You can subscribe to this list here.
| 2001 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
(1) |
Dec
(3) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2002 |
Jan
(3) |
Feb
(2) |
Mar
(8) |
Apr
(3) |
May
(6) |
Jun
(1) |
Jul
(15) |
Aug
(6) |
Sep
|
Oct
(10) |
Nov
(2) |
Dec
(4) |
| 2003 |
Jan
(1) |
Feb
(7) |
Mar
(3) |
Apr
(6) |
May
(7) |
Jun
(5) |
Jul
(5) |
Aug
(25) |
Sep
(14) |
Oct
(2) |
Nov
|
Dec
(2) |
| 2004 |
Jan
(7) |
Feb
(4) |
Mar
(12) |
Apr
(16) |
May
(43) |
Jun
(56) |
Jul
(43) |
Aug
(40) |
Sep
(66) |
Oct
(12) |
Nov
(26) |
Dec
(10) |
| 2005 |
Jan
(13) |
Feb
(33) |
Mar
(16) |
Apr
(7) |
May
(10) |
Jun
(34) |
Jul
(41) |
Aug
(8) |
Sep
(4) |
Oct
(32) |
Nov
(20) |
Dec
(25) |
| 2006 |
Jan
(30) |
Feb
(101) |
Mar
(5) |
Apr
(75) |
May
(74) |
Jun
(22) |
Jul
(6) |
Aug
(70) |
Sep
(19) |
Oct
(21) |
Nov
(31) |
Dec
(50) |
| 2007 |
Jan
(15) |
Feb
(20) |
Mar
(24) |
Apr
(33) |
May
(13) |
Jun
(18) |
Jul
(13) |
Aug
(7) |
Sep
(63) |
Oct
(68) |
Nov
(29) |
Dec
(68) |
| 2008 |
Jan
(30) |
Feb
(33) |
Mar
(30) |
Apr
(103) |
May
(78) |
Jun
(48) |
Jul
(72) |
Aug
(24) |
Sep
(62) |
Oct
(63) |
Nov
(70) |
Dec
(37) |
| 2009 |
Jan
(34) |
Feb
(35) |
Mar
(64) |
Apr
(34) |
May
(34) |
Jun
(58) |
Jul
(30) |
Aug
(30) |
Sep
(46) |
Oct
(52) |
Nov
(12) |
Dec
(23) |
| 2010 |
Jan
(121) |
Feb
(18) |
Mar
(53) |
Apr
(62) |
May
(62) |
Jun
(20) |
Jul
(33) |
Aug
(20) |
Sep
(36) |
Oct
(35) |
Nov
(44) |
Dec
(63) |
| 2011 |
Jan
(19) |
Feb
(32) |
Mar
(94) |
Apr
(41) |
May
(47) |
Jun
(25) |
Jul
(34) |
Aug
(20) |
Sep
(9) |
Oct
(41) |
Nov
(33) |
Dec
(24) |
| 2012 |
Jan
(12) |
Feb
(36) |
Mar
(48) |
Apr
(32) |
May
(20) |
Jun
(15) |
Jul
(32) |
Aug
(13) |
Sep
(33) |
Oct
(54) |
Nov
(25) |
Dec
(16) |
| 2013 |
Jan
(45) |
Feb
(39) |
Mar
(38) |
Apr
(50) |
May
(29) |
Jun
(30) |
Jul
(33) |
Aug
(12) |
Sep
(9) |
Oct
(25) |
Nov
(29) |
Dec
(20) |
| 2014 |
Jan
(25) |
Feb
(19) |
Mar
(16) |
Apr
(33) |
May
(27) |
Jun
(37) |
Jul
(29) |
Aug
(27) |
Sep
(37) |
Oct
(58) |
Nov
(109) |
Dec
(26) |
| 2015 |
Jan
(4) |
Feb
(35) |
Mar
(22) |
Apr
(35) |
May
(28) |
Jun
(20) |
Jul
(4) |
Aug
(16) |
Sep
(37) |
Oct
(13) |
Nov
(13) |
Dec
(14) |
| 2016 |
Jan
(22) |
Feb
(7) |
Mar
(23) |
Apr
(30) |
May
(10) |
Jun
(10) |
Jul
(15) |
Aug
(12) |
Sep
(22) |
Oct
(31) |
Nov
(5) |
Dec
(5) |
| 2017 |
Jan
(30) |
Feb
(25) |
Mar
(28) |
Apr
(4) |
May
(19) |
Jun
(13) |
Jul
(7) |
Aug
(1) |
Sep
(2) |
Oct
(5) |
Nov
(12) |
Dec
(2) |
| 2018 |
Jan
(7) |
Feb
|
Mar
(7) |
Apr
(2) |
May
(8) |
Jun
(18) |
Jul
(6) |
Aug
(3) |
Sep
(15) |
Oct
(33) |
Nov
(13) |
Dec
(7) |
| 2019 |
Jan
(5) |
Feb
(7) |
Mar
(30) |
Apr
(5) |
May
(4) |
Jun
(69) |
Jul
(86) |
Aug
(22) |
Sep
(6) |
Oct
(7) |
Nov
(5) |
Dec
(3) |
| 2020 |
Jan
(10) |
Feb
(12) |
Mar
(22) |
Apr
(5) |
May
(1) |
Jun
(4) |
Jul
(6) |
Aug
|
Sep
(9) |
Oct
|
Nov
|
Dec
(1) |
| 2021 |
Jan
(4) |
Feb
(11) |
Mar
(7) |
Apr
(7) |
May
|
Jun
(3) |
Jul
(10) |
Aug
(6) |
Sep
|
Oct
|
Nov
(18) |
Dec
(2) |
| 2022 |
Jan
(1) |
Feb
(1) |
Mar
|
Apr
|
May
|
Jun
(2) |
Jul
|
Aug
(4) |
Sep
|
Oct
|
Nov
|
Dec
|
| 2023 |
Jan
|
Feb
|
Mar
|
Apr
(1) |
May
(1) |
Jun
|
Jul
|
Aug
(5) |
Sep
|
Oct
|
Nov
|
Dec
|
|
From: Tomas G. <to...@pr...> - 2013-02-15 10:35:18
|
The EJBCA team is happy to announce that EJBCA 4.0.14 has been released! This is a maintenance release – 5 issues have been resolved. The most noteworthy changes can be seen below. - Active certificates published to a VA publisher that only publishes revoked certificates are no longer stored in the queue. - Publishers are cached for improved performance. - New and fixed settings that makes EJBCA work better behind an Apache using ProxyPass. - Some passwords are not displayed in the console during build anymore. Download it from http://www.ejbca.org/ Kind Regards, PrimeKey EJBCA Team -- ** VISIT US AT RSA EXPO - BOOTH #459 ** **** FREE EXPO PASS CODE: FXE13PKS **** https://ae.rsaconference.com/US13/portal/login.ww |
|
From: ejbca-support <ejb...@pr...> - 2013-02-15 04:43:18
|
On 2013-02-14 23:20, 孙伟 wrote: > Hi, > > Recently I have been working on building the EJBCA server with an internal OCSP responder. > > In order to make it work as an external CA, I need to import the certificate as well as the crl file. The "importca" and "importcert" worked perfect, while the "importcrl" always has an "error: null" message. > > [root@kevinejbca bin]# ./ejbca.sh ca importcrl "Root CA" /opt/ejbca/kevin/RootCA.cacert.pem STRICT > CA: XXXXXXXXXXXXXXXXXXXXXXXXXX > Error: null > > The RootCA.cacert.pem is signed by the Root CA itself. > > I have also tried with another crl file with some revoked certificate information inside, so it should not be null pointer issue. So I am very confused about this. > > Can anybody tell me what goes wrong? Is the "importcrl" command fully functional? I think I know this problem... Although not mentioned in the help-text the CRL must be in DER format. Cheers Anders tech support > > My system: > CentOS 6.2 > MySQL 5.1.66 > jboss 5.1.0 > EJBCA 4.0.13 > > Any idea or comment will be appreciated! > > Thanks, > Kevin > > > ------------------------------------------------------------------------------ > Free Next-Gen Firewall Hardware Offer > Buy your Sophos next-gen firewall before the end March 2013 > and get the hardware for free! Learn more. > http://p.sf.net/sfu/sophos-d2d-feb > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: 孙伟 <kev...@gm...> - 2013-02-14 22:20:12
|
Hi, Recently I have been working on building the EJBCA server with an internal OCSP responder. In order to make it work as an external CA, I need to import the certificate as well as the crl file. The "importca" and "importcert" worked perfect, while the "importcrl" always has an "error: null" message. [root@kevinejbca bin]# ./ejbca.sh ca importcrl "Root CA" /opt/ejbca/kevin/RootCA.cacert.pem STRICT CA: XXXXXXXXXXXXXXXXXXXXXXXXXX Error: null The RootCA.cacert.pem is signed by the Root CA itself. I have also tried with another crl file with some revoked certificate information inside, so it should not be null pointer issue. So I am very confused about this. Can anybody tell me what goes wrong? Is the "importcrl" command fully functional? My system: CentOS 6.2 MySQL 5.1.66 jboss 5.1.0 EJBCA 4.0.13 Any idea or comment will be appreciated! Thanks, Kevin |
|
From: Tomas G. <to...@pr...> - 2013-02-11 11:36:30
|
Hi, Sorry for everyone considering this as off-topic on the mailing list. Since we are looking for a new EJBCA integrator I though it might be interesting for someone. PrimeKey is looking for a PKI Specialist / Integrator working globally with integration of EJBCA and SignServer. For the full job description, please see: http://www.primekey.se/Company/Career/ Kind regards, Tomas ********** PrimeKey Solutions AB Anderstorpsvägen 16, 171 54 Solna, Sweden Mob: +46 (0)707421096 Internet: www.primekey.se Twitter: twitter.com/primekeyPKI ********** |
|
From: ejbca-support <ejb...@pr...> - 2013-02-09 15:19:20
|
On 2013-02-09 14:37, Alireza Karbasian wrote: > > Well I figured out the problem and i thought to explain it here maybe it can help someone! > in fact the problem was with crl issuer filed in certificate profiles under CDP Address! if you generate this field it will appear in certificate under CDP as Directory access info! > now the bug or mistake is with adobe reader! it compares this filed with certificate (or CRL) issuer and generates an "issuer mismatch" error! but it must compare for example cert.authorityKeyIdentifier=crl.authortyKeyIdentifier=ca.subjectKeyIdentifier > > I removed this filed and it's working! Alireza, I happy to hear that it works and very much appreciate that you shared the solution with the EJBCA community! Cheers Anders tech support > > ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ > *From:* Tham Wickenberg <ejb...@pr...> > *To:* Alireza Karbasian <ili...@ya...>; ejb...@li... > *Sent:* Friday, February 8, 2013 7:44 PM > *Subject:* Re: [Ejbca-develop] Issuer mismatch error > > Hello, > > * I curled the CRL from the CDP and the the CRL verifies with OpenSSL > > * I printed info in certificates, it looks good to me > > * I verified the certificate against CA chain but NOT CRL it checks out OK > openssl verify -verbose -CAfile chain.pem certdownloadedFromEJBCA.pem > > certdownloadedFromEJBCA.pem: OK > > * I try to verify the certificate against CA AND CRL (CDP) and it fails > openssl verify -verbose -crl_check -CAfile chain.pem > certdownloadedFromEJBCA.pem > > certdownloadedFromEJBCA.pem: /CN=RooznamehRasmi/OU=rooznameh > rasmi/O=JUD/C=IR > error 3 at 0 depth lookup:unable to get certificate CRL > > I am unsure what this means however. > > /Tham Wickenberg > > > On 2/8/13 4:37 PM, ejbca-support wrote: >> On 2013-02-08 15:31, Alireza Karbasian wrote: >>> ok if we assume that this is just a printout issue in openssl so what's happenning to main certificates from ejbca? i used the PEM certificate downloaded from EJBCA and not the converted one with openssl. i send the ca chain and signed pdf so you can check it out! i see the error in adobe acrobat 9,10 and 11 ! >> Hi Alireza >> Could you check that the CRL does not verify with OpenSSL? >> I don't see any problems but the PDF didn't validate here either :-) >> >> Anders >>> ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ ------------------------ >>> *From:* ejbca-support <ejb...@pr... <mailto:ejb...@pr...>> >>> *To:* Alireza Karbasian <ili...@ya... <mailto:ili...@ya...>>; ejb...@li... <mailto:ejb...@li...> >>> *Sent:* Friday, February 8, 2013 3:48 PM >>> *Subject:* Re: [Ejbca-develop] Issuer mismatch error >>> >>> On 2013-02-08 13:05, Alireza Karbasian wrote: >>>> yes! this is what i guessed also! but the problem is this that i did not >>>> convert the certificates with openssl but i downloaded the PEM certificate >>>> from EJBCA and published CRL in CDP and same thing happens! >>>> is it possible that this is something related to PEM standard? >>> No, this is just a printout formatting issue in OpenSSL. >>> Cheers >>> Anders >>> tech support >>>> ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ > ------------------------ >>>> *From:* martijn.list <mar...@gm... <mailto:mar...@gm...> <mailto:mar...@gm... <mailto:mar...@gm...>>> >>>> *To:* ejb...@li... <mailto:ejb...@li...> <mailto:ejb...@li... <mailto:ejb...@li...>> >>>> *Sent:* Thursday, February 7, 2013 11:03 PM >>>> *Subject:* Re: [Ejbca-develop] Issuer mismatch error >>>> >>>> Hi, >>>> >>>> On 02/07/2013 08:12 PM, Alireza Karbasian wrote: >>>>> The attached file contains the test certificates. the certificate here >>>>> is not issued for pdf signing but this is the same thing that happens to >>>>> original certificates. >>>> Verification with OpenSSL seems to be ok after conversion of ca.cer to >>>> PEM (ca.cer.pem) >>>> >>>> openssl crl -in AdminCA1\(downloadedFromEJBCA\).crl -CAfile ca.cer.pem >>>> -inform DER >>>> >>>> martijn@coolermaster:~/temp/certs$ openssl crl -in >>>> AdminCA1\(downloadedFromEJBCA\).crl -CAfile ca.cer.pem -inform DER >>>> verify OK >>>> -----BEGIN X509 CRL----- >>>> MIICLDCCARQCAQEwDQYJKoZIhvcNAQEFBQAwNzERMA8GA1UEAwwIQWRtaW5DQTEx >>>> FTATBgNVBAoMDEVKQkNBIFNhbXBsZTELMAkGA1UEBhMCU0UXDTEzMDIwNzEyMzY0 >>>> N1oXDTEzMDIwODEyMzY0N1qggagwgaUwHwYDVR0jBBgwFoAU3BKuSh4TQDbsjtGJ >>>> S9LNaUfIO5gwCgYDVR0UBAMCAQIwdgYDVR0cBG8wbaBroGmGZ2h0dHA6Ly9pbGlh >>>> Y2EuaXI6ODA4MC9lamJjYS9wdWJsaWN3ZWIvd2ViZGlzdC9jZXJ0ZGlzdD9jbWQ9 >>>> Y3JsJmlzc3Vlcj1DTj1BZG1pbkNBMSxPPUVKQkNBJTIwU2FtcGxlLEM9U0UwDQYJ >>>> KoZIhvcNAQEFBQADggEBAHEj9XbM6634R2TtGOtSRGIpbML+/ZF9C/dLBxb76b21 >>>> 7cOdm/DGQ7u4cfaW5iU57RRYBXZCajE7xQWRj3yyMJGBm/pn+0IXNN50sjtO6VX2 >>>> AEwFtOVxvqSph8x7DDCUK3ZFQgmBgTouigqgKfM41ipamNn/Ri9IR0PxSxXfpo30 >>>> akCMYmN/gkmSxgZNzECzdc5kAe9mp+gRemoTZLLgZonzW/bD4H4i6jhrmzD/kCp9 >>>> i95y6jSZJR4sPMpSKJ7F8Pa8U0i1H0emBHVK+i9QPBDucH4CncZObm4O/MH7+H1p >>>> u3AjjVKUSWaKl419WOvL7FbXAbt0U2IVaBq5MTPgC9o= >>>> -----END X509 CRL----- >>>> >>>> So OpenSSL thinks the CRL is ok. My own application also thinks the CRL >>>> is ok. The issue with the extra space is an OpenSSL "issue". It seems >>>> that the code for x509 outputs an extra space after : but the code for >>>> crl does not. >>>> >>>> Kind regards, >>>> >>>> Martijn Brinkers >>>> >>>> >>>> -- >>>> DJIGZO email encryption >>>> >>>>> ------------------------------------------------------------------------ >>>>> *From:* ejbca-support <ejb...@pr... <mailto:ejb...@pr...> <mailto:ejb...@pr... <mailto:ejb...@pr...>> <mailto:ejb...@pr... <mailto:ejb...@pr...> <mailto:ejb...@pr... <mailto:ejb...@pr...>>>> >>>>> *To:* Alireza Karbasian <ili...@ya... <mailto:ili...@ya...> <mailto:ili...@ya... <mailto:ili...@ya...>> <mailto:ili...@ya... <mailto:ili...@ya...> <mailto:ili...@ya... <mailto:ili...@ya...>>>>; >>>>> ejb...@li... <mailto:ejb...@li...> <mailto:ejb...@li... <mailto:ejb...@li...>> <mailto:ejb...@li... <mailto:ejb...@li...> <mailto:ejb...@li... <mailto:ejb...@li...