You can subscribe to this list here.
| 2001 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
(1) |
Dec
(3) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2002 |
Jan
(3) |
Feb
(2) |
Mar
(8) |
Apr
(3) |
May
(6) |
Jun
(1) |
Jul
(15) |
Aug
(6) |
Sep
|
Oct
(10) |
Nov
(2) |
Dec
(4) |
| 2003 |
Jan
(1) |
Feb
(7) |
Mar
(3) |
Apr
(6) |
May
(7) |
Jun
(5) |
Jul
(5) |
Aug
(25) |
Sep
(14) |
Oct
(2) |
Nov
|
Dec
(2) |
| 2004 |
Jan
(7) |
Feb
(4) |
Mar
(12) |
Apr
(16) |
May
(43) |
Jun
(56) |
Jul
(43) |
Aug
(40) |
Sep
(66) |
Oct
(12) |
Nov
(26) |
Dec
(10) |
| 2005 |
Jan
(13) |
Feb
(33) |
Mar
(16) |
Apr
(7) |
May
(10) |
Jun
(34) |
Jul
(41) |
Aug
(8) |
Sep
(4) |
Oct
(32) |
Nov
(20) |
Dec
(25) |
| 2006 |
Jan
(30) |
Feb
(101) |
Mar
(5) |
Apr
(75) |
May
(74) |
Jun
(22) |
Jul
(6) |
Aug
(70) |
Sep
(19) |
Oct
(21) |
Nov
(31) |
Dec
(50) |
| 2007 |
Jan
(15) |
Feb
(20) |
Mar
(24) |
Apr
(33) |
May
(13) |
Jun
(18) |
Jul
(13) |
Aug
(7) |
Sep
(63) |
Oct
(68) |
Nov
(29) |
Dec
(68) |
| 2008 |
Jan
(30) |
Feb
(33) |
Mar
(30) |
Apr
(103) |
May
(78) |
Jun
(48) |
Jul
(72) |
Aug
(24) |
Sep
(62) |
Oct
(63) |
Nov
(70) |
Dec
(37) |
| 2009 |
Jan
(34) |
Feb
(35) |
Mar
(64) |
Apr
(34) |
May
(34) |
Jun
(58) |
Jul
(30) |
Aug
(30) |
Sep
(46) |
Oct
(52) |
Nov
(12) |
Dec
(23) |
| 2010 |
Jan
(121) |
Feb
(18) |
Mar
(53) |
Apr
(62) |
May
(62) |
Jun
(20) |
Jul
(33) |
Aug
(20) |
Sep
(36) |
Oct
(35) |
Nov
(44) |
Dec
(63) |
| 2011 |
Jan
(19) |
Feb
(32) |
Mar
(94) |
Apr
(41) |
May
(47) |
Jun
(25) |
Jul
(34) |
Aug
(20) |
Sep
(9) |
Oct
(41) |
Nov
(33) |
Dec
(24) |
| 2012 |
Jan
(12) |
Feb
(36) |
Mar
(48) |
Apr
(32) |
May
(20) |
Jun
(15) |
Jul
(32) |
Aug
(13) |
Sep
(33) |
Oct
(54) |
Nov
(25) |
Dec
(16) |
| 2013 |
Jan
(45) |
Feb
(39) |
Mar
(38) |
Apr
(50) |
May
(29) |
Jun
(30) |
Jul
(33) |
Aug
(12) |
Sep
(9) |
Oct
(25) |
Nov
(29) |
Dec
(20) |
| 2014 |
Jan
(25) |
Feb
(19) |
Mar
(16) |
Apr
(33) |
May
(27) |
Jun
(37) |
Jul
(29) |
Aug
(27) |
Sep
(37) |
Oct
(58) |
Nov
(109) |
Dec
(26) |
| 2015 |
Jan
(4) |
Feb
(35) |
Mar
(22) |
Apr
(35) |
May
(28) |
Jun
(20) |
Jul
(4) |
Aug
(16) |
Sep
(37) |
Oct
(13) |
Nov
(13) |
Dec
(14) |
| 2016 |
Jan
(22) |
Feb
(7) |
Mar
(23) |
Apr
(30) |
May
(10) |
Jun
(10) |
Jul
(15) |
Aug
(12) |
Sep
(22) |
Oct
(31) |
Nov
(5) |
Dec
(5) |
| 2017 |
Jan
(30) |
Feb
(25) |
Mar
(28) |
Apr
(4) |
May
(19) |
Jun
(13) |
Jul
(7) |
Aug
(1) |
Sep
(2) |
Oct
(5) |
Nov
(12) |
Dec
(2) |
| 2018 |
Jan
(7) |
Feb
|
Mar
(7) |
Apr
(2) |
May
(8) |
Jun
(18) |
Jul
(6) |
Aug
(3) |
Sep
(15) |
Oct
(33) |
Nov
(13) |
Dec
(7) |
| 2019 |
Jan
(5) |
Feb
(7) |
Mar
(30) |
Apr
(5) |
May
(4) |
Jun
(69) |
Jul
(86) |
Aug
(22) |
Sep
(6) |
Oct
(7) |
Nov
(5) |
Dec
(3) |
| 2020 |
Jan
(10) |
Feb
(12) |
Mar
(22) |
Apr
(5) |
May
(1) |
Jun
(4) |
Jul
(6) |
Aug
|
Sep
(9) |
Oct
|
Nov
|
Dec
(1) |
| 2021 |
Jan
(4) |
Feb
(11) |
Mar
(7) |
Apr
(7) |
May
|
Jun
(3) |
Jul
(10) |
Aug
(6) |
Sep
|
Oct
|
Nov
(18) |
Dec
(2) |
| 2022 |
Jan
(1) |
Feb
(1) |
Mar
|
Apr
|
May
|
Jun
(2) |
Jul
|
Aug
(4) |
Sep
|
Oct
|
Nov
|
Dec
|
| 2023 |
Jan
|
Feb
|
Mar
|
Apr
(1) |
May
(1) |
Jun
|
Jul
|
Aug
(5) |
Sep
|
Oct
|
Nov
|
Dec
|
|
From: Tomas G. <to...@pr...> - 2014-04-05 13:33:23
|
Do you mean an api interface or a GUI function? Key I'd is available as a column in the database for all certificates, apart from in the cert itself. Cheers, Tomas On 4 april 2014 13:58:11 CEST, Andreas Kuehne <ku...@tr...> wrote: >Hi Folks, > >for certificate chain building it's convenient to select the parent >certificate by an 'Authority Key Info' extension given in the child >certificate. But this requires an interface to identify a certificate >by >its 'Subject Key Indentifier'. Is there an interface available in the >ejba? > >Thanks in advance, > >Andreas |
|
From: Andreas K. <ku...@tr...> - 2014-04-04 11:58:27
|
Hi Folks, for certificate chain building it's convenient to select the parent certificate by an 'Authority Key Info' extension given in the child certificate. But this requires an interface to identify a certificate by its 'Subject Key Indentifier'. Is there an interface available in the ejba? Thanks in advance, Andreas -- Andreas Kühne phone: +49 177 293 24 97 mailto: ku...@tr... Trustable Ltd. Niederlassung Deutschland Ströverstr. 18 - 59427 Unna Amtsgericht Hamm HRB 5868 Directors Andreas Kühne, Heiko Veit Company UK Company No: 5218868 Registered in England and Wales |
|
From: Andreas K. <ku...@tr...> - 2014-03-28 15:37:43
|
Hi Tomas, yes, it's a benign problem. If no one got a solution at hand I'll try minimize the restarts by puppet tooling. To me it looks like the 'reload' causes the problem and so I added an ugly stop/start pair. Thanks for your quick reply, Andreas > I have noticed I needed to do a restart sometimes. I just thought is was > some issue in JBoss. Older versions of JBoss always needed a restart to > configure TLS. This version should not...but then again reload works so > so in Jboss 7 in general, so I was never surprised... > > Cheers, > Tomas > > On 2014-03-28 14:55, Andreas Kuehne wrote: >> Hi folks, >> >> when scripting the ejbca for automatic installation I noticed a strange >> behaviour regarding the SSL ports. At the end of the 'ant install' the >> ports are activated and available. But the subsequent 'reload' seem to >> deactivate them again. >> >> After a restart of the jboss everything's OK again ... did anyone see >> this issue, too? >> >> I'm using jboss as 7.1.1 final and a recent source version 'ejbca >> 6.2.0.alpha'. >> >> Greetings and thanks in advance, >> >> Andreas >> > ------------------------------------------------------------------------------ > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > -- Andreas Kühne phone: +49 177 293 24 97 mailto: ku...@tr... Trustable Ltd. Niederlassung Deutschland Ströverstr. 18 - 59427 Unna Amtsgericht Hamm HRB 5868 Directors Andreas Kühne, Heiko Veit Company UK Company No: 5218868 Registered in England and Wales |
|
From: Tomas G. <to...@pr...> - 2014-03-28 15:27:14
|
I have noticed I needed to do a restart sometimes. I just thought is was some issue in JBoss. Older versions of JBoss always needed a restart to configure TLS. This version should not...but then again reload works so so in Jboss 7 in general, so I was never surprised... Cheers, Tomas On 2014-03-28 14:55, Andreas Kuehne wrote: > Hi folks, > > when scripting the ejbca for automatic installation I noticed a strange > behaviour regarding the SSL ports. At the end of the 'ant install' the > ports are activated and available. But the subsequent 'reload' seem to > deactivate them again. > > After a restart of the jboss everything's OK again ... did anyone see > this issue, too? > > I'm using jboss as 7.1.1 final and a recent source version 'ejbca > 6.2.0.alpha'. > > Greetings and thanks in advance, > > Andreas > |
|
From: Andreas K. <ku...@tr...> - 2014-03-28 14:08:42
|
Hi folks, when scripting the ejbca for automatic installation I noticed a strange behaviour regarding the SSL ports. At the end of the 'ant install' the ports are activated and available. But the subsequent 'reload' seem to deactivate them again. After a restart of the jboss everything's OK again ... did anyone see this issue, too? I'm using jboss as 7.1.1 final and a recent source version 'ejbca 6.2.0.alpha'. Greetings and thanks in advance, Andreas -- Andreas Kühne phone: +49 177 293 24 97 mailto: ku...@tr... Trustable Ltd. Niederlassung Deutschland Ströverstr. 18 - 59427 Unna Amtsgericht Hamm HRB 5868 Directors Andreas Kühne, Heiko Veit Company UK Company No: 5218868 Registered in England and Wales |
|
From: Tomas G. <to...@pr...> - 2014-03-24 16:11:42
|
The PrimeKey EJBCA team is happy to announce the release of EJBCA Enterprise 6.1.0. Community will follow. This release resolves several issues, with a few highlights: Increased performance through OCSP improvements; Key Recovery improvements; support for EAC 2.10 (ePassport) access control templates. Running on the latest technology platforms, EJBCA Enterprise v.6 is so flexible it is suitable for any organization, cloud, social or mobile system. Faster, more resource efficient, more secure and more user friendly than ever. EJBCA Enterprise *6.1.0* release notes A maintenance release containing 32 new features and improvements, below a selection of the most noteworthy: * New features - New OCSP features related to RFC 6960, minimizing size of OCSP responses. - Implemented OCSP signing algorithm selection from client requested algorithms. - CVC certificate profiles (ePassport PKI) now supports EAC 2.10 access control templates. (Enterprise only) * Improvements - OCSP improvements with more cache control settings. - Improvements to Key Recovery, enabling encryption key rollover and providing more information about encryption keys. - Ability to build and install EJBCA on Windows platforms. - The ManagementCA created during default install, now uses SHA256WithRSA. - EJBCA compiles cleanly with Java 8, WildFly 8 and Glassfish 4 (running on those platforms however, is not yet supported). - EJBCA can now use certificate serial number longer than 64 bits. - Many reported minor issues have been fixed, as well as minor GUI improvements. Regards, PrimeKey EJBCA Team ********** PrimeKey Solutions AB Internet: www.primekey.se Twitter: twitter.com/primekeyPKI ********** |
|
From: Tomas G. <to...@pr...> - 2014-03-24 10:20:02
|
Hi, As a sub project to EJBCA the cert-cvc java library implements API support for EAC CVC (ePassport) certificates. cert-cvc 1.4.0 includes support for EAC 2.10 Access Control Templates. 1.4.0 ----- - Added authorization roles and access rights for Authentication Terminals and Signature Terminals, which were added in the EAC 2.10 specification. You can download cert-cvc 1.4.0 from the sourceforge download page (it will appear in due time on the download page at ejbca.org). http://sourceforge.net/projects/ejbca/files/cert-cvc/cert-cvc-1.4.0/ Cheers, PrimeKey EJBCA Team ********** PrimeKey Solutions AB Internet: www.primekey.se Twitter: twitter.com/primekeyPKI ********** |
|
From: Branko M. <br...@ma...> - 2014-03-21 10:31:52
|
On Thu, 20 Mar 2014 19:41:42 +0530 rishu singh <jm...@gm...> wrote: > HI , > > > > I wish to run ejbca as a e SCEP server . Can ejbca server be run as a SCEP > server ? If yes , please provide the steps for dong the same . Please > revert back to the query ASAP . Thanking You ! > > > > Regards , > > Rishu Singh > > Have a look at documentation available at http://www.ejbca.org/docs/adminguide.html#Scep Additionally, SCEP is configured via scep.properties in EJBCA's conf directory. Have a look at scep.properties.sample for documentation on possible properties within that file. Best regards -- Branko Majic Jabber: br...@ma... Please use only Free formats when sending attachments to me. Бранко Мајић Џабер: br...@ma... Молим вас да додатке шаљете искључиво у слободним форматима. |
|
From: Branko M. <br...@ma...> - 2014-03-21 10:26:52
|
On Tue, 18 Mar 2014 12:56:48 +0000 (GMT)
Ebtehal Hassan <h.e...@ya...> wrote:
>
> Hi all;
>
>
> i faced some problem on publishing CRL to LDAP server:
> i was use ejbca 4.0.16 , JBOSS 5.0.11 ,openldap-2.0.26
> when publish the CRL i get the following error on JBOSS log:
> .
> .
> .
>
>
> 14:06:47,982 ERROR [LdapPublisher] LDAP ERROR: Error storing CRL (certificateRevocationList;binary) in LDAP (top;cRLDistributionPoint;pkiCA) for DN (cn=AdminCA,o=TEST,c=SE). Message: Unwilling To Perform.
> LDAPException: Unwilling To Perform (53) Unwilling To Perform
> LDAPException: Server Message: operation not permitted within namingContext
> LDAPException: Matched DN:
> at com.novell.ldap.LDAPResponse.getResultException(Unknown Source)
> at com.novell.ldap.LDAPResponse.chkResultCode(Unknown
> Source)
> at com.novell.ldap.LDAPConnection.chkResultCode(Unknown Source)
> at com.novell.ldap.LDAPConnection.add(Unknown Source)
> at org.ejbca.core.model.ca.publisher.LdapPublisher.storeCRL(LdapPublisher.java:535)
> at org.ejbca.core.ejb.ca.publisher.PublisherQueueSessionBean.storeCRLNonTransactional(PublisherQueueSessionBean.java:376)
> at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
> at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:57)
> at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
> at java.lang.reflect.Method.invoke(Method.java:616)
> at org.jboss.aop.joinpoint.MethodInvocation.invokeTarget(MethodInvocation.java:122)
> at
> org.jboss.aop.joinpoint.MethodInvocation.invokeNext(MethodInvocation.java:111)
> at org.jboss.ejb3.EJBContainerInvocationWrapper.invokeNext(EJBContainerInvocationWrapper.java:69)
> at org.jboss.ejb3.interceptors.aop.InterceptorSequencer.invoke(InterceptorSequencer.java:73)
> at org.jboss.ejb3.interceptors.aop.InterceptorSequencer.aroundInvoke(InterceptorSequencer.java:59)
> at sun.reflect.GeneratedMethodAccessor421.invoke(Unknown Source)
> at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
> at java.lang.reflect.Method.invoke(Method.java:616)
> at org.jboss.aop.advice.PerJoinpointAdvice.invoke(PerJoinpointAdvice.java:174)
> at org.jboss.aop.joinpoint.MethodInvocation.invokeNext(MethodInvocation.java:102)
> at
> org.jboss.ejb3.interceptors.aop.InvocationContextInterceptor.fillMethod(InvocationContextInterceptor.java:72)
> at org.jboss.aop.advice.org.jboss.ejb3.interceptors.aop.InvocationContextInterceptor_z_fillMethod_900891812.invoke(InvocationContextInterceptor_z_fillMethod_900891812.java)
> at org.jboss.aop.joinpoint.MethodInvocation.invokeNext(MethodInvocation.java:102)
> at org.jboss.ejb3.interceptors.aop.InvocationContextInterceptor.setup(InvocationContextInterceptor.java:88)
> at org.jboss.aop.advice.org.jboss.ejb3.interceptors.aop.InvocationContextInterceptor_z_setup_900891812.invoke(InvocationContextInterceptor_z_setup_900891812.java)
> at org.jboss.aop.joinpoint.MethodInvocation.invokeNext(MethodInvocation.java:102)
> at
> org.jboss.ejb3.connectionmanager.CachedConnectionInterceptor.invoke(CachedConnectionInterceptor.java:62)
> at org.jboss.aop.joinpoint.MethodInvocation.invokeNext(MethodInvocation.java:102)
> at org.jboss.ejb3.entity.TransactionScopedEntityManagerInterceptor.invoke(TransactionScopedEntityManagerInterceptor.java:56)
> at org.jboss.aop.joinpoint.MethodInvocation.invokeNext(MethodInvocation.java:102)
> at org.jboss.ejb3.AllowedOperationsInterceptor.invoke(AllowedOperationsInterceptor.java:47)
> at org.jboss.aop.joinpoint.MethodInvocation.invokeNext(MethodInvocation.java:102)
> at org.jboss.ejb3.tx.NullInterceptor.invoke(NullInterceptor.java:42)
> at org.jboss.aop.joinpoint.MethodInvocation.invokeNext(MethodInvocation.java:102)
> at
> org.jboss.ejb3.stateless.StatelessInstanceInterceptor.invoke(StatelessInstanceInterceptor.java:68)
> at org.jboss.aop.joinpoint.MethodInvocation.invokeNext(MethodInvocation.java:102)
> at org.jboss.aspects.tx.TxPolicy.invokeInNoTx(TxPolicy.java:66)
> at org.jboss.ejb3.tx.TxInterceptor$NotSupported.invoke(TxInterceptor.java:92)
> at org.jboss.aop.joinpoint.MethodInvocation.invokeNext(MethodInvocation.java:102)
> at org.jboss.aspects.tx.TxPropagationInterceptor.invoke(TxPropagationInterceptor.java:76)
> at org.jboss.aop.joinpoint.MethodInvocation.invokeNext(MethodInvocation.java:102)
> at org.jboss.ejb3.tx.NullInterceptor.invoke(NullInterceptor.java:42)
> at org.jboss.aop.joinpoint.MethodInvocation.invokeNext(MethodInvocation.java:102)
> at
> org.jboss.ejb3.security.RoleBasedAuthorizationInterceptorv2.invoke(RoleB
> __________________________
>
>
> and on the log of LDAP server i found :
>
> .
> .
> .
> backsql_modify(): modifying entry "cn=AdminCA,o=TEST,c=SE" (id=12)
> ==>backsql_modify_internal(): traversing modifications list
> backsql_modify_internal(): modifying attribute "certificateRevocationList;binary" (replace) according to mappings for objectClass "cRLDistributionPoint"
> backsql_modify_internal(): attribute "certificateRevocationList;binary" is not registered in objectClass "cRLDistributionPoint"
> backsql_modify_internal(): modifying attribute "authorityRevocationList;binary" (replace) according to mappings for objectClass "cRLDistributionPoint"
> backsql_modify_internal(): attribute "authorityRevocationList;binary" is not registered in objectClass "cRLDistributionPoint"
> backsql_modify_internal(): modifying attribute "entryCSN" (replace) according to mappings for objectClass "cRLDistributionPoint"
> backsql_modify_internal(): modifying attribute "modifiersName" (replace) according to mappings for objectClass "cRLDistributionPoint"
> backsql_modify_internal(): modifying attribute "modifyTimestamp" (replace) according to mappings for objectClass "cRLDistributionPoint"
> <==backsql_modify_internal(): 0
> ==>backsql_id2entry()
> backsql_id2entry(): retrieving all attributes
> ==>backsql_get_attr_vals(): oc="cRLDistributionPoint" attr="objectClass" keyval=12
> backsql_get_attr_vals(): number of values in query: 0
> <==backsql_id2entry()
> backsql_modify("cn=AdminCA,o=TEST,c=SE"): entry failed schema check -- aborting
> send_ldap_result: conn=1013 op=1 p=3
> send_ldap_response: msgid=20 tag=103 err=64
> ber_flush2: 59 bytes to sd 12
> <==backsql_modify()
> connection_get(12): got connid=1013
> connection_read(12): checking for input on id=1013
> ber_get_next
> ber_get_next: tag 0x30 len 5 contents:
> op tag 0x42, time 1395138415
> ber_get_next
> ber_get_next on fd 12 failed errno=0 (Success)
> conn=1013 op=2 do_unbind
> connection_close: conn=1013 sd=12
>
>
>
>
> so how i can solve this problem...
>
>
> Regards;
> Ebtehal Hassan.
The object classes you have configured in your publisher don't seem to
allow the storage of some of the attributes. This should give you a
reather good hint:
> backsql_modify_internal(): attribute "certificateRevocationList;binary" is not registered in objectClass "cRLDistributionPoint"
> backsql_modify_internal(): attribute "authorityRevocationList;binary" is not registered in objectClass "cRLDistributionPoint"
You should either change object classes used in your publisher, or
attributes used for storing CRL and ARL.
Best regards
--
Branko Majic
Jabber: br...@ma...
Please use only Free formats when sending attachments to me.
Бранко Мајић
Џабер: br...@ma...
Молим вас да додатке шаљете искључиво у слободним форматима.
|
|
From: rishu s. <jm...@gm...> - 2014-03-20 14:11:49
|
HI , I wish to run ejbca as a e SCEP server . Can ejbca server be run as a SCEP server ? If yes , please provide the steps for dong the same . Please revert back to the query ASAP . Thanking You ! Regards , Rishu Singh -- Rishu Singh |
|
From: Ebtehal H. <h.e...@ya...> - 2014-03-18 12:56:57
|
Hi all;
i faced some problem on publishing CRL to LDAP server:
i was use ejbca 4.0.16 , JBOSS 5.0.11 ,openldap-2.0.26
when publish the CRL i get the following error on JBOSS log:
.
.
.
14:06:47,982 ERROR [LdapPublisher] LDAP ERROR: Error storing CRL (certificateRevocationList;binary) in LDAP (top;cRLDistributionPoint;pkiCA) for DN (cn=AdminCA,o=TEST,c=SE). Message: Unwilling To Perform.
LDAPException: Unwilling To Perform (53) Unwilling To Perform
LDAPException: Server Message: operation not permitted within namingContext
LDAPException: Matched DN:
at com.novell.ldap.LDAPResponse.getResultException(Unknown Source)
at com.novell.ldap.LDAPResponse.chkResultCode(Unknown
Source)
at com.novell.ldap.LDAPConnection.chkResultCode(Unknown Source)
at com.novell.ldap.LDAPConnection.add(Unknown Source)
at org.ejbca.core.model.ca.publisher.LdapPublisher.storeCRL(LdapPublisher.java:535)
at org.ejbca.core.ejb.ca.publisher.PublisherQueueSessionBean.storeCRLNonTransactional(PublisherQueueSessionBean.java:376)
at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:57)
at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
at java.lang.reflect.Method.invoke(Method.java:616)
at org.jboss.aop.joinpoint.MethodInvocation.invokeTarget(MethodInvocation.java:122)
at
org.jboss.aop.joinpoint.MethodInvocation.invokeNext(MethodInvocation.java:111)
at org.jboss.ejb3.EJBContainerInvocationWrapper.invokeNext(EJBContainerInvocationWrapper.java:69)
at org.jboss.ejb3.interceptors.aop.InterceptorSequencer.invoke(InterceptorSequencer.java:73)
at org.jboss.ejb3.interceptors.aop.InterceptorSequencer.aroundInvoke(InterceptorSequencer.java:59)
at sun.reflect.GeneratedMethodAccessor421.invoke(Unknown Source)
at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
at java.lang.reflect.Method.invoke(Method.java:616)
at org.jboss.aop.advice.PerJoinpointAdvice.invoke(PerJoinpointAdvice.java:174)
at org.jboss.aop.joinpoint.MethodInvocation.invokeNext(MethodInvocation.java:102)
at
org.jboss.ejb3.interceptors.aop.InvocationContextInterceptor.fillMethod(InvocationContextInterceptor.java:72)
at org.jboss.aop.advice.org.jboss.ejb3.interceptors.aop.InvocationContextInterceptor_z_fillMethod_900891812.invoke(InvocationContextInterceptor_z_fillMethod_900891812.java)
at org.jboss.aop.joinpoint.MethodInvocation.invokeNext(MethodInvocation.java:102)
at org.jboss.ejb3.interceptors.aop.InvocationContextInterceptor.setup(InvocationContextInterceptor.java:88)
at org.jboss.aop.advice.org.jboss.ejb3.interceptors.aop.InvocationContextInterceptor_z_setup_900891812.invoke(InvocationContextInterceptor_z_setup_900891812.java)
at org.jboss.aop.joinpoint.MethodInvocation.invokeNext(MethodInvocation.java:102)
at
org.jboss.ejb3.connectionmanager.CachedConnectionInterceptor.invoke(CachedConnectionInterceptor.java:62)
at org.jboss.aop.joinpoint.MethodInvocation.invokeNext(MethodInvocation.java:102)
at org.jboss.ejb3.entity.TransactionScopedEntityManagerInterceptor.invoke(TransactionScopedEntityManagerInterceptor.java:56)
at org.jboss.aop.joinpoint.MethodInvocation.invokeNext(MethodInvocation.java:102)
at org.jboss.ejb3.AllowedOperationsInterceptor.invoke(AllowedOperationsInterceptor.java:47)
at org.jboss.aop.joinpoint.MethodInvocation.invokeNext(MethodInvocation.java:102)
at org.jboss.ejb3.tx.NullInterceptor.invoke(NullInterceptor.java:42)
at org.jboss.aop.joinpoint.MethodInvocation.invokeNext(MethodInvocation.java:102)
at
org.jboss.ejb3.stateless.StatelessInstanceInterceptor.invoke(StatelessInstanceInterceptor.java:68)
at org.jboss.aop.joinpoint.MethodInvocation.invokeNext(MethodInvocation.java:102)
at org.jboss.aspects.tx.TxPolicy.invokeInNoTx(TxPolicy.java:66)
at org.jboss.ejb3.tx.TxInterceptor$NotSupported.invoke(TxInterceptor.java:92)
at org.jboss.aop.joinpoint.MethodInvocation.invokeNext(MethodInvocation.java:102)
at org.jboss.aspects.tx.TxPropagationInterceptor.invoke(TxPropagationInterceptor.java:76)
at org.jboss.aop.joinpoint.MethodInvocation.invokeNext(MethodInvocation.java:102)
at org.jboss.ejb3.tx.NullInterceptor.invoke(NullInterceptor.java:42)
at org.jboss.aop.joinpoint.MethodInvocation.invokeNext(MethodInvocation.java:102)
at
org.jboss.ejb3.security.RoleBasedAuthorizationInterceptorv2.invoke(RoleB
__________________________
and on the log of LDAP server i found :
.
.
.
backsql_modify(): modifying entry "cn=AdminCA,o=TEST,c=SE" (id=12)
==>backsql_modify_internal(): traversing modifications list
backsql_modify_internal(): modifying attribute "certificateRevocationList;binary" (replace) according to mappings for objectClass "cRLDistributionPoint"
backsql_modify_internal(): attribute "certificateRevocationList;binary" is not registered in objectClass "cRLDistributionPoint"
backsql_modify_internal(): modifying attribute "authorityRevocationList;binary" (replace) according to mappings for objectClass "cRLDistributionPoint"
backsql_modify_internal(): attribute "authorityRevocationList;binary" is not registered in objectClass "cRLDistributionPoint"
backsql_modify_internal(): modifying attribute "entryCSN" (replace) according to mappings for objectClass "cRLDistributionPoint"
backsql_modify_internal(): modifying attribute "modifiersName" (replace) according to mappings for objectClass "cRLDistributionPoint"
backsql_modify_internal(): modifying attribute "modifyTimestamp" (replace) according to mappings for objectClass "cRLDistributionPoint"
<==backsql_modify_internal(): 0
==>backsql_id2entry()
backsql_id2entry(): retrieving all attributes
==>backsql_get_attr_vals(): oc="cRLDistributionPoint" attr="objectClass" keyval=12
backsql_get_attr_vals(): number of values in query: 0
<==backsql_id2entry()
backsql_modify("cn=AdminCA,o=TEST,c=SE"): entry failed schema check -- aborting
send_ldap_result: conn=1013 op=1 p=3
send_ldap_response: msgid=20 tag=103 err=64
ber_flush2: 59 bytes to sd 12
<==backsql_modify()
connection_get(12): got connid=1013
connection_read(12): checking for input on id=1013
ber_get_next
ber_get_next: tag 0x30 len 5 contents:
op tag 0x42, time 1395138415
ber_get_next
ber_get_next on fd 12 failed errno=0 (Success)
conn=1013 op=2 do_unbind
connection_close: conn=1013 sd=12
so how i can solve this problem...
Regards;
Ebtehal Hassan. |
|
From: Ebtehal H. <h.e...@ya...> - 2014-03-12 12:31:48
|
OK , Thanks Tomas but What is the form of the expected result of the stress test ??? because when i excute the following command i get this result ./ejbcaClientToolBox.sh EjbcaWsRaCli stress AdminCA1 Parsing as textfile failed (For input string: "3309F6B"). Trying to use it as a file with Java Objects. Number of certificates in list: 0 Test client started, tail info and error files in this directory for output. Statistic will be written to standard output each 10 second. The test was started at Wed Mar 12 15:14:18 EAT 2014 Total # of successfully performed tests: 0 Total # of failed tests: 7129 # of tests completed each second: 0.0 # of tests completed each second in last period: 0.0 Relative average time for different tasks (all should sum up to 1): Time waiting between jobs: 0.9978361 Time spent with test client work: 0.002163911 Absolute extremes: Min time for job 'Time waiting between jobs' (ms): 1 (Wed Mar 12 15:17:47 EAT 2014) Max time per job 'Time waiting between jobs' (ms): 4999 (Wed Mar 12 15:27:44 EAT 2014) So, Are the result is correct ?? Regards; Ebtehal H. ________________________________ From: Tomas Gustavsson <to...@pr...> To: ejb...@li... Sent: Tuesday, 11 March 2014, 19:01:22 Subject: Re: [Ejbca-develop] ClientToolBox You need to check the JBoss section (assume you are using JBoss 5) in the install guide. Cheers, Tomas ********** PrimeKey Solutions AB Anderstorpsvägen 16, 171 54 Solna, Sweden Mob: +46 (0)707421096 Internet: www.primekey.se Twitter: twitter.com/primetomas ********** On 03/11/2014 10:45 AM, Ebtehal Hassan wrote: > Hi ; > > i would like to use client tool box in ejbca , but when i run this > command i get the following error: > > > ./ejbcaClientToolBox.sh EjbcaWsRaCli finduser USERNAME EQUALS superadmin > > > ./ejbcaClientToolBox.sh EjbcaWsRaCli finduser USERNAME EQUALS superadmin > com.sun.xml.internal.ws.client.ClientTransportException: The server sent > HTTP status code 302: Moved Temporarily > org.ejbca.ui.cli.ErrorAdminCommandException: > com.sun.xml.internal.ws.client.ClientTransportException: The server sent > HTTP status code 302: Moved Temporarily > at > org.ejbca.core.protocol.ws.client.FindUserCommand.execute(FindUserCommand.java:161) > at > org.ejbca.core.protocol.ws.client.ejbcawsracli.main(ejbcawsracli.java:36) > at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method) > at > sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:57) > at > sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43) > at java.lang.reflect.Method.invoke(Method.java:622) > at org.ejbca.ui.cli.EjbcaWsRaCli.execute(EjbcaWsRaCli.java:36) > at > org.ejbca.ui.cli.ClientToolBox.executeIfSelected(ClientToolBox.java:40) > at org.ejbca.ui.cli.ClientToolBox.main(ClientToolBox.java:70) > Caused by: com.sun.xml.internal.ws.client.ClientTransportException: The > server sent HTTP status code 302: Moved Temporarily > at > com.sun.xml.internal.ws.transport.http.client.HttpTransportPipe.checkStatusCode(HttpTransportPipe.java:196) > at > com.sun.xml.internal.ws.transport.http.client.HttpTransportPipe.process(HttpTransportPipe.java:168) > at > com.sun.xml.internal.ws.transport.http.client.HttpTransportPipe.processRequest(HttpTransportPipe.java:83) > at > com.sun.xml.internal.ws.transport.DeferredTransportPipe.processRequest(DeferredTransportPipe.java:105) > at com.sun.xml.internal.ws.api.pipe.Fiber.__doRun(Fiber.java:587) > at com.sun.xml.internal.ws.api.pipe.Fiber._doRun(Fiber.java:546) > at com.sun.xml.internal.ws.api.pipe.Fiber.doRun(Fiber.java:531) > at com.sun.xml.internal.ws.api.pipe.Fiber.runSync(Fiber.java:428) > at com.sun.xml.internal.ws.client.Stub.process(Stub.java:211) > at > com.sun.xml.internal.ws.client.sei.SEIStub.doProcess(SEIStub.java:138) > at > com.sun.xml.internal.ws.client.sei.SyncMethodHandler.invoke(SyncMethodHandler.java:98) > at > com.sun.xml.internal.ws.client.sei.SyncMethodHandler.invoke(SyncMethodHandler.java:78) > at com.sun.xml.internal.ws.client.sei.SEIStub.invoke(SEIStub.java:110) > at com.sun.proxy.$Proxy27.findUser(Unknown Source) > at > org.ejbca.core.protocol.ws.client.FindUserCommand.execute(FindUserCommand.java:121) > ... 8 more > > > > > > ------------------------------------------------------------------------------ > Learn Graph Databases - Download FREE O'Reilly Book > "Graph Databases" is the definitive new guide to graph databases and their > applications. Written by three acclaimed leaders in the field, > this first edition is now available. Download your free book today! > http://p.sf.net/sfu/13534_NeoTech > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > ------------------------------------------------------------------------------ Learn Graph Databases - Download FREE O'Reilly Book "Graph Databases" is the definitive new guide to graph databases and their applications. Written by three acclaimed leaders in the field, this first edition is now available. Download your free book today! http://p.sf.net/sfu/13534_NeoTech _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Tomas G. <to...@pr...> - 2014-03-11 16:01:35
|
You need to check the JBoss section (assume you are using JBoss 5) in the install guide. Cheers, Tomas ********** PrimeKey Solutions AB Anderstorpsvägen 16, 171 54 Solna, Sweden Mob: +46 (0)707421096 Internet: www.primekey.se Twitter: twitter.com/primetomas ********** On 03/11/2014 10:45 AM, Ebtehal Hassan wrote: > Hi ; > > i would like to use client tool box in ejbca , but when i run this > command i get the following error: > > > ./ejbcaClientToolBox.sh EjbcaWsRaCli finduser USERNAME EQUALS superadmin > > > ./ejbcaClientToolBox.sh EjbcaWsRaCli finduser USERNAME EQUALS superadmin > com.sun.xml.internal.ws.client.ClientTransportException: The server sent > HTTP status code 302: Moved Temporarily > org.ejbca.ui.cli.ErrorAdminCommandException: > com.sun.xml.internal.ws.client.ClientTransportException: The server sent > HTTP status code 302: Moved Temporarily > at > org.ejbca.core.protocol.ws.client.FindUserCommand.execute(FindUserCommand.java:161) > at > org.ejbca.core.protocol.ws.client.ejbcawsracli.main(ejbcawsracli.java:36) > at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method) > at > sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:57) > at > sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43) > at java.lang.reflect.Method.invoke(Method.java:622) > at org.ejbca.ui.cli.EjbcaWsRaCli.execute(EjbcaWsRaCli.java:36) > at > org.ejbca.ui.cli.ClientToolBox.executeIfSelected(ClientToolBox.java:40) > at org.ejbca.ui.cli.ClientToolBox.main(ClientToolBox.java:70) > Caused by: com.sun.xml.internal.ws.client.ClientTransportException: The > server sent HTTP status code 302: Moved Temporarily > at > com.sun.xml.internal.ws.transport.http.client.HttpTransportPipe.checkStatusCode(HttpTransportPipe.java:196) > at > com.sun.xml.internal.ws.transport.http.client.HttpTransportPipe.process(HttpTransportPipe.java:168) > at > com.sun.xml.internal.ws.transport.http.client.HttpTransportPipe.processRequest(HttpTransportPipe.java:83) > at > com.sun.xml.internal.ws.transport.DeferredTransportPipe.processRequest(DeferredTransportPipe.java:105) > at com.sun.xml.internal.ws.api.pipe.Fiber.__doRun(Fiber.java:587) > at com.sun.xml.internal.ws.api.pipe.Fiber._doRun(Fiber.java:546) > at com.sun.xml.internal.ws.api.pipe.Fiber.doRun(Fiber.java:531) > at com.sun.xml.internal.ws.api.pipe.Fiber.runSync(Fiber.java:428) > at com.sun.xml.internal.ws.client.Stub.process(Stub.java:211) > at > com.sun.xml.internal.ws.client.sei.SEIStub.doProcess(SEIStub.java:138) > at > com.sun.xml.internal.ws.client.sei.SyncMethodHandler.invoke(SyncMethodHandler.java:98) > at > com.sun.xml.internal.ws.client.sei.SyncMethodHandler.invoke(SyncMethodHandler.java:78) > at com.sun.xml.internal.ws.client.sei.SEIStub.invoke(SEIStub.java:110) > at com.sun.proxy.$Proxy27.findUser(Unknown Source) > at > org.ejbca.core.protocol.ws.client.FindUserCommand.execute(FindUserCommand.java:121) > ... 8 more > > > > > > ------------------------------------------------------------------------------ > Learn Graph Databases - Download FREE O'Reilly Book > "Graph Databases" is the definitive new guide to graph databases and their > applications. Written by three acclaimed leaders in the field, > this first edition is now available. Download your free book today! > http://p.sf.net/sfu/13534_NeoTech > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Ebtehal H. <h.e...@ya...> - 2014-03-11 09:45:35
|
Hi ; i would like to use client tool box in ejbca , but when i run this command i get the following error: ./ejbcaClientToolBox.sh EjbcaWsRaCli finduser USERNAME EQUALS superadmin ./ejbcaClientToolBox.sh EjbcaWsRaCli finduser USERNAME EQUALS superadmin com.sun.xml.internal.ws.client.ClientTransportException: The server sent HTTP status code 302: Moved Temporarily org.ejbca.ui.cli.ErrorAdminCommandException: com.sun.xml.internal.ws.client.ClientTransportException: The server sent HTTP status code 302: Moved Temporarily at org.ejbca.core.protocol.ws.client.FindUserCommand.execute(FindUserCommand.java:161) at org.ejbca.core.protocol.ws.client.ejbcawsracli.main(ejbcawsracli.java:36) at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method) at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:57) at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43) at java.lang.reflect.Method.invoke(Method.java:622) at org.ejbca.ui.cli.EjbcaWsRaCli.execute(EjbcaWsRaCli.java:36) at org.ejbca.ui.cli.ClientToolBox.executeIfSelected(ClientToolBox.java:40) at org.ejbca.ui.cli.ClientToolBox.main(ClientToolBox.java:70) Caused by: com.sun.xml.internal.ws.client.ClientTransportException: The server sent HTTP status code 302: Moved Temporarily at com.sun.xml.internal.ws.transport.http.client.HttpTransportPipe.checkStatusCode(HttpTransportPipe.java:196) at com.sun.xml.internal.ws.transport.http.client.HttpTransportPipe.process(HttpTransportPipe.java:168) at com.sun.xml.internal.ws.transport.http.client.HttpTransportPipe.processRequest(HttpTransportPipe.java:83) at com.sun.xml.internal.ws.transport.DeferredTransportPipe.processRequest(DeferredTransportPipe.java:105) at com.sun.xml.internal.ws.api.pipe.Fiber.__doRun(Fiber.java:587) at com.sun.xml.internal.ws.api.pipe.Fiber._doRun(Fiber.java:546) at com.sun.xml.internal.ws.api.pipe.Fiber.doRun(Fiber.java:531) at com.sun.xml.internal.ws.api.pipe.Fiber.runSync(Fiber.java:428) at com.sun.xml.internal.ws.client.Stub.process(Stub.java:211) at com.sun.xml.internal.ws.client.sei.SEIStub.doProcess(SEIStub.java:138) at com.sun.xml.internal.ws.client.sei.SyncMethodHandler.invoke(SyncMethodHandler.java:98) at com.sun.xml.internal.ws.client.sei.SyncMethodHandler.invoke(SyncMethodHandler.java:78) at com.sun.xml.internal.ws.client.sei.SEIStub.invoke(SEIStub.java:110) at com.sun.proxy.$Proxy27.findUser(Unknown Source) at org.ejbca.core.protocol.ws.client.FindUserCommand.execute(FindUserCommand.java:121) ... 8 more |
|
From: Tomas G. <to...@pr...> - 2014-03-05 14:10:28
|
There is now a pre-installed Virtual Machine image with EJBCA Community 6.0.3 available for download. http://ejbca.org/ JBoss 7.1.1.GA, OpenJDK 7, MariaDB. Only 850MB, works with KVM, VirtualBox and VMware. Cheers, Tomas ********** PrimeKey Solutions AB Internet: www.primekey.se Twitter: twitter.com/primetomas ********** |
|
From: Tomas G. <to...@pr...> - 2014-03-03 14:03:52
|
Hi, We are pleased to announce the release of EJBCA Community version 6.0.4. This is a maintenance release with new features, improvements and bug fixes. In all 53 issues have been fixed, including all issues reported by the community for EJBCA 6.0.3. One of the fixes is a security fix. The security issue is rated as low, and can lead to excessive CPU usage, if exposed to untrusted networks. This issue was due to a bug in an Apache library we are using. * Noteworthy changes: - Support for Certificate Transparency, RFC6962 (EJBCA Enterprise only). - Support for JBoss EAP 6.2 that changed default behaviour when creating datasources. - SCEP GetCACaps command now works from iOS. - Ensure that OCSP RFC5019 responses with nonces are not cached. - Minor Command Line improvement. - Fixed most issues reported from installations of EJBCA 6.0.3. You can find the complete changelog in our issue tracker: https://jira.primekey.se/secure/ReleaseNote.jspa?projectId=10000&version=10647 * Known issues: - One test failure on DB2: https://jira.primekey.se/browse/ECA-3298 - OCSP request signer verification does an additional database lookup: https://jira.primekey.se/browse/ECA-3299 - Deployment on Windows does not work due to jboss-cli.bat arguments differing from jboss-cli.sh (half fixed, some remaining) Regards, PrimeKey EJBCA Team |
|
From: Tomas G. <to...@pr...> - 2014-03-03 12:49:49
|
Hmm, could not find it. Created https://jira.primekey.se/browse/ECA-3445 Anyhow, the old i1 should work there as well I guess. /Tomas On 03/03/2014 10:00 AM, Bruno Bonfils wrote: > On Thu 27 February, Tomas Gustavsson wrote: >> >> Oh, and I would recommend using the new slot label functionality instead >> of using "i1" > > > Any idea where to investigate? > > Thanks! > |
|
From: Bruno B. <as...@as...> - 2014-03-03 09:20:04
|
On Thu 27 February, Tomas Gustavsson wrote: > > Oh, and I would recommend using the new slot label functionality instead > of using "i1" Any idea where to investigate? Thanks! -- http://asyd.net/home/ - Home Page http://netvibes.com/asyd - Portal |
|
From: Bruno B. <as...@as...> - 2014-02-27 16:53:08
|
On Thu 27 February, Bruno Bonfils wrote: > On Thu 27 February, Tomas Gustavsson wrote: > > > > Oh, and I would recommend using the new slot label functionality instead > > of using "i1" > > Same issue (with label = 'EJBCA', verified in ckinfo output) and if provide a wrong label, I have a 'Token label 'something' not found', so I guess it's not the issue. -- http://asyd.net/home/ - Home Page http://netvibes.com/asyd - Portal |
|
From: Bruno B. <as...@as...> - 2014-02-27 16:39:48
|
On Thu 27 February, Tomas Gustavsson wrote: > > Oh, and I would recommend using the new slot label functionality instead > of using "i1" Same issue (with label = 'EJBCA', verified in ckinfo output) -- http://asyd.net/home/ - Home Page http://netvibes.com/asyd - Portal |
|
From: Bruno B. <as...@as...> - 2014-02-27 16:35:19
|
On Thu 27 February, Tomas Gustavsson wrote:
>
> When using clientToolBox JBoss is not involved at all.
Ok, just wanna be sure.
>
> You need to check the error message returned from nCipher PKCS#11, it
> will be in the stack trace that you only showed the first line from.
>
java.security.ProviderException: sun.security.pkcs11.wrapper.PKCS11Exception: CKR_FUNCTION_FAILED
at sun.security.pkcs11.P11KeyPairGenerator.generateKeyPair(P11KeyPairGenerator.java:323)
at java.security.KeyPairGenerator$Delegate.generateKeyPair(KeyPairGenerator.java:681)
at org.ejbca.util.keystore.KeyStoreContainerBase.generate(KeyStoreContainerBase.java:273)
at org.ejbca.util.keystore.KeyStoreContainerBase.generateRSA(KeyStoreContainerBase.java:196)
at org.ejbca.util.keystore.KeyStoreContainerBase.generate(KeyStoreContainerBase.java:226)
at org.ejbca.ui.cli.HSMKeyTool.doIt(HSMKeyTool.java:209)
at org.ejbca.ui.cli.HSMKeyTool.execute(HSMKeyTool.java:448)
at org.ejbca.ui.cli.PKCS11HSMKeyTool.execute(PKCS11HSMKeyTool.java:47)
at org.ejbca.ui.cli.ClientToolBox.executeIfSelected(ClientToolBox.java:40)
at org.ejbca.ui.cli.ClientToolBox.main(ClientToolBox.java:66)
Caused by: sun.security.pkcs11.wrapper.PKCS11Exception: CKR_FUNCTION_FAILED
at sun.security.pkcs11.wrapper.PKCS11.C_GenerateKeyPair(Native Method)
at sun.security.pkcs11.P11KeyPairGenerator.generateKeyPair(P11KeyPairGenerator.java:314)
... 9 more
I can also provide output of CKNFAST_DEBUG if that can help, last lines here:
pPrivateKeyTemplate[4]
CKA_TOKEN: true
CKA_PRIVATE: true
CKA_DECRYPT: true
Error: Generic stub command GenerateKeyPair returned 17
Error: Status_UnknownParameter
> Did you start pre-load loading all the cards first?
Yeah sure, works well.
By the way, we're running nFast drivers/softwares version 11.60, on Linux 64 bits.
Thanks for you help
--
http://asyd.net/home/ - Home Page
http://netvibes.com/asyd - Portal
|
|
From: Tomas G. <to...@pr...> - 2014-02-27 16:15:29
|
Oh, and I would recommend using the new slot label functionality instead of using "i1" On 02/27/2014 06:29 AM, Bruno Bonfils wrote: > Hello folks, > > I'm trying to have a CA managed by a nshield NCipher, here what I did : > > - create the RFS > - create a persistent OCS named "EJBCA" > > - uncomment all references to PKCS11 provider in web.properties > > When I try to create a key, using the following command: > > /opt/nfast/bin/preload -c EJBCA ./dist/clientToolBox/ejbcaClientToolBox.sh PKCS11HSMKeyTool generate /opt/nfast/toolkits/pkcs11/libcknfast.so 4096 defaultRoot i1 > > I have the following exception: > > java.security.ProviderException: sun.security.pkcs11.wrapper.PKCS11Exception: > > whatever the password I gave. > > Environnment: > > - JBoss 7.1.1 Final, with sun/security/pkcs11 added in JDK modules.xml, > otherwhise nCipher Token Provider was not found > - Oracle JDK 1.7.51 with JCE extension > > Note that I'm able to create a key using nCipher's tool generatekey, > with pkcs11 application. > > Thanks a lot for you help! > |
|
From: Tomas G. <to...@pr...> - 2014-02-27 16:14:40
|
When using clientToolBox JBoss is not involved at all. You need to check the error message returned from nCipher PKCS#11, it will be in the stack trace that you only showed the first line from. Did you start pre-load loading all the cards first? On 02/27/2014 06:29 AM, Bruno Bonfils wrote: > Hello folks, > > I'm trying to have a CA managed by a nshield NCipher, here what I did : > > - create the RFS > - create a persistent OCS named "EJBCA" > > - uncomment all references to PKCS11 provider in web.properties > > When I try to create a key, using the following command: > > /opt/nfast/bin/preload -c EJBCA ./dist/clientToolBox/ejbcaClientToolBox.sh PKCS11HSMKeyTool generate /opt/nfast/toolkits/pkcs11/libcknfast.so 4096 defaultRoot i1 > > I have the following exception: > > java.security.ProviderException: sun.security.pkcs11.wrapper.PKCS11Exception: > > whatever the password I gave. > > Environnment: > > - JBoss 7.1.1 Final, with sun/security/pkcs11 added in JDK modules.xml, > otherwhise nCipher Token Provider was not found > - Oracle JDK 1.7.51 with JCE extension > > Note that I'm able to create a key using nCipher's tool generatekey, > with pkcs11 application. > > Thanks a lot for you help! > |
|
From: Bruno B. <as...@as...> - 2014-02-27 14:47:05
|
Hello folks, I'm trying to have a CA managed by a nshield NCipher, here what I did : - create the RFS - create a persistent OCS named "EJBCA" - uncomment all references to PKCS11 provider in web.properties When I try to create a key, using the following command: /opt/nfast/bin/preload -c EJBCA ./dist/clientToolBox/ejbcaClientToolBox.sh PKCS11HSMKeyTool generate /opt/nfast/toolkits/pkcs11/libcknfast.so 4096 defaultRoot i1 I have the following exception: java.security.ProviderException: sun.security.pkcs11.wrapper.PKCS11Exception: whatever the password I gave. Environnment: - JBoss 7.1.1 Final, with sun/security/pkcs11 added in JDK modules.xml, otherwhise nCipher Token Provider was not found - Oracle JDK 1.7.51 with JCE extension Note that I'm able to create a key using nCipher's tool generatekey, with pkcs11 application. Thanks a lot for you help! -- http://asyd.net/home/ - Home Page http://netvibes.com/asyd - Portal |
|
From: Pushkar M. <pus...@st...> - 2014-02-24 21:56:28
|
Hi How can we use EJBCA to have utimaco hsm generate rsa keys -- Thank You Regards Pushkar Marathe Senior Software Engineer StrongAuth, Inc. 408-331-2000 Office pus...@st... www.strongauth.com ---------------- |