You can subscribe to this list here.
| 2001 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
(1) |
Dec
(3) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2002 |
Jan
(3) |
Feb
(2) |
Mar
(8) |
Apr
(3) |
May
(6) |
Jun
(1) |
Jul
(15) |
Aug
(6) |
Sep
|
Oct
(10) |
Nov
(2) |
Dec
(4) |
| 2003 |
Jan
(1) |
Feb
(7) |
Mar
(3) |
Apr
(6) |
May
(7) |
Jun
(5) |
Jul
(5) |
Aug
(25) |
Sep
(14) |
Oct
(2) |
Nov
|
Dec
(2) |
| 2004 |
Jan
(7) |
Feb
(4) |
Mar
(12) |
Apr
(16) |
May
(43) |
Jun
(56) |
Jul
(43) |
Aug
(40) |
Sep
(66) |
Oct
(12) |
Nov
(26) |
Dec
(10) |
| 2005 |
Jan
(13) |
Feb
(33) |
Mar
(16) |
Apr
(7) |
May
(10) |
Jun
(34) |
Jul
(41) |
Aug
(8) |
Sep
(4) |
Oct
(32) |
Nov
(20) |
Dec
(25) |
| 2006 |
Jan
(30) |
Feb
(101) |
Mar
(5) |
Apr
(75) |
May
(74) |
Jun
(22) |
Jul
(6) |
Aug
(70) |
Sep
(19) |
Oct
(21) |
Nov
(31) |
Dec
(50) |
| 2007 |
Jan
(15) |
Feb
(20) |
Mar
(24) |
Apr
(33) |
May
(13) |
Jun
(18) |
Jul
(13) |
Aug
(7) |
Sep
(63) |
Oct
(68) |
Nov
(29) |
Dec
(68) |
| 2008 |
Jan
(30) |
Feb
(33) |
Mar
(30) |
Apr
(103) |
May
(78) |
Jun
(48) |
Jul
(72) |
Aug
(24) |
Sep
(62) |
Oct
(63) |
Nov
(70) |
Dec
(37) |
| 2009 |
Jan
(34) |
Feb
(35) |
Mar
(64) |
Apr
(34) |
May
(34) |
Jun
(58) |
Jul
(30) |
Aug
(30) |
Sep
(46) |
Oct
(52) |
Nov
(12) |
Dec
(23) |
| 2010 |
Jan
(121) |
Feb
(18) |
Mar
(53) |
Apr
(62) |
May
(62) |
Jun
(20) |
Jul
(33) |
Aug
(20) |
Sep
(36) |
Oct
(35) |
Nov
(44) |
Dec
(63) |
| 2011 |
Jan
(19) |
Feb
(32) |
Mar
(94) |
Apr
(41) |
May
(47) |
Jun
(25) |
Jul
(34) |
Aug
(20) |
Sep
(9) |
Oct
(41) |
Nov
(33) |
Dec
(24) |
| 2012 |
Jan
(12) |
Feb
(36) |
Mar
(48) |
Apr
(32) |
May
(20) |
Jun
(15) |
Jul
(32) |
Aug
(13) |
Sep
(33) |
Oct
(54) |
Nov
(25) |
Dec
(16) |
| 2013 |
Jan
(45) |
Feb
(39) |
Mar
(38) |
Apr
(50) |
May
(29) |
Jun
(30) |
Jul
(33) |
Aug
(12) |
Sep
(9) |
Oct
(25) |
Nov
(29) |
Dec
(20) |
| 2014 |
Jan
(25) |
Feb
(19) |
Mar
(16) |
Apr
(33) |
May
(27) |
Jun
(37) |
Jul
(29) |
Aug
(27) |
Sep
(37) |
Oct
(58) |
Nov
(109) |
Dec
(26) |
| 2015 |
Jan
(4) |
Feb
(35) |
Mar
(22) |
Apr
(35) |
May
(28) |
Jun
(20) |
Jul
(4) |
Aug
(16) |
Sep
(37) |
Oct
(13) |
Nov
(13) |
Dec
(14) |
| 2016 |
Jan
(22) |
Feb
(7) |
Mar
(23) |
Apr
(30) |
May
(10) |
Jun
(10) |
Jul
(15) |
Aug
(12) |
Sep
(22) |
Oct
(31) |
Nov
(5) |
Dec
(5) |
| 2017 |
Jan
(30) |
Feb
(25) |
Mar
(28) |
Apr
(4) |
May
(19) |
Jun
(13) |
Jul
(7) |
Aug
(1) |
Sep
(2) |
Oct
(5) |
Nov
(12) |
Dec
(2) |
| 2018 |
Jan
(7) |
Feb
|
Mar
(7) |
Apr
(2) |
May
(8) |
Jun
(18) |
Jul
(6) |
Aug
(3) |
Sep
(15) |
Oct
(33) |
Nov
(13) |
Dec
(7) |
| 2019 |
Jan
(5) |
Feb
(7) |
Mar
(30) |
Apr
(5) |
May
(4) |
Jun
(69) |
Jul
(86) |
Aug
(22) |
Sep
(6) |
Oct
(7) |
Nov
(5) |
Dec
(3) |
| 2020 |
Jan
(10) |
Feb
(12) |
Mar
(22) |
Apr
(5) |
May
(1) |
Jun
(4) |
Jul
(6) |
Aug
|
Sep
(9) |
Oct
|
Nov
|
Dec
(1) |
| 2021 |
Jan
(4) |
Feb
(11) |
Mar
(7) |
Apr
(7) |
May
|
Jun
(3) |
Jul
(10) |
Aug
(6) |
Sep
|
Oct
|
Nov
(18) |
Dec
(2) |
| 2022 |
Jan
(1) |
Feb
(1) |
Mar
|
Apr
|
May
|
Jun
(2) |
Jul
|
Aug
(4) |
Sep
|
Oct
|
Nov
|
Dec
|
| 2023 |
Jan
|
Feb
|
Mar
|
Apr
(1) |
May
(1) |
Jun
|
Jul
|
Aug
(5) |
Sep
|
Oct
|
Nov
|
Dec
|
|
From: Tomas G. <to...@pr...> - 2014-04-28 06:38:36
|
Check the documentation for approvals at http://ejbca.org/docs/adminguide.html#Approving%20Actions Cheers, Tomas --- Save time and money with an Enterprise support subscription. Please see www.primekey.se for more information. http://www.primekey.se/Products/EJBCA+PKI/ http://www.primekey.se/Services/Support/ On 2014-04-26 10:07, sara ibrahim wrote: > Hi, > > I set my CA to connect with utimaco HSM and the installation went > straight forward, but when i opened the admnweb my CA is not able to do > anything , can not add end entity or perform any other task, it gives > the message "the request has been sent for approval" and the approval > never happens ! > can you help me please ? > > regards, > > Sara > > > ------------------------------------------------------------------------------ > Start Your Social Network Today - Download eXo Platform > Build your Enterprise Intranet with eXo Platform Software > Java Based Open Source Intranet - Social, Extensible, Cloud Ready > Get Started Now And Turn Your Intranet Into A Collaboration Platform > http://p.sf.net/sfu/ExoPlatform > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: sara i. <sar...@gm...> - 2014-04-27 09:31:21
|
yes i mean V2 , but in ejbca documentation all the instructions use PKCS11 (which is version 1) to configure HSM On Sat, Apr 26, 2014 at 8:09 PM, ejbca-support <ejb...@pr...>wrote: > On 2014-04-26 17:44, sara ibrahim wrote: > > Hi > > > > can i use the security module PKCS11_R2 instead of PKCS11 to configure > my CA with HSM? does primkey support PKCS11_R2 ? > > I don't know exactly what PKCS11_R2 is unless it refers to V2 of PKCS11 > which is > the current standard which EJBCA supports. > > Cheers, > Anders > > > > > Regards, > > > > Sara > > > > > > > ------------------------------------------------------------------------------ > > Start Your Social Network Today - Download eXo Platform > > Build your Enterprise Intranet with eXo Platform Software > > Java Based Open Source Intranet - Social, Extensible, Cloud Ready > > Get Started Now And Turn Your Intranet Into A Collaboration Platform > > http://p.sf.net/sfu/ExoPlatform > > > > > > > > _______________________________________________ > > Ejbca-develop mailing list > > Ejb...@li... > > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > > > ------------------------------------------------------------------------------ > Start Your Social Network Today - Download eXo Platform > Build your Enterprise Intranet with eXo Platform Software > Java Based Open Source Intranet - Social, Extensible, Cloud Ready > Get Started Now And Turn Your Intranet Into A Collaboration Platform > http://p.sf.net/sfu/ExoPlatform > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Manuel D. <ma...@de...> - 2014-04-27 00:42:15
|
On Sat, Apr 26, 2014 at 7:09 PM, ejbca-support <ejb...@pr...> wrote: >> can i use the security module PKCS11_R2 instead of PKCS11 to configure my CA with HSM? does primkey support PKCS11_R2 ? > > I don't know exactly what PKCS11_R2 is unless it refers to V2 of PKCS11 which is > the current standard which EJBCA supports. Are you referring to a utimaco HSM ? That is their nomenclature for a reimplementation of the running PKCS#11 standard. AFAIK, it should be 100% compatible on the basics of PKCS#11, might differ on the vendor/manufacturer-specific details like authentication. ~manuel |
|
From: ejbca-support <ejb...@pr...> - 2014-04-26 17:09:34
|
On 2014-04-26 17:44, sara ibrahim wrote: > Hi > > can i use the security module PKCS11_R2 instead of PKCS11 to configure my CA with HSM? does primkey support PKCS11_R2 ? I don't know exactly what PKCS11_R2 is unless it refers to V2 of PKCS11 which is the current standard which EJBCA supports. Cheers, Anders > > Regards, > > Sara > > > ------------------------------------------------------------------------------ > Start Your Social Network Today - Download eXo Platform > Build your Enterprise Intranet with eXo Platform Software > Java Based Open Source Intranet - Social, Extensible, Cloud Ready > Get Started Now And Turn Your Intranet Into A Collaboration Platform > http://p.sf.net/sfu/ExoPlatform > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: sara i. <sar...@gm...> - 2014-04-26 15:44:39
|
Hi can i use the security module PKCS11_R2 instead of PKCS11 to configure my CA with HSM? does primkey support PKCS11_R2 ? Regards, Sara |
|
From: ejbca-support <ejb...@pr...> - 2014-04-26 15:18:33
|
On 2014-04-26 12:19, Andreas Kuehne wrote: > Am 25.04.2014 18:44, schrieb ejbca-support: >>> As far as I understood the command line tool is just a wrapper around >>> the well known remote interfaces. Is there a simple user/status method >>> in the web services interface? >> This would be the closest: >> http://ejbca.org/docs/ws/org/ejbca/core/protocol/ws/client/gen/EjbcaWS.html#editUser(org.ejbca.core.protocol.ws.client.gen.UserDataVOWS) > Yes, found it, tried it. But if I get right it requires aspects of the > user to re-transmitted correctly. The command line functionality is much > more what I would expect ... >> >>> Or is there another (private) gate into the heart of the EJBCA? >> Yes, all EJBCA functionality is exposed through Java Beans. >> The CLI are using these. >> >> However, they are indeed considered as private but naturally you are free >> to use them anyway but at your own risk since we reserve the right to >> change them whenever it is needed. > Oh, yes, I see ... in our ejb applcation we consider exposing internals > Java-Bean-wise more as a security risk rather than a handy interface. > Moreover, as you mentioned, the 'internal use only' nature makes it > difficult to depend on it. Regarding the closely coupled command line > tools this is not a severe restriction ... > But what about the security impacts? I'm sure you discussed this ... > could you share your thoughts? We came to the conclusion to allow bean > access process-internal only ... Of course the less you expose the more secure. Anyway, for you particular use-case the CLI or the remote EJB it calls should be perfect since it also supports client authentication. Cheers Anders > > Greetings, > > Andreas > > > ------------------------------------------------------------------------------ > Start Your Social Network Today - Download eXo Platform > Build your Enterprise Intranet with eXo Platform Software > Java Based Open Source Intranet - Social, Extensible, Cloud Ready > Get Started Now And Turn Your Intranet Into A Collaboration Platform > http://p.sf.net/sfu/ExoPlatform > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Andreas K. <ku...@tr...> - 2014-04-26 10:20:29
|
Am 25.04.2014 18:44, schrieb ejbca-support: >> As far as I understood the command line tool is just a wrapper around >> the well known remote interfaces. Is there a simple user/status method >> in the web services interface? > This would be the closest: > http://ejbca.org/docs/ws/org/ejbca/core/protocol/ws/client/gen/EjbcaWS.html#editUser(org.ejbca.core.protocol.ws.client.gen.UserDataVOWS) Yes, found it, tried it. But if I get right it requires aspects of the user to re-transmitted correctly. The command line functionality is much more what I would expect ... > >> Or is there another (private) gate into the heart of the EJBCA? > Yes, all EJBCA functionality is exposed through Java Beans. > The CLI are using these. > > However, they are indeed considered as private but naturally you are free > to use them anyway but at your own risk since we reserve the right to > change them whenever it is needed. Oh, yes, I see ... in our ejb applcation we consider exposing internals Java-Bean-wise more as a security risk rather than a handy interface. Moreover, as you mentioned, the 'internal use only' nature makes it difficult to depend on it. Regarding the closely coupled command line tools this is not a severe restriction ... But what about the security impacts? I'm sure you discussed this ... could you share your thoughts? We came to the conclusion to allow bean access process-internal only ... Greetings, Andreas |
|
From: sara i. <sar...@gm...> - 2014-04-26 08:07:57
|
Hi, I set my CA to connect with utimaco HSM and the installation went straight forward, but when i opened the admnweb my CA is not able to do anything , can not add end entity or perform any other task, it gives the message "the request has been sent for approval" and the approval never happens ! can you help me please ? regards, Sara |
|
From: ejbca-support <ejb...@pr...> - 2014-04-25 16:44:30
|
On 2014-04-25 18:29, Andreas Kuehne wrote: > Hi Tomas, just for curiosity and to nag you again: >> bin/ejbca.sh ra setuserstatus <username> NEW > As far as I understood the command line tool is just a wrapper around > the well known remote interfaces. Is there a simple user/status method > in the web services interface? This would be the closest: http://ejbca.org/docs/ws/org/ejbca/core/protocol/ws/client/gen/EjbcaWS.html#editUser(org.ejbca.core.protocol.ws.client.gen.UserDataVOWS) > Or is there another (private) gate into the heart of the EJBCA? Yes, all EJBCA functionality is exposed through Java Beans. The CLI are using these. However, they are indeed considered as private but naturally you are free to use them anyway but at your own risk since we reserve the right to change them whenever it is needed. Cheers Anders > > Have a nice weekend, > > Andreas > |
|
From: Andreas K. <ku...@tr...> - 2014-04-25 16:29:52
|
Hi Tomas, just for curiosity and to nag you again: > bin/ejbca.sh ra setuserstatus <username> NEW As far as I understood the command line tool is just a wrapper around the well known remote interfaces. Is there a simple user/status method in the web services interface? Or is there another (private) gate into the heart of the EJBCA? Have a nice weekend, Andreas -- Andreas Kühne phone: +49 177 293 24 97 mailto: ku...@tr... Trustable Ltd. Niederlassung Deutschland Ströverstr. 18 - 59427 Unna Amtsgericht Hamm HRB 5868 Directors Andreas Kühne, Heiko Veit Company UK Company No: 5218868 Registered in England and Wales |
|
From: ejbca-support <ejb...@pr...> - 2014-04-25 11:02:55
|
On 2014-04-25 12:29, sara ibrahim wrote: > Hi, > > can i configure two HSMs with my CA as master and slave HSM? and how could it be done ? You mean the slave would work as a backup? As far as I know, if this is possible the solution is HSM-specific. Consult your HSM-vendor for details. Cheers Anders > > regards, > > Sara > > > ------------------------------------------------------------------------------ > Start Your Social Network Today - Download eXo Platform > Build your Enterprise Intranet with eXo Platform Software > Java Based Open Source Intranet - Social, Extensible, Cloud Ready > Get Started Now And Turn Your Intranet Into A Collaboration Platform > http://p.sf.net/sfu/ExoPlatform > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: sara i. <sar...@gm...> - 2014-04-25 10:30:02
|
Hi, can i configure two HSMs with my CA as master and slave HSM? and how could it be done ? regards, Sara |
|
From: Andreas K. <ku...@tr...> - 2014-04-25 10:22:53
|
Thanks Tomas, I missed the obvious! Thanks, Andreas > Using command line command is very easy. > > bin/ejbca.sh ra setuserstatus <username> NEW > > Cheers, > Tomas > > On 2014-04-25 11:21, Andreas Kuehne wrote: >> Hi Folks, >> >> I'm looking for an easy way to reset the End Entity status to 'New' ... >> preferably without too much knowledge about the End Entity settings ... >> >> Background: We set up and tear down several VMs. Each VM gets its SSL >> certificate from the CA. Fine. >> But especially in the development stage VMs get discarded and restarted >> frequently. So the VMs loose their certificate and keys but the CA >> remembers the End Entity state! >> >> Is there an easy way to reset an End Entity to 'New' without providing >> all the required attributes in the 'Edit End Entity' form? >> >> Greetings, >> >> Andreas >> > ------------------------------------------------------------------------------ > Start Your Social Network Today - Download eXo Platform > Build your Enterprise Intranet with eXo Platform Software > Java Based Open Source Intranet - Social, Extensible, Cloud Ready > Get Started Now And Turn Your Intranet Into A Collaboration Platform > http://p.sf.net/sfu/ExoPlatform > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > -- Andreas Kühne phone: +49 177 293 24 97 mailto: ku...@tr... Trustable Ltd. Niederlassung Deutschland Ströverstr. 18 - 59427 Unna Amtsgericht Hamm HRB 5868 Directors Andreas Kühne, Heiko Veit Company UK Company No: 5218868 Registered in England and Wales |
|
From: Tomas G. <to...@pr...> - 2014-04-25 10:04:42
|
Using command line command is very easy. bin/ejbca.sh ra setuserstatus <username> NEW Cheers, Tomas On 2014-04-25 11:21, Andreas Kuehne wrote: > Hi Folks, > > I'm looking for an easy way to reset the End Entity status to 'New' ... > preferably without too much knowledge about the End Entity settings ... > > Background: We set up and tear down several VMs. Each VM gets its SSL > certificate from the CA. Fine. > But especially in the development stage VMs get discarded and restarted > frequently. So the VMs loose their certificate and keys but the CA > remembers the End Entity state! > > Is there an easy way to reset an End Entity to 'New' without providing > all the required attributes in the 'Edit End Entity' form? > > Greetings, > > Andreas > |
|
From: Andreas K. <ku...@tr...> - 2014-04-25 09:22:14
|
Hi Folks, I'm looking for an easy way to reset the End Entity status to 'New' ... preferably without too much knowledge about the End Entity settings ... Background: We set up and tear down several VMs. Each VM gets its SSL certificate from the CA. Fine. But especially in the development stage VMs get discarded and restarted frequently. So the VMs loose their certificate and keys but the CA remembers the End Entity state! Is there an easy way to reset an End Entity to 'New' without providing all the required attributes in the 'Edit End Entity' form? Greetings, Andreas -- Andreas Kühne phone: +49 177 293 24 97 mailto: ku...@tr... Trustable Ltd. Niederlassung Deutschland Ströverstr. 18 - 59427 Unna Amtsgericht Hamm HRB 5868 Directors Andreas Kühne, Heiko Veit Company UK Company No: 5218868 Registered in England and Wales |
|
From: Andreas B. <ab...@an...> - 2014-04-21 18:09:38
|
FYI... Great place to hack, have fun with your Community Mates and enjoy Swiss alps :-) -------- Original-Nachricht -------- Betreff: [talk-ch] OSM Mappers and developpers invited to the Randa Meetings 2014 Datum: Sun, 20 Apr 2014 12:57:37 +0200 Von: Pascal Mages <pa...@pl...> Antwort an: Openstreetmap Schweiz/Suisse/Svizzera/Svizra <ta...@op...> An: Openstreetmap Schweiz/Suisse/Svizzera/Svizra <ta...@op...> Kopie (CC): fu...@kd... Dear all Randa [1] is a small and beautiful village in the swiss alps just two train stops away from Zermatt with its world famous Matterhorn! The next Randa Meetings take place from Saturday, 9th to Friday, 15th of August 2014. The association Randa Meetings lead by Mario Fux organises the 5th Hacking Meeting already. What are these Randa Meetings? The goal of the Randa Meetings is to bring groups and people from the global free software, open source and open data community together for one week in a nice place to discuss, work and hack on the next big (or small) thing. Due to its origin so far mainly the KDE community has participated and we have hosted as much as 50 developers (the house has a capacity of approx. 100) [2]. The organisers of Randa Meetings provide the place and basic services such as food, drinks and accomodation (not for free but for a very low price, see below), meeting rooms and the probably nicest view you can have for a (developer) meeting. The content comes from the participants. So you can come with your group and discuss, map or hack on whatever is important to you. So do you have a project you are working on within the OSM community? Bring your people to Randa in August and you will most probably have a boost for the project. The past meetings have shown that the great atmosphere and the peaceful suroundings are very positive for the productivity and focused work. And you can come for just a day or two or the whole week. It's totally up to you. Family and friends are welcome, too! Randa is great also for your family. There are a lot of opportunities for hiking, mountain biking or just enjoying yourself in a great panorama. This year we know already from a few bringing their kids along with them. What does it cost me? The accomodation is approx. 20 CHF/person and night (+/-5 CHF) and also depending on how much sponsoring we can obtain. Family members have to pay for themself (no sponsored stays). Food (full board) is provided at 15 CHF/person and day. Travel expenses are to be covered by the participants. For international participants on low budget we can provide a special fare train ticket on request (limited availability). Interested? Get in contact with us! Pascal Mages (pas...@so...) or Mario Fux (fu...@kd...). For further information visit http://randa-meetings.ch/ Looking forward to see you in Randa! Pascal & Mario [1] http://www.openstreetmap.org/#map=14/46.0999/7.7652 [2] http://community.kde.org/Sprints/Randa -- e-mail signed with CAcert certificate (www.cacert.org) |
|
From: Andreas K. <ku...@tr...> - 2014-04-15 16:15:34
|
Hi Miguel, > I wish to run ejbca with a soft ca.tokentype to store keys . Is possible > then, in a short time, migrate these keys to hardware hsm? once you create the keys outside a HSM they must be considered unsecure forever! Importing into an HSM don't make them 'better' ... consider creating a new key pair once the HSM is installed. Greetings, Andreas -- Andreas Kühne phone: +49 177 293 24 97 mailto: ku...@tr... Trustable Ltd. Niederlassung Deutschland Ströverstr. 18 - 59427 Unna Amtsgericht Hamm HRB 5868 Directors Andreas Kühne, Heiko Veit Company UK Company No: 5218868 Registered in England and Wales |
|
From: Miguel A. R. <mar...@sa...> - 2014-04-15 15:54:35
|
Hi , I wish to run ejbca with a soft ca.tokentype to store keys . Is possible then, in a short time, migrate these keys to hardware hsm? Is the hsm nshield solo pci supported? Thanking You ! Regards , Miguel -- Ing. Miguel Angel Robledo Infraestructura de Firma Digital Secretaría de Tecnologías para la Gestión Ministerio de Gobierno y Reforma del Estado Provincia de Santa Fe San Martín 2466 3° Piso (S3000FSB) Santa Fe +54 342 4508700/4574891 int 5132 |
|
From: Tomas G. <to...@pr...> - 2014-04-15 06:48:04
|
You can add subjectAltName to any end entity, and any CA, simply by using the correct fields in Certificate Profiles, EndEntity Profiles and/or CAs. For issuerAltName you currently need to use a Custom extension. See admin guide for details how to use custom extensions. Cheers, Tomas ----- PrimeKey Solutions offers commercial EJBCA and SignServer support subscriptions and training courses. Please see www.primekey.se or contact in...@pr... for more information. http://www.primekey.se/Services/Support/ http://www.primekey.se/Services/Training/ On 2014-04-12 18:44, Tomás Estani wrote: > After created a CA, we need to add some attributes. For instance: > Subject alternative name (with RFC822Name in it) and populate that info > to the end entities profile. I wasn´t able to achieve this with the same > CA, so my questions are: > 1) is it possible or we need to create a new one? > 2) regardless of 1) how can I populate the end entity certificate with > the issuer alternative name (CA subject alternative name)? > > Regards, > > > ------------------------------------------------------------------------------ > Put Bad Developers to Shame > Dominate Development with Jenkins Continuous Integration > Continuously Automate Build, Test & Deployment > Start a new project now. Try Jenkins in the cloud. > http://p.sf.net/sfu/13600_Cloudbees > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Tomás E. <tom...@gm...> - 2014-04-12 16:44:15
|
After created a CA, we need to add some attributes. For instance: Subject alternative name (with RFC822Name in it) and populate that info to the end entities profile. I wasn´t able to achieve this with the same CA, so my questions are: 1) is it possible or we need to create a new one? 2) regardless of 1) how can I populate the end entity certificate with the issuer alternative name (CA subject alternative name)? Regards, |
|
From: ejbca-support <ejb...@pr...> - 2014-04-09 12:53:25
|
On 2014-04-09 13:57, Lembitu Ling wrote: > > Hi, > > as i was issuing certificate through EJBCA command line and through CRL I noticed > one issue. I do not know if it is by the standard or a bug - if either RSA key or > exponent begins with byte 00 HEX this byte will be truncated from key or exponent > inside issued certificate. Is there any way to prevent EJBCA doing this ? Hi, RSA exponents are positive integers and the EJBCA makes sure they are represented as such in certificates. This means that the most significant bit (not byte) always is zero (assuming I haven't misunderstood ASN.1...). Anders > > Wbr, > Lembitu Ling > ------------------------------------------------------------------------------ > Put Bad Developers to Shame > Dominate Development with Jenkins Continuous Integration > Continuously Automate Build, Test & Deployment > Start a new project now. Try Jenkins in the cloud. > http://p.sf.net/sfu/13600_Cloudbees > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Lembitu L. <lem...@cb...> - 2014-04-09 12:28:10
|
Hi, as i was issuing certificate through EJBCA command line and through CRL I noticed one issue. I do not know if it is by the standard or a bug - if either RSA key or exponent begins with byte 00 HEX this byte will be truncated from key or exponent inside issued certificate. Is there any way to prevent EJBCA doing this ? Wbr, Lembitu Ling |
|
From: Lembitu L. <lem...@cb...> - 2014-04-09 12:18:01
|
Hi, being relatively new here i just want to add that although EJBCA nor JBoss are affected, many setups use Apache or Nginx as proxy in front of JBoss/EJBCA as many of the the setup guides suggest. Those setups need to be checked for vulnerable openssl versions. Wbr, Lembitu Ling On 09 Apr 2014, at 14:36, Tomas Gustavsson <to...@pr...> wrote: > > No there is no impact in EJBCA per se. EJBCA does not use, or link with, > OpenSSL in any way. JBoss, as EJBCA is running on does not either, by > default, use OpenSSL. > > If you have custom components or linkage in your environment, outside if > EJBCA control, you need to be in control of that yourself of course. > > Cheers, > Tomas > ********** > PrimeKey Solutions AB > Anderstorpsvägen 16, 171 54 Solna, Sweden > Mob: +46 (0)707421096 > Internet: www.primekey.se > Twitter: twitter.com/primetomas > ********** > > On 2014-04-09 12:56, Brahim zaki wrote: >> >> Hi Tomas, >> Is there any impact in EJBCA linked to the openSSL bug : >> https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0160 >> >> is EJBCA use openSSL as an embedded lib??? >> Thanks. >> ZAKI. > > ------------------------------------------------------------------------------ > Put Bad Developers to Shame > Dominate Development with Jenkins Continuous Integration > Continuously Automate Build, Test & Deployment > Start a new project now. Try Jenkins in the cloud. > http://p.sf.net/sfu/13600_Cloudbees > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Tomas G. <to...@pr...> - 2014-04-09 11:36:48
|
No there is no impact in EJBCA per se. EJBCA does not use, or link with, OpenSSL in any way. JBoss, as EJBCA is running on does not either, by default, use OpenSSL. If you have custom components or linkage in your environment, outside if EJBCA control, you need to be in control of that yourself of course. Cheers, Tomas ********** PrimeKey Solutions AB Anderstorpsvägen 16, 171 54 Solna, Sweden Mob: +46 (0)707421096 Internet: www.primekey.se Twitter: twitter.com/primetomas ********** On 2014-04-09 12:56, Brahim zaki wrote: > > Hi Tomas, > Is there any impact in EJBCA linked to the openSSL bug : > https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0160 > > is EJBCA use openSSL as an embedded lib??? > Thanks. > ZAKI. |
|
From: Tomas G. <to...@pr...> - 2014-04-07 08:55:09
|
Hi, We are happy to announce that EJBCA Community 6.1.1 has been released! This is a maintenance release with new features, bug fixes and improvements. In all 32 issues have been fixed. The biggest news in this release are support for EAC 2.10 access control templates (Enterprise only), more OCSP improvements as well as improvements for Key Recovery. * Noteworthy changes: - OCSP improvements and new features related to RFC 6960, minimizing size of OCSP responses (see note below). - Implemented OCSP signing algorithm selecttion including client requested algorithms. - CVC certificate profiles (ePassport PKI) now supports EAC 2.10 access control templates (Enterprise only) - Improvements to Key Recovery enabling encryption key rollover and providing more information about encryption keys. - Windows build/install is now working. - ManagementCA created during a default install now uses SHA256WithRSA. - EJBCA now compiles (deployment/running not supported however) on WildFly 8 and Glasshish 4, also using Java 8. - EJBCA can now use certificate serial number longer than 64 bits. - Minor improvements and fixes to make life easier for everyone. Note 1: OCSP responses no longer includes the Root CA Certificate, unless the Root CA is the OCSP signer, and it is configured to include the signer certificate. Having OCSP responses as small as possible is an important performance feature, and since the client must have the root certificate as trusted there is no need to include the root certificate in the chain. Note 2: In EJBCA 6.1.0 the Public Web interface logo filename was changed. If you have customized your own logo, you need to rename the logo filename from 'logotype.png' or 'ejbca_pki_by_primekey_logo.png' to 'banner_ejbca-public.png'. Read the full Changelog for details. For upgrade instructions, please see UPGRADE. - Known issues: * One test failure on DB2: https://jira.primekey.se/browse/ECA-3298 * OCSP request signer verification does an additional database lookup: https://jira.primekey.se/browse/ECA-3299 * Poorly created primary keys for the AdminEntityData table causes issues in some cases: https://jira.primekey.se/browse/ECA-3469 Regards, The PrimeKey EJBCA Team |