>>> >>>>> *Sent:* Thursday, February 7, 2013 4:55 PM >>>>> *Subject:* Re: [Ejbca-develop] Issuer mismatch error >>>>> >>>>> On 2013-02-07 14:05, Alireza Karbasian wrote: >>>>> > hello >>>>> > >>>>> > I used EJBCA (4.0.13) to issue a certificate for PDF signing. >>>>> everything seemed good and documents got signed! now when I opens my PDF >>>>> in adobe reader it tries to validate certificate against the CRL with my >>>>> CDP. it can access it but it gives me an error that "Issuer names mismatch". >>>>> > I used these commands to check the issuer names: >>>>> >>>openssl x509 -in signing.pem -issuer -noout >>>>> >>>openssl crl -in crl.pem -issuer -noout >>>>> > >>>>> > and this is the output: >>>>> > openssl x509 -in test.pem -issuer -noout >>>>> > *issuer= /CN=AdminCA1/O=EJBCA Sample/C=SE* >>>>> > openssl crl -in crl.pem -issuer -noout >>>>> > *issuer=/CN=AdminCA1/O=EJBCA Sample/C=SE* >>>>> > ** >>>>> >>>>> Hi Alireza, >>>>> I have never heard about this before, can you send a >>>>> pasted certificate for us to study? >>>>> >>>>> Cheers >>>>> Anders >>>>> tech support >>>>> >>>>> >>>>> > as you can see there is space character in the beginning of >>>>> certificate issuer DN. I googled this and came to see there are some >>>>> discussions about this and assumed that this is a bug (in opnessl >>>>> maybe)! but no solutions! >>>>> > I could not find any related configuration in EJBCA to solve this and >>>>> yet I'm not sure even that this is a bug! did anybody encountered such a >>>>> problem? is this a bug in EJBCA? any help or guide will be appreciated! >>>>> > >>>>> > >>>>> > >>>>> ------------------------------------------------------------------------------ >>>>> > Free Next-Gen Firewall Hardware Offer >>>>> > Buy your Sophos next-gen firewall before the end March 2013 >>>>> > and get the hardware for free! Learn more. >>>>> > http://p.sf.net/sfu/sophos-d2d-feb >>>>> > >>>>> > >>>>> > >>>>> > _______________________________________________ >>>>> > Ejbca-develop mailing list >>>>> > Ejb...@li... <mailto:Ejb...@li...> <mailto:Ejb...@li... <mailto:Ejb...@li...>> <mailto:Ejb...@li... <mailto:Ejb...@li...> <mailto:Ejb...@li... <mailto:Ejb...@li...>>> >>>>> <mailto:Ejb...@li... <mailto:Ejb...@li...> <mailto:Ejb...@li... <mailto:Ejb...@li...>> <mailto:Ejb...@li... <mailto:Ejb...@li...> <mailto:Ejb...@li... <mailto:Ejb...@li...>>>> >>>>> > https://lists.sourceforge.net/lists/listinfo/ejbca-develop >>>>> > >>>>> >>>>> >>>>> >>>>> >>>>> >>>>> >>>>> >>>>> ------------------------------------------------------------------------------ >>>>> Free Next-Gen Firewall Hardware Offer >>>>> Buy your Sophos next-gen firewall before the end March 2013 >>>>> and get the hardware for free! Learn more. >>>>> http://p.sf.net/sfu/sophos-d2d-feb >>>>> >>>>> >>>>> >>>>> _______________________________________________ >>>>> Ejbca-develop mailing list >>>>> Ejb...@li... <mailto:Ejb...@li...> <mailto:Ejb...@li... <mailto:Ejb...@li...>> <mailto:Ejb...@li... <mailto:Ejb...@li...> <mailto:Ejb...@li... <mailto:Ejb...@li...>>> >>>>> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >>>>> >>>> >>>> ------------------------------------------------------------------------------ >>>> Free Next-Gen Firewall Hardware Offer >>>> Buy your Sophos next-gen firewall before the end March 2013 >>>> and get the hardware for free! Learn more. >>>> http://p.sf.net/sfu/sophos-d2d-feb >>>> _______________________________________________ >>>> Ejbca-develop mailing list >>>> Ejb...@li... <mailto:Ejb...@li...> <mailto:Ejb...@li... <mailto:Ejb...@li...>> <mailto:Ejb...@li... <mailto:Ejb...@li...> <mailto:Ejb...@li... <mailto:Ejb...@li...>>> >>>> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >>>> >>>> >>>> >>>> >>>> ------------------------------------------------------------------------------ >>>> Free Next-Gen Firewall Hardware Offer >>>> Buy your Sophos next-gen firewall before the end March 2013 >>>> and get the hardware for free! Learn more. >>>> http://p.sf.net/sfu/sophos-d2d-feb >>>> >>>> >>>> >>>> _______________________________________________ >>>> Ejbca-develop mailing list >>>> Ejb...@li... <mailto:Ejb...@li...> <mailto:Ejb...@li... <mailto:Ejb...@li...>> >>>> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >>>> >>> >>> >>> >>> >>> ------------------------------------------------------------------------------ >>> Free Next-Gen Firewall Hardware Offer >>> Buy your Sophos next-gen firewall before the end March 2013 >>> and get the hardware for free! Learn more. >>> http://p.sf.net/sfu/sophos-d2d-feb >>> >>> >>> >>> _______________________________________________ >>> Ejbca-develop mailing list >>> Ejb...@li... <mailto:Ejb...@li...> >>> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >>> >> >> ------------------------------------------------------------------------------ >> Free Next-Gen Firewall Hardware Offer >> Buy your Sophos next-gen firewall before the end March 2013 >> and get the hardware for free! Learn more. >> http://p.sf.net/sfu/sophos-d2d-feb >> _______________________________________________ >> Ejbca-develop mailing list >> Ejb...@li... <mailto:Ejb...@li...> >> https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > > > ------------------------------------------------------------------------------ > Free Next-Gen Firewall Hardware Offer > Buy your Sophos next-gen firewall before the end March 2013 > and get the hardware for free! Learn more. > http://p.sf.net/sfu/sophos-d2d-feb > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... <mailto:Ejb...@li...> > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > > ------------------------------------------------------------------------------ > Free Next-Gen Firewall Hardware Offer > Buy your Sophos next-gen firewall before the end March 2013 > and get the hardware for free! Learn more. > http://p.sf.net/sfu/sophos-d2d-feb > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Andreas B. <ab...@an...> - 2013-02-09 15:14:12
|
Dear Alireza Am 09.02.2013 14:37, schrieb Alireza Karbasian: > > Well I figured out the problem and i thought to explain it here maybe it > can help someone! Great you share your findings and learnings with this list ! This is, what I call F/OSS spirit and helps to promote and improve EJBCA at the end of the day. Thanks again. cheeers, h. > ------------------------------------------------------------------------ > *From:* Tham Wickenberg <ejb...@pr...> > *To:* Alireza Karbasian <ili...@ya...>; > ejb...@li... > *Sent:* Friday, February 8, 2013 7:44 PM > *Subject:* Re: [Ejbca-develop] Issuer mismatch error > > Hello, > > * I curled the CRL from the CDP and the the CRL verifies with OpenSSL > > * I printed info in certificates, it looks good to me > > * I verified the certificate against CA chain but NOT CRL it checks out OK > openssl verify -verbose -CAfile chain.pem certdownloadedFromEJBCA.pem > > certdownloadedFromEJBCA.pem: OK > > * I try to verify the certificate against CA AND CRL (CDP) and it fails > openssl verify -verbose -crl_check -CAfile chain.pem > certdownloadedFromEJBCA.pem > > certdownloadedFromEJBCA.pem: /CN=RooznamehRasmi/OU=rooznameh > rasmi/O=JUD/C=IR > error 3 at 0 depth lookup:unable to get certificate CRL > > I am unsure what this means however. > > /Tham Wickenberg > > > On 2/8/13 4:37 PM, ejbca-support wrote: >> On 2013-02-08 15:31, Alireza Karbasian wrote: >>> ok if we assume that this is just a printout issue in openssl so > what's happenning to main certificates from ejbca? i used the PEM > certificate downloaded from EJBCA and not the converted one with > openssl. i send the ca chain and signed pdf so you can check it out! i > see the error in adobe acrobat 9,10 and 11 ! >> Hi Alireza >> Could you check that the CRL does not verify with OpenSSL? >> I don't see any problems but the PDF didn't validate here either :-) >> >> Anders >>> > ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ > ------------------------ >>> *From:* ejbca-support <ejb...@pr... > <mailto:ejb...@pr...>> >>> *To:* Alireza Karbasian <ili...@ya... > <mailto:ili...@ya...>>; ejb...@li... > <mailto:ejb...@li...> >>> *Sent:* Friday, February 8, 2013 3:48 PM >>> *Subject:* Re: [Ejbca-develop] Issuer mismatch error >>> >>> On 2013-02-08 13:05, Alireza Karbasian wrote: >>>> yes! this is what i guessed also! but the problem is this that i did not >>>> convert the certificates with openssl but i downloaded the PEM > certificate >>>> from EJBCA and published CRL in CDP and same thing happens! >>>> is it possible that this is something related to PEM standard? >>> No, this is just a printout formatting issue in OpenSSL. >>> Cheers >>> Anders >>> tech support >>>> > ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ > ------------------------ >>>> *From:* martijn.list <mar...@gm... > <mailto:mar...@gm...> <mailto:mar...@gm... > <mailto:mar...@gm...>>> >>>> *To:* ejb...@li... > <mailto:ejb...@li...> > <mailto:ejb...@li... > <mailto:ejb...@li...>> >>>> *Sent:* Thursday, February 7, 2013 11:03 PM >>>> *Subject:* Re: [Ejbca-develop] Issuer mismatch error >>>> >>>> Hi, >>>> >>>> On 02/07/2013 08:12 PM, Alireza Karbasian wrote: >>>>> The attached file contains the test certificates. the certificate here >>>>> is not issued for pdf signing but this is the same thing that > happens to >>>>> original certificates. >>>> Verification with OpenSSL seems to be ok after conversion of ca.cer to >>>> PEM (ca.cer.pem) >>>> >>>> openssl crl -in AdminCA1\(downloadedFromEJBCA\).crl -CAfile ca.cer.pem >>>> -inform DER >>>> >>>> martijn@coolermaster:~/temp/certs$ openssl crl -in >>>> AdminCA1\(downloadedFromEJBCA\).crl -CAfile ca.cer.pem -inform DER >>>> verify OK >>>> -----BEGIN X509 CRL----- >>>> MIICLDCCARQCAQEwDQYJKoZIhvcNAQEFBQAwNzERMA8GA1UEAwwIQWRtaW5DQTEx >>>> FTATBgNVBAoMDEVKQkNBIFNhbXBsZTELMAkGA1UEBhMCU0UXDTEzMDIwNzEyMzY0 >>>> N1oXDTEzMDIwODEyMzY0N1qggagwgaUwHwYDVR0jBBgwFoAU3BKuSh4TQDbsjtGJ >>>> S9LNaUfIO5gwCgYDVR0UBAMCAQIwdgYDVR0cBG8wbaBroGmGZ2h0dHA6Ly9pbGlh >>>> Y2EuaXI6ODA4MC9lamJjYS9wdWJsaWN3ZWIvd2ViZGlzdC9jZXJ0ZGlzdD9jbWQ9 >>>> Y3JsJmlzc3Vlcj1DTj1BZG1pbkNBMSxPPUVKQkNBJTIwU2FtcGxlLEM9U0UwDQYJ >>>> KoZIhvcNAQEFBQADggEBAHEj9XbM6634R2TtGOtSRGIpbML+/ZF9C/dLBxb76b21 >>>> 7cOdm/DGQ7u4cfaW5iU57RRYBXZCajE7xQWRj3yyMJGBm/pn+0IXNN50sjtO6VX2 >>>> AEwFtOVxvqSph8x7DDCUK3ZFQgmBgTouigqgKfM41ipamNn/Ri9IR0PxSxXfpo30 >>>> akCMYmN/gkmSxgZNzECzdc5kAe9mp+gRemoTZLLgZonzW/bD4H4i6jhrmzD/kCp9 >>>> i95y6jSZJR4sPMpSKJ7F8Pa8U0i1H0emBHVK+i9QPBDucH4CncZObm4O/MH7+H1p >>>> u3AjjVKUSWaKl419WOvL7FbXAbt0U2IVaBq5MTPgC9o= >>>> -----END X509 CRL----- >>>> >>>> So OpenSSL thinks the CRL is ok. My own application also thinks the CRL >>>> is ok. The issue with the extra space is an OpenSSL "issue". It seems >>>> that the code for x509 outputs an extra space after : but the code for >>>> crl does not. >>>> >>>> Kind regards, >>>> >>>> Martijn Brinkers >>>> >>>> >>>> -- >>>> DJIGZO email encryption >>>> >>>>> > ------------------------------------------------------------------------ >>>>> *From:* ejbca-support <ejb...@pr... > <mailto:ejb...@pr...> <mailto:ejb...@pr... > <mailto:ejb...@pr...>> <mailto:ejb...@pr... > <mailto:ejb...@pr...> <mailto:ejb...@pr... > <mailto:ejb...@pr...>>>> >>>>> *To:* Alireza Karbasian <ili...@ya... > <mailto:ili...@ya...> <mailto:ili...@ya... > <mailto:ili...@ya...>> <mailto:ili...@ya... > <mailto:ili...@ya...> <mailto:ili...@ya... > <mailto:ili...@ya...>>>>; >>>>> ejb...@li... > <mailto:ejb...@li...> > <mailto:ejb...@li... > <mailto:ejb...@li...>> > <mailto:ejb...@li... > <mailto:ejb...@li...> > <mailto:ejb...@li... > <mailto:ejb...@li...>>> >>>>> *Sent:* Thursday, February 7, 2013 4:55 PM >>>>> *Subject:* Re: [Ejbca-develop] Issuer mismatch error >>>>> >>>>> On 2013-02-07 14:05, Alireza Karbasian wrote: >>>>> > hello >>>>> > >>>>> > I used EJBCA (4.0.13) to issue a certificate for PDF signing. >>>>> everything seemed good and documents got signed! now when I opens > my PDF >>>>> in adobe reader it tries to validate certificate against the CRL > with my >>>>> CDP. it can access it but it gives me an error that "Issuer names > mismatch". >>>>> > I used these commands to check the issuer names: >>>>> >>>openssl x509 -in signing.pem -issuer -noout >>>>> >>>openssl crl -in crl.pem -issuer -noout >>>>> > >>>>> > and this is the output: >>>>> > openssl x509 -in test.pem -issuer -noout >>>>> > *issuer= /CN=AdminCA1/O=EJBCA Sample/C=SE* >>>>> > openssl crl -in crl.pem -issuer -noout >>>>> > *issuer=/CN=AdminCA1/O=EJBCA Sample/C=SE* >>>>> > ** >>>>> >>>>> Hi Alireza, >>>>> I have never heard about this before, can you send a >>>>> pasted certificate for us to study? >>>>> >>>>> Cheers >>>>> Anders >>>>> tech support >>>>> >>>>> >>>>> > as you can see there is space character in the beginning of >>>>> certificate issuer DN. I googled this and came to see there are some >>>>> discussions about this and assumed that this is a bug (in opnessl >>>>> maybe)! but no solutions! >>>>> > I could not find any related configuration in EJBCA to solve > this and >>>>> yet I'm not sure even that this is a bug! did anybody encountered > such a >>>>> problem? is this a bug in EJBCA? any help or guide will be appreciated! >>>>> > >>>>> > >>>>> > >>>>> > ------------------------------------------------------------------------------ >>>>> > Free Next-Gen Firewall Hardware Offer >>>>> > Buy your Sophos next-gen firewall before the end March 2013 >>>>> > and get the hardware for free! Learn more. >>>>> > http://p.sf.net/sfu/sophos-d2d-feb >>>>> > >>>>> > >>>>> > >>>>> > _______________________________________________ >>>>> > Ejbca-develop mailing list >>>>> > Ejb...@li... > <mailto:Ejb...@li...> > <mailto:Ejb...@li... > <mailto:Ejb...@li...>> > <mailto:Ejb...@li... > <mailto:Ejb...@li...> > <mailto:Ejb...@li... > <mailto:Ejb...@li...>>> >>>>> <mailto:Ejb...@li... > <mailto:Ejb...@li...> > <mailto:Ejb...@li... > <mailto:Ejb...@li...>> > <mailto:Ejb...@li... > <mailto:Ejb...@li...> > <mailto:Ejb...@li... > <mailto:Ejb...@li...>>>> >>>>> > https://lists.sourceforge.net/lists/listinfo/ejbca-develop >>>>> > >>>>> >>>>> >>>>> >>>>> >>>>> >>>>> >>>>> >>>>> > ------------------------------------------------------------------------------ >>>>> Free Next-Gen Firewall Hardware Offer >>>>> Buy your Sophos next-gen firewall before the end March 2013 >>>>> and get the hardware for free! Learn more. >>>>> http://p.sf.net/sfu/sophos-d2d-feb >>>>> >>>>> >>>>> >>>>> _______________________________________________ >>>>> Ejbca-develop mailing list >>>>> Ejb...@li... > <mailto:Ejb...@li...> > <mailto:Ejb...@li... > <mailto:Ejb...@li...>> > <mailto:Ejb...@li... > <mailto:Ejb...@li...> > <mailto:Ejb...@li... > <mailto:Ejb...@li...>>> >>>>> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >>>>> >>>> >>>> > ------------------------------------------------------------------------------ >>>> Free Next-Gen Firewall Hardware Offer >>>> Buy your Sophos next-gen firewall before the end March 2013 >>>> and get the hardware for free! Learn more. >>>> http://p.sf.net/sfu/sophos-d2d-feb >>>> _______________________________________________ >>>> Ejbca-develop mailing list >>>> Ejb...@li... > <mailto:Ejb...@li...> > <mailto:Ejb...@li... > <mailto:Ejb...@li...>> > <mailto:Ejb...@li... > <mailto:Ejb...@li...> > <mailto:Ejb...@li... > <mailto:Ejb...@li...>>> >>>> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >>>> >>>> >>>> >>>> >>>> > ------------------------------------------------------------------------------ >>>> Free Next-Gen Firewall Hardware Offer >>>> Buy your Sophos next-gen firewall before the end March 2013 >>>> and get the hardware for free! Learn more. >>>> http://p.sf.net/sfu/sophos-d2d-feb >>>> >>>> >>>> >>>> _______________________________________________ >>>> Ejbca-develop mailing list >>>> Ejb...@li... > <mailto:Ejb...@li...> > <mailto:Ejb...@li... > <mailto:Ejb...@li...>> >>>> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >>>> >>> >>> >>> >>> >>> > ------------------------------------------------------------------------------ >>> Free Next-Gen Firewall Hardware Offer >>> Buy your Sophos next-gen firewall before the end March 2013 >>> and get the hardware for free! Learn more. >>> http://p.sf.net/sfu/sophos-d2d-feb >>> >>> >>> >>> _______________________________________________ >>> Ejbca-develop mailing list >>> Ejb...@li... > <mailto:Ejb...@li...> >>> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >>> >> >> > ------------------------------------------------------------------------------ >> Free Next-Gen Firewall Hardware Offer >> Buy your Sophos next-gen firewall before the end March 2013 >> and get the hardware for free! Learn more. >> http://p.sf.net/sfu/sophos-d2d-feb >> _______________________________________________ >> Ejbca-develop mailing list >> Ejb...@li... > <mailto:Ejb...@li...> >> https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > > > ------------------------------------------------------------------------------ > Free Next-Gen Firewall Hardware Offer > Buy your Sophos next-gen firewall before the end March 2013 > and get the hardware for free! Learn more. > http://p.sf.net/sfu/sophos-d2d-feb > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > <mailto:Ejb...@li...> > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > > ------------------------------------------------------------------------------ > Free Next-Gen Firewall Hardware Offer > Buy your Sophos next-gen firewall before the end March 2013 > and get the hardware for free! Learn more. > http://p.sf.net/sfu/sophos-d2d-feb > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop -- Andreas Bürki ab...@an... S/MIME certificate - SHA1 fingerprint: ED:A5:F3:60:70:8B:4C:16:44:18:96:AE:67:B9:CA:77:AE:DA:83:11 GnuPG - GPG fingerprint: 5DA7 5F48 25BD D2D7 E488 05DF 5A99 A321 7E42 0227 |
|
From: Alireza K. <ili...@ya...> - 2013-02-09 13:37:33
|
Well I figured out the problem and i thought to explain it here maybe it can help someone! in fact the problem was with crl issuer filed in certificate profiles under CDP Address! if you generate this field it will appear in certificate under CDP as Directory access info! now the bug or mistake is with adobe reader! it compares this filed with certificate (or CRL) issuer and generates an "issuer mismatch" error! but it must compare for example cert.authorityKeyIdentifier=crl.authortyKeyIdentifier=ca.subjectKeyIdentifier I removed this filed and it's working! ________________________________ From: Tham Wickenberg <ejb...@pr...> To: Alireza Karbasian <ili...@ya...>; ejb...@li... Sent: Friday, February 8, 2013 7:44 PM Subject: Re: [Ejbca-develop] Issuer mismatch error Hello, * I curled the CRL from the CDP and the the CRL verifies with OpenSSL * I printed info in certificates, it looks good to me * I verified the certificate against CA chain but NOT CRL it checks out OK openssl verify -verbose -CAfile chain.pem certdownloadedFromEJBCA.pem certdownloadedFromEJBCA.pem: OK * I try to verify the certificate against CA AND CRL (CDP) and it fails openssl verify -verbose -crl_check -CAfile chain.pem certdownloadedFromEJBCA.pem certdownloadedFromEJBCA.pem: /CN=RooznamehRasmi/OU=rooznameh rasmi/O=JUD/C=IR error 3 at 0 depth lookup:unable to get certificate CRL I am unsure what this means however. /Tham Wickenberg On 2/8/13 4:37 PM, ejbca-support wrote: > On 2013-02-08 15:31, Alireza Karbasian wrote: >> ok if we assume that this is just a printout issue in openssl so what's happenning to main certificates from ejbca? i used the PEM certificate downloaded from EJBCA and not the converted one with openssl. i send the ca chain and signed pdf so you can check it out! i see the error in adobe acrobat 9,10 and 11 ! > Hi Alireza > Could you check that the CRL does not verify with OpenSSL? > I don't see any problems but the PDF didn't validate here either :-) > > Anders >> ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ ------------------------ >> *From:* ejbca-support <ejb...@pr...> >> *To:* Alireza Karbasian <ili...@ya...>; ejb...@li... >> *Sent:* Friday, February 8, 2013 3:48 PM >> *Subject:* Re: [Ejbca-develop] Issuer mismatch error >> >> On 2013-02-08 13:05, Alireza Karbasian wrote: >>> yes! this is what i guessed also! but the problem is this that i did not >>> convert the certificates with openssl but i downloaded the PEM certificate >>> from EJBCA and published CRL in CDP and same thing happens! >>> is it possible that this is something related to PEM standard? >> No, this is just a printout formatting issue in OpenSSL. >> Cheers >> Anders >> tech support >>> ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ ------------------------ >>> *From:* martijn.list <mar...@gm... <mailto:mar...@gm...>> >>> *To:* ejb...@li... <mailto:ejb...@li...> >>> *Sent:* Thursday, February 7, 2013 11:03 PM >>> *Subject:* Re: [Ejbca-develop] Issuer mismatch error >>> >>> Hi, >>> >>> On 02/07/2013 08:12 PM, Alireza Karbasian wrote: >>>> The attached file contains the test certificates. the certificate here >>>> is not issued for pdf signing but this is the same thing that happens to >>>> original certificates. >>> Verification with OpenSSL seems to be ok after conversion of ca.cer to >>> PEM (ca.cer.pem) >>> >>> openssl crl -in AdminCA1\(downloadedFromEJBCA\).crl -CAfile ca.cer.pem >>> -inform DER >>> >>> martijn@coolermaster:~/temp/certs$ openssl crl -in >>> AdminCA1\(downloadedFromEJBCA\).crl -CAfile ca.cer.pem -inform DER >>> verify OK >>> -----BEGIN X509 CRL----- >>> MIICLDCCARQCAQEwDQYJKoZIhvcNAQEFBQAwNzERMA8GA1UEAwwIQWRtaW5DQTEx >>> FTATBgNVBAoMDEVKQkNBIFNhbXBsZTELMAkGA1UEBhMCU0UXDTEzMDIwNzEyMzY0 >>> N1oXDTEzMDIwODEyMzY0N1qggagwgaUwHwYDVR0jBBgwFoAU3BKuSh4TQDbsjtGJ >>> S9LNaUfIO5gwCgYDVR0UBAMCAQIwdgYDVR0cBG8wbaBroGmGZ2h0dHA6Ly9pbGlh >>> Y2EuaXI6ODA4MC9lamJjYS9wdWJsaWN3ZWIvd2ViZGlzdC9jZXJ0ZGlzdD9jbWQ9 >>> Y3JsJmlzc3Vlcj1DTj1BZG1pbkNBMSxPPUVKQkNBJTIwU2FtcGxlLEM9U0UwDQYJ >>> KoZIhvcNAQEFBQADggEBAHEj9XbM6634R2TtGOtSRGIpbML+/ZF9C/dLBxb76b21 >>> 7cOdm/DGQ7u4cfaW5iU57RRYBXZCajE7xQWRj3yyMJGBm/pn+0IXNN50sjtO6VX2 >>> AEwFtOVxvqSph8x7DDCUK3ZFQgmBgTouigqgKfM41ipamNn/Ri9IR0PxSxXfpo30 >>> akCMYmN/gkmSxgZNzECzdc5kAe9mp+gRemoTZLLgZonzW/bD4H4i6jhrmzD/kCp9 >>> i95y6jSZJR4sPMpSKJ7F8Pa8U0i1H0emBHVK+i9QPBDucH4CncZObm4O/MH7+H1p >>> u3AjjVKUSWaKl419WOvL7FbXAbt0U2IVaBq5MTPgC9o= >>> -----END X509 CRL----- >>> >>> So OpenSSL thinks the CRL is ok. My own application also thinks the CRL >>> is ok. The issue with the extra space is an OpenSSL "issue". It seems >>> that the code for x509 outputs an extra space after : but the code for >>> crl does not. >>> >>> Kind regards, >>> >>> Martijn Brinkers >>> >>> >>> -- >>> DJIGZO email encryption >>> >>>> ------------------------------------------------------------------------ >>>> *From:* ejbca-support <ejb...@pr... <mailto:ejb...@pr...> <mailto:ejb...@pr... <mailto:ejb...@pr...>>> >>>> *To:* Alireza Karbasian <ili...@ya... <mailto:ili...@ya...> <mailto:ili...@ya... <mailto:ili...@ya...>>>; >>>> ejb...@li... <mailto:ejb...@li...> <mailto:ejb...@li... <mailto:ejb...@li...>> >>>> *Sent:* Thursday, February 7, 2013 4:55 PM >>>> *Subject:* Re: [Ejbca-develop] Issuer mismatch error >>>> >>>> On 2013-02-07 14:05, Alireza Karbasian wrote: >>>> > hello >>>> > >>>> > I used EJBCA (4.0.13) to issue a certificate for PDF signing. >>>> everything seemed good and documents got signed! now when I opens my PDF >>>> in adobe reader it tries to validate certificate against the CRL with my >>>> CDP. it can access it but it gives me an error that "Issuer names mismatch". >>>> > I used these commands to check the issuer names: >>>> >>>openssl x509 -in signing.pem -issuer -noout >>>> >>>openssl crl -in crl.pem -issuer -noout >>>> > >>>> > and this is the output: >>>> > openssl x509 -in test.pem -issuer -noout >>>> > *issuer= /CN=AdminCA1/O=EJBCA Sample/C=SE* >>>> > openssl crl -in crl.pem -issuer -noout >>>> > *issuer=/CN=AdminCA1/O=EJBCA Sample/C=SE* >>>> > ** >>>> >>>> Hi Alireza, >>>> I have never heard about this before, can you send a >>>> pasted certificate for us to study? >>>> >>>> Cheers >>>> Anders >>>> tech support >>>> >>>> >>>> > as you can see there is space character in the beginning of >>>> certificate issuer DN. I googled this and came to see there are some >>>> discussions about this and assumed that this is a bug (in opnessl >>>> maybe)! but no solutions! >>>> > I could not find any related configuration in EJBCA to solve this and >>>> yet I'm not sure even that this is a bug! did anybody encountered such a >>>> problem? is this a bug in EJBCA? any help or guide will be appreciated! >>>> > >>>> > >>>> > >>>> ------------------------------------------------------------------------------ >>>> > Free Next-Gen Firewall Hardware Offer >>>> > Buy your Sophos next-gen firewall before the end March 2013 >>>> > and get the hardware for free! Learn more. >>>> > http://p.sf.net/sfu/sophos-d2d-feb >>>> > >>>> > >>>> > >>>> > _______________________________________________ >>>> > Ejbca-develop mailing list >>>> > Ejb...@li... <mailto:Ejb...@li...> <mailto:Ejb...@li... <mailto:Ejb...@li...>> >>>> <mailto:Ejb...@li... <mailto:Ejb...@li...> <mailto:Ejb...@li... <mailto:Ejb...@li...>>> >>>> > https://lists.sourceforge.net/lists/listinfo/ejbca-develop >>>> > >>>> >>>> >>>> >>>> >>>> >>>> >>>> >>>> ------------------------------------------------------------------------------ >>>> Free Next-Gen Firewall Hardware Offer >>>> Buy your Sophos next-gen firewall before the end March 2013 >>>> and get the hardware for free! Learn more. >>>> http://p.sf.net/sfu/sophos-d2d-feb >>>> >>>> >>>> >>>> _______________________________________________ >>>> Ejbca-develop mailing list >>>> Ejb...@li... <mailto:Ejb...@li...> <mailto:Ejb...@li... <mailto:Ejb...@li...>> >>>> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >>>> >>> >>> ------------------------------------------------------------------------------ >>> Free Next-Gen Firewall Hardware Offer >>> Buy your Sophos next-gen firewall before the end March 2013 >>> and get the hardware for free! Learn more. >>> http://p.sf.net/sfu/sophos-d2d-feb >>> _______________________________________________ >>> Ejbca-develop mailing list >>> Ejb...@li... <mailto:Ejb...@li...> <mailto:Ejb...@li... <mailto:Ejb...@li...>> >>> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >>> >>> >>> >>> >>> ------------------------------------------------------------------------------ >>> Free Next-Gen Firewall Hardware Offer >>> Buy your Sophos next-gen firewall before the end March 2013 >>> and get the hardware for free! Learn more. >>> http://p.sf.net/sfu/sophos-d2d-feb >>> >>> >>> >>> _______________________________________________ >>> Ejbca-develop mailing list >>> Ejb...@li... <mailto:Ejb...@li...> >>> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >>> >> >> >> >> >> ------------------------------------------------------------------------------ >> Free Next-Gen Firewall Hardware Offer >> Buy your Sophos next-gen firewall before the end March 2013 >> and get the hardware for free! Learn more. >> http://p.sf.net/sfu/sophos-d2d-feb >> >> >> >> _______________________________________________ >> Ejbca-develop mailing list >> Ejb...@li... >> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >> > > ------------------------------------------------------------------------------ > Free Next-Gen Firewall Hardware Offer > Buy your Sophos next-gen firewall before the end March 2013 > and get the hardware for free! Learn more. > http://p.sf.net/sfu/sophos-d2d-feb > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop ------------------------------------------------------------------------------ Free Next-Gen Firewall Hardware Offer Buy your Sophos next-gen firewall before the end March 2013 and get the hardware for free! Learn more. http://p.sf.net/sfu/sophos-d2d-feb _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Alireza K. <ili...@ya...> - 2013-02-08 16:45:23
|
maybe this error is related to CDP address in ca cert! CDP is not mentioned in ca certificate but it's available in issued certificates. so when openssl wants to verify against CDP it can not find the address in ca certificate and it fails (maybe it grabs CDP from ca cert and not issued certificate)! but when you give it the CRL file it can verify it! but this does not seem to be "issuer mismatch" error cause! ________________________________ From: Tham Wickenberg <ejb...@pr...> To: Alireza Karbasian <ili...@ya...>; ejb...@li... Sent: Friday, February 8, 2013 7:44 PM Subject: Re: [Ejbca-develop] Issuer mismatch error Hello, * I curled the CRL from the CDP and the the CRL verifies with OpenSSL * I printed info in certificates, it looks good to me * I verified the certificate against CA chain but NOT CRL it checks out OK openssl verify -verbose -CAfile chain.pem certdownloadedFromEJBCA.pem certdownloadedFromEJBCA.pem: OK * I try to verify the certificate against CA AND CRL (CDP) and it fails openssl verify -verbose -crl_check -CAfile chain.pem certdownloadedFromEJBCA.pem certdownloadedFromEJBCA.pem: /CN=RooznamehRasmi/OU=rooznameh rasmi/O=JUD/C=IR error 3 at 0 depth lookup:unable to get certificate CRL I am unsure what this means however. /Tham Wickenberg On 2/8/13 4:37 PM, ejbca-support wrote: > On 2013-02-08 15:31, Alireza Karbasian wrote: >> ok if we assume that this is just a printout issue in openssl so what's happenning to main certificates from ejbca? i used the PEM certificate downloaded from EJBCA and not the converted one with openssl. i send the ca chain and signed pdf so you can check it out! i see the error in adobe acrobat 9,10 and 11 ! > Hi Alireza > Could you check that the CRL does not verify with OpenSSL? > I don't see any problems but the PDF didn't validate here either :-) > > Anders >> ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ ------------------------ >> *From:* ejbca-support <ejb...@pr...> >> *To:* Alireza Karbasian <ili...@ya...>; ejb...@li... >> *Sent:* Friday, February 8, 2013 3:48 PM >> *Subject:* Re: [Ejbca-develop] Issuer mismatch error >> >> On 2013-02-08 13:05, Alireza Karbasian wrote: >>> yes! this is what i guessed also! but the problem is this that i did not >>> convert the certificates with openssl but i downloaded the PEM certificate >>> from EJBCA and published CRL in CDP and same thing happens! >>> is it possible that this is something related to PEM standard? >> No, this is just a printout formatting issue in OpenSSL. >> Cheers >> Anders >> tech support >>> ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ ------------------------ >>> *From:* martijn.list <mar...@gm... <mailto:mar...@gm...>> >>> *To:* ejb...@li... <mailto:ejb...@li...> >>> *Sent:* Thursday, February 7, 2013 11:03 PM >>> *Subject:* Re: [Ejbca-develop] Issuer mismatch error >>> >>> Hi, >>> >>> On 02/07/2013 08:12 PM, Alireza Karbasian wrote: >>>> The attached file contains the test certificates. the certificate here >>>> is not issued for pdf signing but this is the same thing that happens to >>>> original certificates. >>> Verification with OpenSSL seems to be ok after conversion of ca.cer to >>> PEM (ca.cer.pem) >>> >>> openssl crl -in AdminCA1\(downloadedFromEJBCA\).crl -CAfile ca.cer.pem >>> -inform DER >>> >>> martijn@coolermaster:~/temp/certs$ openssl crl -in >>> AdminCA1\(downloadedFromEJBCA\).crl -CAfile ca.cer.pem -inform DER >>> verify OK >>> -----BEGIN X509 CRL----- >>> MIICLDCCARQCAQEwDQYJKoZIhvcNAQEFBQAwNzERMA8GA1UEAwwIQWRtaW5DQTEx >>> FTATBgNVBAoMDEVKQkNBIFNhbXBsZTELMAkGA1UEBhMCU0UXDTEzMDIwNzEyMzY0 >>> N1oXDTEzMDIwODEyMzY0N1qggagwgaUwHwYDVR0jBBgwFoAU3BKuSh4TQDbsjtGJ >>> S9LNaUfIO5gwCgYDVR0UBAMCAQIwdgYDVR0cBG8wbaBroGmGZ2h0dHA6Ly9pbGlh >>> Y2EuaXI6ODA4MC9lamJjYS9wdWJsaWN3ZWIvd2ViZGlzdC9jZXJ0ZGlzdD9jbWQ9 >>> Y3JsJmlzc3Vlcj1DTj1BZG1pbkNBMSxPPUVKQkNBJTIwU2FtcGxlLEM9U0UwDQYJ >>> KoZIhvcNAQEFBQADggEBAHEj9XbM6634R2TtGOtSRGIpbML+/ZF9C/dLBxb76b21 >>> 7cOdm/DGQ7u4cfaW5iU57RRYBXZCajE7xQWRj3yyMJGBm/pn+0IXNN50sjtO6VX2 >>> AEwFtOVxvqSph8x7DDCUK3ZFQgmBgTouigqgKfM41ipamNn/Ri9IR0PxSxXfpo30 >>> akCMYmN/gkmSxgZNzECzdc5kAe9mp+gRemoTZLLgZonzW/bD4H4i6jhrmzD/kCp9 >>> i95y6jSZJR4sPMpSKJ7F8Pa8U0i1H0emBHVK+i9QPBDucH4CncZObm4O/MH7+H1p >>> u3AjjVKUSWaKl419WOvL7FbXAbt0U2IVaBq5MTPgC9o= >>> -----END X509 CRL----- >>> >>> So OpenSSL thinks the CRL is ok. My own application also thinks the CRL >>> is ok. The issue with the extra space is an OpenSSL "issue". It seems >>> that the code for x509 outputs an extra space after : but the code for >>> crl does not. >>> >>> Kind regards, >>> >>> Martijn Brinkers >>> >>> >>> -- >>> DJIGZO email encryption >>> >>>> ------------------------------------------------------------------------ >>>> *From:* ejbca-support <ejb...@pr... <mailto:ejb...@pr...> <mailto:ejb...@pr... <mailto:ejb...@pr...>>> >>>> *To:* Alireza Karbasian <ili...@ya... <mailto:ili...@ya...> <mailto:ili...@ya... <mailto:ili...@ya...>>>; >>>> ejb...@li... <mailto:ejb...@li...> <mailto:ejb...@li... <mailto:ejb...@li...>> >>>> *Sent:* Thursday, February 7, 2013 4:55 PM >>>> *Subject:* Re: [Ejbca-develop] Issuer mismatch error >>>> >>>> On 2013-02-07 14:05, Alireza Karbasian wrote: >>>> > hello >>>> > >>>> > I used EJBCA (4.0.13) to issue a certificate for PDF signing. >>>> everything seemed good and documents got signed! now when I opens my PDF >>>> in adobe reader it tries to validate certificate against the CRL with my >>>> CDP. it can access it but it gives me an error that "Issuer names mismatch". >>>> > I used these commands to check the issuer names: >>>> >>>openssl x509 -in signing.pem -issuer -noout >>>> >>>openssl crl -in crl.pem -issuer -noout >>>> > >>>> > and this is the output: >>>> > openssl x509 -in test.pem -issuer -noout >>>> > *issuer= /CN=AdminCA1/O=EJBCA Sample/C=SE* >>>> > openssl crl -in crl.pem -issuer -noout >>>> > *issuer=/CN=AdminCA1/O=EJBCA Sample/C=SE* >>>> > ** >>>> >>>> Hi Alireza, >>>> I have never heard about this before, can you send a >>>> pasted certificate for us to study? >>>> >>>> Cheers >>>> Anders >>>> tech support >>>> >>>> >>>> > as you can see there is space character in the beginning of >>>> certificate issuer DN. I googled this and came to see there are some >>>> discussions about this and assumed that this is a bug (in opnessl >>>> maybe)! but no solutions! >>>> > I could not find any related configuration in EJBCA to solve this and >>>> yet I'm not sure even that this is a bug! did anybody encountered such a >>>> problem? is this a bug in EJBCA? any help or guide will be appreciated! >>>> > >>>> > >>>> > >>>> ------------------------------------------------------------------------------ >>>> > Free Next-Gen Firewall Hardware Offer >>>> > Buy your Sophos next-gen firewall before the end March 2013 >>>> > and get the hardware for free! Learn more. >>>> > http://p.sf.net/sfu/sophos-d2d-feb >>>> > >>>> > >>>> > >>>> > _______________________________________________ >>>> > Ejbca-develop mailing list >>>> > Ejb...@li... <mailto:Ejb...@li...> <mailto:Ejb...@li... <mailto:Ejb...@li...>> >>>> <mailto:Ejb...@li... <mailto:Ejb...@li...> <mailto:Ejb...@li... <mailto:Ejb...@li...>>> >>>> > https://lists.sourceforge.net/lists/listinfo/ejbca-develop >>>> > >>>> >>>> >>>> >>>> >>>> >>>> >>>> >>>> ------------------------------------------------------------------------------ >>>> Free Next-Gen Firewall Hardware Offer >>>> Buy your Sophos next-gen firewall before the end March 2013 >>>> and get the hardware for free! Learn more. >>>> http://p.sf.net/sfu/sophos-d2d-feb >>>> >>>> >>>> >>>> _______________________________________________ >>>> Ejbca-develop mailing list >>>> Ejb...@li... <mailto:Ejb...@li...> <mailto:Ejb...@li... <mailto:Ejb...@li...>> >>>> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >>>> >>> >>> ------------------------------------------------------------------------------ >>> Free Next-Gen Firewall Hardware Offer >>> Buy your Sophos next-gen firewall before the end March 2013 >>> and get the hardware for free! Learn more. >>> http://p.sf.net/sfu/sophos-d2d-feb >>> _______________________________________________ >>> Ejbca-develop mailing list >>> Ejb...@li... <mailto:Ejb...@li...> <mailto:Ejb...@li... <mailto:Ejb...@li...>> >>> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >>> >>> >>> >>> >>> ------------------------------------------------------------------------------ >>> Free Next-Gen Firewall Hardware Offer >>> Buy your Sophos next-gen firewall before the end March 2013 >>> and get the hardware for free! Learn more. >>> http://p.sf.net/sfu/sophos-d2d-feb >>> >>> >>> >>> _______________________________________________ >>> Ejbca-develop mailing list >>> Ejb...@li... <mailto:Ejb...@li...> >>> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >>> >> >> >> >> >> ------------------------------------------------------------------------------ >> Free Next-Gen Firewall Hardware Offer >> Buy your Sophos next-gen firewall before the end March 2013 >> and get the hardware for free! Learn more. >> http://p.sf.net/sfu/sophos-d2d-feb >> >> >> >> _______________________________________________ >> Ejbca-develop mailing list >> Ejb...@li... >> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >> > > ------------------------------------------------------------------------------ > Free Next-Gen Firewall Hardware Offer > Buy your Sophos next-gen firewall before the end March 2013 > and get the hardware for free! Learn more. > http://p.sf.net/sfu/sophos-d2d-feb > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Tham W. <ejb...@pr...> - 2013-02-08 16:14:49
|
Hello,
* I curled the CRL from the CDP and the the CRL verifies with OpenSSL
* I printed info in certificates, it looks good to me
* I verified the certificate against CA chain but NOT CRL it checks out OK
openssl verify -verbose -CAfile chain.pem certdownloadedFromEJBCA.pem
certdownloadedFromEJBCA.pem: OK
* I try to verify the certificate against CA AND CRL (CDP) and it fails
openssl verify -verbose -crl_check -CAfile chain.pem
certdownloadedFromEJBCA.pem
certdownloadedFromEJBCA.pem: /CN=RooznamehRasmi/OU=rooznameh
rasmi/O=JUD/C=IR
error 3 at 0 depth lookup:unable to get certificate CRL
I am unsure what this means however.
/Tham Wickenberg
On 2/8/13 4:37 PM, ejbca-support wrote:
> On 2013-02-08 15:31, Alireza Karbasian wrote:
>> ok if we assume that this is just a printout issue in openssl so what's happenning to main certificates from ejbca? i used the PEM certificate downloaded from EJBCA and not the converted one with openssl. i send the ca chain and signed pdf so you can check it out! i see the error in adobe acrobat 9,10 and 11 !
> Hi Alireza
> Could you check that the CRL does not verify with OpenSSL?
> I don't see any problems but the PDF didn't validate here either :-)
>
> Anders
>> ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
>> *From:* ejbca-support <ejb...@pr...>
>> *To:* Alireza Karbasian <ili...@ya...>; ejb...@li...
>> *Sent:* Friday, February 8, 2013 3:48 PM
>> *Subject:* Re: [Ejbca-develop] Issuer mismatch error
>>
>> On 2013-02-08 13:05, Alireza Karbasian wrote:
>>> yes! this is what i guessed also! but the problem is this that i did not
>>> convert the certificates with openssl but i downloaded the PEM certificate
>>> from EJBCA and published CRL in CDP and same thing happens!
>>> is it possible that this is something related to PEM standard?
>> No, this is just a printout formatting issue in OpenSSL.
>> Cheers
>> Anders
>> tech support
>>> ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ ------------------------
>>> *From:* martijn.list <mar...@gm... <mailto:mar...@gm...>>
>>> *To:* ejb...@li... <mailto:ejb...@li...>
>>> *Sent:* Thursday, February 7, 2013 11:03 PM
>>> *Subject:* Re: [Ejbca-develop] Issuer mismatch error
>>>
>>> Hi,
>>>
>>> On 02/07/2013 08:12 PM, Alireza Karbasian wrote:
>>>> The attached file contains the test certificates. the certificate here
>>>> is not issued for pdf signing but this is the same thing that happens to
>>>> original certificates.
>>> Verification with OpenSSL seems to be ok after conversion of ca.cer to
>>> PEM (ca.cer.pem)
>>>
>>> openssl crl -in AdminCA1\(downloadedFromEJBCA\).crl -CAfile ca.cer.pem
>>> -inform DER
>>>
>>> martijn@coolermaster:~/temp/certs$ openssl crl -in
>>> AdminCA1\(downloadedFromEJBCA\).crl -CAfile ca.cer.pem -inform DER
>>> verify OK
>>> -----BEGIN X509 CRL-----
>>> MIICLDCCARQCAQEwDQYJKoZIhvcNAQEFBQAwNzERMA8GA1UEAwwIQWRtaW5DQTEx
>>> FTATBgNVBAoMDEVKQkNBIFNhbXBsZTELMAkGA1UEBhMCU0UXDTEzMDIwNzEyMzY0
>>> N1oXDTEzMDIwODEyMzY0N1qggagwgaUwHwYDVR0jBBgwFoAU3BKuSh4TQDbsjtGJ
>>> S9LNaUfIO5gwCgYDVR0UBAMCAQIwdgYDVR0cBG8wbaBroGmGZ2h0dHA6Ly9pbGlh
>>> Y2EuaXI6ODA4MC9lamJjYS9wdWJsaWN3ZWIvd2ViZGlzdC9jZXJ0ZGlzdD9jbWQ9
>>> Y3JsJmlzc3Vlcj1DTj1BZG1pbkNBMSxPPUVKQkNBJTIwU2FtcGxlLEM9U0UwDQYJ
>>> KoZIhvcNAQEFBQADggEBAHEj9XbM6634R2TtGOtSRGIpbML+/ZF9C/dLBxb76b21
>>> 7cOdm/DGQ7u4cfaW5iU57RRYBXZCajE7xQWRj3yyMJGBm/pn+0IXNN50sjtO6VX2
>>> AEwFtOVxvqSph8x7DDCUK3ZFQgmBgTouigqgKfM41ipamNn/Ri9IR0PxSxXfpo30
>>> akCMYmN/gkmSxgZNzECzdc5kAe9mp+gRemoTZLLgZonzW/bD4H4i6jhrmzD/kCp9
>>> i95y6jSZJR4sPMpSKJ7F8Pa8U0i1H0emBHVK+i9QPBDucH4CncZObm4O/MH7+H1p
>>> u3AjjVKUSWaKl419WOvL7FbXAbt0U2IVaBq5MTPgC9o=
>>> -----END X509 CRL-----
>>>
>>> So OpenSSL thinks the CRL is ok. My own application also thinks the CRL
>>> is ok. The issue with the extra space is an OpenSSL "issue". It seems
>>> that the code for x509 outputs an extra space after : but the code for
>>> crl does not.
>>>
>>> Kind regards,
>>>
>>> Martijn Brinkers
>>>
>>>
>>> --
>>> DJIGZO email encryption
>>>
>>>> ------------------------------------------------------------------------
>>>> *From:* ejbca-support <ejb...@pr... <mailto:ejb...@pr...> <mailto:ejb...@pr... <mailto:ejb...@pr...>>>
>>>> *To:* Alireza Karbasian <ili...@ya... <mailto:ili...@ya...> <mailto:ili...@ya... <mailto:ili...@ya...>>>;
>>>> ejb...@li... <mailto:ejb...@li...> <mailto:ejb...@li... <mailto:ejb...@li...>>
>>>> *Sent:* Thursday, February 7, 2013 4:55 PM
>>>> *Subject:* Re: [Ejbca-develop] Issuer mismatch error
>>>>
>>>> On 2013-02-07 14:05, Alireza Karbasian wrote:
>>>> > hello
>>>> >
>>>> > I used EJBCA (4.0.13) to issue a certificate for PDF signing.
>>>> everything seemed good and documents got signed! now when I opens my PDF
>>>> in adobe reader it tries to validate certificate against the CRL with my
>>>> CDP. it can access it but it gives me an error that "Issuer names mismatch".
>>>> > I used these commands to check the issuer names:
>>>> >>>openssl x509 -in signing.pem -issuer -noout
>>>> >>>openssl crl -in crl.pem -issuer -noout
>>>> >
>>>> > and this is the output:
>>>> > openssl x509 -in test.pem -issuer -noout
>>>> > *issuer= /CN=AdminCA1/O=EJBCA Sample/C=SE*
>>>> > openssl crl -in crl.pem -issuer -noout
>>>> > *issuer=/CN=AdminCA1/O=EJBCA Sample/C=SE*
>>>> > **
>>>>
>>>> Hi Alireza,
>>>> I have never heard about this before, can you send a
>>>> pasted certificate for us to study?
>>>>
>>>> Cheers
>>>> Anders
>>>> tech support
>>>>
>>>>
>>>> > as you can see there is space character in the beginning of
>>>> certificate issuer DN. I googled this and came to see there are some
>>>> discussions about this and assumed that this is a bug (in opnessl
>>>> maybe)! but no solutions!
>>>> > I could not find any related configuration in EJBCA to solve this and
>>>> yet I'm not sure even that this is a bug! did anybody encountered such a
>>>> problem? is this a bug in EJBCA? any help or guide will be appreciated!
>>>> >
>>>> >
>>>> >
>>>> ------------------------------------------------------------------------------
>>>> > Free Next-Gen Firewall Hardware Offer
>>>> > Buy your Sophos next-gen firewall before the end March 2013
>>>> > and get the hardware for free! Learn more.
>>>> > http://p.sf.net/sfu/sophos-d2d-feb
>>>> >
>>>> >
>>>> >
>>>> > _______________________________________________
>>>> > Ejbca-develop mailing list
>>>> > Ejb...@li... <mailto:Ejb...@li...> <mailto:Ejb...@li... <mailto:Ejb...@li...>>
>>>> <mailto:Ejb...@li... <mailto:Ejb...@li...> <mailto:Ejb...@li... <mailto:Ejb...@li...>>>
>>>> > https://lists.sourceforge.net/lists/listinfo/ejbca-develop
>>>> >
>>>>
>>>>
>>>>
>>>>
>>>>
>>>>
>>>>
>>>> ------------------------------------------------------------------------------
>>>> Free Next-Gen Firewall Hardware Offer
>>>> Buy your Sophos next-gen firewall before the end March 2013
>>>> and get the hardware for free! Learn more.
>>>> http://p.sf.net/sfu/sophos-d2d-feb
>>>>
>>>>
>>>>
>>>> _______________________________________________
>>>> Ejbca-develop mailing list
>>>> Ejb...@li... <mailto:Ejb...@li...> <mailto:Ejb...@li... <mailto:Ejb...@li...>>
>>>> https://lists.sourceforge.net/lists/listinfo/ejbca-develop
>>>>
>>>
>>> ------------------------------------------------------------------------------
>>> Free Next-Gen Firewall Hardware Offer
>>> Buy your Sophos next-gen firewall before the end March 2013
>>> and get the hardware for free! Learn more.
>>> http://p.sf.net/sfu/sophos-d2d-feb
>>> _______________________________________________
>>> Ejbca-develop mailing list
>>> Ejb...@li... <mailto:Ejb...@li...> <mailto:Ejb...@li... <mailto:Ejb...@li...>>
>>> https://lists.sourceforge.net/lists/listinfo/ejbca-develop
>>>
>>>
>>>
>>>
>>> ------------------------------------------------------------------------------
>>> Free Next-Gen Firewall Hardware Offer
>>> Buy your Sophos next-gen firewall before the end March 2013
>>> and get the hardware for free! Learn more.
>>> http://p.sf.net/sfu/sophos-d2d-feb
>>>
>>>
>>>
>>> _______________________________________________
>>> Ejbca-develop mailing list
>>> Ejb...@li... <mailto:Ejb...@li...>
>>> https://lists.sourceforge.net/lists/listinfo/ejbca-develop
>>>
>>
>>
>>
>>
>> ------------------------------------------------------------------------------
>> Free Next-Gen Firewall Hardware Offer
>> Buy your Sophos next-gen firewall before the end March 2013
>> and get the hardware for free! Learn more.
>> http://p.sf.net/sfu/sophos-d2d-feb
>>
>>
>>
>> _______________________________________________
>> Ejbca-develop mailing list
>> Ejb...@li...
>> https://lists.sourceforge.net/lists/listinfo/ejbca-develop
>>
>
> ------------------------------------------------------------------------------
> Free Next-Gen Firewall Hardware Offer
> Buy your Sophos next-gen firewall before the end March 2013
> and get the hardware for free! Learn more.
> http://p.sf.net/sfu/sophos-d2d-feb
> _______________________________________________
> Ejbca-develop mailing list
> Ejb...@li...
> https://lists.sourceforge.net/lists/listinfo/ejbca-develop
|
|
From: ejbca-support <ejb...@pr...> - 2013-02-08 15:37:52
|
On 2013-02-08 15:31, Alireza Karbasian wrote: > ok if we assume that this is just a printout issue in openssl so what's happenning to main certificates from ejbca? i used the PEM certificate downloaded from EJBCA and not the converted one with openssl. i send the ca chain and signed pdf so you can check it out! i see the error in adobe acrobat 9,10 and 11 ! Hi Alireza Could you check that the CRL does not verify with OpenSSL? I don't see any problems but the PDF didn't validate here either :-) Anders > > ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ > *From:* ejbca-support <ejb...@pr...> > *To:* Alireza Karbasian <ili...@ya...>; ejb...@li... > *Sent:* Friday, February 8, 2013 3:48 PM > *Subject:* Re: [Ejbca-develop] Issuer mismatch error > > On 2013-02-08 13:05, Alireza Karbasian wrote: >> yes! this is what i guessed also! but the problem is this that i did not >> convert the certificates with openssl but i downloaded the PEM certificate >> from EJBCA and published CRL in CDP and same thing happens! >> is it possible that this is something related to PEM standard? > > No, this is just a printout formatting issue in OpenSSL. > Cheers > Anders > tech support >> >> ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ ------------------------ >> *From:* martijn.list <mar...@gm... <mailto:mar...@gm...>> >> *To:* ejb...@li... <mailto:ejb...@li...> >> *Sent:* Thursday, February 7, 2013 11:03 PM >> *Subject:* Re: [Ejbca-develop] Issuer mismatch error >> >> Hi, >> >> On 02/07/2013 08:12 PM, Alireza Karbasian wrote: >>> The attached file contains the test certificates. the certificate here >>> is not issued for pdf signing but this is the same thing that happens to >>> original certificates. >> >> Verification with OpenSSL seems to be ok after conversion of ca.cer to >> PEM (ca.cer.pem) >> >> openssl crl -in AdminCA1\(downloadedFromEJBCA\).crl -CAfile ca.cer.pem >> -inform DER >> >> martijn@coolermaster:~/temp/certs$ openssl crl -in >> AdminCA1\(downloadedFromEJBCA\).crl -CAfile ca.cer.pem -inform DER >> verify OK >> -----BEGIN X509 CRL----- >> MIICLDCCARQCAQEwDQYJKoZIhvcNAQEFBQAwNzERMA8GA1UEAwwIQWRtaW5DQTEx >> FTATBgNVBAoMDEVKQkNBIFNhbXBsZTELMAkGA1UEBhMCU0UXDTEzMDIwNzEyMzY0 >> N1oXDTEzMDIwODEyMzY0N1qggagwgaUwHwYDVR0jBBgwFoAU3BKuSh4TQDbsjtGJ >> S9LNaUfIO5gwCgYDVR0UBAMCAQIwdgYDVR0cBG8wbaBroGmGZ2h0dHA6Ly9pbGlh >> Y2EuaXI6ODA4MC9lamJjYS9wdWJsaWN3ZWIvd2ViZGlzdC9jZXJ0ZGlzdD9jbWQ9 >> Y3JsJmlzc3Vlcj1DTj1BZG1pbkNBMSxPPUVKQkNBJTIwU2FtcGxlLEM9U0UwDQYJ >> KoZIhvcNAQEFBQADggEBAHEj9XbM6634R2TtGOtSRGIpbML+/ZF9C/dLBxb76b21 >> 7cOdm/DGQ7u4cfaW5iU57RRYBXZCajE7xQWRj3yyMJGBm/pn+0IXNN50sjtO6VX2 >> AEwFtOVxvqSph8x7DDCUK3ZFQgmBgTouigqgKfM41ipamNn/Ri9IR0PxSxXfpo30 >> akCMYmN/gkmSxgZNzECzdc5kAe9mp+gRemoTZLLgZonzW/bD4H4i6jhrmzD/kCp9 >> i95y6jSZJR4sPMpSKJ7F8Pa8U0i1H0emBHVK+i9QPBDucH4CncZObm4O/MH7+H1p >> u3AjjVKUSWaKl419WOvL7FbXAbt0U2IVaBq5MTPgC9o= >> -----END X509 CRL----- >> >> So OpenSSL thinks the CRL is ok. My own application also thinks the CRL >> is ok. The issue with the extra space is an OpenSSL "issue". It seems >> that the code for x509 outputs an extra space after : but the code for >> crl does not. >> >> Kind regards, >> >> Martijn Brinkers >> >> >> -- >> DJIGZO email encryption >> >>> >>> ------------------------------------------------------------------------ >>> *From:* ejbca-support <ejb...@pr... <mailto:ejb...@pr...> <mailto:ejb...@pr... <mailto:ejb...@pr...>>> >>> *To:* Alireza Karbasian <ili...@ya... <mailto:ili...@ya...> <mailto:ili...@ya... <mailto:ili...@ya...>>>; >>> ejb...@li... <mailto:ejb...@li...> <mailto:ejb...@li... <mailto:ejb...@li...>> >>> *Sent:* Thursday, February 7, 2013 4:55 PM >>> *Subject:* Re: [Ejbca-develop] Issuer mismatch error >>> >>> On 2013-02-07 14:05, Alireza Karbasian wrote: >>> > hello >>> > >>> > I used EJBCA (4.0.13) to issue a certificate for PDF signing. >>> everything seemed good and documents got signed! now when I opens my PDF >>> in adobe reader it tries to validate certificate against the CRL with my >>> CDP. it can access it but it gives me an error that "Issuer names mismatch". >>> > I used these commands to check the issuer names: >>> >>>openssl x509 -in signing.pem -issuer -noout >>> >>>openssl crl -in crl.pem -issuer -noout >>> > >>> > and this is the output: >>> > openssl x509 -in test.pem -issuer -noout >>> > *issuer= /CN=AdminCA1/O=EJBCA Sample/C=SE* >>> > openssl crl -in crl.pem -issuer -noout >>> > *issuer=/CN=AdminCA1/O=EJBCA Sample/C=SE* >>> > ** >>> >>> Hi Alireza, >>> I have never heard about this before, can you send a >>> pasted certificate for us to study? >>> >>> Cheers >>> Anders >>> tech support >>> >>> >>> > as you can see there is space character in the beginning of >>> certificate issuer DN. I googled this and came to see there are some >>> discussions about this and assumed that this is a bug (in opnessl >>> maybe)! but no solutions! >>> > I could not find any related configuration in EJBCA to solve this and >>> yet I'm not sure even that this is a bug! did anybody encountered such a >>> problem? is this a bug in EJBCA? any help or guide will be appreciated! >>> > >>> > >>> > >>> ------------------------------------------------------------------------------ >>> > Free Next-Gen Firewall Hardware Offer >>> > Buy your Sophos next-gen firewall before the end March 2013 >>> > and get the hardware for free! Learn more. >>> > http://p.sf.net/sfu/sophos-d2d-feb >>> > >>> > >>> > >>> > _______________________________________________ >>> > Ejbca-develop mailing list >>> > Ejb...@li... <mailto:Ejb...@li...> <mailto:Ejb...@li... <mailto:Ejb...@li...>> >>> <mailto:Ejb...@li... <mailto:Ejb...@li...> <mailto:Ejb...@li... <mailto:Ejb...@li...>>> >>> > https://lists.sourceforge.net/lists/listinfo/ejbca-develop >>> > >>> >>> >>> >>> >>> >>> >>> >>> ------------------------------------------------------------------------------ >>> Free Next-Gen Firewall Hardware Offer >>> Buy your Sophos next-gen firewall before the end March 2013 >>> and get the hardware for free! Learn more. >>> http://p.sf.net/sfu/sophos-d2d-feb >>> >>> >>> >>> _______________________________________________ >>> Ejbca-develop mailing list >>> Ejb...@li... <mailto:Ejb...@li...> <mailto:Ejb...@li... <mailto:Ejb...@li...>> >>> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >>> >> >> >> ------------------------------------------------------------------------------ >> Free Next-Gen Firewall Hardware Offer >> Buy your Sophos next-gen firewall before the end March 2013 >> and get the hardware for free! Learn more. >> http://p.sf.net/sfu/sophos-d2d-feb >> _______________________________________________ >> Ejbca-develop mailing list >> Ejb...@li... <mailto:Ejb...@li...> <mailto:Ejb...@li... <mailto:Ejb...@li...>> >> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >> >> >> >> >> ------------------------------------------------------------------------------ >> Free Next-Gen Firewall Hardware Offer >> Buy your Sophos next-gen firewall before the end March 2013 >> and get the hardware for free! Learn more. >> http://p.sf.net/sfu/sophos-d2d-feb >> >> >> >> _______________________________________________ >> Ejbca-develop mailing list >> Ejb...@li... <mailto:Ejb...@li...> >> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >> > > > > > > ------------------------------------------------------------------------------ > Free Next-Gen Firewall Hardware Offer > Buy your Sophos next-gen firewall before the end March 2013 > and get the hardware for free! Learn more. > http://p.sf.net/sfu/sophos-d2d-feb > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Alireza K. <ili...@ya...> - 2013-02-08 14:23:17
|
yes it's the correct CRL. there is a script that downloads CRL from EJBCA and copies it to remote ftp so it can be accessed by internet! ________________________________ From: martijn.list <mar...@gm...> To: ejb...@li... Sent: Friday, February 8, 2013 3:47 PM Subject: Re: [Ejbca-develop] Issuer mismatch error On 02/08/2013 01:05 PM, Alireza Karbasian wrote: > yes! this is what i guessed also! but the problem is this that i did not > convert the certificates with openssl but i downloaded the PEM > certificate from EJBCA and published CRL in CDP and same thing happens! > is it possible that this is something related to PEM standard? a PEM encoded certificate is nothing more that a base64 encoded DER encoded certificate with some header and footer (-----BEGIN---- and -----END---- headers). Are you 100% certain that the CRL at the CRL dis. point is the correct CRL? Kind regards, Martijn > > ------------------------------------------------------------------------ > *From:* martijn.list <mar...@gm...> > *To:* ejb...@li... > *Sent:* Thursday, February 7, 2013 11:03 PM > *Subject:* Re: [Ejbca-develop] Issuer mismatch error > > Hi, > > On 02/07/2013 08:12 PM, Alireza Karbasian wrote: > > The attached file contains the test certificates. the certificate here > > is not issued for pdf signing but this is the same thing that happens to > > original certificates. > > Verification with OpenSSL seems to be ok after conversion of ca.cer to > PEM (ca.cer.pem) > > openssl crl -in AdminCA1\(downloadedFromEJBCA\).crl -CAfile ca.cer.pem > -inform DER > > martijn@coolermaster:~/temp/certs$ openssl crl -in > AdminCA1\(downloadedFromEJBCA\).crl -CAfile ca.cer.pem -inform DER > verify OK > -----BEGIN X509 CRL----- > MIICLDCCARQCAQEwDQYJKoZIhvcNAQEFBQAwNzERMA8GA1UEAwwIQWRtaW5DQTEx > FTATBgNVBAoMDEVKQkNBIFNhbXBsZTELMAkGA1UEBhMCU0UXDTEzMDIwNzEyMzY0 > N1oXDTEzMDIwODEyMzY0N1qggagwgaUwHwYDVR0jBBgwFoAU3BKuSh4TQDbsjtGJ > S9LNaUfIO5gwCgYDVR0UBAMCAQIwdgYDVR0cBG8wbaBroGmGZ2h0dHA6Ly9pbGlh > Y2EuaXI6ODA4MC9lamJjYS9wdWJsaWN3ZWIvd2ViZGlzdC9jZXJ0ZGlzdD9jbWQ9 > Y3JsJmlzc3Vlcj1DTj1BZG1pbkNBMSxPPUVKQkNBJTIwU2FtcGxlLEM9U0UwDQYJ > KoZIhvcNAQEFBQADggEBAHEj9XbM6634R2TtGOtSRGIpbML+/ZF9C/dLBxb76b21 > 7cOdm/DGQ7u4cfaW5iU57RRYBXZCajE7xQWRj3yyMJGBm/pn+0IXNN50sjtO6VX2 > AEwFtOVxvqSph8x7DDCUK3ZFQgmBgTouigqgKfM41ipamNn/Ri9IR0PxSxXfpo30 > akCMYmN/gkmSxgZNzECzdc5kAe9mp+gRemoTZLLgZonzW/bD4H4i6jhrmzD/kCp9 > i95y6jSZJR4sPMpSKJ7F8Pa8U0i1H0emBHVK+i9QPBDucH4CncZObm4O/MH7+H1p > u3AjjVKUSWaKl419WOvL7FbXAbt0U2IVaBq5MTPgC9o= > -----END X509 CRL----- > > So OpenSSL thinks the CRL is ok. My own application also thinks the CRL > is ok. The issue with the extra space is an OpenSSL "issue". It seems > that the code for x509 outputs an extra space after : but the code for > crl does not. > > Kind regards, > > Martijn Brinkers > > > -- > DJIGZO email encryption > > > > > ------------------------------------------------------------------------ > > *From:* ejbca-support <ejb...@pr... > <mailto:ejb...@pr...>> > > *To:* Alireza Karbasian <ili...@ya... > <mailto:ili...@ya...>>; > > ejb...@li... > <mailto:ejb...@li...> > > *Sent:* Thursday, February 7, 2013 4:55 PM > > *Subject:* Re: [Ejbca-develop] Issuer mismatch error > > > > On 2013-02-07 14:05, Alireza Karbasian wrote: > > > hello > > > > > > I used EJBCA (4.0.13) to issue a certificate for PDF signing. > > everything seemed good and documents got signed! now when I opens my PDF > > in adobe reader it tries to validate certificate against the CRL with my > > CDP. it can access it but it gives me an error that "Issuer names > mismatch". > > > I used these commands to check the issuer names: > > >>>openssl x509 -in signing.pem -issuer -noout > > >>>openssl crl -in crl.pem -issuer -noout > > > > > > and this is the output: > > > openssl x509 -in test.pem -issuer -noout > > > *issuer= /CN=AdminCA1/O=EJBCA Sample/C=SE* > > > openssl crl -in crl.pem -issuer -noout > > > *issuer=/CN=AdminCA1/O=EJBCA Sample/C=SE* > > > ** > > > > Hi Alireza, > > I have never heard about this before, can you send a > > pasted certificate for us to study? > > > > Cheers > > Anders > > tech support > > > > > > > as you can see there is space character in the beginning of > > certificate issuer DN. I googled this and came to see there are some > > discussions about this and assumed that this is a bug (in opnessl > > maybe)! but no solutions! > > > I could not find any related configuration in EJBCA to solve this and > > yet I'm not sure even that this is a bug! did anybody encountered such a > > problem? is this a bug in EJBCA? any help or guide will be appreciated! > > > > > > > > > > > > ------------------------------------------------------------------------------ > > > Free Next-Gen Firewall Hardware Offer > > > Buy your Sophos next-gen firewall before the end March 2013 > > > and get the hardware for free! Learn more. > > > http://p.sf.net/sfu/sophos-d2d-feb > > > > > > > > > > > > _______________________________________________ > > > Ejbca-develop mailing list > > > Ejb...@li... > <mailto:Ejb...@li...> > > <mailto:Ejb...@li... > <mailto:Ejb...@li...>> > > > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > > > > > > > > > > > > > > > > > ------------------------------------------------------------------------------ > > Free Next-Gen Firewall Hardware Offer > > Buy your Sophos next-gen firewall before the end March 2013 > > and get the hardware for free! Learn more. > > http://p.sf.net/sfu/sophos-d2d-feb > > > > > > > > _______________________________________________ > > Ejbca-develop mailing list > > Ejb...@li... > <mailto:Ejb...@li...> > > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > > ------------------------------------------------------------------------------ > Free Next-Gen Firewall Hardware Offer > Buy your Sophos next-gen firewall before the end March 2013 > and get the hardware for free! Learn more. > http://p.sf.net/sfu/sophos-d2d-feb > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > <mailto:Ejb...@li...> > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > > ------------------------------------------------------------------------------ > Free Next-Gen Firewall Hardware Offer > Buy your Sophos next-gen firewall before the end March 2013 > and get the hardware for free! Learn more. > http://p.sf.net/sfu/sophos-d2d-feb > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > -- DJIGZO email encryption ------------------------------------------------------------------------------ Free Next-Gen Firewall Hardware Offer Buy your Sophos next-gen firewall before the end March 2013 and get the hardware for free! Learn more. http://p.sf.net/sfu/sophos-d2d-feb _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: ejbca-support <ejb...@pr...> - 2013-02-08 12:18:51
|
On 2013-02-08 13:05, Alireza Karbasian wrote: > yes! this is what i guessed also! but the problem is this that i did not > convert the certificates with openssl but i downloaded the PEM certificate > from EJBCA and published CRL in CDP and same thing happens! > is it possible that this is something related to PEM standard? No, this is just a printout formatting issue in OpenSSL. Cheers Anders tech support > > ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ > *From:* martijn.list <mar...@gm...> > *To:* ejb...@li... > *Sent:* Thursday, February 7, 2013 11:03 PM > *Subject:* Re: [Ejbca-develop] Issuer mismatch error > > Hi, > > On 02/07/2013 08:12 PM, Alireza Karbasian wrote: >> The attached file contains the test certificates. the certificate here >> is not issued for pdf signing but this is the same thing that happens to >> original certificates. > > Verification with OpenSSL seems to be ok after conversion of ca.cer to > PEM (ca.cer.pem) > > openssl crl -in AdminCA1\(downloadedFromEJBCA\).crl -CAfile ca.cer.pem > -inform DER > > martijn@coolermaster:~/temp/certs$ openssl crl -in > AdminCA1\(downloadedFromEJBCA\).crl -CAfile ca.cer.pem -inform DER > verify OK > -----BEGIN X509 CRL----- > MIICLDCCARQCAQEwDQYJKoZIhvcNAQEFBQAwNzERMA8GA1UEAwwIQWRtaW5DQTEx > FTATBgNVBAoMDEVKQkNBIFNhbXBsZTELMAkGA1UEBhMCU0UXDTEzMDIwNzEyMzY0 > N1oXDTEzMDIwODEyMzY0N1qggagwgaUwHwYDVR0jBBgwFoAU3BKuSh4TQDbsjtGJ > S9LNaUfIO5gwCgYDVR0UBAMCAQIwdgYDVR0cBG8wbaBroGmGZ2h0dHA6Ly9pbGlh > Y2EuaXI6ODA4MC9lamJjYS9wdWJsaWN3ZWIvd2ViZGlzdC9jZXJ0ZGlzdD9jbWQ9 > Y3JsJmlzc3Vlcj1DTj1BZG1pbkNBMSxPPUVKQkNBJTIwU2FtcGxlLEM9U0UwDQYJ > KoZIhvcNAQEFBQADggEBAHEj9XbM6634R2TtGOtSRGIpbML+/ZF9C/dLBxb76b21 > 7cOdm/DGQ7u4cfaW5iU57RRYBXZCajE7xQWRj3yyMJGBm/pn+0IXNN50sjtO6VX2 > AEwFtOVxvqSph8x7DDCUK3ZFQgmBgTouigqgKfM41ipamNn/Ri9IR0PxSxXfpo30 > akCMYmN/gkmSxgZNzECzdc5kAe9mp+gRemoTZLLgZonzW/bD4H4i6jhrmzD/kCp9 > i95y6jSZJR4sPMpSKJ7F8Pa8U0i1H0emBHVK+i9QPBDucH4CncZObm4O/MH7+H1p > u3AjjVKUSWaKl419WOvL7FbXAbt0U2IVaBq5MTPgC9o= > -----END X509 CRL----- > > So OpenSSL thinks the CRL is ok. My own application also thinks the CRL > is ok. The issue with the extra space is an OpenSSL "issue". It seems > that the code for x509 outputs an extra space after : but the code for > crl does not. > > Kind regards, > > Martijn Brinkers > > > -- > DJIGZO email encryption > >> >> ------------------------------------------------------------------------ >> *From:* ejbca-support <ejb...@pr... <mailto:ejb...@pr...>> >> *To:* Alireza Karbasian <ili...@ya... <mailto:ili...@ya...>>; >> ejb...@li... <mailto:ejb...@li...> >> *Sent:* Thursday, February 7, 2013 4:55 PM >> *Subject:* Re: [Ejbca-develop] Issuer mismatch error >> >> On 2013-02-07 14:05, Alireza Karbasian wrote: >> > hello >> > >> > I used EJBCA (4.0.13) to issue a certificate for PDF signing. >> everything seemed good and documents got signed! now when I opens my PDF >> in adobe reader it tries to validate certificate against the CRL with my >> CDP. it can access it but it gives me an error that "Issuer names mismatch". >> > I used these commands to check the issuer names: >> >>>openssl x509 -in signing.pem -issuer -noout >> >>>openssl crl -in crl.pem -issuer -noout >> > >> > and this is the output: >> > openssl x509 -in test.pem -issuer -noout >> > *issuer= /CN=AdminCA1/O=EJBCA Sample/C=SE* >> > openssl crl -in crl.pem -issuer -noout >> > *issuer=/CN=AdminCA1/O=EJBCA Sample/C=SE* >> > ** >> >> Hi Alireza, >> I have never heard about this before, can you send a >> pasted certificate for us to study? >> >> Cheers >> Anders >> tech support >> >> >> > as you can see there is space character in the beginning of >> certificate issuer DN. I googled this and came to see there are some >> discussions about this and assumed that this is a bug (in opnessl >> maybe)! but no solutions! >> > I could not find any related configuration in EJBCA to solve this and >> yet I'm not sure even that this is a bug! did anybody encountered such a >> problem? is this a bug in EJBCA? any help or guide will be appreciated! >> > >> > >> > >> ------------------------------------------------------------------------------ >> > Free Next-Gen Firewall Hardware Offer >> > Buy your Sophos next-gen firewall before the end March 2013 >> > and get the hardware for free! Learn more. >> > http://p.sf.net/sfu/sophos-d2d-feb >> > >> > >> > >> > _______________________________________________ >> > Ejbca-develop mailing list >> > Ejb...@li... <mailto:Ejb...@li...> >> <mailto:Ejb...@li... <mailto:Ejb...@li...>> >> > https://lists.sourceforge.net/lists/listinfo/ejbca-develop >> > >> >> >> >> >> >> >> >> ------------------------------------------------------------------------------ >> Free Next-Gen Firewall Hardware Offer >> Buy your Sophos next-gen firewall before the end March 2013 >> and get the hardware for free! Learn more. >> http://p.sf.net/sfu/sophos-d2d-feb >> >> >> >> _______________________________________________ >> Ejbca-develop mailing list >> Ejb...@li... <mailto:Ejb...@li...> >> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >> > > > ------------------------------------------------------------------------------ > Free Next-Gen Firewall Hardware Offer > Buy your Sophos next-gen firewall before the end March 2013 > and get the hardware for free! Learn more. > http://p.sf.net/sfu/sophos-d2d-feb > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... <mailto:Ejb...@li...> > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > > ------------------------------------------------------------------------------ > Free Next-Gen Firewall Hardware Offer > Buy your Sophos next-gen firewall before the end March 2013 > and get the hardware for free! Learn more. > http://p.sf.net/sfu/sophos-d2d-feb > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: martijn.list <mar...@gm...> - 2013-02-08 12:17:55
|
On 02/08/2013 01:05 PM, Alireza Karbasian wrote: > yes! this is what i guessed also! but the problem is this that i did not > convert the certificates with openssl but i downloaded the PEM > certificate from EJBCA and published CRL in CDP and same thing happens! > is it possible that this is something related to PEM standard? a PEM encoded certificate is nothing more that a base64 encoded DER encoded certificate with some header and footer (-----BEGIN---- and -----END---- headers). Are you 100% certain that the CRL at the CRL dis. point is the correct CRL? Kind regards, Martijn > > ------------------------------------------------------------------------ > *From:* martijn.list <mar...@gm...> > *To:* ejb...@li... > *Sent:* Thursday, February 7, 2013 11:03 PM > *Subject:* Re: [Ejbca-develop] Issuer mismatch error > > Hi, > > On 02/07/2013 08:12 PM, Alireza Karbasian wrote: > > The attached file contains the test certificates. the certificate here > > is not issued for pdf signing but this is the same thing that happens to > > original certificates. > > Verification with OpenSSL seems to be ok after conversion of ca.cer to > PEM (ca.cer.pem) > > openssl crl -in AdminCA1\(downloadedFromEJBCA\).crl -CAfile ca.cer.pem > -inform DER > > martijn@coolermaster:~/temp/certs$ openssl crl -in > AdminCA1\(downloadedFromEJBCA\).crl -CAfile ca.cer.pem -inform DER > verify OK > -----BEGIN X509 CRL----- > MIICLDCCARQCAQEwDQYJKoZIhvcNAQEFBQAwNzERMA8GA1UEAwwIQWRtaW5DQTEx > FTATBgNVBAoMDEVKQkNBIFNhbXBsZTELMAkGA1UEBhMCU0UXDTEzMDIwNzEyMzY0 > N1oXDTEzMDIwODEyMzY0N1qggagwgaUwHwYDVR0jBBgwFoAU3BKuSh4TQDbsjtGJ > S9LNaUfIO5gwCgYDVR0UBAMCAQIwdgYDVR0cBG8wbaBroGmGZ2h0dHA6Ly9pbGlh > Y2EuaXI6ODA4MC9lamJjYS9wdWJsaWN3ZWIvd2ViZGlzdC9jZXJ0ZGlzdD9jbWQ9 > Y3JsJmlzc3Vlcj1DTj1BZG1pbkNBMSxPPUVKQkNBJTIwU2FtcGxlLEM9U0UwDQYJ > KoZIhvcNAQEFBQADggEBAHEj9XbM6634R2TtGOtSRGIpbML+/ZF9C/dLBxb76b21 > 7cOdm/DGQ7u4cfaW5iU57RRYBXZCajE7xQWRj3yyMJGBm/pn+0IXNN50sjtO6VX2 > AEwFtOVxvqSph8x7DDCUK3ZFQgmBgTouigqgKfM41ipamNn/Ri9IR0PxSxXfpo30 > akCMYmN/gkmSxgZNzECzdc5kAe9mp+gRemoTZLLgZonzW/bD4H4i6jhrmzD/kCp9 > i95y6jSZJR4sPMpSKJ7F8Pa8U0i1H0emBHVK+i9QPBDucH4CncZObm4O/MH7+H1p > u3AjjVKUSWaKl419WOvL7FbXAbt0U2IVaBq5MTPgC9o= > -----END X509 CRL----- > > So OpenSSL thinks the CRL is ok. My own application also thinks the CRL > is ok. The issue with the extra space is an OpenSSL "issue". It seems > that the code for x509 outputs an extra space after : but the code for > crl does not. > > Kind regards, > > Martijn Brinkers > > > -- > DJIGZO email encryption > > > > > ------------------------------------------------------------------------ > > *From:* ejbca-support <ejb...@pr... > <mailto:ejb...@pr...>> > > *To:* Alireza Karbasian <ili...@ya... > <mailto:ili...@ya...>>; > > ejb...@li... > <mailto:ejb...@li...> > > *Sent:* Thursday, February 7, 2013 4:55 PM > > *Subject:* Re: [Ejbca-develop] Issuer mismatch error > > > > On 2013-02-07 14:05, Alireza Karbasian wrote: > > > hello > > > > > > I used EJBCA (4.0.13) to issue a certificate for PDF signing. > > everything seemed good and documents got signed! now when I opens my PDF > > in adobe reader it tries to validate certificate against the CRL with my > > CDP. it can access it but it gives me an error that "Issuer names > mismatch". > > > I used these commands to check the issuer names: > > >>>openssl x509 -in signing.pem -issuer -noout > > >>>openssl crl -in crl.pem -issuer -noout > > > > > > and this is the output: > > > openssl x509 -in test.pem -issuer -noout > > > *issuer= /CN=AdminCA1/O=EJBCA Sample/C=SE* > > > openssl crl -in crl.pem -issuer -noout > > > *issuer=/CN=AdminCA1/O=EJBCA Sample/C=SE* > > > ** > > > > Hi Alireza, > > I have never heard about this before, can you send a > > pasted certificate for us to study? > > > > Cheers > > Anders > > tech support > > > > > > > as you can see there is space character in the beginning of > > certificate issuer DN. I googled this and came to see there are some > > discussions about this and assumed that this is a bug (in opnessl > > maybe)! but no solutions! > > > I could not find any related configuration in EJBCA to solve this and > > yet I'm not sure even that this is a bug! did anybody encountered such a > > problem? is this a bug in EJBCA? any help or guide will be appreciated! > > > > > > > > > > > > ------------------------------------------------------------------------------ > > > Free Next-Gen Firewall Hardware Offer > > > Buy your Sophos next-gen firewall before the end March 2013 > > > and get the hardware for free! Learn more. > > > http://p.sf.net/sfu/sophos-d2d-feb > > > > > > > > > > > > _______________________________________________ > > > Ejbca-develop mailing list > > > Ejb...@li... > <mailto:Ejb...@li...> > > <mailto:Ejb...@li... > <mailto:Ejb...@li...>> > > > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > > > > > > > > > > > > > > > > > ------------------------------------------------------------------------------ > > Free Next-Gen Firewall Hardware Offer > > Buy your Sophos next-gen firewall before the end March 2013 > > and get the hardware for free! Learn more. > > http://p.sf.net/sfu/sophos-d2d-feb > > > > > > > > _______________________________________________ > > Ejbca-develop mailing list > > Ejb...@li... > <mailto:Ejb...@li...> > > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > > ------------------------------------------------------------------------------ > Free Next-Gen Firewall Hardware Offer > Buy your Sophos next-gen firewall before the end March 2013 > and get the hardware for free! Learn more. > http://p.sf.net/sfu/sophos-d2d-feb > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > <mailto:Ejb...@li...> > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > > ------------------------------------------------------------------------------ > Free Next-Gen Firewall Hardware Offer > Buy your Sophos next-gen firewall before the end March 2013 > and get the hardware for free! Learn more. > http://p.sf.net/sfu/sophos-d2d-feb > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > -- DJIGZO email encryption |
|
From: Alireza K. <ili...@ya...> - 2013-02-08 12:05:26
|
yes! this is what i guessed also! but the problem is this that i did not convert the certificates with openssl but i downloaded the PEM certificate from EJBCA and published CRL in CDP and same thing happens! is it possible that this is something related to PEM standard? ________________________________ From: martijn.list <mar...@gm...> To: ejb...@li... Sent: Thursday, February 7, 2013 11:03 PM Subject: Re: [Ejbca-develop] Issuer mismatch error Hi, On 02/07/2013 08:12 PM, Alireza Karbasian wrote: > The attached file contains the test certificates. the certificate here > is not issued for pdf signing but this is the same thing that happens to > original certificates. Verification with OpenSSL seems to be ok after conversion of ca.cer to PEM (ca.cer.pem) openssl crl -in AdminCA1\(downloadedFromEJBCA\).crl -CAfile ca.cer.pem -inform DER martijn@coolermaster:~/temp/certs$ openssl crl -in AdminCA1\(downloadedFromEJBCA\).crl -CAfile ca.cer.pem -inform DER verify OK -----BEGIN X509 CRL----- MIICLDCCARQCAQEwDQYJKoZIhvcNAQEFBQAwNzERMA8GA1UEAwwIQWRtaW5DQTEx FTATBgNVBAoMDEVKQkNBIFNhbXBsZTELMAkGA1UEBhMCU0UXDTEzMDIwNzEyMzY0 N1oXDTEzMDIwODEyMzY0N1qggagwgaUwHwYDVR0jBBgwFoAU3BKuSh4TQDbsjtGJ S9LNaUfIO5gwCgYDVR0UBAMCAQIwdgYDVR0cBG8wbaBroGmGZ2h0dHA6Ly9pbGlh Y2EuaXI6ODA4MC9lamJjYS9wdWJsaWN3ZWIvd2ViZGlzdC9jZXJ0ZGlzdD9jbWQ9 Y3JsJmlzc3Vlcj1DTj1BZG1pbkNBMSxPPUVKQkNBJTIwU2FtcGxlLEM9U0UwDQYJ KoZIhvcNAQEFBQADggEBAHEj9XbM6634R2TtGOtSRGIpbML+/ZF9C/dLBxb76b21 7cOdm/DGQ7u4cfaW5iU57RRYBXZCajE7xQWRj3yyMJGBm/pn+0IXNN50sjtO6VX2 AEwFtOVxvqSph8x7DDCUK3ZFQgmBgTouigqgKfM41ipamNn/Ri9IR0PxSxXfpo30 akCMYmN/gkmSxgZNzECzdc5kAe9mp+gRemoTZLLgZonzW/bD4H4i6jhrmzD/kCp9 i95y6jSZJR4sPMpSKJ7F8Pa8U0i1H0emBHVK+i9QPBDucH4CncZObm4O/MH7+H1p u3AjjVKUSWaKl419WOvL7FbXAbt0U2IVaBq5MTPgC9o= -----END X509 CRL----- So OpenSSL thinks the CRL is ok. My own application also thinks the CRL is ok. The issue with the extra space is an OpenSSL "issue". It seems that the code for x509 outputs an extra space after : but the code for crl does not. Kind regards, Martijn Brinkers -- DJIGZO email encryption > > ------------------------------------------------------------------------ > *From:* ejbca-support <ejb...@pr...> > *To:* Alireza Karbasian <ili...@ya...>; > ejb...@li... > *Sent:* Thursday, February 7, 2013 4:55 PM > *Subject:* Re: [Ejbca-develop] Issuer mismatch error > > On 2013-02-07 14:05, Alireza Karbasian wrote: > > hello > > > > I used EJBCA (4.0.13) to issue a certificate for PDF signing. > everything seemed good and documents got signed! now when I opens my PDF > in adobe reader it tries to validate certificate against the CRL with my > CDP. it can access it but it gives me an error that "Issuer names mismatch". > > I used these commands to check the issuer names: > >>>openssl x509 -in signing.pem -issuer -noout > >>>openssl crl -in crl.pem -issuer -noout > > > > and this is the output: > > openssl x509 -in test.pem -issuer -noout > > *issuer= /CN=AdminCA1/O=EJBCA Sample/C=SE* > > openssl crl -in crl.pem -issuer -noout > > *issuer=/CN=AdminCA1/O=EJBCA Sample/C=SE* > > ** > > Hi Alireza, > I have never heard about this before, can you send a > pasted certificate for us to study? > > Cheers > Anders > tech support > > > > as you can see there is space character in the beginning of > certificate issuer DN. I googled this and came to see there are some > discussions about this and assumed that this is a bug (in opnessl > maybe)! but no solutions! > > I could not find any related configuration in EJBCA to solve this and > yet I'm not sure even that this is a bug! did anybody encountered such a > problem? is this a bug in EJBCA? any help or guide will be appreciated! > > > > > > > ------------------------------------------------------------------------------ > > Free Next-Gen Firewall Hardware Offer > > Buy your Sophos next-gen firewall before the end March 2013 > > and get the hardware for free! Learn more. > > http://p.sf.net/sfu/sophos-d2d-feb > > > > > > > > _______________________________________________ > > Ejbca-develop mailing list > > Ejb...@li... > <mailto:Ejb...@li...> > > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > > > > > > > ------------------------------------------------------------------------------ > Free Next-Gen Firewall Hardware Offer > Buy your Sophos next-gen firewall before the end March 2013 > and get the hardware for free! Learn more. > http://p.sf.net/sfu/sophos-d2d-feb > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > ------------------------------------------------------------------------------ Free Next-Gen Firewall Hardware Offer Buy your Sophos next-gen firewall before the end March 2013 and get the hardware for free! Learn more. http://p.sf.net/sfu/sophos-d2d-feb _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: martijn.list <mar...@gm...> - 2013-02-07 19:33:57
|
Hi, On 02/07/2013 08:12 PM, Alireza Karbasian wrote: > The attached file contains the test certificates. the certificate here > is not issued for pdf signing but this is the same thing that happens to > original certificates. Verification with OpenSSL seems to be ok after conversion of ca.cer to PEM (ca.cer.pem) openssl crl -in AdminCA1\(downloadedFromEJBCA\).crl -CAfile ca.cer.pem -inform DER martijn@coolermaster:~/temp/certs$ openssl crl -in AdminCA1\(downloadedFromEJBCA\).crl -CAfile ca.cer.pem -inform DER verify OK -----BEGIN X509 CRL----- MIICLDCCARQCAQEwDQYJKoZIhvcNAQEFBQAwNzERMA8GA1UEAwwIQWRtaW5DQTEx FTATBgNVBAoMDEVKQkNBIFNhbXBsZTELMAkGA1UEBhMCU0UXDTEzMDIwNzEyMzY0 N1oXDTEzMDIwODEyMzY0N1qggagwgaUwHwYDVR0jBBgwFoAU3BKuSh4TQDbsjtGJ S9LNaUfIO5gwCgYDVR0UBAMCAQIwdgYDVR0cBG8wbaBroGmGZ2h0dHA6Ly9pbGlh Y2EuaXI6ODA4MC9lamJjYS9wdWJsaWN3ZWIvd2ViZGlzdC9jZXJ0ZGlzdD9jbWQ9 Y3JsJmlzc3Vlcj1DTj1BZG1pbkNBMSxPPUVKQkNBJTIwU2FtcGxlLEM9U0UwDQYJ KoZIhvcNAQEFBQADggEBAHEj9XbM6634R2TtGOtSRGIpbML+/ZF9C/dLBxb76b21 7cOdm/DGQ7u4cfaW5iU57RRYBXZCajE7xQWRj3yyMJGBm/pn+0IXNN50sjtO6VX2 AEwFtOVxvqSph8x7DDCUK3ZFQgmBgTouigqgKfM41ipamNn/Ri9IR0PxSxXfpo30 akCMYmN/gkmSxgZNzECzdc5kAe9mp+gRemoTZLLgZonzW/bD4H4i6jhrmzD/kCp9 i95y6jSZJR4sPMpSKJ7F8Pa8U0i1H0emBHVK+i9QPBDucH4CncZObm4O/MH7+H1p u3AjjVKUSWaKl419WOvL7FbXAbt0U2IVaBq5MTPgC9o= -----END X509 CRL----- So OpenSSL thinks the CRL is ok. My own application also thinks the CRL is ok. The issue with the extra space is an OpenSSL "issue". It seems that the code for x509 outputs an extra space after : but the code for crl does not. Kind regards, Martijn Brinkers -- DJIGZO email encryption > > ------------------------------------------------------------------------ > *From:* ejbca-support <ejb...@pr...> > *To:* Alireza Karbasian <ili...@ya...>; > ejb...@li... > *Sent:* Thursday, February 7, 2013 4:55 PM > *Subject:* Re: [Ejbca-develop] Issuer mismatch error > > On 2013-02-07 14:05, Alireza Karbasian wrote: > > hello > > > > I used EJBCA (4.0.13) to issue a certificate for PDF signing. > everything seemed good and documents got signed! now when I opens my PDF > in adobe reader it tries to validate certificate against the CRL with my > CDP. it can access it but it gives me an error that "Issuer names mismatch". > > I used these commands to check the issuer names: > >>>openssl x509 -in signing.pem -issuer -noout > >>>openssl crl -in crl.pem -issuer -noout > > > > and this is the output: > > openssl x509 -in test.pem -issuer -noout > > *issuer= /CN=AdminCA1/O=EJBCA Sample/C=SE* > > openssl crl -in crl.pem -issuer -noout > > *issuer=/CN=AdminCA1/O=EJBCA Sample/C=SE* > > ** > > Hi Alireza, > I have never heard about this before, can you send a > pasted certificate for us to study? > > Cheers > Anders > tech support > > > > as you can see there is space character in the beginning of > certificate issuer DN. I googled this and came to see there are some > discussions about this and assumed that this is a bug (in opnessl > maybe)! but no solutions! > > I could not find any related configuration in EJBCA to solve this and > yet I'm not sure even that this is a bug! did anybody encountered such a > problem? is this a bug in EJBCA? any help or guide will be appreciated! > > > > > > > ------------------------------------------------------------------------------ > > Free Next-Gen Firewall Hardware Offer > > Buy your Sophos next-gen firewall before the end March 2013 > > and get the hardware for free! Learn more. > > http://p.sf.net/sfu/sophos-d2d-feb > > > > > > > > _______________________________________________ > > Ejbca-develop mailing list > > Ejb...@li... > <mailto:Ejb...@li...> > > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > > > > > > > ------------------------------------------------------------------------------ > Free Next-Gen Firewall Hardware Offer > Buy your Sophos next-gen firewall before the end March 2013 > and get the hardware for free! Learn more. > http://p.sf.net/sfu/sophos-d2d-feb > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Tomas G. <to...@pr...> - 2013-02-07 14:14:57
|
At least we know PDF signing with EJBCA issued certificates works in practice in a couple of places (in production). It looks to me a bug just in the display outout of openssl. Cheers, Tomas On 02/07/2013 02:25 PM, ejbca-support wrote: > On 2013-02-07 14:05, Alireza Karbasian wrote: >> hello >> >> I used EJBCA (4.0.13) to issue a certificate for PDF signing. everything seemed good and documents got signed! now when I opens my PDF in adobe reader it tries to validate certificate against the CRL with my CDP. it can access it but it gives me an error that "Issuer names mismatch". >> I used these commands to check the issuer names: >>>> openssl x509 -in signing.pem -issuer -noout >>>> openssl crl -in crl.pem -issuer -noout >> >> and this is the output: >> openssl x509 -in test.pem -issuer -noout >> *issuer= /CN=AdminCA1/O=EJBCA Sample/C=SE* >> openssl crl -in crl.pem -issuer -noout >> *issuer=/CN=AdminCA1/O=EJBCA Sample/C=SE* >> ** > > Hi Alireza, > I have never heard about this before, can you send a > pasted certificate for us to study? > > Cheers > Anders > tech support > > >> as you can see there is space character in the beginning of certificate issuer DN. I googled this and came to see there are some discussions about this and assumed that this is a bug (in opnessl maybe)! but no solutions! >> I could not find any related configuration in EJBCA to solve this and yet I'm not sure even that this is a bug! did anybody encountered such a problem? is this a bug in EJBCA? any help or guide will be appreciated! >> >> >> ------------------------------------------------------------------------------ >> Free Next-Gen Firewall Hardware Offer >> Buy your Sophos next-gen firewall before the end March 2013 >> and get the hardware for free! Learn more. >> http://p.sf.net/sfu/sophos-d2d-feb >> >> >> >> _______________________________________________ >> Ejbca-develop mailing list >> Ejb...@li... >> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >> > > > ------------------------------------------------------------------------------ > Free Next-Gen Firewall Hardware Offer > Buy your Sophos next-gen firewall before the end March 2013 > and get the hardware for free! Learn more. > http://p.sf.net/sfu/sophos-d2d-feb > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: ejbca-support <ejb...@pr...> - 2013-02-07 13:25:31
|
On 2013-02-07 14:05, Alireza Karbasian wrote: > hello > > I used EJBCA (4.0.13) to issue a certificate for PDF signing. everything seemed good and documents got signed! now when I opens my PDF in adobe reader it tries to validate certificate against the CRL with my CDP. it can access it but it gives me an error that "Issuer names mismatch". > I used these commands to check the issuer names: >>>openssl x509 -in signing.pem -issuer -noout >>>openssl crl -in crl.pem -issuer -noout > > and this is the output: > openssl x509 -in test.pem -issuer -noout > *issuer= /CN=AdminCA1/O=EJBCA Sample/C=SE* > openssl crl -in crl.pem -issuer -noout > *issuer=/CN=AdminCA1/O=EJBCA Sample/C=SE* > ** Hi Alireza, I have never heard about this before, can you send a pasted certificate for us to study? Cheers Anders tech support > as you can see there is space character in the beginning of certificate issuer DN. I googled this and came to see there are some discussions about this and assumed that this is a bug (in opnessl maybe)! but no solutions! > I could not find any related configuration in EJBCA to solve this and yet I'm not sure even that this is a bug! did anybody encountered such a problem? is this a bug in EJBCA? any help or guide will be appreciated! > > > ------------------------------------------------------------------------------ > Free Next-Gen Firewall Hardware Offer > Buy your Sophos next-gen firewall before the end March 2013 > and get the hardware for free! Learn more. > http://p.sf.net/sfu/sophos-d2d-feb > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Alireza K. <ili...@ya...> - 2013-02-07 13:05:49
|
hello I used EJBCA (4.0.13) to issue a certificate for PDF signing. everything seemed good and documents got signed! now when I opens my PDF in adobe reader it tries to validate certificate against the CRL with my CDP. it can access it but it gives me an error that "Issuer names mismatch". I used these commands to check the issuer names: >>openssl x509 -in signing.pem -issuer -noout >>openssl crl -in crl.pem -issuer -noout and this is the output: openssl x509 -in test.pem -issuer -noout issuer= /CN=AdminCA1/O=EJBCA Sample/C=SE openssl crl -in crl.pem -issuer -noout issuer=/CN=AdminCA1/O=EJBCA Sample/C=SE as you can see there is space character in the beginning of certificate issuer DN. I googled this and came to see there are some discussions about this and assumed that this is a bug (in opnessl maybe)! but no solutions! I could not find any related configuration in EJBCA to solve this and yet I'm not sure even that this is a bug! did anybody encountered such a problem? is this a bug in EJBCA? any help or guide will be appreciated! |
|
From: Tomas G. <to...@pr...> - 2013-02-05 16:06:43
|
You should check "JBoss 5.1 WS WSDL location" at http://www.ejbca.org/installation.html#JBoss. Cheers, Tomas ** VISIT US AT RSA EXPO - BOOTH #459 ** **** FREE EXPO PASS CODE: FXE13PKS **** https://ae.rsaconference.com/US13/portal/login.ww ********** PrimeKey Solutions AB Anderstorpsvägen 16, 171 54 Solna, Sweden Mob: +46 (0)707421096 Internet: www.primekey.se Twitter: twitter.com/primekeyPKI ********** On 02/05/2013 04:30 PM, Henrik wrote: > Hello, > > I currently got a problem with my wsdl file for EJBCA 4.0.13 (r16055). > It contains the localhost (127.0.0.1) instead of the external hostname > for the webservice. > > <service name="EjbcaWSService"><port binding="tns:EjbcaWSBinding" > name="EjbcaWSPort"><soap:address > location="http://127.0.0.1:8080/ejbca/ejbcaws/ejbcaws"/></port></service> > > Is there a way to change the hostname without reinstalling EJBCA? > > Greetings, > --henrik > > ------------------------------------------------------------------------------ > Free Next-Gen Firewall Hardware Offer > Buy your Sophos next-gen firewall before the end March 2013 > and get the hardware for free! Learn more. > http://p.sf.net/sfu/sophos-d2d-feb > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Henrik <Hen...@Go...> - 2013-02-05 16:06:14
|
Hello, Nevermind, I just found the answer in http://www.ejbca.org/installation.html *** JBoss 5.1 WS WSDL location *** On JBoss 5.1.x (not on JBoss 6.0.x) the WSDL location gets incorrectly generated by default. To fix this (see JBoss settings during install) edit: APPSRV_HOME/server/default/deployers/jbossws.deployer/META-INF/jboss-beans.xml and comment out the line: <property name="webServiceHost">${jboss.bind.address}</property> to force the location to be generated with info from the WSDL request. If this is not done you will get "HTTP 302 Moved Temporarily" errors when running the WS client. Greetings, --henrik On Tue, Feb 5, 2013 at 4:30 PM, Henrik <Hen...@go...> wrote: > Hello, > > I currently got a problem with my wsdl file for EJBCA 4.0.13 (r16055). > It contains the localhost (127.0.0.1) instead of the external hostname > for the webservice. > > <service name="EjbcaWSService"><port binding="tns:EjbcaWSBinding" > name="EjbcaWSPort"><soap:address > location="http://127.0.0.1:8080/ejbca/ejbcaws/ejbcaws"/></port></service> > > Is there a way to change the hostname without reinstalling EJBCA? > > Greetings, > --henrik |
|
From: Henrik <Hen...@Go...> - 2013-02-05 15:37:35
|
Hello, I currently got a problem with my wsdl file for EJBCA 4.0.13 (r16055). It contains the localhost (127.0.0.1) instead of the external hostname for the webservice. <service name="EjbcaWSService"><port binding="tns:EjbcaWSBinding" name="EjbcaWSPort"><soap:address location="http://127.0.0.1:8080/ejbca/ejbcaws/ejbcaws"/></port></service> Is there a way to change the hostname without reinstalling EJBCA? Greetings, --henrik |
|
From: Tomas G. <to...@pr...> - 2013-02-04 14:30:58
|
Hi, We will be, with EJBCA, in a booth at the RSA Conference in San Francisco this year. If you are in the neighbourhood between Feb 25 and March 1, come and visit. You can find the free expo pass code below or at http://ejbca.org/. Cheers, Tomas -- ** VISIT US AT RSA EXPO - BOOTH #459 ** **** FREE EXPO PASS CODE: FXE13PKS **** https://ae.rsaconference.com/US13/portal/login.ww |
|
From: Juan C. <ju...@re...> - 2013-01-24 19:44:23
|
Kevin, try putting the DB driver's jar into JBOSS_HOME/servers/default/lib and try again. Do you have the enviroment variables setted up as the install document said? Do you change the jboss path in the property file? Cheers! El 23/01/2013 23:17, "孙伟" <kev...@gm...> escribió: > Hello, > > I am a tester who is new to EJBCA. Recently I was trying to install EJBCA > on CentOS 6.2 box. The "ant bootstrap" process is OK, while I encountered > the problem with "ant install": javax.naming.NameNotFoundException: ejbca > not bound, and this cause the batch generation failure. Searched online > that this may be the issue of database binding, and that is why I found my > ejbca database with empty table. > > My environment: > CentOS 6.2 > java-1.6.0-openjdk > apache-ant-1.8.4 > jboss-5.1.0-GA-jdk6 > > Thanks in advance! > Kevin > > > ------------------------------------------------------------------------------ > Master Visual Studio, SharePoint, SQL, ASP.NET, C# 2012, HTML5, CSS, > MVC, Windows 8 Apps, JavaScript and much more. Keep your skills current > with LearnDevNow - 3,200 step-by-step video tutorials by Microsoft > MVPs and experts. ON SALE this month only -- learn more at: > http://p.sf.net/sfu/learnnow-d2d > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > |
|
From: ejbca-support <ejb...@pr...> - 2013-01-24 16:41:25
|
On 2013-01-24 16:17, Valerie Bauche wrote: > IAIK javadoc for this method : > > Throws: > java.lang.UnsupportedOperationException - If the value is not present or if the value is sensitive. > > So it does not seem to be a bug as it's clearly indicated in javadoc.... Shouldn't ejbca handle this case ? http://javadoc.iaik.tugraz.at/pkcs11_provider/current/iaik/pkcs/pkcs11/provider/keys/IAIKPKCS11RsaPrivateKey.html A problem is that this definition is unique to IAIK. http://docs.oracle.com/javase/6/docs/api/java/security/interfaces/RSAPrivateKey.html#getPrivateExponent() Anyway, is there a problem with using the Oracle P11 provider? Cheers, Anders > > Valérie > > -----Message d'origine----- > De : ejbca-support [mailto:ejb...@pr...] > Envoyé : jeudi 24 janvier 2013 16:00 > À : ejb...@li... > Cc : Valerie Bauche > Objet : Re: [Ejbca-develop] Problem using IAIK > > On 2013-01-24 13:33, Valerie Bauche wrote: >> HI, >> >> >> >> I try to use EJBCA with a HSM not already tested by EJBCA >> (crypt2protect from Bull) >> >> I can generate a CA using SUN PKCS11 provider >> >> But when I try it with IAIK provider I get the following error: >> >> >> >> Erreur : l'autorisation du token d'AC a échoué. >> >> >> >> Failed to initialize PKCS11 provider slot '0'. >> Private Exponent value is sensitive. >> >> >> >> >> >> Of course private exponent is sensitive and cannot be extracted ! So why ejbca tries to extract it ? > > Hi Valerie, > > I believe this is a bug in the IAIK provider since it is OK trying to extract, you should just get a null if you fail. > > Cheers, > Anders > tech support > >> >> Log file gives the following trace : >> >> >> >> ERROR [org.ejbca.core.model.ca.catoken.PKCS11CAToken] (http-0.0.0.0-44328-1) Failed to initialize PKCS11 provider slot '0'. >> >> java.lang.UnsupportedOperationException: Private Exponent value is sensitive. >> >> at >> iaik.pkcs.pkcs11.provider.keys.IAIKPKCS11RsaPrivateKey.getPrivateExpon >> ent(IAIKPKCS11RsaPrivateKey.java:251) >> >> at >> org.ejbca.util.keystore.KeyTools.isPrivateKeyExtractable(KeyTools.java >> :1063) >> >> at >> org.ejbca.core.model.ca.catoken.BaseCAToken.testKey(BaseCAToken.java:9 >> 7) >> >> at >> org.ejbca.core.model.ca.catoken.BaseCAToken.setKeys(BaseCAToken.java:1 >> 42) >> >> at >> org.ejbca.core.model.ca.catoken.PKCS11CAToken.activate(PKCS11CAToken.j >> ava:93) >> >> at >> org.ejbca.core.model.ca.catoken.CATokenContainerImpl.activate(CATokenC >> ontainerImpl.java:302) >> >> at >> org.ejbca.core.ejb.ca.caadmin.CAAdminSessionBean.createCA(CAAdminSessi >> onBean.java:249) >> * >> Valérie * >> >> >> >> >> >> ---------------------------------------------------------------------- >> -------- Master Visual Studio, SharePoint, SQL, ASP.NET, C# 2012, >> HTML5, CSS, MVC, Windows 8 Apps, JavaScript and much more. Keep your >> skills current with LearnDevNow - 3,200 step-by-step video tutorials >> by Microsoft MVPs and experts. ON SALE this month only -- learn more >> at: >> http://p.sf.net/sfu/learnnow-d2d >> >> >> >> _______________________________________________ >> Ejbca-develop mailing list >> Ejb...@li... >> https://lists.sourceforge.net/lists/listinfo/ejbca-develop >> > |
|
From: ejbca-support <ejb...@pr...> - 2013-01-24 15:00:00
|
On 2013-01-24 13:33, Valerie Bauche wrote: > HI, > > > > I try to use EJBCA with a HSM not already tested by EJBCA (crypt2protect from Bull) > > I can generate a CA using SUN PKCS11 provider > > But when I try it with IAIK provider I get the following error: > > > > Erreur : l’autorisation du token d’AC a échoué. > > > > Failed to initialize PKCS11 provider slot '0'. > Private Exponent value is sensitive. > > > > > > Of course private exponent is sensitive and cannot be extracted ! So why ejbca tries to extract it ? Hi Valerie, I believe this is a bug in the IAIK provider since it is OK trying to extract, you should just get a null if you fail. Cheers, Anders tech support > > Log file gives the following trace : > > > > ERROR [org.ejbca.core.model.ca.catoken.PKCS11CAToken] (http-0.0.0.0-44328-1) Failed to initialize PKCS11 provider slot '0'. > > java.lang.UnsupportedOperationException: Private Exponent value is sensitive. > > at iaik.pkcs.pkcs11.provider.keys.IAIKPKCS11RsaPrivateKey.getPrivateExponent(IAIKPKCS11RsaPrivateKey.java:251) > > at org.ejbca.util.keystore.KeyTools.isPrivateKeyExtractable(KeyTools.java:1063) > > at org.ejbca.core.model.ca.catoken.BaseCAToken.testKey(BaseCAToken.java:97) > > at org.ejbca.core.model.ca.catoken.BaseCAToken.setKeys(BaseCAToken.java:142) > > at org.ejbca.core.model.ca.catoken.PKCS11CAToken.activate(PKCS11CAToken.java:93) > > at org.ejbca.core.model.ca.catoken.CATokenContainerImpl.activate(CATokenContainerImpl.java:302) > > at org.ejbca.core.ejb.ca.caadmin.CAAdminSessionBean.createCA(CAAdminSessionBean.java:249) > * > Valérie * > > > > > > ------------------------------------------------------------------------------ > Master Visual Studio, SharePoint, SQL, ASP.NET, C# 2012, HTML5, CSS, > MVC, Windows 8 Apps, JavaScript and much more. Keep your skills current > with LearnDevNow - 3,200 step-by-step video tutorials by Microsoft > MVPs and experts. ON SALE this month only -- learn more at: > http://p.sf.net/sfu/learnnow-d2d > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |