invoke(BaseLocalProxyFactory.java:413)
>>
>> at
>> org.jboss.ejb.plugins.local.StatelessSessionProxy.invoke(StatelessSessionProxy.java:82)
>>
>> at $Proxy194.extendedService(Unknown Source)
>> at
>> org.ejbca.ui.web.protocol.OCSPServlet.extendedService(OCSPServlet.java:106)
>>
>> at
>> org.ejbca.ui.web.protocol.OCSPServletBase.signOCSPResponse(OCSPServletBase.java:313)
>>
>> at
>> org.ejbca.ui.web.protocol.OCSPServletBase.service(OCSPServletBase.java:662)
>>
>> at
>> org.ejbca.ui.web.protocol.OCSPServletBase.doPost(OCSPServletBase.java:439)
>>
>> at javax.servlet.http.HttpServlet.service(HttpServlet.java:717)
>> at javax.servlet.http.HttpServlet.service(HttpServlet.java:810)
>> at
>> org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:237)
>>
>> at
>> org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:157)
>>
>> at
>> org.jboss.web.tomcat.filters.ReplyHeaderFilter.doFilter(ReplyHeaderFilter.java:75)
>>
>> at
>> org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:186)
>>
>> at
>> org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:157)
>>
>> at
>> org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:214)
>>
>> at
>> org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104)
>>
>> at
>> org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520)
>>
>> at
>> org.apache.catalina.core.StandardContextValve.invokeInternal(StandardContextValve.java:198)
>>
>> at
>> org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:152)
>>
>> at
>> org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104)
>>
>> at
>> org.jboss.web.tomcat.security.CustomPrincipalValve.invoke(CustomPrincipalValve.java:66)
>>
>> at
>> org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102)
>>
>> at
>> org.jboss.web.tomcat.security.SecurityAssociationValve.invoke(SecurityAssociationValve.java:150)
>>
>> at
>> org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102)
>>
>> at
>> org.jboss.web.tomcat.security.JaccContextValve.invoke(JaccContextValve.java:54)
>>
>> at
>> org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102)
>>
>> at
>> org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520)
>>
>> at
>> org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:137)
>>
>> at
>> org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104)
>>
>> at
>> org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:118)
>>
>> at
>> org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102)
>>
>> at
>> org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520)
>>
>> at
>> org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:109)
>>
>> at
>> org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104)
>>
>> at
>> org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520)
>>
>> at
>> org.apache.catalina.core.ContainerBase.invoke(ContainerBase.java:929)
>> at
>> org.apache.coyote.tomcat5.CoyoteAdapter.service(CoyoteAdapter.java:160)
>> at
>> org.apache.coyote.http11.Http11Processor.process(Http11Processor.java:799)
>>
>> at
>> org.apache.coyote.http11.Http11Protocol$Http11ConnectionHandler.processConnection(Http11Protocol.java:705)
>>
>> at
>> org.apache.tomcat.util.net.TcpWorkerThread.runIt(PoolTcpEndpoint.java:577)
>>
>> at
>> org.apache.tomcat.util.threads.ThreadPool$ControlRunnable.run(ThreadPool.java:683)
>>
>> at java.lang.Thread.run(Thread.java:595)
>> 2014-09-02 19:09:22,041 ERROR
>> [org.ejbca.ui.web.protocol.OCSPServletBase] Unable to handle OCSP
>> request.
>> javax.ejb.EJBException: RuntimeException; CausedByException is:
>> unknown signing algorithm specified
>> at
>> org.jboss.ejb.plugins.LogInterceptor.handleException(LogInterceptor.java:382)
>>
>> at
>> org.jboss.ejb.plugins.LogInterceptor.invoke(LogInterceptor.java:196)
>> at
>> org.jboss.ejb.plugins.ProxyFactoryFinderInterceptor.invoke(ProxyFactoryFinderInterceptor.java:122)
>>
>> at
>> org.jboss.ejb.SessionContainer.internalInvoke(SessionContainer.java:624)
>> at org.jboss.ejb.Container.invoke(Container.java:870)
>> at
>> org.jboss.ejb.plugins.local.BaseLocalProxyFactory.invoke(BaseLocalProxyFactory.java:413)
>>
>> at
>> org.jboss.ejb.plugins.local.StatelessSessionProxy.invoke(StatelessSessionProxy.java:82)
>>
>> at $Proxy194.extendedService(Unknown Source)
>> at
>> org.ejbca.ui.web.protocol.OCSPServlet.extendedService(OCSPServlet.java:106)
>>
>> at
>> org.ejbca.ui.web.protocol.OCSPServletBase.signOCSPResponse(OCSPServletBase.java:313)
>>
>> at
>> org.ejbca.ui.web.protocol.OCSPServletBase.service(OCSPServletBase.java:662)
>>
>> at
>> org.ejbca.ui.web.protocol.OCSPServletBase.doPost(OCSPServletBase.java:439)
>>
>> at javax.servlet.http.HttpServlet.service(HttpServlet.java:717)
>> at javax.servlet.http.HttpServlet.service(HttpServlet.java:810)
>> at
>> org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:237)
>>
>> at
>> org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:157)
>>
>> at
>> org.jboss.web.tomcat.filters.ReplyHeaderFilter.doFilter(ReplyHeaderFilter.java:75)
>>
>> at
>> org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:186)
>>
>> at
>> org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:157)
>>
>> at
>> org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:214)
>>
>> at
>> org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104)
>>
>> at
>> org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520)
>>
>> at
>> org.apache.catalina.core.StandardContextValve.invokeInternal(StandardContextValve.java:198)
>>
>> at
>> org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:152)
>>
>> at
>> org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104)
>>
>> at
>> org.jboss.web.tomcat.security.CustomPrincipalValve.invoke(CustomPrincipalValve.java:66)
>>
>> at
>> org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102)
>>
>> at
>> org.jboss.web.tomcat.security.SecurityAssociationValve.invoke(SecurityAssociationValve.java:150)
>>
>> at
>> org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102)
>>
>> at
>> org.jboss.web.tomcat.security.JaccContextValve.invoke(JaccContextValve.java:54)
>>
>> at
>> org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102)
>>
>> at
>> org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520)
>>
>> at
>> org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:137)
>>
>> at
>> org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104)
>>
>> at
>> org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:118)
>>
>> at
>> org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102)
>>
>> at
>> org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520)
>>
>> at
>> org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:109)
>>
>> at
>> org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104)
>>
>> at
>> org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520)
>>
>> at
>> org.apache.catalina.core.ContainerBase.invoke(ContainerBase.java:929)
>> at
>> org.apache.coyote.tomcat5.CoyoteAdapter.service(CoyoteAdapter.java:160)
>> at
>> org.apache.coyote.http11.Http11Processor.process(Http11Processor.java:799)
>>
>> at
>> org.apache.coyote.http11.Http11Protocol$Http11ConnectionHandler.processConnection(Http11Protocol.java:705)
>>
>> at
>> org.apache.tomcat.util.net.TcpWorkerThread.runIt(PoolTcpEndpoint.java:577)
>>
>> at
>> org.apache.tomcat.util.threads.ThreadPool$ControlRunnable.run(ThreadPool.java:683)
>>
>> at java.lang.Thread.run(Thread.java:595)
>>
>> Randy
>>
>> ------------------------------------------------------------------------------
>>
>> Slashdot TV.
>> Video for Nerds. Stuff that matters.
>> http://tv.slashdot.org/
>> _______________________________________________
>> Ejbca-develop mailing list
>> Ejb...@li...
>> https://lists.sourceforge.net/lists/listinfo/ejbca-develop
>>
>> ------------------------------------------------------------------------------
>>
>> Slashdot TV.
>> Video for Nerds. Stuff that matters.
>> http://tv.slashdot.org/
>> _______________________________________________
>> Ejbca-develop mailing list
>> Ejb...@li...
>> https://lists.sourceforge.net/lists/listinfo/ejbca-develop
>>
|
|
From: Tomas G. <to...@pr...> - 2014-09-07 05:53:19
|
These errors seem to be totally different things. For the first user, I'd recommend trying a new version of EJBCA. Digging into old 3.x is probably not something anyone want to do. For you Randy, it seems your OCSP request is missing issuerKeyHash and/or issuerNameHash. If you can extract an OCSP request we can take a look at it. Cheers, Tomas On 2014-09-05 21:57, Randy Yu wrote: > I have also tried a similar verification against EJBCA 6.2 VM with importing my CA. I am using the Windows CertUtil application to verify against my OCSP server. The following error occurs on the EJBCA server.log. Any tips are appreciated: > > 20:27:10,129 ERROR [org.jboss.ejb3.invocation] (http--0.0.0.0-8080-3) JBAS014134: EJB Invocation failed on component OcspResponseGeneratorSessionBean for method public abstract org.cesecore.certificates.ocsp.OcspResponseInformation org.cesecore.certificates.ocsp.OcspResponseGeneratorSession.getOcspResponse(byte[],java.security.cert.X509Certificate[],java.lang.String,java.lang.String,java.lang.StringBuffer,org.cesecore.certificates.ocsp.logging.AuditLogger,org.cesecore.certificates.ocsp.logging.TransactionLogger) throws org.cesecore.certificates.ocsp.exception.MalformedRequestException,java.io.IOException,org.bouncycastle.cert.ocsp.OCSPException: java.lang.NumberFormatException: Zero length BigInteger > at java.math.BigInteger.<init>(BigInteger.java:190) [rt.jar:1.7.0_51] > at org.cesecore.certificates.ocsp.cache.OcspSigningCache.getCacheIdFromCertificateID(OcspSigningCache.java:136) [cesecore-ejb-interface.jar:] > at org.cesecore.certificates.ocsp.cache.OcspSigningCache.getEntry(OcspSigningCache.java:47) [cesecore-ejb-interface.jar:] > at org.cesecore.certificates.ocsp.OcspResponseGeneratorSessionBean.translateRequestFromByteArray(OcspResponseGeneratorSessionBean.java:612) [cesecore-ejb.jar:] > at org.cesecore.certificates.ocsp.OcspResponseGeneratorSessionBean.getOcspResponse(OcspResponseGeneratorSessionBean.java:865) [cesecore-ejb.jar:] > at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method) [rt.jar:1.7.0_51] > at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:57) [rt.jar:1.7.0_51] > at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43) [rt.jar:1.7.0_51] > at java.lang.reflect.Method.invoke(Method.java:606) [rt.jar:1.7.0_51] > at org.jboss.as.ee.component.ManagedReferenceMethodInterceptorFactory$ManagedReferenceMethodInterceptor.processInvocation(ManagedReferenceMethodInterceptorFactory.java:72) [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] > at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at org.jboss.invocation.WeavedInterceptor.processInvocation(WeavedInterceptor.java:53) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at org.jboss.as.ee.component.interceptors.UserInterceptorFactory$1.processInvocation(UserInterceptorFactory.java:36) [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] > at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at org.jboss.as.jpa.interceptor.SBInvocationInterceptor.processInvocation(SBInvocationInterceptor.java:47) [jboss-as-jpa-7.1.1.Final.jar:7.1.1.Final] > at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at org.jboss.invocation.InitialInterceptor.processInvocation(InitialInterceptor.java:21) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at org.jboss.invocation.ChainedInterceptor.processInvocation(ChainedInterceptor.java:61) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at org.jboss.as.ee.component.interceptors.ComponentDispatcherInterceptor.processInvocation(ComponentDispatcherInterceptor.java:53) [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] > at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at org.jboss.as.ejb3.component.pool.PooledInstanceInterceptor.processInvocation(PooledInstanceInterceptor.java:51) [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final] > at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at org.jboss.as.ejb3.tx.CMTTxInterceptor.invokeInNoTx(CMTTxInterceptor.java:211) [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final] > at org.jboss.as.ejb3.tx.CMTTxInterceptor.supports(CMTTxInterceptor.java:363) [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final] > at org.jboss.as.ejb3.tx.CMTTxInterceptor.processInvocation(CMTTxInterceptor.java:194) [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final] > at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at org.jboss.as.ejb3.component.interceptors.CurrentInvocationContextInterceptor.processInvocation(CurrentInvocationContextInterceptor.java:41) [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final] > at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at org.jboss.as.ejb3.component.interceptors.LoggingInterceptor.processInvocation(LoggingInterceptor.java:59) [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final] > at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at org.jboss.as.ee.component.NamespaceContextInterceptor.processInvocation(NamespaceContextInterceptor.java:50) [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] > at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at org.jboss.as.ejb3.component.interceptors.AdditionalSetupInterceptor.processInvocation(AdditionalSetupInterceptor.java:32) [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final] > at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at org.jboss.as.ee.component.TCCLInterceptor.processInvocation(TCCLInterceptor.java:45) [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] > at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at org.jboss.invocation.ChainedInterceptor.processInvocation(ChainedInterceptor.java:61) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at org.jboss.as.ee.component.ViewService$View.invoke(ViewService.java:165) [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] > at org.jboss.as.ee.component.ViewDescription$1.processInvocation(ViewDescription.java:173) [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] > at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at org.jboss.invocation.ChainedInterceptor.processInvocation(ChainedInterceptor.java:61) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final] > at org.jboss.as.ee.component.ProxyInvocationHandler.invoke(ProxyInvocationHandler.java:72) [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final] > at org.cesecore.certificates.ocsp.OcspResponseGeneratorSessionLocal$$$view13.getOcspResponse(Unknown Source) [cesecore-ejb-interface.jar:] > at org.ejbca.ui.web.protocol.OCSPServlet.processOcspRequest(OCSPServlet.java:239) > at org.ejbca.ui.web.protocol.OCSPServlet.doPost(OCSPServlet.java:181) > at javax.servlet.http.HttpServlet.service(HttpServlet.java:754) [jboss-servlet-api_3.0_spec-1.0.0.Final.jar:1.0.0.Final] > at javax.servlet.http.HttpServlet.service(HttpServlet.java:847) [jboss-servlet-api_3.0_spec-1.0.0.Final.jar:1.0.0.Final] > at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:329) > at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:248) > at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:275) > at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:161) > at org.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:397) > at org.jboss.as.jpa.interceptor.WebNonTxEmCloserValve.invoke(WebNonTxEmCloserValve.java:50) [jboss-as-jpa-7.1.1.Final.jar:7.1.1.Final] > at org.jboss.as.web.security.SecurityContextAssociationValve.invoke(SecurityContextAssociationValve.java:153) > at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:155) > at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:102) > at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:109) > at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:368) > at org.apache.coyote.http11.Http11Processor.process(Http11Processor.java:877) > at org.apache.coyote.http11.Http11Protocol$Http11ConnectionHandler.process(Http11Protocol.java:671) > at org.apache.tomcat.util.net.JIoEndpoint$Worker.run(JIoEndpoint.java:930) > at java.lang.Thread.run(Thread.java:744) [rt.jar:1.7.0_51] > > -- > Randy Yu > 416-226-8615 | www.echoworx.com > > > -----Original Message----- > From: Randy Yu [mailto:yu...@ec...] > Sent: September-02-14 4:05 PM > To: ejb...@li... > Subject: [Ejbca-develop] EJBCA ocsp verification error > > When using the ejbca.sh ocsp cmd for OCSP verification, I am seeing the following error with an early version 3.x EJBCA. Any comments/recommendations for what could be causing this? > > 2014-09-02 19:09:22,009 DEBUG [org.ejbca.util.CertTools] >getCertfromByteArray: > 2014-09-02 19:09:22,009 DEBUG [org.ejbca.util.CertTools] <getCertfromByteArray: > 2014-09-02 19:09:22,009 DEBUG [org.ejbca.util.CertTools] >getCertfromByteArray: > 2014-09-02 19:09:22,009 DEBUG [org.ejbca.util.CertTools] <getCertfromByteArray: > 2014-09-02 19:09:22,037 ERROR [org.jboss.ejb.plugins.LogInterceptor] RuntimeException in method: public abstract org.ejbca.core.model.ca.caadmin.extendedcaservices.ExtendedCAServiceResponse org.ejbca.core.ejb.ca.sign.ISignSessionLocal.extendedService(org.ejbca.core.model.log.Admin,int,org.ejbca.core.model.ca.caadmin.extendedcaservices.ExtendedCAServiceRequest) throws org.ejbca.core.model.ca.caadmin.extendedcaservices.ExtendedCAServiceRequestException,org.ejbca.core.model.ca.caadmin.extendedcaservices.IllegalExtendedCAServiceRequestException,org.ejbca.core.model.ca.caadmin.extendedcaservices.ExtendedCAServiceNotActiveException,org.ejbca.core.model.ca.caadmin.CADoesntExistsException: > java.lang.IllegalArgumentException: unknown signing algorithm specified > at org.bouncycastle.ocsp.BasicOCSPRespGenerator.generate(Unknown Source) > at org.bouncycastle.ocsp.BasicOCSPRespGenerator.generate(Unknown Source) > at org.ejbca.core.model.ca.caadmin.X509CA.extendedService(X509CA.java:629) > at org.ejbca.core.ejb.ca.sign.RSASignSessionBean.extendedService(RSASignSessionBean.java:1377) > at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method) > at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:39) > at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:25) > at java.lang.reflect.Method.invoke(Method.java:592) > at org.jboss.invocation.Invocation.performCall(Invocation.java:345) > at org.jboss.ejb.StatelessSessionContainer$ContainerInterceptor.invoke(StatelessSessionContainer.java:214) > at org.jboss.resource.connectionmanager.CachedConnectionInterceptor.invoke(CachedConnectionInterceptor.java:185) > at org.jboss.ejb.plugins.StatelessSessionInstanceInterceptor.invoke(StatelessSessionInstanceInterceptor.java:113) > at org.jboss.webservice.server.ServiceEndpointInterceptor.invoke(ServiceEndpointInterceptor.java:51) > at org.jboss.ejb.plugins.CallValidationInterceptor.invoke(CallValidationInterceptor.java:48) > at org.jboss.ejb.plugins.AbstractTxInterceptor.invokeNext(AbstractTxInterceptor.java:105) > at org.jboss.ejb.plugins.TxInterceptorCMT.runWithTransactions(TxInterceptorCMT.java:313) > at org.jboss.ejb.plugins.TxInterceptorCMT.invoke(TxInterceptorCMT.java:146) > at org.jboss.ejb.plugins.SecurityInterceptor.invoke(SecurityInterceptor.java:122) > at org.jboss.ejb.plugins.LogInterceptor.invoke(LogInterceptor.java:192) > at org.jboss.ejb.plugins.ProxyFactoryFinderInterceptor.invoke(ProxyFactoryFinderInterceptor.java:122) > at org.jboss.ejb.SessionContainer.internalInvoke(SessionContainer.java:624) > at org.jboss.ejb.Container.invoke(Container.java:870) > at org.jboss.ejb.plugins.local.BaseLocalProxyFactory.invoke(BaseLocalProxyFactory.java:413) > at org.jboss.ejb.plugins.local.StatelessSessionProxy.invoke(StatelessSessionProxy.java:82) > at $Proxy194.extendedService(Unknown Source) > at org.ejbca.ui.web.protocol.OCSPServlet.extendedService(OCSPServlet.java:106) > at org.ejbca.ui.web.protocol.OCSPServletBase.signOCSPResponse(OCSPServletBase.java:313) > at org.ejbca.ui.web.protocol.OCSPServletBase.service(OCSPServletBase.java:662) > at org.ejbca.ui.web.protocol.OCSPServletBase.doPost(OCSPServletBase.java:439) > at javax.servlet.http.HttpServlet.service(HttpServlet.java:717) > at javax.servlet.http.HttpServlet.service(HttpServlet.java:810) > at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:237) > at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:157) > at org.jboss.web.tomcat.filters.ReplyHeaderFilter.doFilter(ReplyHeaderFilter.java:75) > at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:186) > at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:157) > at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:214) > at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104) > at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520) > at org.apache.catalina.core.StandardContextValve.invokeInternal(StandardContextValve.java:198) > at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:152) > at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104) > at org.jboss.web.tomcat.security.CustomPrincipalValve.invoke(CustomPrincipalValve.java:66) > at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102) > at org.jboss.web.tomcat.security.SecurityAssociationValve.invoke(SecurityAssociationValve.java:150) > at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102) > at org.jboss.web.tomcat.security.JaccContextValve.invoke(JaccContextValve.java:54) > at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102) > at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520) > at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:137) > at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104) > at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:118) > at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102) > at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520) > at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:109) > at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104) > at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520) > at org.apache.catalina.core.ContainerBase.invoke(ContainerBase.java:929) > at org.apache.coyote.tomcat5.CoyoteAdapter.service(CoyoteAdapter.java:160) > at org.apache.coyote.http11.Http11Processor.process(Http11Processor.java:799) > at org.apache.coyote.http11.Http11Protocol$Http11ConnectionHandler.processConnection(Http11Protocol.java:705) > at org.apache.tomcat.util.net.TcpWorkerThread.runIt(PoolTcpEndpoint.java:577) > at org.apache.tomcat.util.threads.ThreadPool$ControlRunnable.run(ThreadPool.java:683) > at java.lang.Thread.run(Thread.java:595) > 2014-09-02 19:09:22,041 ERROR [org.ejbca.ui.web.protocol.OCSPServletBase] Unable to handle OCSP request. > javax.ejb.EJBException: RuntimeException; CausedByException is: > unknown signing algorithm specified > at org.jboss.ejb.plugins.LogInterceptor.handleException(LogInterceptor.java:382) > at org.jboss.ejb.plugins.LogInterceptor.invoke(LogInterceptor.java:196) > at org.jboss.ejb.plugins.ProxyFactoryFinderInterceptor.invoke(ProxyFactoryFinderInterceptor.java:122) > at org.jboss.ejb.SessionContainer.internalInvoke(SessionContainer.java:624) > at org.jboss.ejb.Container.invoke(Container.java:870) > at org.jboss.ejb.plugins.local.BaseLocalProxyFactory.invoke(BaseLocalProxyFactory.java:413) > at org.jboss.ejb.plugins.local.StatelessSessionProxy.invoke(StatelessSessionProxy.java:82) > at $Proxy194.extendedService(Unknown Source) > at org.ejbca.ui.web.protocol.OCSPServlet.extendedService(OCSPServlet.java:106) > at org.ejbca.ui.web.protocol.OCSPServletBase.signOCSPResponse(OCSPServletBase.java:313) > at org.ejbca.ui.web.protocol.OCSPServletBase.service(OCSPServletBase.java:662) > at org.ejbca.ui.web.protocol.OCSPServletBase.doPost(OCSPServletBase.java:439) > at javax.servlet.http.HttpServlet.service(HttpServlet.java:717) > at javax.servlet.http.HttpServlet.service(HttpServlet.java:810) > at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:237) > at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:157) > at org.jboss.web.tomcat.filters.ReplyHeaderFilter.doFilter(ReplyHeaderFilter.java:75) > at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:186) > at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:157) > at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:214) > at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104) > at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520) > at org.apache.catalina.core.StandardContextValve.invokeInternal(StandardContextValve.java:198) > at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:152) > at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104) > at org.jboss.web.tomcat.security.CustomPrincipalValve.invoke(CustomPrincipalValve.java:66) > at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102) > at org.jboss.web.tomcat.security.SecurityAssociationValve.invoke(SecurityAssociationValve.java:150) > at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102) > at org.jboss.web.tomcat.security.JaccContextValve.invoke(JaccContextValve.java:54) > at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102) > at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520) > at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:137) > at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104) > at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:118) > at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102) > at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520) > at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:109) > at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104) > at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520) > at org.apache.catalina.core.ContainerBase.invoke(ContainerBase.java:929) > at org.apache.coyote.tomcat5.CoyoteAdapter.service(CoyoteAdapter.java:160) > at org.apache.coyote.http11.Http11Processor.process(Http11Processor.java:799) > at org.apache.coyote.http11.Http11Protocol$Http11ConnectionHandler.processConnection(Http11Protocol.java:705) > at org.apache.tomcat.util.net.TcpWorkerThread.runIt(PoolTcpEndpoint.java:577) > at org.apache.tomcat.util.threads.ThreadPool$ControlRunnable.run(ThreadPool.java:683) > at java.lang.Thread.run(Thread.java:595) > > Randy > > ------------------------------------------------------------------------------ > Slashdot TV. > Video for Nerds. Stuff that matters. > http://tv.slashdot.org/ > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > ------------------------------------------------------------------------------ > Slashdot TV. > Video for Nerds. Stuff that matters. > http://tv.slashdot.org/ > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Randy Yu <yu...@ec...> - 2014-09-05 19:57:47
|
I have also tried a similar verification against EJBCA 6.2 VM with importing my CA. I am using the Windows CertUtil application to verify against my OCSP server. The following error occurs on the EJBCA server.log. Any tips are appreciated:
20:27:10,129 ERROR [org.jboss.ejb3.invocation] (http--0.0.0.0-8080-3) JBAS014134: EJB Invocation failed on component OcspResponseGeneratorSessionBean for method public abstract org.cesecore.certificates.ocsp.OcspResponseInformation org.cesecore.certificates.ocsp.OcspResponseGeneratorSession.getOcspResponse(byte[],java.security.cert.X509Certificate[],java.lang.String,java.lang.String,java.lang.StringBuffer,org.cesecore.certificates.ocsp.logging.AuditLogger,org.cesecore.certificates.ocsp.logging.TransactionLogger) throws org.cesecore.certificates.ocsp.exception.MalformedRequestException,java.io.IOException,org.bouncycastle.cert.ocsp.OCSPException: java.lang.NumberFormatException: Zero length BigInteger
at java.math.BigInteger.<init>(BigInteger.java:190) [rt.jar:1.7.0_51]
at org.cesecore.certificates.ocsp.cache.OcspSigningCache.getCacheIdFromCertificateID(OcspSigningCache.java:136) [cesecore-ejb-interface.jar:]
at org.cesecore.certificates.ocsp.cache.OcspSigningCache.getEntry(OcspSigningCache.java:47) [cesecore-ejb-interface.jar:]
at org.cesecore.certificates.ocsp.OcspResponseGeneratorSessionBean.translateRequestFromByteArray(OcspResponseGeneratorSessionBean.java:612) [cesecore-ejb.jar:]
at org.cesecore.certificates.ocsp.OcspResponseGeneratorSessionBean.getOcspResponse(OcspResponseGeneratorSessionBean.java:865) [cesecore-ejb.jar:]
at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method) [rt.jar:1.7.0_51]
at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:57) [rt.jar:1.7.0_51]
at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43) [rt.jar:1.7.0_51]
at java.lang.reflect.Method.invoke(Method.java:606) [rt.jar:1.7.0_51]
at org.jboss.as.ee.component.ManagedReferenceMethodInterceptorFactory$ManagedReferenceMethodInterceptor.processInvocation(ManagedReferenceMethodInterceptorFactory.java:72) [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final]
at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at org.jboss.invocation.WeavedInterceptor.processInvocation(WeavedInterceptor.java:53) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at org.jboss.as.ee.component.interceptors.UserInterceptorFactory$1.processInvocation(UserInterceptorFactory.java:36) [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final]
at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at org.jboss.as.jpa.interceptor.SBInvocationInterceptor.processInvocation(SBInvocationInterceptor.java:47) [jboss-as-jpa-7.1.1.Final.jar:7.1.1.Final]
at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at org.jboss.invocation.InitialInterceptor.processInvocation(InitialInterceptor.java:21) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at org.jboss.invocation.ChainedInterceptor.processInvocation(ChainedInterceptor.java:61) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at org.jboss.as.ee.component.interceptors.ComponentDispatcherInterceptor.processInvocation(ComponentDispatcherInterceptor.java:53) [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final]
at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at org.jboss.as.ejb3.component.pool.PooledInstanceInterceptor.processInvocation(PooledInstanceInterceptor.java:51) [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final]
at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at org.jboss.as.ejb3.tx.CMTTxInterceptor.invokeInNoTx(CMTTxInterceptor.java:211) [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final]
at org.jboss.as.ejb3.tx.CMTTxInterceptor.supports(CMTTxInterceptor.java:363) [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final]
at org.jboss.as.ejb3.tx.CMTTxInterceptor.processInvocation(CMTTxInterceptor.java:194) [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final]
at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at org.jboss.as.ejb3.component.interceptors.CurrentInvocationContextInterceptor.processInvocation(CurrentInvocationContextInterceptor.java:41) [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final]
at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at org.jboss.as.ejb3.component.interceptors.LoggingInterceptor.processInvocation(LoggingInterceptor.java:59) [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final]
at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at org.jboss.as.ee.component.NamespaceContextInterceptor.processInvocation(NamespaceContextInterceptor.java:50) [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final]
at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at org.jboss.as.ejb3.component.interceptors.AdditionalSetupInterceptor.processInvocation(AdditionalSetupInterceptor.java:32) [jboss-as-ejb3-7.1.1.Final.jar:7.1.1.Final]
at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at org.jboss.as.ee.component.TCCLInterceptor.processInvocation(TCCLInterceptor.java:45) [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final]
at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at org.jboss.invocation.ChainedInterceptor.processInvocation(ChainedInterceptor.java:61) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at org.jboss.as.ee.component.ViewService$View.invoke(ViewService.java:165) [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final]
at org.jboss.as.ee.component.ViewDescription$1.processInvocation(ViewDescription.java:173) [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final]
at org.jboss.invocation.InterceptorContext.proceed(InterceptorContext.java:288) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at org.jboss.invocation.ChainedInterceptor.processInvocation(ChainedInterceptor.java:61) [jboss-invocation-1.1.1.Final.jar:1.1.1.Final]
at org.jboss.as.ee.component.ProxyInvocationHandler.invoke(ProxyInvocationHandler.java:72) [jboss-as-ee-7.1.1.Final.jar:7.1.1.Final]
at org.cesecore.certificates.ocsp.OcspResponseGeneratorSessionLocal$$$view13.getOcspResponse(Unknown Source) [cesecore-ejb-interface.jar:]
at org.ejbca.ui.web.protocol.OCSPServlet.processOcspRequest(OCSPServlet.java:239)
at org.ejbca.ui.web.protocol.OCSPServlet.doPost(OCSPServlet.java:181)
at javax.servlet.http.HttpServlet.service(HttpServlet.java:754) [jboss-servlet-api_3.0_spec-1.0.0.Final.jar:1.0.0.Final]
at javax.servlet.http.HttpServlet.service(HttpServlet.java:847) [jboss-servlet-api_3.0_spec-1.0.0.Final.jar:1.0.0.Final]
at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:329)
at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:248)
at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:275)
at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:161)
at org.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:397)
at org.jboss.as.jpa.interceptor.WebNonTxEmCloserValve.invoke(WebNonTxEmCloserValve.java:50) [jboss-as-jpa-7.1.1.Final.jar:7.1.1.Final]
at org.jboss.as.web.security.SecurityContextAssociationValve.invoke(SecurityContextAssociationValve.java:153)
at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:155)
at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:102)
at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:109)
at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:368)
at org.apache.coyote.http11.Http11Processor.process(Http11Processor.java:877)
at org.apache.coyote.http11.Http11Protocol$Http11ConnectionHandler.process(Http11Protocol.java:671)
at org.apache.tomcat.util.net.JIoEndpoint$Worker.run(JIoEndpoint.java:930)
at java.lang.Thread.run(Thread.java:744) [rt.jar:1.7.0_51]
--
Randy Yu
416-226-8615 | www.echoworx.com
-----Original Message-----
From: Randy Yu [mailto:yu...@ec...]
Sent: September-02-14 4:05 PM
To: ejb...@li...
Subject: [Ejbca-develop] EJBCA ocsp verification error
When using the ejbca.sh ocsp cmd for OCSP verification, I am seeing the following error with an early version 3.x EJBCA. Any comments/recommendations for what could be causing this?
2014-09-02 19:09:22,009 DEBUG [org.ejbca.util.CertTools] >getCertfromByteArray:
2014-09-02 19:09:22,009 DEBUG [org.ejbca.util.CertTools] <getCertfromByteArray:
2014-09-02 19:09:22,009 DEBUG [org.ejbca.util.CertTools] >getCertfromByteArray:
2014-09-02 19:09:22,009 DEBUG [org.ejbca.util.CertTools] <getCertfromByteArray:
2014-09-02 19:09:22,037 ERROR [org.jboss.ejb.plugins.LogInterceptor] RuntimeException in method: public abstract org.ejbca.core.model.ca.caadmin.extendedcaservices.ExtendedCAServiceResponse org.ejbca.core.ejb.ca.sign.ISignSessionLocal.extendedService(org.ejbca.core.model.log.Admin,int,org.ejbca.core.model.ca.caadmin.extendedcaservices.ExtendedCAServiceRequest) throws org.ejbca.core.model.ca.caadmin.extendedcaservices.ExtendedCAServiceRequestException,org.ejbca.core.model.ca.caadmin.extendedcaservices.IllegalExtendedCAServiceRequestException,org.ejbca.core.model.ca.caadmin.extendedcaservices.ExtendedCAServiceNotActiveException,org.ejbca.core.model.ca.caadmin.CADoesntExistsException:
java.lang.IllegalArgumentException: unknown signing algorithm specified
at org.bouncycastle.ocsp.BasicOCSPRespGenerator.generate(Unknown Source)
at org.bouncycastle.ocsp.BasicOCSPRespGenerator.generate(Unknown Source)
at org.ejbca.core.model.ca.caadmin.X509CA.extendedService(X509CA.java:629)
at org.ejbca.core.ejb.ca.sign.RSASignSessionBean.extendedService(RSASignSessionBean.java:1377)
at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:39)
at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:25)
at java.lang.reflect.Method.invoke(Method.java:592)
at org.jboss.invocation.Invocation.performCall(Invocation.java:345)
at org.jboss.ejb.StatelessSessionContainer$ContainerInterceptor.invoke(StatelessSessionContainer.java:214)
at org.jboss.resource.connectionmanager.CachedConnectionInterceptor.invoke(CachedConnectionInterceptor.java:185)
at org.jboss.ejb.plugins.StatelessSessionInstanceInterceptor.invoke(StatelessSessionInstanceInterceptor.java:113)
at org.jboss.webservice.server.ServiceEndpointInterceptor.invoke(ServiceEndpointInterceptor.java:51)
at org.jboss.ejb.plugins.CallValidationInterceptor.invoke(CallValidationInterceptor.java:48)
at org.jboss.ejb.plugins.AbstractTxInterceptor.invokeNext(AbstractTxInterceptor.java:105)
at org.jboss.ejb.plugins.TxInterceptorCMT.runWithTransactions(TxInterceptorCMT.java:313)
at org.jboss.ejb.plugins.TxInterceptorCMT.invoke(TxInterceptorCMT.java:146)
at org.jboss.ejb.plugins.SecurityInterceptor.invoke(SecurityInterceptor.java:122)
at org.jboss.ejb.plugins.LogInterceptor.invoke(LogInterceptor.java:192)
at org.jboss.ejb.plugins.ProxyFactoryFinderInterceptor.invoke(ProxyFactoryFinderInterceptor.java:122)
at org.jboss.ejb.SessionContainer.internalInvoke(SessionContainer.java:624)
at org.jboss.ejb.Container.invoke(Container.java:870)
at org.jboss.ejb.plugins.local.BaseLocalProxyFactory.invoke(BaseLocalProxyFactory.java:413)
at org.jboss.ejb.plugins.local.StatelessSessionProxy.invoke(StatelessSessionProxy.java:82)
at $Proxy194.extendedService(Unknown Source)
at org.ejbca.ui.web.protocol.OCSPServlet.extendedService(OCSPServlet.java:106)
at org.ejbca.ui.web.protocol.OCSPServletBase.signOCSPResponse(OCSPServletBase.java:313)
at org.ejbca.ui.web.protocol.OCSPServletBase.service(OCSPServletBase.java:662)
at org.ejbca.ui.web.protocol.OCSPServletBase.doPost(OCSPServletBase.java:439)
at javax.servlet.http.HttpServlet.service(HttpServlet.java:717)
at javax.servlet.http.HttpServlet.service(HttpServlet.java:810)
at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:237)
at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:157)
at org.jboss.web.tomcat.filters.ReplyHeaderFilter.doFilter(ReplyHeaderFilter.java:75)
at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:186)
at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:157)
at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:214)
at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104)
at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520)
at org.apache.catalina.core.StandardContextValve.invokeInternal(StandardContextValve.java:198)
at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:152)
at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104)
at org.jboss.web.tomcat.security.CustomPrincipalValve.invoke(CustomPrincipalValve.java:66)
at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102)
at org.jboss.web.tomcat.security.SecurityAssociationValve.invoke(SecurityAssociationValve.java:150)
at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102)
at org.jboss.web.tomcat.security.JaccContextValve.invoke(JaccContextValve.java:54)
at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102)
at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520)
at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:137)
at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104)
at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:118)
at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102)
at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520)
at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:109)
at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104)
at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520)
at org.apache.catalina.core.ContainerBase.invoke(ContainerBase.java:929)
at org.apache.coyote.tomcat5.CoyoteAdapter.service(CoyoteAdapter.java:160)
at org.apache.coyote.http11.Http11Processor.process(Http11Processor.java:799)
at org.apache.coyote.http11.Http11Protocol$Http11ConnectionHandler.processConnection(Http11Protocol.java:705)
at org.apache.tomcat.util.net.TcpWorkerThread.runIt(PoolTcpEndpoint.java:577)
at org.apache.tomcat.util.threads.ThreadPool$ControlRunnable.run(ThreadPool.java:683)
at java.lang.Thread.run(Thread.java:595)
2014-09-02 19:09:22,041 ERROR [org.ejbca.ui.web.protocol.OCSPServletBase] Unable to handle OCSP request.
javax.ejb.EJBException: RuntimeException; CausedByException is:
unknown signing algorithm specified
at org.jboss.ejb.plugins.LogInterceptor.handleException(LogInterceptor.java:382)
at org.jboss.ejb.plugins.LogInterceptor.invoke(LogInterceptor.java:196)
at org.jboss.ejb.plugins.ProxyFactoryFinderInterceptor.invoke(ProxyFactoryFinderInterceptor.java:122)
at org.jboss.ejb.SessionContainer.internalInvoke(SessionContainer.java:624)
at org.jboss.ejb.Container.invoke(Container.java:870)
at org.jboss.ejb.plugins.local.BaseLocalProxyFactory.invoke(BaseLocalProxyFactory.java:413)
at org.jboss.ejb.plugins.local.StatelessSessionProxy.invoke(StatelessSessionProxy.java:82)
at $Proxy194.extendedService(Unknown Source)
at org.ejbca.ui.web.protocol.OCSPServlet.extendedService(OCSPServlet.java:106)
at org.ejbca.ui.web.protocol.OCSPServletBase.signOCSPResponse(OCSPServletBase.java:313)
at org.ejbca.ui.web.protocol.OCSPServletBase.service(OCSPServletBase.java:662)
at org.ejbca.ui.web.protocol.OCSPServletBase.doPost(OCSPServletBase.java:439)
at javax.servlet.http.HttpServlet.service(HttpServlet.java:717)
at javax.servlet.http.HttpServlet.service(HttpServlet.java:810)
at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:237)
at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:157)
at org.jboss.web.tomcat.filters.ReplyHeaderFilter.doFilter(ReplyHeaderFilter.java:75)
at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:186)
at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:157)
at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:214)
at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104)
at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520)
at org.apache.catalina.core.StandardContextValve.invokeInternal(StandardContextValve.java:198)
at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:152)
at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104)
at org.jboss.web.tomcat.security.CustomPrincipalValve.invoke(CustomPrincipalValve.java:66)
at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102)
at org.jboss.web.tomcat.security.SecurityAssociationValve.invoke(SecurityAssociationValve.java:150)
at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102)
at org.jboss.web.tomcat.security.JaccContextValve.invoke(JaccContextValve.java:54)
at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102)
at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520)
at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:137)
at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104)
at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:118)
at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:102)
at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520)
at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:109)
at org.apache.catalina.core.StandardValveContext.invokeNext(StandardValveContext.java:104)
at org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:520)
at org.apache.catalina.core.ContainerBase.invoke(ContainerBase.java:929)
at org.apache.coyote.tomcat5.CoyoteAdapter.service(CoyoteAdapter.java:160)
at org.apache.coyote.http11.Http11Processor.process(Http11Processor.java:799)
at org.apache.coyote.http11.Http11Protocol$Http11ConnectionHandler.processConnection(Http11Protocol.java:705)
at org.apache.tomcat.util.net.TcpWorkerThread.runIt(PoolTcpEndpoint.java:577)
at org.apache.tomcat.util.threads.ThreadPool$ControlRunnable.run(ThreadPool.java:683)
at java.lang.Thread.run(Thread.java:595)
Randy
------------------------------------------------------------------------------
Slashdot TV.
Video for Nerds. Stuff that matters.
http://tv.slashdot.org/
_______________________________________________
Ejbca-develop mailing list
Ejb...@li...
https://lists.sourceforge.net/lists/listinfo/ejbca-develop
|
|
From: Andreas S. <and...@ca...> - 2014-09-05 14:42:06
|
In a manual install (configure, make, make install) it ends up in /usr/local/lib On Ubuntu 64 and Debian it's located in /usr/lib/x86_64-linux-gnu On Ubuntu 32 and Debian it's in /usr/lib/i386-linux-gnu On Windows in ends up in c:\Windows\system32 On 09/05/2014 04:04 PM, Tomas Gustavsson wrote: > Very cool. Absolutely, what are the paths to the p11 library on different platforms? > > Cheers, > Tomas > > > On 5 september 2014 15:13:19 CEST, Andreas Schwier <and...@ca...> wrote: >> Hi Tomas, >> >> we've done some tests to integrate the SmartCard-HSM as crypto token >> via >> OpenSC [1]. >> >> Would it be possible to add OpenSC as one of the default PKCS#11 >> provider in EJBCA ? >> >> Kind regards, >> >> Andreas >> >> >> [1] >> http://www.smartcard-hsm.com/2014/09/05/Accessing_your_SmartCard-HSM_from_EJBCA.html >> >> >> -- >> >> --------- CardContact Software & System Consulting >> |.##> <##.| Andreas Schwier >> |# #| Schülerweg 38 >> |# #| 32429 Minden, Germany >> |'##> <##'| Phone +49 571 56149 >> --------- http://www.cardcontact.de >> http://www.tscons.de >> http://www.openscdp.org >> http://www.smartcard-hsm.com >> >> >> ------------------------------------------------------------------------------ >> Slashdot TV. >> Video for Nerds. Stuff that matters. >> http://tv.slashdot.org/ >> _______________________________________________ >> Ejbca-develop mailing list >> Ejb...@li... >> https://lists.sourceforge.net/lists/listinfo/ejbca-develop > -- --------- CardContact Software & System Consulting |.##> <##.| Andreas Schwier |# #| Schülerweg 38 |# #| 32429 Minden, Germany |'##> <##'| Phone +49 571 56149 --------- http://www.cardcontact.de http://www.tscons.de http://www.openscdp.org http://www.smartcard-hsm.com |
|
From: Tomas G. <to...@pr...> - 2014-09-05 14:04:58
|
Very cool. Absolutely, what are the paths to the p11 library on different platforms? Cheers, Tomas On 5 september 2014 15:13:19 CEST, Andreas Schwier <and...@ca...> wrote: >Hi Tomas, > >we've done some tests to integrate the SmartCard-HSM as crypto token >via >OpenSC [1]. > >Would it be possible to add OpenSC as one of the default PKCS#11 >provider in EJBCA ? > >Kind regards, > >Andreas > > >[1] >http://www.smartcard-hsm.com/2014/09/05/Accessing_your_SmartCard-HSM_from_EJBCA.html > > >-- > > --------- CardContact Software & System Consulting > |.##> <##.| Andreas Schwier > |# #| Schülerweg 38 > |# #| 32429 Minden, Germany > |'##> <##'| Phone +49 571 56149 > --------- http://www.cardcontact.de > http://www.tscons.de > http://www.openscdp.org > http://www.smartcard-hsm.com > > >------------------------------------------------------------------------------ >Slashdot TV. >Video for Nerds. Stuff that matters. >http://tv.slashdot.org/ >_______________________________________________ >Ejbca-develop mailing list >Ejb...@li... >https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Andreas S. <and...@ca...> - 2014-09-05 13:13:27
|
Hi Tomas, we've done some tests to integrate the SmartCard-HSM as crypto token via OpenSC [1]. Would it be possible to add OpenSC as one of the default PKCS#11 provider in EJBCA ? Kind regards, Andreas [1] http://www.smartcard-hsm.com/2014/09/05/Accessing_your_SmartCard-HSM_from_EJBCA.html -- --------- CardContact Software & System Consulting |.##> <##.| Andreas Schwier |# #| Schülerweg 38 |# #| 32429 Minden, Germany |'##> <##'| Phone +49 571 56149 --------- http://www.cardcontact.de http://www.tscons.de http://www.openscdp.org http://www.smartcard-hsm.com |
|
From: SIMI M. P. S. <si...@di...> - 2014-09-05 11:50:44
|
Michael P. Schieferer schrieb am 05.09.2014 13:34:
________________________________
Hi!
When I try to "ant deploy" the current EJBCA CE 6.2.0 the build fails with the following:
cesecore-common.jar:
[mkdir] Created dir: /home/pi/install/ejbca_ce_6_2_0/modules/cesecore-common/build/classes
[javac] Compiling 244 source files to /home/pi/install/ejbca_ce_6_2_0/modules/cesecore-common/build/classes
[javac] /home/pi/install/ejbca_ce_6_2_0/modules/cesecore-common/src/org/cesecore/certificates/ca/internal/CertificateValidity.java:207: error: incompatible types
[javac] final DERGeneralizedTime notBefore = pku.getNotBefore();
[javac] ^
[javac] required: DERGeneralizedTime
[javac] found: ASN1GeneralizedTime
[javac] /home/pi/install/ejbca_ce_6_2_0/modules/cesecore-common/src/org/cesecore/certificates/ca/internal/CertificateValidity.java:227: error: incompatible types
[javac] final DERGeneralizedTime notAfter = pku.getNotAfter();
[javac] ^
[javac] required: DERGeneralizedTime
[javac] found: ASN1GeneralizedTime
[javac] /home/pi/install/ejbca_ce_6_2_0/modules/cesecore-common/src/org/cesecore/certificates/certificate/certextensions/standard/SubjectKeyIdentifier.java:55: error: no suitable constructor found for SubjectKeyIdentifier(SubjectPublicKeyInfo)
[javac] return new org.bouncycastle.asn1.x509.SubjectKeyIdentifier(spki);
[javac] ^
[javac] constructor SubjectKeyIdentifier.SubjectKeyIdentifier(ASN1OctetString) is not applicable
[javac] (actual argument SubjectPublicKeyInfo cannot be converted to ASN1OctetString by method invocation conversion)
[javac] constructor SubjectKeyIdentifier.SubjectKeyIdentifier(byte[]) is not applicable
[javac] (actual argument SubjectPublicKeyInfo cannot be converted to byte[] by method invocation conversion)
[javac] /home/pi/install/ejbca_ce_6_2_0/modules/cesecore-common/src/org/cesecore/certificates/util/cert/CrlExtensions.java:110: error: incompatible types
[javac] final DEREnumerated reasonCodeExtension = DEREnumerated.getInstance(X509ExtensionUtil.fromExtensionValue(extensionValue));
[javac] ^
[javac] required: DEREnumerated
[javac] found: ASN1Enumerated
[javac] /home/pi/install/ejbca_ce_6_2_0/modules/cesecore-common/src/org/cesecore/util/CertTools.java:1663: error: no suitable constructor found for SubjectKeyIdentifier(SubjectPublicKeyInfo)
[javac] SubjectKeyIdentifier ski = new SubjectKeyIdentifier(spki);
[javac] ^
[javac] constructor SubjectKeyIdentifier.SubjectKeyIdentifier(ASN1OctetString) is not applicable
[javac] (actual argument SubjectPublicKeyInfo cannot be converted to ASN1OctetString by method invocation conversion)
[javac] constructor SubjectKeyIdentifier.SubjectKeyIdentifier(byte[]) is not applicable
[javac] (actual argument SubjectPublicKeyInfo cannot be converted to byte[] by method invocation conversion)
[javac] /home/pi/install/ejbca_ce_6_2_0/modules/cesecore-common/src/org/cesecore/certificates/util/cert/SubjectDirAttrExtension.java:96: error: incompatible types
[javac] DERGeneralizedTime time = DERGeneralizedTime.getInstance(set.getObjectAt(0));
[javac] ^
[javac] required: DERGeneralizedTime
[javac] found: ASN1GeneralizedTime
[javac] /home/pi/install/ejbca_ce_6_2_0/modules/cesecore-common/src/org/cesecore/keys/util/KeyTools.java:892: error: no suitable constructor found for SubjectKeyIdentifier(SubjectPublicKeyInfo)
[javac] return new SubjectKeyIdentifier(new SubjectPublicKeyInfo(keyASN1Sequence));
[javac] ^
[javac] constructor SubjectKeyIdentifier.SubjectKeyIdentifier(ASN1OctetString) is not applicable
[javac] (actual argument SubjectPublicKeyInfo cannot be converted to ASN1OctetString by method invocation conversion)
[javac] constructor SubjectKeyIdentifier.SubjectKeyIdentifier(byte[]) is not applicable
[javac] (actual argument SubjectPublicKeyInfo cannot be converted to byte[] by method invocation conversion)
[javac] Note: Some input files use or override a deprecated API.
[javac] Note: Recompile with -Xlint:deprecation for details.
[javac] Note: Some input files use unchecked or unsafe operations.
[javac] Note: Recompile with -Xlint:unchecked for details.
[javac] 7 errors
BUILD FAILED
/home/pi/install/ejbca_ce_6_2_0/build.xml:965: The following error occurred while executing this line:
/home/pi/install/ejbca_ce_6_2_0/modules/build.xml:148: The following error occurred while executing this line:
/home/pi/install/ejbca_ce_6_2_0/modules/cesecore-common/build.xml:33: Compile failed; see the compiler error output for details.
Mit freundlichen Gr??en | Best Regards
Michael P. Schieferer
Stv. IT-Leitung
IT
[LOGO] Digital Elektronik Ges.m.b.H | Berchtesgadner Str. 10 | 5083 St. Leonhard / Salzburg | ?sterreich
phone: +43 (6246) 8966 - 617 | mobile: +43 (664) 5464026 | Fax: +43 (6246) 8966 - 10
E-Mail: si...@di...<mailto:si...@di...> | Web: http://www.digital-elektronik.com<http://www.digital-elektronik.com/>
Gesch?ftsf?hrer: Richard Auer | UID ATU34880803 | FN 66287g | DVR 0686778 | Gerichtsstand Salzburg
--
The information contained in this email is confidential. It is intended solely for the addressee. Access to this email by anyone else is unauthorized. If you are not the intended recipient, any form of disclosure, reproduction, distribution or any action taken or refrained from in reliance on it, is prohibited and my be unlawful. Please notify the sender immediately. Any opinion containing is those of the author and respresents not necesariliy the opinion of Digital Elektronik Ges.m.b.H.
Neither Digital Elektronik Ges.m.b.H nor the sender (Michael P. Schieferer) take responsibility for any viruses, although we check our mails with up-to-date virus scanner. It is incumbent on your responsibility to check the mail and its attachments.
Attachement(s)
Sent: 05.09.2014 13:34 by Michael P. Schieferer
________________________________
|
|
From: eilaf s. <eil...@gm...> - 2014-09-05 07:51:12
|
Hi,
I want to issue super Adminstrator card for EJBCA, I use prime card i face
this problem:
05-Sep-2014 10:46:19
se.primeKey.cardPersonalization.administrator.basic.ExceptionWriter <init>
WARNING: A fault has occurred. Please notify the administrator. The fault
is: com.ibm.opencard.terminal.pcsc10.OCFPCSC1.reset()V
java.lang.UnsatisfiedLinkError:
com.ibm.opencard.terminal.pcsc10.OCFPCSC1.reset()V
at com.ibm.opencard.terminal.pcsc10.OCFPCSC1.reset(Native Method)
at
com.ibm.opencard.terminal.pcsc10.Pcsc10CardTerminalFactory.listReaders(Pcsc10CardTerminalFactory.java:134)
at
com.ibm.opencard.terminal.pcsc10.Pcsc10CardTerminalFactory.createCardTerminals(Pcsc10CardTerminalFactory.java:108)
at
opencard.core.service.SmartCard.handleTerminalFactoryEntries(SmartCard.java:432)
at
opencard.core.service.SmartCard.configureTerminalRegistry(SmartCard.java:261)
at opencard.core.service.SmartCard.start(SmartCard.java:534)
at se.primeKey.smartCard.ocf.CardImpl.startSC(CardImpl.java:44)
at se.primeKey.smartCard.ocf.CardImpl.<init>(CardImpl.java:129)
at se.primeKey.smartCard.ocf.CardImpl.<init>(CardImpl.java:123)
at se.primeKey.smartCard.CardFactory.create(CardFactory.java:36)
at
se.primeKey.cardPersonalization.card.pkcs15.BasicImpl.<init>(BasicImpl.java:53)
at
se.primeKey.cardPersonalization.card.pkcs15.BasicImpl.<init>(BasicImpl.java:97)
at
se.primeKey.cardPersonalization.card.pkcs15.UserCardImpl.<init>(UserCardImpl.java:105)
at se.primeKey.cardPersonalization.Factory.getUserCard(Factory.java:65)
at
se.primeKey.cardPersonalization.administrator.basic.EIDCardImpl.start(EIDCardImpl.java:515)
at
se.primeKey.cardPersonalization.administrator.basic.EIDCardImpl.run(EIDCardImpl.java:90)
at se.primeKey.cardPersonalization.Main$Basic.<init>(Main.java:73)
at se.primeKey.cardPersonalization.Main.<init>(Main.java:97)
at se.primeKey.cardPersonalization.Main.main(Main.java:112)
--
Eilaf Hamad Elnil Mugbil
University Of Khartoum
School Of Mathematical science
|
|
From: Тимур <tim...@gm...> - 2014-09-04 06:50:26
|
Hello, Tomas ! Does EJBCA 6.x.x require openjdk-1.7.0 with java-1.7.0-openjdk-devel package or only JRE is enough ? "...The java-1.7.0-openjdk package contains just the Java Runtime Environment. If you want to develop Java programs then install the java-1.7.0-openjdk-develpackage." thank you beforehand, Regards, Timur 2014-09-03 19:57 GMT+06:00 Tomas Gustavsson <to...@pr...>: > > I use Ubuntu personally, but RHEL also works fine. > > On 2014-09-03 15:55, Тимур wrote: > > Tomas, > > what operation system is used with openjdk-1.7 ? > > > > regards, Timur. > > > > > > > > 2014-09-03 19:05 GMT+06:00 Tomas Gustavsson <to...@pr... > > <mailto:to...@pr...>>: > > > > > > It works fine for me in OpenJDK 7. What does not work with Java 7 is > > JBoss 5. > > > > /Tomas > > On 2014-09-03 14:56, Тимур wrote: > > > Hello ! > > > > > > EJBCA 6.1.1 works with openjdk-1.6; > > > but EJBCA 6.1.1 works neither openjdk-1.7 nor Oracle Java 7. > > > People say about EJBCA : > > > >>>Java: DO NOT waste time trying to get java 1.7 to work with > > this app > > > at present. > > > >>>If you install java 1.7, then the "java" command will invoke > > 1.7 by > > > virtue of alternatives. Theoretically, alternatives > > > >>>should take care of redirecting all java-related executable > > paths to > > > the correct executables. However, what I found is > > > >>>that the 1.7 implementation from openjdk is incomplete, and > ejbca > > > will end up needing to use portions of version > > > >>>1.6. This inevitably ends up with a non-working ejbca install. > > > > > > Can you please to explain steps for providing openjdk-1.7 (or > Oracle > > > Java 7) support in EJBCA 6.1.1 ? > > > > > > Regards, Timur. > > > > > > > > > > > > > > > > > > > > > ------------------------------------------------------------------------------ > > > Slashdot TV. > > > Video for Nerds. Stuff that matters. > > > http://tv.slashdot.org/ > > > > > > > > > > > > _______________________________________________ > > > Ejbca-develop mailing list > > > Ejb...@li... > > <mailto:Ejb...@li...> > > > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > > > > > ------------------------------------------------------------------------------ > > Slashdot TV. > > Video for Nerds. Stuff that matters. > > http://tv.slashdot.org/ > > _______________________________________________ > > Ejbca-develop mailing list > > Ejb...@li... > > <mailto:Ejb...@li...> > > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > > > > > > > > ------------------------------------------------------------------------------ > > Slashdot TV. > > Video for Nerds. Stuff that matters. > > http://tv.slashdot.org/ > > > > > > > > _______________________________________________ > > Ejbca-develop mailing list > > Ejb...@li... > > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > > ------------------------------------------------------------------------------ > Slashdot TV. > Video for Nerds. Stuff that matters. > http://tv.slashdot.org/ > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Bruno B. <as...@as...> - 2014-09-03 17:10:18
|
On Wed 03 September, Christian Felsing wrote: > Hello, > > I have a problem with EJBCA 4.0.14 on cli: > > $ cd ~ejbca/ejbca > $ bin/ejbca.sh ca listcas > > [..] > EJBCA 4.0.14 is running on JBoss 5.1.0GA as user ejbca and MySQL. Platform is RedHat ES 6.5 > > EJBCA installation on web works, it creates CRLs and allows signing certificates, so I consider that problem is local to CLI only. > > Is there a way to fix that? can you ping the server with it's own name? like # ping $(hostname) and it can be a firewall issue iirc Regards -- http://asyd.net/home/ - Home Page http://netvibes.com/asyd - Portal |
|
From: Tomas G. <to...@pr...> - 2014-09-03 17:06:34
|
Something blocking remote ejb? Cheers, Tomas On 2014-09-03 15:47, Christian Felsing wrote: > Hello, > > I have a problem with EJBCA 4.0.14 on cli: > > $ cd ~ejbca/ejbca > $ bin/ejbca.sh ca listcas > > javax.naming.NamingException: Could not dereference object [Root exception is java.lang.RuntimeException: Exception while trying to > locate proxy factory in JNDI, at key ProxyFactory/ejbca/CaSessionBean/ejbca/CaSessionRemote] > at org.jnp.interfaces.NamingContext.getObjectInstanceWrapFailure(NamingContext.java:1508) > at org.jnp.interfaces.NamingContext.lookup(NamingContext.java:824) > at org.jnp.interfaces.NamingContext.lookup(NamingContext.java:688) > at javax.naming.InitialContext.lookup(InitialContext.java:409) > at org.ejbca.core.ejb.JndiHelper.getRemoteSession(JndiHelper.java:57) > at org.ejbca.core.model.util.EjbRemoteHelper.getCaSession(EjbRemoteHelper.java:101) > at org.ejbca.ui.cli.ca.CaListCAsCommand.execute(CaListCAsCommand.java:39) > at org.ejbca.ui.cli.EjbcaEjbCli.executeCommand(EjbcaEjbCli.java:118) > at org.ejbca.ui.cli.EjbcaEjbCli.main(EjbcaEjbCli.java:80) > Caused by: java.lang.RuntimeException: Exception while trying to locate proxy factory in JNDI, at key > ProxyFactory/ejbca/CaSessionBean/ejbca/CaSessionRemote > at org.jboss.ejb3.proxy.impl.objectfactory.ProxyObjectFactory.getProxyFactoryFromJNDI(ProxyObjectFactory.java:249) > at org.jboss.ejb3.proxy.impl.objectfactory.ProxyObjectFactory.getObjectInstance(ProxyObjectFactory.java:157) > at javax.naming.spi.NamingManager.getObjectInstance(NamingManager.java:321) > at org.jnp.interfaces.NamingContext.getObjectInstance(NamingContext.java:1483) > at org.jnp.interfaces.NamingContext.getObjectInstanceWrapFailure(NamingContext.java:1500) > ... 8 more > Caused by: javax.naming.NameNotFoundException: ProxyFactory not bound > at org.jnp.server.NamingServer.getBinding(NamingServer.java:771) > at org.jnp.server.NamingServer.getBinding(NamingServer.java:779) > at org.jnp.server.NamingServer.getObject(NamingServer.java:785) > at org.jnp.server.NamingServer.lookup(NamingServer.java:396) > at sun.reflect.GeneratedMethodAccessor523.invoke(Unknown Source) > at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43) > at java.lang.reflect.Method.invoke(Method.java:622) > at sun.rmi.server.UnicastServerRef.dispatch(UnicastServerRef.java:322) > at sun.rmi.transport.Transport$1.run(Transport.java:177) > at java.security.AccessController.doPrivileged(Native Method) > at sun.rmi.transport.Transport.serviceCall(Transport.java:173) > at sun.rmi.transport.tcp.TCPTransport.handleMessages(TCPTransport.java:553) > at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.run0(TCPTransport.java:808) > at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.run(TCPTransport.java:667) > at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1146) > at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:615) > at java.lang.Thread.run(Thread.java:701) > at sun.rmi.transport.StreamRemoteCall.exceptionReceivedFromServer(StreamRemoteCall.java:273) > at sun.rmi.transport.StreamRemoteCall.executeCall(StreamRemoteCall.java:251) > at sun.rmi.server.UnicastRef.invoke(UnicastRef.java:160) > at org.jnp.server.NamingServer_Stub.lookup(Unknown Source) > at org.jnp.interfaces.NamingContext.lookup(NamingContext.java:728) > at org.jnp.interfaces.NamingContext.lookup(NamingContext.java:688) > at org.jboss.ejb3.proxy.impl.objectfactory.ProxyObjectFactory.getProxyFactoryFromJNDI(ProxyObjectFactory.java:240) > ... 12 more > Could not run execute method for class class org.ejbca.ui.cli.ca.CaListCAsCommand > org.ejbca.ui.cli.ErrorAdminCommandException: java.lang.NullPointerException > at org.ejbca.ui.cli.ca.CaListCAsCommand.execute(CaListCAsCommand.java:61) > at org.ejbca.ui.cli.EjbcaEjbCli.executeCommand(EjbcaEjbCli.java:118) > at org.ejbca.ui.cli.EjbcaEjbCli.main(EjbcaEjbCli.java:80) > Caused by: java.lang.NullPointerException > at org.ejbca.ui.cli.ca.CaListCAsCommand.execute(CaListCAsCommand.java:39) > ... 2 more > $ > > EJBCA 4.0.14 is running on JBoss 5.1.0GA as user ejbca and MySQL. Platform is RedHat ES 6.5 > > EJBCA installation on web works, it creates CRLs and allows signing certificates, so I consider that problem is local to CLI only. > > Is there a way to fix that? > > best Regards > Christian > > ------------------------------------------------------------------------------ > Slashdot TV. > Video for Nerds. Stuff that matters. > http://tv.slashdot.org/ > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Christian F. <pu...@fe...> - 2014-09-03 14:03:34
|
Hello, I have a problem with EJBCA 4.0.14 on cli: $ cd ~ejbca/ejbca $ bin/ejbca.sh ca listcas javax.naming.NamingException: Could not dereference object [Root exception is java.lang.RuntimeException: Exception while trying to locate proxy factory in JNDI, at key ProxyFactory/ejbca/CaSessionBean/ejbca/CaSessionRemote] at org.jnp.interfaces.NamingContext.getObjectInstanceWrapFailure(NamingContext.java:1508) at org.jnp.interfaces.NamingContext.lookup(NamingContext.java:824) at org.jnp.interfaces.NamingContext.lookup(NamingContext.java:688) at javax.naming.InitialContext.lookup(InitialContext.java:409) at org.ejbca.core.ejb.JndiHelper.getRemoteSession(JndiHelper.java:57) at org.ejbca.core.model.util.EjbRemoteHelper.getCaSession(EjbRemoteHelper.java:101) at org.ejbca.ui.cli.ca.CaListCAsCommand.execute(CaListCAsCommand.java:39) at org.ejbca.ui.cli.EjbcaEjbCli.executeCommand(EjbcaEjbCli.java:118) at org.ejbca.ui.cli.EjbcaEjbCli.main(EjbcaEjbCli.java:80) Caused by: java.lang.RuntimeException: Exception while trying to locate proxy factory in JNDI, at key ProxyFactory/ejbca/CaSessionBean/ejbca/CaSessionRemote at org.jboss.ejb3.proxy.impl.objectfactory.ProxyObjectFactory.getProxyFactoryFromJNDI(ProxyObjectFactory.java:249) at org.jboss.ejb3.proxy.impl.objectfactory.ProxyObjectFactory.getObjectInstance(ProxyObjectFactory.java:157) at javax.naming.spi.NamingManager.getObjectInstance(NamingManager.java:321) at org.jnp.interfaces.NamingContext.getObjectInstance(NamingContext.java:1483) at org.jnp.interfaces.NamingContext.getObjectInstanceWrapFailure(NamingContext.java:1500) ... 8 more Caused by: javax.naming.NameNotFoundException: ProxyFactory not bound at org.jnp.server.NamingServer.getBinding(NamingServer.java:771) at org.jnp.server.NamingServer.getBinding(NamingServer.java:779) at org.jnp.server.NamingServer.getObject(NamingServer.java:785) at org.jnp.server.NamingServer.lookup(NamingServer.java:396) at sun.reflect.GeneratedMethodAccessor523.invoke(Unknown Source) at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43) at java.lang.reflect.Method.invoke(Method.java:622) at sun.rmi.server.UnicastServerRef.dispatch(UnicastServerRef.java:322) at sun.rmi.transport.Transport$1.run(Transport.java:177) at java.security.AccessController.doPrivileged(Native Method) at sun.rmi.transport.Transport.serviceCall(Transport.java:173) at sun.rmi.transport.tcp.TCPTransport.handleMessages(TCPTransport.java:553) at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.run0(TCPTransport.java:808) at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.run(TCPTransport.java:667) at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1146) at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:615) at java.lang.Thread.run(Thread.java:701) at sun.rmi.transport.StreamRemoteCall.exceptionReceivedFromServer(StreamRemoteCall.java:273) at sun.rmi.transport.StreamRemoteCall.executeCall(StreamRemoteCall.java:251) at sun.rmi.server.UnicastRef.invoke(UnicastRef.java:160) at org.jnp.server.NamingServer_Stub.lookup(Unknown Source) at org.jnp.interfaces.NamingContext.lookup(NamingContext.java:728) at org.jnp.interfaces.NamingContext.lookup(NamingContext.java:688) at org.jboss.ejb3.proxy.impl.objectfactory.ProxyObjectFactory.getProxyFactoryFromJNDI(ProxyObjectFactory.java:240) ... 12 more Could not run execute method for class class org.ejbca.ui.cli.ca.CaListCAsCommand org.ejbca.ui.cli.ErrorAdminCommandException: java.lang.NullPointerException at org.ejbca.ui.cli.ca.CaListCAsCommand.execute(CaListCAsCommand.java:61) at org.ejbca.ui.cli.EjbcaEjbCli.executeCommand(EjbcaEjbCli.java:118) at org.ejbca.ui.cli.EjbcaEjbCli.main(EjbcaEjbCli.java:80) Caused by: java.lang.NullPointerException at org.ejbca.ui.cli.ca.CaListCAsCommand.execute(CaListCAsCommand.java:39) ... 2 more $ EJBCA 4.0.14 is running on JBoss 5.1.0GA as user ejbca and MySQL. Platform is RedHat ES 6.5 EJBCA installation on web works, it creates CRLs and allows signing certificates, so I consider that problem is local to CLI only. Is there a way to fix that? best Regards Christian |
|
From: Tomas G. <to...@pr...> - 2014-09-03 13:57:51
|
I use Ubuntu personally, but RHEL also works fine. On 2014-09-03 15:55, Тимур wrote: > Tomas, > what operation system is used with openjdk-1.7 ? > > regards, Timur. > > > > 2014-09-03 19:05 GMT+06:00 Tomas Gustavsson <to...@pr... > <mailto:to...@pr...>>: > > > It works fine for me in OpenJDK 7. What does not work with Java 7 is > JBoss 5. > > /Tomas > On 2014-09-03 14:56, Тимур wrote: > > Hello ! > > > > EJBCA 6.1.1 works with openjdk-1.6; > > but EJBCA 6.1.1 works neither openjdk-1.7 nor Oracle Java 7. > > People say about EJBCA : > > >>>Java: DO NOT waste time trying to get java 1.7 to work with > this app > > at present. > > >>>If you install java 1.7, then the "java" command will invoke > 1.7 by > > virtue of alternatives. Theoretically, alternatives > > >>>should take care of redirecting all java-related executable > paths to > > the correct executables. However, what I found is > > >>>that the 1.7 implementation from openjdk is incomplete, and ejbca > > will end up needing to use portions of version > > >>>1.6. This inevitably ends up with a non-working ejbca install. > > > > Can you please to explain steps for providing openjdk-1.7 (or Oracle > > Java 7) support in EJBCA 6.1.1 ? > > > > Regards, Timur. > > > > > > > > > > > > > ------------------------------------------------------------------------------ > > Slashdot TV. > > Video for Nerds. Stuff that matters. > > http://tv.slashdot.org/ > > > > > > > > _______________________________________________ > > Ejbca-develop mailing list > > Ejb...@li... > <mailto:Ejb...@li...> > > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > ------------------------------------------------------------------------------ > Slashdot TV. > Video for Nerds. Stuff that matters. > http://tv.slashdot.org/ > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > <mailto:Ejb...@li...> > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > > ------------------------------------------------------------------------------ > Slashdot TV. > Video for Nerds. Stuff that matters. > http://tv.slashdot.org/ > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Тимур <tim...@gm...> - 2014-09-03 13:55:09
|
Tomas, what operation system is used with openjdk-1.7 ? regards, Timur. 2014-09-03 19:05 GMT+06:00 Tomas Gustavsson <to...@pr...>: > > It works fine for me in OpenJDK 7. What does not work with Java 7 is > JBoss 5. > > /Tomas > On 2014-09-03 14:56, Тимур wrote: > > Hello ! > > > > EJBCA 6.1.1 works with openjdk-1.6; > > but EJBCA 6.1.1 works neither openjdk-1.7 nor Oracle Java 7. > > People say about EJBCA : > > >>>Java: DO NOT waste time trying to get java 1.7 to work with this app > > at present. > > >>>If you install java 1.7, then the "java" command will invoke 1.7 by > > virtue of alternatives. Theoretically, alternatives > > >>>should take care of redirecting all java-related executable paths to > > the correct executables. However, what I found is > > >>>that the 1.7 implementation from openjdk is incomplete, and ejbca > > will end up needing to use portions of version > > >>>1.6. This inevitably ends up with a non-working ejbca install. > > > > Can you please to explain steps for providing openjdk-1.7 (or Oracle > > Java 7) support in EJBCA 6.1.1 ? > > > > Regards, Timur. > > > > > > > > > > > > > ------------------------------------------------------------------------------ > > Slashdot TV. > > Video for Nerds. Stuff that matters. > > http://tv.slashdot.org/ > > > > > > > > _______________________________________________ > > Ejbca-develop mailing list > > Ejb...@li... > > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > > ------------------------------------------------------------------------------ > Slashdot TV. > Video for Nerds. Stuff that matters. > http://tv.slashdot.org/ > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |