You can subscribe to this list here.
| 2001 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
(1) |
Dec
(3) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2002 |
Jan
(3) |
Feb
(2) |
Mar
(8) |
Apr
(3) |
May
(6) |
Jun
(1) |
Jul
(15) |
Aug
(6) |
Sep
|
Oct
(10) |
Nov
(2) |
Dec
(4) |
| 2003 |
Jan
(1) |
Feb
(7) |
Mar
(3) |
Apr
(6) |
May
(7) |
Jun
(5) |
Jul
(5) |
Aug
(25) |
Sep
(14) |
Oct
(2) |
Nov
|
Dec
(2) |
| 2004 |
Jan
(7) |
Feb
(4) |
Mar
(12) |
Apr
(16) |
May
(43) |
Jun
(56) |
Jul
(43) |
Aug
(40) |
Sep
(66) |
Oct
(12) |
Nov
(26) |
Dec
(10) |
| 2005 |
Jan
(13) |
Feb
(33) |
Mar
(16) |
Apr
(7) |
May
(10) |
Jun
(34) |
Jul
(41) |
Aug
(8) |
Sep
(4) |
Oct
(32) |
Nov
(20) |
Dec
(25) |
| 2006 |
Jan
(30) |
Feb
(101) |
Mar
(5) |
Apr
(75) |
May
(74) |
Jun
(22) |
Jul
(6) |
Aug
(70) |
Sep
(19) |
Oct
(21) |
Nov
(31) |
Dec
(50) |
| 2007 |
Jan
(15) |
Feb
(20) |
Mar
(24) |
Apr
(33) |
May
(13) |
Jun
(18) |
Jul
(13) |
Aug
(7) |
Sep
(63) |
Oct
(68) |
Nov
(29) |
Dec
(68) |
| 2008 |
Jan
(30) |
Feb
(33) |
Mar
(30) |
Apr
(103) |
May
(78) |
Jun
(48) |
Jul
(72) |
Aug
(24) |
Sep
(62) |
Oct
(63) |
Nov
(70) |
Dec
(37) |
| 2009 |
Jan
(34) |
Feb
(35) |
Mar
(64) |
Apr
(34) |
May
(34) |
Jun
(58) |
Jul
(30) |
Aug
(30) |
Sep
(46) |
Oct
(52) |
Nov
(12) |
Dec
(23) |
| 2010 |
Jan
(121) |
Feb
(18) |
Mar
(53) |
Apr
(62) |
May
(62) |
Jun
(20) |
Jul
(33) |
Aug
(20) |
Sep
(36) |
Oct
(35) |
Nov
(44) |
Dec
(63) |
| 2011 |
Jan
(19) |
Feb
(32) |
Mar
(94) |
Apr
(41) |
May
(47) |
Jun
(25) |
Jul
(34) |
Aug
(20) |
Sep
(9) |
Oct
(41) |
Nov
(33) |
Dec
(24) |
| 2012 |
Jan
(12) |
Feb
(36) |
Mar
(48) |
Apr
(32) |
May
(20) |
Jun
(15) |
Jul
(32) |
Aug
(13) |
Sep
(33) |
Oct
(54) |
Nov
(25) |
Dec
(16) |
| 2013 |
Jan
(45) |
Feb
(39) |
Mar
(38) |
Apr
(50) |
May
(29) |
Jun
(30) |
Jul
(33) |
Aug
(12) |
Sep
(9) |
Oct
(25) |
Nov
(29) |
Dec
(20) |
| 2014 |
Jan
(25) |
Feb
(19) |
Mar
(16) |
Apr
(33) |
May
(27) |
Jun
(37) |
Jul
(29) |
Aug
(27) |
Sep
(37) |
Oct
(58) |
Nov
(109) |
Dec
(26) |
| 2015 |
Jan
(4) |
Feb
(35) |
Mar
(22) |
Apr
(35) |
May
(28) |
Jun
(20) |
Jul
(4) |
Aug
(16) |
Sep
(37) |
Oct
(13) |
Nov
(13) |
Dec
(14) |
| 2016 |
Jan
(22) |
Feb
(7) |
Mar
(23) |
Apr
(30) |
May
(10) |
Jun
(10) |
Jul
(15) |
Aug
(12) |
Sep
(22) |
Oct
(31) |
Nov
(5) |
Dec
(5) |
| 2017 |
Jan
(30) |
Feb
(25) |
Mar
(28) |
Apr
(4) |
May
(19) |
Jun
(13) |
Jul
(7) |
Aug
(1) |
Sep
(2) |
Oct
(5) |
Nov
(12) |
Dec
(2) |
| 2018 |
Jan
(7) |
Feb
|
Mar
(7) |
Apr
(2) |
May
(8) |
Jun
(18) |
Jul
(6) |
Aug
(3) |
Sep
(15) |
Oct
(33) |
Nov
(13) |
Dec
(7) |
| 2019 |
Jan
(5) |
Feb
(7) |
Mar
(30) |
Apr
(5) |
May
(4) |
Jun
(69) |
Jul
(86) |
Aug
(22) |
Sep
(6) |
Oct
(7) |
Nov
(5) |
Dec
(3) |
| 2020 |
Jan
(10) |
Feb
(12) |
Mar
(22) |
Apr
(5) |
May
(1) |
Jun
(4) |
Jul
(6) |
Aug
|
Sep
(9) |
Oct
|
Nov
|
Dec
(1) |
| 2021 |
Jan
(4) |
Feb
(11) |
Mar
(7) |
Apr
(7) |
May
|
Jun
(3) |
Jul
(10) |
Aug
(6) |
Sep
|
Oct
|
Nov
(18) |
Dec
(2) |
| 2022 |
Jan
(1) |
Feb
(1) |
Mar
|
Apr
|
May
|
Jun
(2) |
Jul
|
Aug
(4) |
Sep
|
Oct
|
Nov
|
Dec
|
| 2023 |
Jan
|
Feb
|
Mar
|
Apr
(1) |
May
(1) |
Jun
|
Jul
|
Aug
(5) |
Sep
|
Oct
|
Nov
|
Dec
|
|
From: Tomas G. <to...@pr...> - 2013-10-21 15:03:10
|
It's programming, everything is possible :-). Realistically though, probably not. Jboss 5.1.0.ga does not start on JDK 7. Cheers, Tomas "Michael Ströder" <mi...@st...> wrote: >HI! > >We're running ejbca 4.0.11 with jboss-5.1.0.GA. >Any chance to get this setup working with an update to OpenJDK 7? > >Ciao, Michael. > > > >------------------------------------------------------------------------------ >October Webinars: Code for Performance >Free Intel webinars can help you accelerate application performance. >Explore tips for MPI, OpenMP, advanced profiling, and more. Get the >most from >the latest Intel processors and coprocessors. See abstracts and >register > >http://pubads.g.doubleclick.net/gampad/clk?id=60135031&iu=/4140/ostg.clktrk >_______________________________________________ >Ejbca-develop mailing list >Ejb...@li... >https://lists.sourceforge.net/lists/listinfo/ejbca-develop -- PrimeKey Solutions AB Internet: www.primekey.se Twitter: twitter.com/primekeyPKI Mob: +46 (0)707421096 |
|
From: Tomas G. <to...@pr...> - 2013-10-21 12:43:10
|
Very interesting! Thanks for the update. Cheers, Tomas On 10/21/2013 02:20 PM, Peut Kotze wrote: > Hi Tomas > Just to let you know, I finally solved the "apparent" HTTP version problem. > I have used Branko Majic's excellent guide to setup EJBCA. He uses CA > names with spaces "Example Server CA" in his guide. > I created a trustpoint in Cisco with the exact same CA name by using quotes: > # crypto pki trustpoint "Example Server CA" > # ... > # ... > # crypto pki authenticate "Example Server CA" > However, when Cisco sends the SCEP request to authenticate the CA, the > request on the wire is formatted as follows: > > .../scep/pkiclient.exe?operation=GetCACert&message=Example Server CA > HTTP/1.0 > > Upon which the EJBCA server sends back the reply: > > HTTP/1.1 505 HTTP Version Not Supported > > This is because EJBCA interpret the last part of the message as the HTTP > protocol definition part: " Server CA HTTP/1.0". > I dont' know if it is Cisco who is supposed to insert quotes in > names containing spaces, or if it is the java connector the should read > everything until it gets to the HTTP part. > But my problem is solved, it is due to incompatibility when using CA > names containing spaces between EJBCA and Cisco, I hace changed my CA > authority names to single names not containing spaces and everything is > working fine now. > Thank you for your time and effort. > Best regards > Peut > PS. Thanks to Murphy it happens to be that Cisco uses HTTP/1.0 in their > requests, throwing me totally off track. > > > ------------------------------------------------------------------------------ > October Webinars: Code for Performance > Free Intel webinars can help you accelerate application performance. > Explore tips for MPI, OpenMP, advanced profiling, and more. Get the most from > the latest Intel processors and coprocessors. See abstracts and register > > http://pubads.g.doubleclick.net/gampad/clk?id=60135031&iu=/4140/ostg.clktrk > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Peut K. <pe...@as...> - 2013-10-21 12:20:24
|
Hi Tomas Just to let you know, I finally solved the "apparent" HTTP version problem. I have used Branko Majic's excellent guide to setup EJBCA. He uses CA names with spaces "Example Server CA" in his guide. I created a trustpoint in Cisco with the exact same CA name by using quotes: # crypto pki trustpoint "Example Server CA" # ... # ... # crypto pki authenticate "Example Server CA" However, when Cisco sends the SCEP request to authenticate the CA, the request on the wire is formatted as follows: .../scep/pkiclient.exe?operation=GetCACert&message=Example Server CA HTTP/1.0 Upon which the EJBCA server sends back the reply: HTTP/1.1 505 HTTP Version Not Supported This is because EJBCA interpret the last part of the message as the HTTP protocol definition part: " Server CA HTTP/1.0". I dont' know if it is Cisco who is supposed to insert quotes in names containing spaces, or if it is the java connector the should read everything until it gets to the HTTP part. But my problem is solved, it is due to incompatibility when using CA names containing spaces between EJBCA and Cisco, I hace changed my CA authority names to single names not containing spaces and everything is working fine now. Thank you for your time and effort. Best regards Peut PS. Thanks to Murphy it happens to be that Cisco uses HTTP/1.0 in their requests, throwing me totally off track. |
|
From: Michael S. <mi...@st...> - 2013-10-21 09:49:40
|
HI! We're running ejbca 4.0.11 with jboss-5.1.0.GA. Any chance to get this setup working with an update to OpenJDK 7? Ciao, Michael. |
|
From: Luc P. <luc...@gm...> - 2013-10-19 18:00:08
|
Hello,
I want to use an HSM to create a CA. When I create it with the admin-GUI i
have this error :
"CA token is off-line, Please activate the token before continuing"
But, when I use the CLI to generate a new key, It works fine :
./ejbcaClientToolBox.sh PKCS11HSMKeyTool generate /usr/local/lib/libhsm.so
2048 defaultkey 0
I don't understand why I can't create a new CA with the HSM. Can you help
me please ?
This is my log :
[#|2013-10-19T19:31:52.905+0200|INFO|sun-appserver2.1|javax.enterprise.system.stream.out|_ThreadID=38;_ThreadName=httpSSLWorkerThread-8443-1;|19:31:52.905
[httpSSLWorkerThread-8443-1] DEBUG org.ejbca.util.keystore.KeyTools -
{SLOT_ID=0, PKCS11_NATIVE_MODULE=/usr/local/lib/libcryptosec.so}
|#]
[#|2013-10-19T19:31:52.905+0200|INFO|sun-appserver2.1|javax.enterprise.system.stream.out|_ThreadID=38;_ThreadName=httpSSLWorkerThread-8443-1;|19:31:52.905
[httpSSLWorkerThread-8443-1] INFO org.ejbca.util.keystore.KeyTools - Using
SUN PKCS11 provider: sun.security.pkcs11.SunPKCS11
|#]
[#|2013-10-19T19:31:52.906+0200|INFO|sun-appserver2.1|javax.enterprise.system.stream.out|_ThreadID=38;_ThreadName=httpSSLWorkerThread-8443-1;|19:31:52.906
[httpSSLWorkerThread-8443-1] ERROR org.ejbca.util.keystore.KeyTools - Error
constructing pkcs11 provider: null
|#]
[#|2013-10-19T19:31:52.908+0200|INFO|sun-appserver2.1|javax.enterprise.system.stream.out|_ThreadID=38;_ThreadName=httpSSLWorkerThread-8443-1;|19:31:52.908
[httpSSLWorkerThread-8443-1] ERROR o.e.c.m.c.c.CATokenContainerImpl - Error
contructing CA Token (setting to null):
org.ejbca.core.model.ca.catoken.CATokenOfflineException: Erreur pendant la
cr?ation d'un token d'AC.
at org.ejbca.util.keystore.P11Slot.getInstance(P11Slot.java:192)
~[ejbca-util.jar:na]
at org.ejbca.util.keystore.P11Slot.getInstance(P11Slot.java:146)
~[ejbca-util.jar:na]
at
org.ejbca.core.model.ca.catoken.PKCS11CAToken.init(PKCS11CAToken.java:132)
~[ejbca-util.jar:na]
at
org.ejbca.core.model.ca.catoken.CATokenContainerImpl.getCAToken(CATokenContainerImpl.java:987)
[ejbca-util.jar:na]
at
org.ejbca.core.model.ca.catoken.CATokenContainerImpl.activate(CATokenContainerImpl.java:300)
[ejbca-util.jar:na]
at
org.ejbca.core.ejb.ca.caadmin.CAAdminSessionBean.createCA(CAAdminSessionBean.java:249)
[ejbca-ejb_jar/:na]
at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
~[na:1.6.0_26]
at
sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:39)
~[na:1.6.0_26]
at
sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:25)
~[na:1.6.0_26]
at java.lang.reflect.Method.invoke(Method.java:597) ~[na:1.6.0_26]
at
com.sun.enterprise.security.application.EJBSecurityManager.runMethod(EJBSecurityManager.java:1011)
[appserv-rt.jar:9.1]
at com.sun.enterprise.security.SecurityUtil.invoke(SecurityUtil.java:175)
[appserv-rt.jar:9.1]
at
com.sun.ejb.containers.BaseContainer.invokeTargetBeanMethod(BaseContainer.java:2929)
[appserv-rt.jar:9.1]
at com.sun.ejb.containers.BaseContainer.intercept(BaseContainer.java:4020)
[appserv-rt.jar:9.1]
at
com.sun.ejb.containers.EJBLocalObjectInvocationHandler.invoke(EJBLocalObjectInvocationHandler.java:197)
[appserv-rt.jar:9.1]
at
com.sun.ejb.containers.EJBLocalObjectInvocationHandlerDelegate.invoke(EJBLocalObjectInvocationHandlerDelegate.java:83)
[appserv-rt.jar:9.1]
at $Proxy63.createCA(Unknown Source) [na:na]
at
org.ejbca.ui.web.admin.cainterface.CADataHandler.createCA(CADataHandler.java:119)
[classes/:na]
at org.apache.jsp.ca.editcas.editcas_jsp._jspService(editcas_jsp.java from
:871) [na:na]
at org.apache.jasper.runtime.HttpJspBase.service(HttpJspBase.java:109)
[appserv-rt.jar:9.1]
at javax.servlet.http.HttpServlet.service(HttpServlet.java:847)
[javaee.jar:9.1]
at
org.apache.jasper.servlet.JspServletWrapper.service(JspServletWrapper.java:389)
[appserv-rt.jar:9.1]
at org.apache.jasper.servlet.JspServlet.serviceJspFile(JspServlet.java:486)
[appserv-rt.jar:9.1]
at org.apache.jasper.servlet.JspServlet.service(JspServlet.java:380)
[appserv-rt.jar:9.1]
at javax.servlet.http.HttpServlet.service(HttpServlet.java:847)
[javaee.jar:9.1]
at
org.apache.catalina.core.ApplicationFilterChain.servletService(ApplicationFilterChain.java:427)
[appserv-rt.jar:9.1]
at
org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:333)
[appserv-rt.jar:9.1]
at
org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:214)
[appserv-rt.jar:9.1]
at
org.ejbca.ui.web.admin.ProxiedAuthenticationFilter.doFilter(ProxiedAuthenticationFilter.java:103)
[classes/:na]
at
org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:246)
[appserv-rt.jar:9.1]
at
org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:214)
[appserv-rt.jar:9.1]
at
org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:313)
[appserv-rt.jar:9.1]
at
org.apache.catalina.core.StandardContextValve.invokeInternal(StandardContextValve.java:287)
[appserv-rt.jar:9.1]
at
org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:218)
[appserv-rt.jar:9.1]
at
org.apache.catalina.core.StandardPipeline.doInvoke(StandardPipeline.java:648)
[appserv-rt.jar:9.1]
at
org.apache.catalina.core.StandardPipeline.doInvoke(StandardPipeline.java:593)
[appserv-rt.jar:9.1]
at com.sun.enterprise.web.WebPipeline.invoke(WebPipeline.java:94)
[appserv-rt.jar:9.1]
at
com.sun.enterprise.web.PESessionLockingStandardPipeline.invoke(PESessionLockingStandardPipeline.java:98)
[appserv-rt.jar:9.1]
at
org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:222)
[appserv-rt.jar:9.1]
at
org.apache.catalina.core.StandardPipeline.doInvoke(StandardPipeline.java:648)
[appserv-rt.jar:9.1]
at
org.apache.catalina.core.StandardPipeline.doInvoke(StandardPipeline.java:593)
[appserv-rt.jar:9.1]
at
org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:587)
[appserv-rt.jar:9.1]
at org.apache.catalina.core.ContainerBase.invoke(ContainerBase.java:1093)
[appserv-rt.jar:9.1]
at
org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:166)
[appserv-rt.jar:9.1]
at
org.apache.catalina.core.StandardPipeline.doInvoke(StandardPipeline.java:648)
[appserv-rt.jar:9.1]
at
org.apache.catalina.core.StandardPipeline.doInvoke(StandardPipeline.java:593)
[appserv-rt.jar:9.1]
at
org.apache.catalina.core.StandardPipeline.invoke(StandardPipeline.java:587)
[appserv-rt.jar:9.1]
at org.apache.catalina.core.ContainerBase.invoke(ContainerBase.java:1093)
[appserv-rt.jar:9.1]
at org.apache.coyote.tomcat5.CoyoteAdapter.service(CoyoteAdapter.java:291)
[appserv-rt.jar:9.1]
at
com.sun.enterprise.web.connector.grizzly.DefaultProcessorTask.invokeAdapter(DefaultProcessorTask.java:666)
[appserv-rt.jar:9.1]
at
com.sun.enterprise.web.connector.grizzly.DefaultProcessorTask.doProcess(DefaultProcessorTask.java:597)
[appserv-rt.jar:9.1]
at
com.sun.enterprise.web.connector.grizzly.DefaultProcessorTask.process(DefaultProcessorTask.java:872)
[appserv-rt.jar:9.1]
at
com.sun.enterprise.web.connector.grizzly.DefaultReadTask.executeProcessorTask(DefaultReadTask.java:341)
[appserv-rt.jar:9.1]
at
com.sun.enterprise.web.connector.grizzly.ssl.SSLReadTask.process(SSLReadTask.java:444)
[appserv-rt.jar:9.1]
at
com.sun.enterprise.web.connector.grizzly.ssl.SSLReadTask.doTask(SSLReadTask.java:230)
[appserv-rt.jar:9.1]
at com.sun.enterprise.web.connector.grizzly.TaskBase.run(TaskBase.java:264)
[appserv-rt.jar:9.1]
at
com.sun.enterprise.web.connector.grizzly.ssl.SSLWorkerThread.run(SSLWorkerThread.java:106)
[appserv-rt.jar:9.1]
|#]
--
Pallavidino Luc Tél. : +33-6-8070-3133
Mail :
luc...@gm... <pal...@ho...>
Ingénieur en monétique et sécurité des systèmes
|
|
From: Peut K. <pe...@as...> - 2013-10-18 10:43:31
|
Thanks Tomas, I'll have a look at the tomcat docs then rather... Cheers Peut |
|
From: Tomas G. <to...@pr...> - 2013-10-18 10:12:36
|
Sounds very strange. I have enrolled Cisco before, check the Guides section at ejbca.org. You can search tomcat documentation regarding http 1.0, the server.xml is just plain tomcat config. The JBoss 6 series (old one) is quite bad, we do not recommend it. You may have problems deploying to it, although it could work we do not test on it commonly. (we are looing ahead for JBoss 7 support later this year) Cheers, Tomas On 10/18/2013 12:05 PM, Peut Kotze wrote: > Hallo Tomas > > Thank you for the reply. I have no idea what to replace the > coyote.http11.http11Protocol with in the server.xml config. > > What I will try is to replace JBoss 5.1.0 with JBoss 6.1.0-final and build a > new server leaving the rest of my configuration as is: > Ubuntu 12.04 > EJBCA 4.0.16 > JBOSS 6.1.0-final <<< > JAVA-6-JDK > > Just to be100% sure I checked the error again using WireShark to inspect the > traffic: > After adding a new Trustpoint to Cisco, the command to authenticate the CA > "crypto ca authenticate MYCA" sends out a request in HTTP 1.0 format. EJBCA > receives the request and sends back an error stating that it does not > support HTTP vesion 1.0. > > Regards > Peut > > > ------------------------------------------------------------------------------ > October Webinars: Code for Performance > Free Intel webinars can help you accelerate application performance. > Explore tips for MPI, OpenMP, advanced profiling, and more. Get the most from > the latest Intel processors and coprocessors. See abstracts and register > > http://pubads.g.doubleclick.net/gampad/clk?id=60135031&iu=/4140/ostg.clktrk > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Peut K. <pe...@as...> - 2013-10-18 10:05:40
|
Hallo Tomas Thank you for the reply. I have no idea what to replace the coyote.http11.http11Protocol with in the server.xml config. What I will try is to replace JBoss 5.1.0 with JBoss 6.1.0-final and build a new server leaving the rest of my configuration as is: Ubuntu 12.04 EJBCA 4.0.16 JBOSS 6.1.0-final <<< JAVA-6-JDK Just to be100% sure I checked the error again using WireShark to inspect the traffic: After adding a new Trustpoint to Cisco, the command to authenticate the CA "crypto ca authenticate MYCA" sends out a request in HTTP 1.0 format. EJBCA receives the request and sends back an error stating that it does not support HTTP vesion 1.0. Regards Peut |
|
From: Tomas G. <to...@pr...> - 2013-10-18 06:33:24
|
I have not seen this before, even with Cisco equipment. You can change configuration of the connector if you like. It is defined in EJBCA in src/appserver/jboss/tomcat60jboss5/server.xml and with "ant deploy" it is copied to jboss_home/server/default/deploy/jboss-web/server.xml. Cheers, Tomas On 10/17/2013 03:20 PM, Peut Kotze wrote: > Hi > I configured Cisco routers to enroll to EJBCA using scep, but the > request fails with an error on the Cisco side. WireShark shows the CISCO > request ends with HTTP/1.0 followed by an error reply from EJBCA stating: > HTTP/1.1 505 HTTP Version Not Supported > Apache-Coyote/1.1 > Connection: Close > On the Apache site they claim that their coyote.http11 connector DOES > support HTTP 1.0 and will gracefully fallback to HTTP 1.0 if needed. > Is their any way to solve this by changing the EJBCA / JBOSS / > Apache configurations on the CA Server? > My current setup: > EJBCA 4.0.16 > JBOSS 5.1.0.GA > Ubuntu 12.04 > Best Regards > Peut Kotze > PS. Thank you for a great product. > > > ------------------------------------------------------------------------------ > October Webinars: Code for Performance > Free Intel webinars can help you accelerate application performance. > Explore tips for MPI, OpenMP, advanced profiling, and more. Get the most from > the latest Intel processors and coprocessors. See abstracts and register > > http://pubads.g.doubleclick.net/gampad/clk?id=60135031&iu=/4140/ostg.clktrk > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Peut K. <pe...@as...> - 2013-10-17 13:20:55
|
Hi I configured Cisco routers to enroll to EJBCA using scep, but the request fails with an error on the Cisco side. WireShark shows the CISCO request ends with HTTP/1.0 followed by an error reply from EJBCA stating: HTTP/1.1 505 HTTP Version Not Supported Apache-Coyote/1.1 Connection: Close On the Apache site they claim that their coyote.http11 connector DOES support HTTP 1.0 and will gracefully fallback to HTTP 1.0 if needed. Is their any way to solve this by changing the EJBCA / JBOSS / Apache configurations on the CA Server? My current setup: EJBCA 4.0.16 JBOSS 5.1.0.GA Ubuntu 12.04 Best Regards Peut Kotze PS. Thank you for a great product. |
|
From: Tomas G. <to...@pr...> - 2013-10-10 14:12:13
|
Hi, I have written the third blog post in the series about what's new in EJBCA 6. Enjoy... http://blog.ejbca.org/2013/10/whats-new-in-ejbca-6-part-3-internal.html Cheers, Tomas -- ********** PrimeKey Solutions AB Anderstorpsvägen 16, 171 54 Solna, Sweden Mob: +46 (0)707421096 Internet: www.primekey.se Twitter: twitter.com/primekeyPKI ********** |
|
From: Tomas G. <to...@pr...> - 2013-09-27 13:34:06
|
On 09/25/2013 04:22 PM, Bruno Bonfils wrote: > Hello folks, > > I have some questions about SCEP support in EJBCA, > > according, modules/externalra-scep/src/org/ejbca/extra/ra/ScepRAServlet.java, > only the following operations are supported in EJBCA SCEP : > - GetCACert, GetCACertChain, GetCACaps, PKIOperation (for certificate signing) are supported > - GetCert is NOT supported Correct. Is not getCert a part of PKIOperation right? PKIOperation currently supports PKCSReq and GetCertInitial (they are the same), and GetCRL, but not GetCert. > However, in modules/ejbca-scep-war/src/org/ejbca/ui/web/protocol/ScepServlet.java > (it's the code of standalone SCEP responder, right?) there is the > following comments: It is the code of the internal SCEP responder, available directly against the CA. > > * 4. branch to different actions depending on the type of the message: > * - PKCSReq > * - GetCertInitial > * - GetCert > > but I can't find code about GetCert and GetCertInitial, are they > supported? Correct, it is not supported, see above answer. > > And a last question about the Standalone SCEP responser, can I use CA > identifier to request certificates from differents CA using a single > SCEP server when createOrEditUser is in true mode? The Scep RA server will get CA from "reqmsg.IssuerDN", and if that is not found (or matching a mapping in scep.properties) the default CA. > > Thanks you! > |
|
From: Bruno B. <as...@as...> - 2013-09-26 14:53:10
|
On Thu 26 September, Tomas Gustavsson wrote: > > Yes only those messages are available ouf of the box. > > The External RA is probably not useful for driving a GUI, due to the > polling lag. This is why these other things have not been implemented, > i.e. no-one has requested them. But the idea of RA is client of CA is very nice, that's why I'm investing around Ext RA API. > In most production environments things like available CAs are so static > it is much easier to configure this in the external RA application. Yeah indeed, was just an example. > > Here is described how to add new messages: > http://ejbca.org/externalra.html#External%20RA%20API%20Clients Oh sorry, I miss this chapter (or to be brank doesn't understand it before looking at the source code). Very thanks! -- http://asyd.net/home/ - Home Page http://netvibes.com/asyd - Portal |
|
From: Tomas G. <to...@pr...> - 2013-09-26 14:24:47
|
Yes only those messages are available ouf of the box. The External RA is probably not useful for driving a GUI, due to the polling lag. This is why these other things have not been implemented, i.e. no-one has requested them. In most production environments things like available CAs are so static it is much easier to configure this in the external RA application. Here is described how to add new messages: http://ejbca.org/externalra.html#External%20RA%20API%20Clients Cheers, Tomas On 09/26/2013 04:14 PM, Bruno Bonfils wrote: > Hello again, > > I have some question about the External RA API. Can you confirm only > these functions are available at the moment are in > org.ejbca.extca.caservice.processor. > > What do you think to provides some other methods, like getAvailableCAs, > search for a certificate, etc. do you think it's not the goal of a RA, > or they are just not implemented, in that case how is diffucult to > create a new message type? > > Thanks you very much! > |
|
From: Bruno B. <as...@as...> - 2013-09-26 14:14:44
|
Hello again, I have some question about the External RA API. Can you confirm only these functions are available at the moment are in org.ejbca.extca.caservice.processor. What do you think to provides some other methods, like getAvailableCAs, search for a certificate, etc. do you think it's not the goal of a RA, or they are just not implemented, in that case how is diffucult to create a new message type? Thanks you very much! -- http://asyd.net/home/ - Home Page http://netvibes.com/asyd - Portal |
|
From: Bruno B. <as...@as...> - 2013-09-25 14:40:07
|
Hello folks, I have some questions about SCEP support in EJBCA, according, modules/externalra-scep/src/org/ejbca/extra/ra/ScepRAServlet.java, only the following operations are supported in EJBCA SCEP : - GetCACert, GetCACertChain, GetCACaps, PKIOperation (for certificate signing) are supported - GetCert is NOT supported However, in modules/ejbca-scep-war/src/org/ejbca/ui/web/protocol/ScepServlet.java (it's the code of standalone SCEP responder, right?) there is the following comments: * 4. branch to different actions depending on the type of the message: * - PKCSReq * - GetCertInitial * - GetCert but I can't find code about GetCert and GetCertInitial, are they supported? And a last question about the Standalone SCEP responser, can I use CA identifier to request certificates from differents CA using a single SCEP server when createOrEditUser is in true mode? Thanks you! -- http://asyd.net/home/ - Home Page http://netvibes.com/asyd - Portal |
|
From: Tomas G. <to...@pr...> - 2013-09-10 16:12:01
|
EJBCA 4 will not work with Glassfish 3 without programming effort. EJBCA 6 should in principle be easier to deploy on Glassfish 3, but it will not be tested with that when it comes out. Cheers, Tomas ********** PrimeKey Solutions AB Internet: www.primekey.se Twitter: twitter.com/primekeyPKI ********** On 09/10/2013 05:35 PM, Miguel Angel Robledo wrote: > Hi, > > I need install ejbca on Glassfish appserver. I deployed successful in > Glassfish version 2 but I have the next message un Glassfish version 3 > when deploy: > > /remote failure: Error occurred during deployment: Exception while > deploying the app [ejbca] : Unable to locate the DTD to validate your > deployment descriptor file [META-INF/sun-ejb-jar.xml] in archive > [ejbca-ws-ejb_jar]. Please make sure the DOCTYPE is correct (no typo in > public ID or system ID) and you have proper access to the Internet.. > Please see server.log for more details.// > //Command deploy failed.// > / > Is compatible ejbca with the glassfishv3's requirement? > > Regards, > > Miguel > > -- > Ing. Miguel Angel Robledo > Infraestructura de Firma Digital > Secretaría de Tecnologías para la Gestión > Ministerio de Gobierno y Reforma del Estado > Provincia de Santa Fe > San Martín 2466 3° Piso (S3000FSB) Santa Fe > +54 342 4508700/4574891 int 5132 > > > > ------------------------------------------------------------------------------ > How ServiceNow helps IT people transform IT departments: > 1. Consolidate legacy IT systems to a single system of record for IT > 2. Standardize and globalize service processes across IT > 3. Implement zero-touch automation to replace manual, redundant tasks > http://pubads.g.doubleclick.net/gampad/clk?id=51271111&iu=/4140/ostg.clktrk > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Miguel A. R. <mar...@sa...> - 2013-09-10 15:36:08
|
Hi, I need install ejbca on Glassfish appserver. I deployed successful in Glassfish version 2 but I have the next message un Glassfish version 3 when deploy: /remote failure: Error occurred during deployment: Exception while deploying the app [ejbca] : Unable to locate the DTD to validate your deployment descriptor file [META-INF/sun-ejb-jar.xml] in archive [ejbca-ws-ejb_jar]. Please make sure the DOCTYPE is correct (no typo in public ID or system ID) and you have proper access to the Internet.. Please see server.log for more details.// //Command deploy failed.// / Is compatible ejbca with the glassfishv3's requirement? Regards, Miguel -- Ing. Miguel Angel Robledo Infraestructura de Firma Digital Secretaría de Tecnologías para la Gestión Ministerio de Gobierno y Reforma del Estado Provincia de Santa Fe San Martín 2466 3° Piso (S3000FSB) Santa Fe +54 342 4508700/4574891 int 5132 |
|
From: Tomas G. <to...@pr...> - 2013-09-05 18:04:50
|
There is now "What's new in EJBCA 6. Part 2" up on blog.ejbca.org. CMP aliases and GUI configuration, as many different CMP clients as you can handle. http://blog.ejbca.org/2013/09/whats-new-in-ejbca-6-part-2-cmp-aliases.html Kind regards, Tomas Gustavsson ********** PrimeKey Solutions AB Anderstorpsvägen 16, 171 54 Solna, Sweden Mob: +46 (0)707421096 Internet: www.primekey.se Twitter: twitter.com/primekeyPKI ********** |
|
From: Tomas G. <to...@pr...> - 2013-09-02 07:32:17
|
Hi, You can find information in the User Guide. http://ejbca.org/userguide.html#Administrator%20roles There is a list of common mistakes here: http://wiki.ejbca.org/ejbca-admin#toc11 Cheers, Tomas ********** PrimeKey Solutions AB Anderstorpsvägen 16, 171 54 Solna, Sweden Mob: +46 (0)707421096 Internet: www.primekey.se Twitter: twitter.com/primekeyPKI ********** On 08/29/2013 06:26 PM, Miguel Angel Robledo wrote: > Hi, > > I need to create a new user with administrator profile. I have installed > EJBCA with glassfish as application server. > > I created a new personal end entity certificate and added this to the > group "Temporary Super Administrator Group" associating the user by > certificate number but I can not access. When I try to access the > generated certificate does not allow me access. > > I wanted to know the steps needed to create a new administrative user, > of course thank you very much. > > Thanks > |
|
From: Miguel A. R. <mar...@sa...> - 2013-08-29 16:51:47
|
Hi, I need to create a new user with administrator profile. I have installed EJBCA with glassfish as application server. I created a new personal end entity certificate and added this to the group "Temporary Super Administrator Group" associating the user by certificate number but I can not access. When I try to access the generated certificate does not allow me access. I wanted to know the steps needed to create a new administrative user, of course thank you very much. Thanks -- Ing. Miguel Angel Robledo Infraestructura de Firma Digital Secretaría de Tecnologías para la Gestión Ministerio de Gobierno y Reforma del Estado Provincia de Santa Fe San Martín 2466 3° Piso (S3000FSB) Santa Fe +54 342 4508700/4574891 int 5132 |
|
From: Tomas G. <to...@pr...> - 2013-08-28 12:21:59
|
Hi,
We use this class in performance tests. We have not seen any issues with
it so far.
Cheers,
Tomas
On 08/24/2013 01:43 AM, Jing Xu wrote:
> Hi everyone,
>
> I am developing a software testing tool to detect thread stress
> vulnerability of server application. And our tool detects the
> vulnerability on ejbca in following function in
> java.org.ejbca.util.PerformanceTest.TestInstance:
>
> public void run(){
>
> PerformanceTest.this.log.info
> <http://performancetest.this.log.info/>("Thread nr " + this.nr
> <http://this.nr/> + " started.");
>
> while (true) {
>
> try {
>
> final long startTime=new Date().getTime();
>
> Command failingCommand=null;
>
> for (int i=0; failingCommand == null && i < this.commands.length;
> i++) {
>
> if (this.maxWaitTime > 0) {
>
> final int waitTime=(int)(this.maxWaitTime *
> PerformanceTest.this.random.nextFloat());
>
> if (waitTime > 0) {
>
> synchronized (this) {
>
> wait(waitTime);
>
> }
>
> this.statistic.addTime("Time waiting between jobs",waitTime);
>
> }
>
> }
>
> final Command command=this.commands[i];
>
> final JobRunner jobRunner=new JobRunner(command);
>
> if (!jobRunner.execute()) {
>
> failingCommand=command;
>
> }
>
>
> this.statistic.addTime(command.getJobTimeDescription(),jobRunner.getTimeConsumed());
>
> }
>
> String sResult="Test in thread " + this.nr <http://this.nr/> + "
> completed ";
>
> if (failingCommand == null) {
>
> this.statistic.taskFinished();
>
> sResult+="successfully";
>
> }
>
> else {
>
> this.statistic.taskFailed();
>
> sResult+="but failed when the command '" +
> failingCommand.getClass().getCanonicalName() + "' was executed";
>
> }
>
> sResult+=". The time it took was " + (new Date().getTime() -
> startTime) + " ms.";
>
> if (failingCommand == null) {
>
> PerformanceTest.this.log.info
> <http://performancetest.this.log.info/>(sResult);
>
> }
>
> else {
>
> PerformanceTest.this.log.error(sResult);
>
> }
>
> }
>
> catch ( Throwable t) {
>
> this.statistic.taskFailed();
>
> PerformanceTest.this.log.error("Exeption in thread " + this.nr
> <http://this.nr/> + ".",t);
>
> }
>
> }
>
> }
>
> Is it possible that jobRunner.execute() will create unbounded number of
> threads? Thanks advanced for your help.
>
> Best,
> Jing
>
>
> ------------------------------------------------------------------------------
> Introducing Performance Central, a new site from SourceForge and
> AppDynamics. Performance Central is your source for news, insights,
> analysis and resources for efficient Application Performance Management.
> Visit us today!
> http://pubads.g.doubleclick.net/gampad/clk?id=48897511&iu=/4140/ostg.clktrk
>
>
>
> _______________________________________________
> Ejbca-develop mailing list
> Ejb...@li...
> https://lists.sourceforge.net/lists/listinfo/ejbca-develop
>
|
|
From: Tomas G. <to...@pr...> - 2013-08-26 13:04:56
|
During the summer there was an update to the OCSP RFC, RFC6960. OCSP has been one of the most stable RFC's, and protocols, to come out in PKI. I took a look at the new RFC and wrote a blog post about it, with regards to EJBCA. http://blog.ejbca.org/2013/08/ejbca-and-updated-ocsp-rfc-6960.html Cheers, Tomas -- ********** PrimeKey Solutions AB Anderstorpsvägen 16, 171 54 Solna, Sweden Mob: +46 (0)707421096 Internet: www.primekey.se Twitter: twitter.com/primekeyPKI ********** |
|
From: Jing Xu <rob...@gm...> - 2013-08-23 23:43:24
|
Hi everyone,
I am developing a software testing tool to detect thread stress
vulnerability of server application. And our tool detects the vulnerability
on ejbca in following function in
java.org.ejbca.util.PerformanceTest.TestInstance:
public void run(){
PerformanceTest.this.log.info <http://performancetest.this.log.info/>("Thread
nr " + this.nr + " started.");
while (true) {
try {
final long startTime=new Date().getTime();
Command failingCommand=null;
for (int i=0; failingCommand == null && i < this.commands.length;
i++) {
if (this.maxWaitTime > 0) {
final int waitTime=(int)(this.maxWaitTime *
PerformanceTest.this.random.nextFloat());
if (waitTime > 0) {
synchronized (this) {
wait(waitTime);
}
this.statistic.addTime("Time waiting between jobs",waitTime);
}
}
final Command command=this.commands[i];
final JobRunner jobRunner=new JobRunner(command);
if (!jobRunner.execute()) {
failingCommand=command;
}
this.statistic.addTime(command.getJobTimeDescription(),jobRunner.getTimeConsumed());
}
String sResult="Test in thread " + this.nr + " completed ";
if (failingCommand == null) {
this.statistic.taskFinished();
sResult+="successfully";
}
else {
this.statistic.taskFailed();
sResult+="but failed when the command '" +
failingCommand.getClass().getCanonicalName() + "' was executed";
}
sResult+=". The time it took was " + (new Date().getTime() -
startTime) + " ms.";
if (failingCommand == null) {
PerformanceTest.this.log.info<http://performancetest.this.log.info/>
(sResult);
}
else {
PerformanceTest.this.log.error(sResult);
}
}
catch ( Throwable t) {
this.statistic.taskFailed();
PerformanceTest.this.log.error("Exeption in thread " + this.nr +
".",t);
}
}
}
Is it possible that jobRunner.execute() will create unbounded number of
threads? Thanks advanced for your help.
Best,
Jing
|
|
From: Tomas G. <to...@pr...> - 2013-08-21 15:43:06
|
No you have to rebuild the whole PKI from scratch. Just kidding :-). Naturally there is an upgrade path, EJBCA has always provided upgrade paths. Cheers, Tomas ********** PrimeKey Solutions AB Anderstorpsvägen 16, 171 54 Solna, Sweden Mob: +46 (0)707421096 Internet: www.primekey.se Twitter: twitter.com/primekeyPKI ********** On 08/21/2013 03:42 PM, Christian Felsing wrote: > Hi Tomas, > > one question which may arise, is upgrade from Ejbca 4.0.x to 6.x possible w/o data loss? > > Cheers > Christian > > Am 19.08.13 10:01, schrieb Tomas Gustavsson: >> EJBCA v6 is brewing, for release later this autumn. I have started a > > > ------------------------------------------------------------------------------ > Introducing Performance Central, a new site from SourceForge and > AppDynamics. Performance Central is your source for news, insights, > analysis and resources for efficient Application Performance Management. > Visit us today! > http://pubads.g.doubleclick.net/gampad/clk?id=48897511&iu=/4140/ostg.clktrk > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |