You can subscribe to this list here.
| 2001 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
(1) |
Dec
(3) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2002 |
Jan
(3) |
Feb
(2) |
Mar
(8) |
Apr
(3) |
May
(6) |
Jun
(1) |
Jul
(15) |
Aug
(6) |
Sep
|
Oct
(10) |
Nov
(2) |
Dec
(4) |
| 2003 |
Jan
(1) |
Feb
(7) |
Mar
(3) |
Apr
(6) |
May
(7) |
Jun
(5) |
Jul
(5) |
Aug
(25) |
Sep
(14) |
Oct
(2) |
Nov
|
Dec
(2) |
| 2004 |
Jan
(7) |
Feb
(4) |
Mar
(12) |
Apr
(16) |
May
(43) |
Jun
(56) |
Jul
(43) |
Aug
(40) |
Sep
(66) |
Oct
(12) |
Nov
(26) |
Dec
(10) |
| 2005 |
Jan
(13) |
Feb
(33) |
Mar
(16) |
Apr
(7) |
May
(10) |
Jun
(34) |
Jul
(41) |
Aug
(8) |
Sep
(4) |
Oct
(32) |
Nov
(20) |
Dec
(25) |
| 2006 |
Jan
(30) |
Feb
(101) |
Mar
(5) |
Apr
(75) |
May
(74) |
Jun
(22) |
Jul
(6) |
Aug
(70) |
Sep
(19) |
Oct
(21) |
Nov
(31) |
Dec
(50) |
| 2007 |
Jan
(15) |
Feb
(20) |
Mar
(24) |
Apr
(33) |
May
(13) |
Jun
(18) |
Jul
(13) |
Aug
(7) |
Sep
(63) |
Oct
(68) |
Nov
(29) |
Dec
(68) |
| 2008 |
Jan
(30) |
Feb
(33) |
Mar
(30) |
Apr
(103) |
May
(78) |
Jun
(48) |
Jul
(72) |
Aug
(24) |
Sep
(62) |
Oct
(63) |
Nov
(70) |
Dec
(37) |
| 2009 |
Jan
(34) |
Feb
(35) |
Mar
(64) |
Apr
(34) |
May
(34) |
Jun
(58) |
Jul
(30) |
Aug
(30) |
Sep
(46) |
Oct
(52) |
Nov
(12) |
Dec
(23) |
| 2010 |
Jan
(121) |
Feb
(18) |
Mar
(53) |
Apr
(62) |
May
(62) |
Jun
(20) |
Jul
(33) |
Aug
(20) |
Sep
(36) |
Oct
(35) |
Nov
(44) |
Dec
(63) |
| 2011 |
Jan
(19) |
Feb
(32) |
Mar
(94) |
Apr
(41) |
May
(47) |
Jun
(25) |
Jul
(34) |
Aug
(20) |
Sep
(9) |
Oct
(41) |
Nov
(33) |
Dec
(24) |
| 2012 |
Jan
(12) |
Feb
(36) |
Mar
(48) |
Apr
(32) |
May
(20) |
Jun
(15) |
Jul
(32) |
Aug
(13) |
Sep
(33) |
Oct
(54) |
Nov
(25) |
Dec
(16) |
| 2013 |
Jan
(45) |
Feb
(39) |
Mar
(38) |
Apr
(50) |
May
(29) |
Jun
(30) |
Jul
(33) |
Aug
(12) |
Sep
(9) |
Oct
(25) |
Nov
(29) |
Dec
(20) |
| 2014 |
Jan
(25) |
Feb
(19) |
Mar
(16) |
Apr
(33) |
May
(27) |
Jun
(37) |
Jul
(29) |
Aug
(27) |
Sep
(37) |
Oct
(58) |
Nov
(109) |
Dec
(26) |
| 2015 |
Jan
(4) |
Feb
(35) |
Mar
(22) |
Apr
(35) |
May
(28) |
Jun
(20) |
Jul
(4) |
Aug
(16) |
Sep
(37) |
Oct
(13) |
Nov
(13) |
Dec
(14) |
| 2016 |
Jan
(22) |
Feb
(7) |
Mar
(23) |
Apr
(30) |
May
(10) |
Jun
(10) |
Jul
(15) |
Aug
(12) |
Sep
(22) |
Oct
(31) |
Nov
(5) |
Dec
(5) |
| 2017 |
Jan
(30) |
Feb
(25) |
Mar
(28) |
Apr
(4) |
May
(19) |
Jun
(13) |
Jul
(7) |
Aug
(1) |
Sep
(2) |
Oct
(5) |
Nov
(12) |
Dec
(2) |
| 2018 |
Jan
(7) |
Feb
|
Mar
(7) |
Apr
(2) |
May
(8) |
Jun
(18) |
Jul
(6) |
Aug
(3) |
Sep
(15) |
Oct
(33) |
Nov
(13) |
Dec
(7) |
| 2019 |
Jan
(5) |
Feb
(7) |
Mar
(30) |
Apr
(5) |
May
(4) |
Jun
(69) |
Jul
(86) |
Aug
(22) |
Sep
(6) |
Oct
(7) |
Nov
(5) |
Dec
(3) |
| 2020 |
Jan
(10) |
Feb
(12) |
Mar
(22) |
Apr
(5) |
May
(1) |
Jun
(4) |
Jul
(6) |
Aug
|
Sep
(9) |
Oct
|
Nov
|
Dec
(1) |
| 2021 |
Jan
(4) |
Feb
(11) |
Mar
(7) |
Apr
(7) |
May
|
Jun
(3) |
Jul
(10) |
Aug
(6) |
Sep
|
Oct
|
Nov
(18) |
Dec
(2) |
| 2022 |
Jan
(1) |
Feb
(1) |
Mar
|
Apr
|
May
|
Jun
(2) |
Jul
|
Aug
(4) |
Sep
|
Oct
|
Nov
|
Dec
|
| 2023 |
Jan
|
Feb
|
Mar
|
Apr
(1) |
May
(1) |
Jun
|
Jul
|
Aug
(5) |
Sep
|
Oct
|
Nov
|
Dec
|
|
From: Christian F. <hos...@ip...> - 2012-10-10 14:06:17
|
Hello,
while DemoCertReqServlet.java works with Firefox, I ran into problems
with Internet Explorer. Servlet creates a user and ejbca a certificate.
IE does not like answer from ejbca, I got an error
SCRIPT438: Object doesn't support this property or method.:
'g_objClassFactory.CreateObject'
opencertreq, Zeile 139 Zeichen 4
This is code IE got from ejbca:
<!-- Header -->
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html>
<head>
<meta http-equiv="Content-Type" content="text/html;
charset=ISO-8859-1" />
<title><%=
org.ejbca.config.InternalConfiguration.getAppNameCapital() %> Public
Web</title>
<link rel="shortcut icon" href="images/favicon.png" type="image/png" />
<link rel="stylesheet" href="styles.css" type="text/css" />
<script type="text/javascript" src="scripts/functions.js"></script>
<script type="text/vbscript" src="scripts/functions.vbs"></script>
</head>
<body>
<div id="header">
<div id="banner">
<a href="index.jsp"><img src="images/logotype.png" alt="EJBCA" /></a>
</div>
</div>
<div class="menucontainer">
<div class="menu">
<ul>
<li><div class="menuheader">Enroll</div>
<ul>
<li>
<a href="enrol/browser.jsp">Create Browser Certificate</a>
</li>
<li>
<a href="enrol/server.jsp">Create Server Certificate</a>
</li>
<li>
<a href="enrol/keystore.jsp">Create Keystore</a>
</li>
</ul>
</li>
<li><div class="menuheader">Retrieve</div>
<ul>
<li>
<a href="retrieve/ca_certs.jsp">Fetch CA & OCSP
Certificates</a>
</li>
<li>
<a href="retrieve/ca_crls.jsp">Fetch CA CRLs</a>
</li>
<li>
<a href="retrieve/latest_cert.jsp">Fetch User's Latest
Certificate</a>
</li>
</ul>
</li>
<li><div class="menuheader">Miscellaneous</div>
<ul>
<li>
<a href="retrieve/list_certs.jsp">List User's
Certificates</a>
</li>
<li>
<a href="retrieve/check_status.jsp">Check Certificate
Status</a>
</li>
<li>
<a href="adminweb/index.jsp">Administration</a>
</li>
</ul>
</li>
</ul>
</div>
</div>
<div class="main">
<div class="content">
<!-- Header -->
<object classid="clsid:127698e4-e730-4e5c-a2b1-21490a70c8a1"
CODEBASE="/CertControl/xenroll.cab#Version=5,131,3659,0"
id="g_objClassFactory"></object>
<!-- Updated w CertEnroll for Vista
Class ID: {884e2049-217d-11da-b2a4-000e7bbb2b09}
-->
<!-- New updated enrollment activeX-control 2002-09-02 (Q323172)
New Xenroll.dll information:
Class ID: {127698e4-e730-4e5c-a2b1-21490a70c8a1}
sXEnrollVersion="5,131,3659,0"
New Scrdenrl.dll information:
Class ID: {c2bbea20-1f2b-492f-8a06-b1c5ffeace3b}
sScrdEnrlVersion="5,131,3642,0"
-->
<!-- Old Xenroll.dll information:
Class ID: {43F8F289-7A20-11D0-8F06-00C04FC295E1}
Old Scrdenrl.dll information:
Class ID: {80CB7887-20DE-11D2-8D5C-00C04FC29D45}
-->
<script language="VBScript" type="text/vbscript">
cert =
"MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAaCA" & _
"JIAEBUVKQkNBAAAAAAAAoIAwggMlMIICDaADAgECAghCKLQdjWjN8TANBgkqhkiG" & _
"9w0BAQsFADARMQ8wDQYDVQQDDAZEZW1vQ0EwHhcNMTIxMDEwMTMzODE2WhcNMTQx" & _
"MDEwMTMzODE2WjATMREwDwYDVQQDDAh0ZXN0MDAwMTCCASIwDQYJKoZIhvcNAQEB" & _
"BQADggEPADCCAQoCggEBAM1sXTv9DQtuMmWDEi41hOr4ciAXWgJiz+zIbajcJWKn" & _
"cxWxAPoEuQO/qdPphJLWhnZUZBrGNBebSZt20npkrC/CZAOpH3fCn5UK+nRHn2is" & _
"ehOxaThD7c1tS52zALrFOubHXdraZcKYHmE7MtDWAWM6lgCfQw0RqcG3ncnk0nZ2" & _
"XJpq3Y/gXQ53ff+Cu5xg0lVWGIhf8H67wBY3nX8NnYry81ACkPLFt5UYNMZRAJHY" & _
"6RnOo2xvcXZ1f+8qVc4FsZLptGuOmgnTqBoJIbO0MF/jHG27j4UhnOomNQOB6RjL" & _
"q38lCNr66P1MXkTBiTpvt6B48fA09MrgeHvJlcrz060CAwEAAaN/MH0wHQYDVR0O" & _
"BBYEFN8h9p8GpEAuTbqY4n/uRqhn1OUEMAwGA1UdEwEB/wQCMAAwHwYDVR0jBBgw" & _
"FoAUzDTvpOBPQ8aLW2nt7s0MqDuKfT0wDgYDVR0PAQH/BAQDAgXgMB0GA1UdJQQW" & _
"MBQGCCsGAQUFBwMCBggrBgEFBQcDBDANBgkqhkiG9w0BAQsFAAOCAQEAgdqaP+b0" & _
"9RC8Nmw5VR0kmD3i1KukHUIehRf6oBbsYjWkIKU3HFDreZ9SqYIuVfKr+iyfKGR3" & _
"IMn59nYIq2pL+KY2MH72lsce50/4EifwnO84cxvVnWak2I4d9rXb+9jdA52hkYge" & _
"kXFzjELtEZUP+550nqX1upbil9Gon87ctHvouWvkdb7PlgirW/ZmXFCcHxYaF8VK" & _
"eVsrQj/KCGdCeG57mqIclpNpKOS2zkkB6dCaFg8IaxB6VCNK/wN2+rq1i9lWQkv/" & _
"BncJRNTfTcpxNdJxIMg4Xpe7gq7csz+HRw/7ng9f6f9AX/h6xlsCAxmPewhPp1sq" & _
"f0fPtoQkrRZRdjCCAwcwggHvoAMCAQICCFldFdeJGR3rMA0GCSqGSIb3DQEBCwUA" & _
"MBExDzANBgNVBAMMBkRlbW9DQTAeFw0xMjEwMDcxMjEzNDZaFw0zNzEwMDgxMjEz" & _
"NDZaMBExDzANBgNVBAMMBkRlbW9DQTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCC" & _
"AQoCggEBALbji9I2uyYPBcHcGYvtDghSzENJa4ncXpWO9r95u1FyOrQI28eNt7k3" & _
"f/lovQqD1GzUt2FxjEuziM+YTSWqVGeti3+1rtAnYtn7UXJT70wbhELgDjaED0rL" & _
"N3BiTircxBjpVk4RiLKXoj5feblqOULTdqRpHM/aco7cksXbqv9SN/cUFxjSQ9vj" & _
"YiY+dIEllVUquERUJE+pEs/R1mWJ2WGJHcuvhOeIKYG2nQaE0G6ATXYyvPPyn3r1" & _
"AERRTvw9ESNn6IiN9DtA+D8dpt3jYplNMy3CJ2QgkbahPU1hzakbJ3AfSfgUWOop" & _
"Rpbm5EWe4Whi3LDlw88z9uG3oTqhaXcCAwEAAaNjMGEwHQYDVR0OBBYEFMw076Tg" & _
"T0PGi1tp7e7NDKg7in09MA8GA1UdEwEB/wQFMAMBAf8wHwYDVR0jBBgwFoAUzDTv" & _
"pOBPQ8aLW2nt7s0MqDuKfT0wDgYDVR0PAQH/BAQDAgGGMA0GCSqGSIb3DQEBCwUA" & _
"A4IBAQC08FYY/4ypawrQRbtTG12vya2f/lWY+jMiCZhxyN1ZpFf/bquKHn4gc6cn" & _
"im1OqVkVBh5ToScXooRiFw2NHvt26r2pADqxg78fZw6HoVDzHl3X16V7g9An6lLM" & _
"7PFfDBfoRlD8pxcEewvPscFl7uhP+c9NhGoiLcRNK4UZJRu1a2bTpmNdjWefnJlN" & _
"X0e3dqWpdgyXXwExt4hV4NgJakPteGvn9OOQLGs1oAZ98O1+QpI6Ieg/ipW3c/51" & _
"cgevm3qetMZAovnMj/SoQNCqVrf/Tr1+54OkdZMQV4YX7hPuaj1vMYCbnULfokx2" & _
"voEIw4anzsJRsUyJ79tAVcOPffTvAAAxggGjMIIBnwIBATAdMBExDzANBgNVBAMM" & _
"BkRlbW9DQQIIWV0V14kZHeswCQYFKw4DAhoFAKBdMBgGCSqGSIb3DQEJAzELBgkq" & _
"hkiG9w0BBwEwHAYJKoZIhvcNAQkFMQ8XDTEyMTAxMDEzNDgxNlowIwYJKoZIhvcN" & _
"AQkEMRYEFGAqpHyu+gYYDDL/ObHCjRjA1HtXMA0GCSqGSIb3DQEBAQUABIIBAG22" & _
"ntnlArmfJN11v9Uw+JPE3lVBoBxBVRAFcYhJPmu6rzxPJsKaQGAYta6yQkJMRAO1" & _
"2qYRpnyRUciy+kqmP/ll3bZUmg7Fa1xR1nYmnVLjabSQJi/LBsGixbEU2hha2IdH" & _
"LhiPO60pY9kdygVx7YzxeGqddjMARVGpFiOzmhmmzGT0B4OsaOuMUvAbnaLhPzL/" & _
"S8A7De7AjrNWOF/Is5yoOacvYBDoxISSK8FFtGzJmDhXNdncAP1CzEwfNO4j9iMx" & _
"SOfNvv4Xuk59Mdvuuael6qs4pP2+GDrm4AM2aFBn4DKil3/w7nY1SZsu8jOG/KTh" & _
"kE23CfecV9SivA/ilzgAAAAAAAA="
' This function can be moved to functions.vbs when the header is
parsed as jsp
Sub installcertvista
Dim objEnroll
Set objEnroll =
g_objClassFactory.CreateObject("X509Enrollment.CX509Enrollment")
Call objEnroll.Initialize(1) 'EnrollmentContext UserContext
err.clear
On Error Resume Next
Call objEnroll.InstallResponse(0, cert, 6, "") 'AllowNone, ,
XCN_CRYPT_STRING_BASE64_ANY, pw
If err.number = -2146762487 Then ' 0x800b0109 Not trusted root
r = Msgbox("Could not complete the request since, the CAs'
certificates were not properly installed.", , "Certificate Management")
ElseIf err.number <> 0 Then
r = Msgbox("The certificate could not be installed", , "Certificate
Management")
Else
r = Msgbox("A new certificate has been installed", , "Certificate
Management")
End If
End Sub
Sub installcert
Err.Clear
On Error Resume Next
g_objClassFactory.acceptPKCS7(cert)
If Err.Number <> 0 Then
r = Msgbox("The certificate could not be installed in this web
browser", , "Certificate Management")
Else
r = Msgbox ("A new certificate has been installed", , "Certificate
Management")
End if
End Sub
If InStr(navigator.userAgent, "Windows NT 6") <> 0 Then
installcertvista
Else
installcert
End If
<
any hints?
best regards
Christian
|
|
From: ejbca-support <ejb...@pr...> - 2012-10-10 11:49:36
|
On 2012-10-10 12:59, dominic peter wrote: > Hi Tomas, > > I tried after updating the EJBCA CMP configuration for RA mode and *re-deploy*. > The 'ir' message exchange sequence worked fine. But a 'cr' message exchange after this failed. > > Following are the commands that i executed on the cmpforopenssl cmpclient, > > _*Initial request: > > *_./cmpclient --server localhost --port 8080 --path ejbca/publicweb/cmp --srvcert ~/Downloads/AdminCA1.cacert.pem --ir --user user1 --password password --newclcert user1-cert.der --newkey user1-key.pem --subject "C=IN,CN=User1" > > This command was successful and the initial client certificate was successfully received. > > _*Certificate request:*_ > > ./cmpclient --server localhost --port 8080 --path ejbca/publicweb/cmp --srvcert ~/Downloads/AdminCA1.cacert.pem --cr --user user1 --password password --newclcert user1-cert-new.der --newkey user1-key-new.pem --clcert user1-cert.der --key user1-key.pem > > This command failed. and the following error was observed on the EJBCA side. > > 15:48:28,521 INFO [CmpServlet] CMP message received from: 127.0.0.1. > *15:48:28,535 ERROR [CrmfMessageHandler] Could not create CmpPbeVerifyer* > 15:48:28,538 INFO [CmpServlet] Sent a CMP response to: 127.0.0.1, process time 15 > > Any idea why i am getting this error ? Debugging CMP is very difficult. Is there no strack trace? You may need to set JBoss debug-level to DEBUG. Cheers, Anders tech support > > I am just trying to test cmpforopenssl (basic CMP message exchanges) with EJBCA in RA mode. I tried client mode as nothing was working for me previously. > > Regards > Dominic > > On Wed, Oct 10, 2012 at 3:38 PM, Tomas Gustavsson <to...@pr... <mailto:to...@pr...>> wrote: > > Hi, > > You need to re-deploy after changing configuration. > > You also must be more detailed when asking for help. If you are using > cmpforopenssl you need to give the command you are using, otherwise you > may be using an invalid command and there is no way for anyone to know. > > Since you are playing around with both RA and Client mode, perhaps you > should tell what you actually want to do? > > Cheers, > Tomas > ----- > PrimeKey Solutions offers commercial EJBCA and SignServer support > subscriptions and training courses. Please see www.primekey.se <http://www.primekey.se> or > contact in...@pr... <mailto:in...@pr...> for more information. > http://www.primekey.se/Services/Support/ > http://www.primekey.se/Services/Training/ > > > On 10/10/2012 05:22 PM, dominic peter wrote: > > Hi Anders, > > > > Thank you very much for the reply. > > > > *_RA mode:_ > > > > *I checked by updating the cmp configuration for '*RA*' mode as per the > > link that you sent. > > But still i am getting the same error. Following is the content of the > > cmp.properties file, > > > > cmp.operationmode=ra > > cmp.responseprotection=pbe > > cmp.ra.authenticationsecret=password > > > > Am i missing something here ? Is just updating the configuration file > > enough for the configurations to take effect ? > > > > Also can you please help me understand why i am getting the following > > error on the EJBC server, > > > > *ERROR [CrmfMessageHandler] Could not extract password from CRMF request > > using the RegTokenPwd authentication module > > * > > Is this due to some missing parameters in the 'ir' message sent from > > cmpclient ? > > > > _*Client Mode:*_ > > > > I also tried by configuring the EJBCA in */client mode/*. In this case, > > the 'ir' message exchange was successful. But the 'cr' message exchange > > failed. Following was the error message on the EJBCA server, > > > > *ERROR [CrmfMessageHandler] Could not create CmpPbeVerifyer* > > > > Any idea what is the reason for this error ? > > > > Packet captures for both RA and client mode is attached to this mail. > > > > Also please help me understand the necessary initializations or any > > other prerequisites on the cmpclient side if any for interop with EJBCA. > > > > Regards > > Dominic > > > > On Tue, Oct 9, 2012 at 5:42 PM, ejbca-support <ejb...@pr... <mailto:ejb...@pr...> > > <mailto:ejb...@pr... <mailto:ejb...@pr...>>> wrote: > > > > On 2012-10-09 13:59, dominic peter wrote: > > > Hi, > > > > Hi Dominic, > > > > > > Has anyone tried to interop cmpforopenssl client with EJBCA. > > > > > > Yes, > > http://www.ejbca.org/adminguide.html#Interoperability > > > > > > > > I am trying to send an 'ir' request to EJBCA from the > > cmpforopenssl client using the following command, > > > > > > ./cmpclient --server localhost --port 8080 --path > > ejbca/publicweb/cmp --srvcert myAdminCA.cacert.pem --ir --user test1 > > --password test1 --newclcert test1.pem --newkey test1.key --subject > > "C=IN,ST=KAR,L=TEST,O=TEST,OU= > > > EN,CN=EETest1" > > > > > > I am seeing the following error on the EJBCA after sending the > > 'ir' request from the client, > > > > > > 15:40:36,975 ERROR [CrmfMessageHandler] Could not extract > > password from CRMF request using the RegTokenPwd authentication module > > > 15:40:36,997 INFO [CmpServlet] Sent a CMP response to: > > 127.0.0.1, process time 217. > > > > > > On the cmpclient i am seeing the following error, > > > > > > INFO: Sending Initialization Request > > > ERROR: received no initial Client Certificate. FILE cmpclient.c, > > LINE 401 > > > 3078551176 <tel:3078551176> <tel:3078551176 <tel:3078551176>> <tel:3078551176 <tel:3078551176> > > <tel:3078551176 <tel:3078551176>>>:error:0D0680A8:asn1 encoding > > routines:ASN1_CHECK_TLEN:wrong tag:tasn_dec.c:1319: > > > 3078551176 <tel:3078551176> <tel:3078551176 <tel:3078551176>> <tel:3078551176 <tel:3078551176> > > <tel:3078551176 <tel:3078551176>>>:error:0D07803A:asn1 encoding > > routines:ASN1_ITEM_EX_D2I:nested asn1 error:tasn_dec.c:381:Type=X509 > > > 3078551176 <tel:3078551176> <tel:3078551176 <tel:3078551176>>:error:32090087:CMP > > routines:CMP_doInitialRequestSeq:pkibody > > error:cmp_ses.c:384:bodytype=23, error="PKIStatus: rejection, > > PKIFailureInfo: wrongAuthority" > > > > > > And ideas ? > > > > Check configuration. > > > > Cheers, > > Anders > > tech support > > > > > > > > Thanks in advance. > > > > > > Regards > > > > > > > > > > > ------------------------------------------------------------------------------ > > > Don't let slow site performance ruin your business. Deploy New > > Relic APM > > > Deploy New Relic app performance management and know exactly > > > what is happening inside your Ruby, Python, PHP, Java, and .NET app > > > Try New Relic at no cost today and get our sweet Data Nerd shirt too! > > > http://p.sf.net/sfu/newrelic-dev2dev > > > > > > > > > > > > _______________________________________________ > > > Ejbca-develop mailing list > > > Ejb...@li... <mailto:Ejb...@li...> > > <mailto:Ejb...@li... <mailto:Ejb...@li...>> > > > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > > > > > > > > > > ------------------------------------------------------------------------------ > > Don't let slow site performance ruin your business. Deploy New Relic APM > > Deploy New Relic app performance management and know exactly > > what is happening inside your Ruby, Python, PHP, Java, and .NET app > > Try New Relic at no cost today and get our sweet Data Nerd shirt too! > > http://p.sf.net/sfu/newrelic-dev2dev > > > > > > > > _______________________________________________ > > Ejbca-develop mailing list > > Ejb...@li... <mailto:Ejb...@li...> > > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > > ------------------------------------------------------------------------------ > Don't let slow site performance ruin your business. Deploy New Relic APM > Deploy New Relic app performance management and know exactly > what is happening inside your Ruby, Python, PHP, Java, and .NET app > Try New Relic at no cost today and get our sweet Data Nerd shirt too! > http://p.sf.net/sfu/newrelic-dev2dev > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... <mailto:Ejb...@li...> > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > > ------------------------------------------------------------------------------ > Don't let slow site performance ruin your business. Deploy New Relic APM > Deploy New Relic app performance management and know exactly > what is happening inside your Ruby, Python, PHP, Java, and .NET app > Try New Relic at no cost today and get our sweet Data Nerd shirt too! > http://p.sf.net/sfu/newrelic-dev2dev > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: dominic p. <dom...@gm...> - 2012-10-10 11:00:03
|
Hi Tomas, I tried after updating the EJBCA CMP configuration for RA mode and * re-deploy*. The 'ir' message exchange sequence worked fine. But a 'cr' message exchange after this failed. Following are the commands that i executed on the cmpforopenssl cmpclient, *Initial request: *./cmpclient --server localhost --port 8080 --path ejbca/publicweb/cmp --srvcert ~/Downloads/AdminCA1.cacert.pem --ir --user user1 --password password --newclcert user1-cert.der --newkey user1-key.pem --subject "C=IN,CN=User1" This command was successful and the initial client certificate was successfully received. *Certificate request:* ./cmpclient --server localhost --port 8080 --path ejbca/publicweb/cmp --srvcert ~/Downloads/AdminCA1.cacert.pem --cr --user user1 --password password --newclcert user1-cert-new.der --newkey user1-key-new.pem --clcert user1-cert.der --key user1-key.pem This command failed. and the following error was observed on the EJBCA side. 15:48:28,521 INFO [CmpServlet] CMP message received from: 127.0.0.1. *15:48:28,535 ERROR [CrmfMessageHandler] Could not create CmpPbeVerifyer* 15:48:28,538 INFO [CmpServlet] Sent a CMP response to: 127.0.0.1, process time 15 Any idea why i am getting this error ? I am just trying to test cmpforopenssl (basic CMP message exchanges) with EJBCA in RA mode. I tried client mode as nothing was working for me previously. Regards Dominic On Wed, Oct 10, 2012 at 3:38 PM, Tomas Gustavsson <to...@pr...> wrote: > Hi, > > You need to re-deploy after changing configuration. > > You also must be more detailed when asking for help. If you are using > cmpforopenssl you need to give the command you are using, otherwise you > may be using an invalid command and there is no way for anyone to know. > > Since you are playing around with both RA and Client mode, perhaps you > should tell what you actually want to do? > > Cheers, > Tomas > ----- > PrimeKey Solutions offers commercial EJBCA and SignServer support > subscriptions and training courses. Please see www.primekey.se or > contact in...@pr... for more information. > http://www.primekey.se/Services/Support/ > http://www.primekey.se/Services/Training/ > > > On 10/10/2012 05:22 PM, dominic peter wrote: > > Hi Anders, > > > > Thank you very much for the reply. > > > > *_RA mode:_ > > > > *I checked by updating the cmp configuration for '*RA*' mode as per the > > link that you sent. > > But still i am getting the same error. Following is the content of the > > cmp.properties file, > > > > cmp.operationmode=ra > > cmp.responseprotection=pbe > > cmp.ra.authenticationsecret=password > > > > Am i missing something here ? Is just updating the configuration file > > enough for the configurations to take effect ? > > > > Also can you please help me understand why i am getting the following > > error on the EJBC server, > > > > *ERROR [CrmfMessageHandler] Could not extract password from CRMF request > > using the RegTokenPwd authentication module > > * > > Is this due to some missing parameters in the 'ir' message sent from > > cmpclient ? > > > > _*Client Mode:*_ > > > > I also tried by configuring the EJBCA in */client mode/*. In this case, > > the 'ir' message exchange was successful. But the 'cr' message exchange > > failed. Following was the error message on the EJBCA server, > > > > *ERROR [CrmfMessageHandler] Could not create CmpPbeVerifyer* > > > > Any idea what is the reason for this error ? > > > > Packet captures for both RA and client mode is attached to this mail. > > > > Also please help me understand the necessary initializations or any > > other prerequisites on the cmpclient side if any for interop with EJBCA. > > > > Regards > > Dominic > > > > On Tue, Oct 9, 2012 at 5:42 PM, ejbca-support <ejb...@pr... > > <mailto:ejb...@pr...>> wrote: > > > > On 2012-10-09 13:59, dominic peter wrote: > > > Hi, > > > > Hi Dominic, > > > > > > Has anyone tried to interop cmpforopenssl client with EJBCA. > > > > > > Yes, > > http://www.ejbca.org/adminguide.html#Interoperability > > > > > > > > I am trying to send an 'ir' request to EJBCA from the > > cmpforopenssl client using the following command, > > > > > > ./cmpclient --server localhost --port 8080 --path > > ejbca/publicweb/cmp --srvcert myAdminCA.cacert.pem --ir --user test1 > > --password test1 --newclcert test1.pem --newkey test1.key --subject > > "C=IN,ST=KAR,L=TEST,O=TEST,OU= > > > EN,CN=EETest1" > > > > > > I am seeing the following error on the EJBCA after sending the > > 'ir' request from the client, > > > > > > 15:40:36,975 ERROR [CrmfMessageHandler] Could not extract > > password from CRMF request using the RegTokenPwd authentication > module > > > 15:40:36,997 INFO [CmpServlet] Sent a CMP response to: > > 127.0.0.1, process time 217. > > > > > > On the cmpclient i am seeing the following error, > > > > > > INFO: Sending Initialization Request > > > ERROR: received no initial Client Certificate. FILE cmpclient.c, > > LINE 401 > > > 3078551176 <tel:3078551176> <tel:3078551176 > > <tel:3078551176>>:error:0D0680A8:asn1 encoding > > routines:ASN1_CHECK_TLEN:wrong tag:tasn_dec.c:1319: > > > 3078551176 <tel:3078551176> <tel:3078551176 > > <tel:3078551176>>:error:0D07803A:asn1 encoding > > routines:ASN1_ITEM_EX_D2I:nested asn1 error:tasn_dec.c:381:Type=X509 > > > 3078551176 <tel:3078551176>:error:32090087:CMP > > routines:CMP_doInitialRequestSeq:pkibody > > error:cmp_ses.c:384:bodytype=23, error="PKIStatus: rejection, > > PKIFailureInfo: wrongAuthority" > > > > > > And ideas ? > > > > Check configuration. > > > > Cheers, > > Anders > > tech support > > > > > > > > Thanks in advance. > > > > > > Regards > > > > > > > > > > > > ------------------------------------------------------------------------------ > > > Don't let slow site performance ruin your business. Deploy New > > Relic APM > > > Deploy New Relic app performance management and know exactly > > > what is happening inside your Ruby, Python, PHP, Java, and .NET > app > > > Try New Relic at no cost today and get our sweet Data Nerd shirt > too! > > > http://p.sf.net/sfu/newrelic-dev2dev > > > > > > > > > > > > _______________________________________________ > > > Ejbca-develop mailing list > > > Ejb...@li... > > <mailto:Ejb...@li...> > > > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > > > > > > > > > > > ------------------------------------------------------------------------------ > > Don't let slow site performance ruin your business. Deploy New Relic APM > > Deploy New Relic app performance management and know exactly > > what is happening inside your Ruby, Python, PHP, Java, and .NET app > > Try New Relic at no cost today and get our sweet Data Nerd shirt too! > > http://p.sf.net/sfu/newrelic-dev2dev > > > > > > > > _______________________________________________ > > Ejbca-develop mailing list > > Ejb...@li... > > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > > > ------------------------------------------------------------------------------ > Don't let slow site performance ruin your business. Deploy New Relic APM > Deploy New Relic app performance management and know exactly > what is happening inside your Ruby, Python, PHP, Java, and .NET app > Try New Relic at no cost today and get our sweet Data Nerd shirt too! > http://p.sf.net/sfu/newrelic-dev2dev > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Tomas G. <to...@pr...> - 2012-10-10 10:08:26
|
Hi, You need to re-deploy after changing configuration. You also must be more detailed when asking for help. If you are using cmpforopenssl you need to give the command you are using, otherwise you may be using an invalid command and there is no way for anyone to know. Since you are playing around with both RA and Client mode, perhaps you should tell what you actually want to do? Cheers, Tomas ----- PrimeKey Solutions offers commercial EJBCA and SignServer support subscriptions and training courses. Please see www.primekey.se or contact in...@pr... for more information. http://www.primekey.se/Services/Support/ http://www.primekey.se/Services/Training/ On 10/10/2012 05:22 PM, dominic peter wrote: > Hi Anders, > > Thank you very much for the reply. > > *_RA mode:_ > > *I checked by updating the cmp configuration for '*RA*' mode as per the > link that you sent. > But still i am getting the same error. Following is the content of the > cmp.properties file, > > cmp.operationmode=ra > cmp.responseprotection=pbe > cmp.ra.authenticationsecret=password > > Am i missing something here ? Is just updating the configuration file > enough for the configurations to take effect ? > > Also can you please help me understand why i am getting the following > error on the EJBC server, > > *ERROR [CrmfMessageHandler] Could not extract password from CRMF request > using the RegTokenPwd authentication module > * > Is this due to some missing parameters in the 'ir' message sent from > cmpclient ? > > _*Client Mode:*_ > > I also tried by configuring the EJBCA in */client mode/*. In this case, > the 'ir' message exchange was successful. But the 'cr' message exchange > failed. Following was the error message on the EJBCA server, > > *ERROR [CrmfMessageHandler] Could not create CmpPbeVerifyer* > > Any idea what is the reason for this error ? > > Packet captures for both RA and client mode is attached to this mail. > > Also please help me understand the necessary initializations or any > other prerequisites on the cmpclient side if any for interop with EJBCA. > > Regards > Dominic > > On Tue, Oct 9, 2012 at 5:42 PM, ejbca-support <ejb...@pr... > <mailto:ejb...@pr...>> wrote: > > On 2012-10-09 13:59, dominic peter wrote: > > Hi, > > Hi Dominic, > > > > Has anyone tried to interop cmpforopenssl client with EJBCA. > > > Yes, > http://www.ejbca.org/adminguide.html#Interoperability > > > > > I am trying to send an 'ir' request to EJBCA from the > cmpforopenssl client using the following command, > > > > ./cmpclient --server localhost --port 8080 --path > ejbca/publicweb/cmp --srvcert myAdminCA.cacert.pem --ir --user test1 > --password test1 --newclcert test1.pem --newkey test1.key --subject > "C=IN,ST=KAR,L=TEST,O=TEST,OU= > > EN,CN=EETest1" > > > > I am seeing the following error on the EJBCA after sending the > 'ir' request from the client, > > > > 15:40:36,975 ERROR [CrmfMessageHandler] Could not extract > password from CRMF request using the RegTokenPwd authentication module > > 15:40:36,997 INFO [CmpServlet] Sent a CMP response to: > 127.0.0.1, process time 217. > > > > On the cmpclient i am seeing the following error, > > > > INFO: Sending Initialization Request > > ERROR: received no initial Client Certificate. FILE cmpclient.c, > LINE 401 > > 3078551176 <tel:3078551176> <tel:3078551176 > <tel:3078551176>>:error:0D0680A8:asn1 encoding > routines:ASN1_CHECK_TLEN:wrong tag:tasn_dec.c:1319: > > 3078551176 <tel:3078551176> <tel:3078551176 > <tel:3078551176>>:error:0D07803A:asn1 encoding > routines:ASN1_ITEM_EX_D2I:nested asn1 error:tasn_dec.c:381:Type=X509 > > 3078551176 <tel:3078551176>:error:32090087:CMP > routines:CMP_doInitialRequestSeq:pkibody > error:cmp_ses.c:384:bodytype=23, error="PKIStatus: rejection, > PKIFailureInfo: wrongAuthority" > > > > And ideas ? > > Check configuration. > > Cheers, > Anders > tech support > > > > > Thanks in advance. > > > > Regards > > > > > > > ------------------------------------------------------------------------------ > > Don't let slow site performance ruin your business. Deploy New > Relic APM > > Deploy New Relic app performance management and know exactly > > what is happening inside your Ruby, Python, PHP, Java, and .NET app > > Try New Relic at no cost today and get our sweet Data Nerd shirt too! > > http://p.sf.net/sfu/newrelic-dev2dev > > > > > > > > _______________________________________________ > > Ejbca-develop mailing list > > Ejb...@li... > <mailto:Ejb...@li...> > > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > > > > ------------------------------------------------------------------------------ > Don't let slow site performance ruin your business. Deploy New Relic APM > Deploy New Relic app performance management and know exactly > what is happening inside your Ruby, Python, PHP, Java, and .NET app > Try New Relic at no cost today and get our sweet Data Nerd shirt too! > http://p.sf.net/sfu/newrelic-dev2dev > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: ejbca-support <ejb...@pr...> - 2012-10-09 12:13:11
|
On 2012-10-09 13:59, dominic peter wrote: > Hi, Hi Dominic, > > Has anyone tried to interop cmpforopenssl client with EJBCA. Yes, http://www.ejbca.org/adminguide.html#Interoperability > > I am trying to send an 'ir' request to EJBCA from the cmpforopenssl client using the following command, > > ./cmpclient --server localhost --port 8080 --path ejbca/publicweb/cmp --srvcert myAdminCA.cacert.pem --ir --user test1 --password test1 --newclcert test1.pem --newkey test1.key --subject "C=IN,ST=KAR,L=TEST,O=TEST,OU= > EN,CN=EETest1" > > I am seeing the following error on the EJBCA after sending the 'ir' request from the client, > > 15:40:36,975 ERROR [CrmfMessageHandler] Could not extract password from CRMF request using the RegTokenPwd authentication module > 15:40:36,997 INFO [CmpServlet] Sent a CMP response to: 127.0.0.1, process time 217. > > On the cmpclient i am seeing the following error, > > INFO: Sending Initialization Request > ERROR: received no initial Client Certificate. FILE cmpclient.c, LINE 401 > 3078551176 <tel:3078551176>:error:0D0680A8:asn1 encoding routines:ASN1_CHECK_TLEN:wrong tag:tasn_dec.c:1319: > 3078551176 <tel:3078551176>:error:0D07803A:asn1 encoding routines:ASN1_ITEM_EX_D2I:nested asn1 error:tasn_dec.c:381:Type=X509 > 3078551176 <tel:3078551176>:error:32090087:CMP routines:CMP_doInitialRequestSeq:pkibody error:cmp_ses.c:384:bodytype=23, error="PKIStatus: rejection, PKIFailureInfo: wrongAuthority" > > And ideas ? Check configuration. Cheers, Anders tech support > > Thanks in advance. > > Regards > > > ------------------------------------------------------------------------------ > Don't let slow site performance ruin your business. Deploy New Relic APM > Deploy New Relic app performance management and know exactly > what is happening inside your Ruby, Python, PHP, Java, and .NET app > Try New Relic at no cost today and get our sweet Data Nerd shirt too! > http://p.sf.net/sfu/newrelic-dev2dev > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: dominic p. <dom...@gm...> - 2012-10-09 11:59:20
|
Hi, Has anyone tried to interop cmpforopenssl client with EJBCA. I am trying to send an 'ir' request to EJBCA from the cmpforopenssl client using the following command, ./cmpclient --server localhost --port 8080 --path ejbca/publicweb/cmp --srvcert myAdminCA.cacert.pem --ir --user test1 --password test1 --newclcert test1.pem --newkey test1.key --subject "C=IN,ST=KAR,L=TEST,O=TEST,OU= EN,CN=EETest1" I am seeing the following error on the EJBCA after sending the 'ir' request from the client, 15:40:36,975 ERROR [CrmfMessageHandler] Could not extract password from CRMF request using the RegTokenPwd authentication module 15:40:36,997 INFO [CmpServlet] Sent a CMP response to: 127.0.0.1, process time 217. On the cmpclient i am seeing the following error, INFO: Sending Initialization Request ERROR: received no initial Client Certificate. FILE cmpclient.c, LINE 401 3078551176:error:0D0680A8:asn1 encoding routines:ASN1_CHECK_TLEN:wrong tag:tasn_dec.c:1319: 3078551176:error:0D07803A:asn1 encoding routines:ASN1_ITEM_EX_D2I:nested asn1 error:tasn_dec.c:381:Type=X509 3078551176:error:32090087:CMP routines:CMP_doInitialRequestSeq:pkibody error:cmp_ses.c:384:bodytype=23, error="PKIStatus: rejection, PKIFailureInfo: wrongAuthority" And ideas ? Thanks in advance. Regards |
|
From: Christian F. <hos...@ip...> - 2012-10-07 14:22:52
|
Hi Tomas, thank you for your hint. Problem was user must contain a valid DN, e.g. CN=Testuser a plain "Testuser" is not allowed. best regards Christian Am 07.10.2012 03:17, schrieb Tomas Gustavsson: > > So of course the key question, what's your user DN? > > I.e. "user" parameter from the test.html. |
|
From: Tomas G. <to...@pr...> - 2012-10-07 01:17:59
|
So of course the key question, what's your user DN? I.e. "user" parameter from the test.html. Cheers, Tomas ----- PrimeKey Solutions offers commercial EJBCA and SignServer support subscriptions and training courses. Please see www.primekey.se or contact in...@pr... for more information. http://www.primekey.se/Services/Support/ http://www.primekey.se/Services/Training/ On 10/07/2012 04:03 AM, Christian Felsing wrote: > Hello, > > I try to get DemoCertReqServlet.java running, but I get always a > "IndexOutOfBoundsException" > > My ejbca version is 4.0.12 (r15355) running on JBoss 6.0.0. > > Id of matching "DemoCA" is set: DEFAULT_DEMOCAID = 790723041; > > CA Name: DemoCA > Id: 790723041 > Issuer DN: CN=DemoCA for nothing else than testing > Subject DN: CN=DemoCA for nothing else than testing > Type: 1 > Expire time: Wed Oct 07 20:59:15 CEST 2037 > Signed by: 1 > > Demo servlet was enabled in web.xml > > After sending data by test.html I get following: > > 2012-10-06 21:03:33,764 ERROR > [org.apache.catalina.core.ContainerBase.[jboss.web].[localhost].[/ejbca].[DemoCertReqServlet]] > (ajp-12 > 7.0.0.1-8009-4) Servlet.service() for servlet DemoCertReqServlet threw > exception: java.lang.IndexOutOfBoundsException: Index: 0, Siz > e: 0 > at java.util.ArrayList.rangeCheck(ArrayList.java:571) [:1.6.0_18] > at java.util.ArrayList.get(ArrayList.java:349) [:1.6.0_18] > at > org.ejbca.util.dn.DNFieldsUtil.removeEmpties(DNFieldsUtil.java:80) > [:EJBCA 4.0.12 (r15355)] > at org.ejbca.core.model.ra.UserDataVO.setDN(UserDataVO.java:154) > [:EJBCA 4.0.12 (r15355)] > at > org.ejbca.ui.web.pub.DemoCertReqServlet.doPost(DemoCertReqServlet.java:195) > [:EJBCA 4.0.12 (r15355)] > at javax.servlet.http.HttpServlet.service(HttpServlet.java:754) > [:1.0.0.Final] > at javax.servlet.http.HttpServlet.service(HttpServlet.java:847) > [:1.0.0.Final] > at > org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:324) > [:6.0.0.Final] > at > org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:242) > [:6.0.0.Final] > at > org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:275) > [:6.0.0.Final] > at > org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:191) > [:6.0.0.Final] > at > org.jboss.web.tomcat.security.SecurityAssociationValve.invoke(SecurityAssociationValve.java:181) > [:6.0.0.Final] > at > org.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:501) > [:6.0.0.Final] > at > org.jboss.modcluster.catalina.CatalinaContext$RequestListenerValve.event(CatalinaContext.java:285) > [:1.1.0.Final] > at > org.jboss.modcluster.catalina.CatalinaContext$RequestListenerValve.invoke(CatalinaContext.java:261) > [:1.1.0.Final] > at > org.jboss.web.tomcat.security.JaccContextValve.invoke(JaccContextValve.java:88) > [:6.0.0.Final] > at > org.jboss.web.tomcat.security.SecurityContextEstablishmentValve.invoke(SecurityContextEstablishmentValve.java:100) > [:6.0. > 0.Final] > at > org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:127) > [:6.0.0.Final] > at > org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:102) > [:6.0.0.Final] > at > org.jboss.web.tomcat.service.jca.CachedConnectionValve.invoke(CachedConnectionValve.java:158) > [:6.0.0.Final] > at > org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:109) > [:6.0.0.Final] > at > org.jboss.web.tomcat.service.request.ActiveRequestResponseCacheValve.invoke(ActiveRequestResponseCacheValve.java:53) > [:6. > 0.0.Final] > at > org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:362) > [:6.0.0.Final] > at > org.apache.coyote.ajp.AjpProcessor.process(AjpProcessor.java:504) > [:6.0.0.Final] > at > org.apache.coyote.ajp.AjpProtocol$AjpConnectionHandler.process(AjpProtocol.java:437) > [:6.0.0.Final] > at > org.apache.tomcat.util.net.JIoEndpoint$Worker.run(JIoEndpoint.java:951) > [:6.0.0.Final] > at java.lang.Thread.run(Thread.java:636) [:1.6.0_18] > > > form action is called by same reverse proxy I am using for general ejbca > access, which works flawless even with pkcs11 cards. > > It seems problem occures while setDN > > best regards > Christian > > ------------------------------------------------------------------------------ > Don't let slow site performance ruin your business. Deploy New Relic APM > Deploy New Relic app performance management and know exactly > what is happening inside your Ruby, Python, PHP, Java, and .NET app > Try New Relic at no cost today and get our sweet Data Nerd shirt too! > http://p.sf.net/sfu/newrelic-dev2dev > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Christian F. <hos...@ip...> - 2012-10-06 20:22:08
|
Hello,
I try to get DemoCertReqServlet.java running, but I get always a
"IndexOutOfBoundsException"
My ejbca version is 4.0.12 (r15355) running on JBoss 6.0.0.
Id of matching "DemoCA" is set: DEFAULT_DEMOCAID = 790723041;
CA Name: DemoCA
Id: 790723041
Issuer DN: CN=DemoCA for nothing else than testing
Subject DN: CN=DemoCA for nothing else than testing
Type: 1
Expire time: Wed Oct 07 20:59:15 CEST 2037
Signed by: 1
Demo servlet was enabled in web.xml
After sending data by test.html I get following:
2012-10-06 21:03:33,764 ERROR
[org.apache.catalina.core.ContainerBase.[jboss.web].[localhost].[/ejbca].[DemoCertReqServlet]]
(ajp-12
7.0.0.1-8009-4) Servlet.service() for servlet DemoCertReqServlet threw
exception: java.lang.IndexOutOfBoundsException: Index: 0, Siz
e: 0
at java.util.ArrayList.rangeCheck(ArrayList.java:571) [:1.6.0_18]
at java.util.ArrayList.get(ArrayList.java:349) [:1.6.0_18]
at
org.ejbca.util.dn.DNFieldsUtil.removeEmpties(DNFieldsUtil.java:80)
[:EJBCA 4.0.12 (r15355)]
at org.ejbca.core.model.ra.UserDataVO.setDN(UserDataVO.java:154)
[:EJBCA 4.0.12 (r15355)]
at
org.ejbca.ui.web.pub.DemoCertReqServlet.doPost(DemoCertReqServlet.java:195)
[:EJBCA 4.0.12 (r15355)]
at javax.servlet.http.HttpServlet.service(HttpServlet.java:754)
[:1.0.0.Final]
at javax.servlet.http.HttpServlet.service(HttpServlet.java:847)
[:1.0.0.Final]
at
org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:324)
[:6.0.0.Final]
at
org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:242)
[:6.0.0.Final]
at
org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:275)
[:6.0.0.Final]
at
org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:191)
[:6.0.0.Final]
at
org.jboss.web.tomcat.security.SecurityAssociationValve.invoke(SecurityAssociationValve.java:181)
[:6.0.0.Final]
at
org.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:501)
[:6.0.0.Final]
at
org.jboss.modcluster.catalina.CatalinaContext$RequestListenerValve.event(CatalinaContext.java:285)
[:1.1.0.Final]
at
org.jboss.modcluster.catalina.CatalinaContext$RequestListenerValve.invoke(CatalinaContext.java:261)
[:1.1.0.Final]
at
org.jboss.web.tomcat.security.JaccContextValve.invoke(JaccContextValve.java:88)
[:6.0.0.Final]
at
org.jboss.web.tomcat.security.SecurityContextEstablishmentValve.invoke(SecurityContextEstablishmentValve.java:100)
[:6.0.
0.Final]
at
org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:127)
[:6.0.0.Final]
at
org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:102)
[:6.0.0.Final]
at
org.jboss.web.tomcat.service.jca.CachedConnectionValve.invoke(CachedConnectionValve.java:158)
[:6.0.0.Final]
at
org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:109)
[:6.0.0.Final]
at
org.jboss.web.tomcat.service.request.ActiveRequestResponseCacheValve.invoke(ActiveRequestResponseCacheValve.java:53)
[:6.
0.0.Final]
at
org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:362)
[:6.0.0.Final]
at
org.apache.coyote.ajp.AjpProcessor.process(AjpProcessor.java:504)
[:6.0.0.Final]
at
org.apache.coyote.ajp.AjpProtocol$AjpConnectionHandler.process(AjpProtocol.java:437)
[:6.0.0.Final]
at
org.apache.tomcat.util.net.JIoEndpoint$Worker.run(JIoEndpoint.java:951)
[:6.0.0.Final]
at java.lang.Thread.run(Thread.java:636) [:1.6.0_18]
form action is called by same reverse proxy I am using for general ejbca
access, which works flawless even with pkcs11 cards.
It seems problem occures while setDN
best regards
Christian
|
|
From: martijn.list <mar...@gm...> - 2012-09-25 21:16:43
|
There are lo4j to slf4j bridges which supposedly do not require any code change and work for existing jars. http://www.slf4j.org/legacy.html Haven't tested it though Kind regards, Martijn Brinkers On 09/25/2012 10:49 PM, Tomas Gustavsson wrote: > > I am not an expert with slf4j, but does that not require changes to > source code? > > /Tomas > > On 09/25/2012 06:05 PM, Pallavidino Luc wrote: >> Hi, >> >> I want to use slf4j instead of log4j. I don't know how to proceed to >> change the logger. Can you help me please ? >> >> I deployed EJBCA on glassfish, where I use slf4j and logback. >> >> Thank you. >> > > > ------------------------------------------------------------------------------ > Live Security Virtual Conference > Exclusive live event will cover all the ways today's security and > threat landscape has changed and how IT managers can respond. Discussions > will include endpoint security, mobile security and the latest in malware > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > -- DJIGZO email encryption |
|
From: Tomas G. <to...@pr...> - 2012-09-25 20:50:11
|
I am not an expert with slf4j, but does that not require changes to source code? /Tomas On 09/25/2012 06:05 PM, Pallavidino Luc wrote: > Hi, > > I want to use slf4j instead of log4j. I don't know how to proceed to > change the logger. Can you help me please ? > > I deployed EJBCA on glassfish, where I use slf4j and logback. > > Thank you. > |
|
From: Pallavidino L. <luc...@gm...> - 2012-09-25 16:05:57
|
Hi, I want to use slf4j instead of log4j. I don't know how to proceed to change the logger. Can you help me please ? I deployed EJBCA on glassfish, where I use slf4j and logback. Thank you. -- Pallavidino Luc Ingénieur en monétique et sécurité des systèmes Tél. : +33-6-8070-3133 Mail : luc...@yo... |
|
From: Pallavidino L. <luc...@gm...> - 2012-09-25 10:01:28
|
Hi,
I've got a problem to access ejba web service through an EJB deploy on
Glassfish.
I use this code :
Properties systemProps = System.getProperties();
systemProps.put("javax.net.ssl.trustStoreType",
props.getProperty("ejbca.truststoretype"));
systemProps.put("javax.net.ssl.trustStore",props.getProperty("ejbca.truststore"));
systemProps.put("javax.net.ssl.trustStorePassword",props.getProperty("ejbca.truststorepass"));
systemProps.put("javax.net.ssl.keyStoreType",
props.getProperty("ejbca.keystoretype"));
systemProps.put("javax.net.ssl.keyStore",props.getProperty("ejbca.keystore"));
systemProps.put("javax.net.ssl.keyStorePassword",props.getProperty("ejbca.storepass"));
System.setProperties(systemProps);
// Initialisation de l'accès aux web services
QName qname = new QName("http://ws.protocol.core.ejbca.org/",
"EjbcaWSService");
EjbcaWSService service = new EjbcaWSService(new URL(urlstr),qname);
EjbcaWS ejbcaraws = service.getEjbcaWSPort();
All is ok, my truststore and my keystore are good (it works in a simple
java project). But in an EJB deploy on Glassfish, I've got an error
(server certificate not trusted).
I've you got an idea to solve this problem please ?
|
|
From: Toru T. <tanaka_toru@g.ogis-ri.co.jp> - 2012-09-24 10:14:30
|
Hi Tomas Thank you for quick reply and good advise. I understood. I modify JSP page directoly. Toru Tanaka 2012/9/24 Tomas Gustavsson <to...@pr...> > > Hi Toru, > > I guess this means the error page in the Admin GUI. > > The reason you get a text description of hte link is that we use JSF to > encode all output to protect against Cross Site Scripting attacks (XSS). > > You will need to modify the jsp page in order to get a "real" link in > there. > > Kind regards, > Tomas > > On 09/24/2012 06:59 AM, Toru Tanaka wrote: > > Hi all. > > I want to dispaly URL link on the error page. > > Therefore, I modify the properties file. > > But EJBCA does not display the URL link and directly display "<a href > > ="http://test.co.jp">test</a>" > > I think surely EJBCA can display URL link on the error page. > > If you know the way or idea, please teach me. > > > > thanks in advance. > > Toru Tanaka > > > > > > > > > > > ------------------------------------------------------------------------------ > > Live Security Virtual Conference > > Exclusive live event will cover all the ways today's security and > > threat landscape has changed and how IT managers can respond. Discussions > > will include endpoint security, mobile security and the latest in malware > > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > > > > > > > > _______________________________________________ > > Ejbca-develop mailing list > > Ejb...@li... > > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > > > ------------------------------------------------------------------------------ > Live Security Virtual Conference > Exclusive live event will cover all the ways today's security and > threat landscape has changed and how IT managers can respond. Discussions > will include endpoint security, mobile security and the latest in malware > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Tomas G. <to...@pr...> - 2012-09-24 07:28:47
|
Hi Toru, I guess this means the error page in the Admin GUI. The reason you get a text description of hte link is that we use JSF to encode all output to protect against Cross Site Scripting attacks (XSS). You will need to modify the jsp page in order to get a "real" link in there. Kind regards, Tomas On 09/24/2012 06:59 AM, Toru Tanaka wrote: > Hi all. > I want to dispaly URL link on the error page. > Therefore, I modify the properties file. > But EJBCA does not display the URL link and directly display "<a href > ="http://test.co.jp">test</a>" > I think surely EJBCA can display URL link on the error page. > If you know the way or idea, please teach me. > > thanks in advance. > Toru Tanaka > > > > > ------------------------------------------------------------------------------ > Live Security Virtual Conference > Exclusive live event will cover all the ways today's security and > threat landscape has changed and how IT managers can respond. Discussions > will include endpoint security, mobile security and the latest in malware > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Toru T. <tanaka_toru@g.ogis-ri.co.jp> - 2012-09-24 05:57:48
|
Hi all. I want to dispaly URL link on the error page. Therefore, I modify the properties file. But EJBCA does not display the URL link and directly display "<a href =" http://test.co.jp">test</a>" I think surely EJBCA can display URL link on the error page. If you know the way or idea, please teach me. thanks in advance. Toru Tanaka |
|
From: Tomas G. <to...@pr...> - 2012-09-22 08:08:39
|
EJBCA works great with Postgres. If you have any issues it is most likely related to configuration issues. Common problems are privilege configuration with your database. If you want more help you need to provide a lot more details. Like versions of software and OS used, error logs from JBoss etc. Cheers, Tomas ----- PrimeKey Solutions offers commercial EJBCA and SignServer support subscriptions and training courses. Please see www.primekey.se or contact in...@pr... for more information. http://www.primekey.se/Services/Support/ http://www.primekey.se/Services/Training/ On 09/21/2012 08:17 PM, Noe Gutierrez wrote: > *hi > * > *I.S.C. Noe Adahi Gutiérrez Romero* > ***Oracle® Certified Professional, Java® SE 6 Programmer* > *IBM® InfoShere® Guardium® Technical Professional v1* > > > > On Fri, Sep 21, 2012 at 1:15 PM, Noe Gutierrez <noe...@gm... > <mailto:noe...@gm...>> wrote: > > *hi: > > I have a problem when Try to install EJBCA, my database's instance > is across the Pgpool (is a postgresSQL 9.1's cluster) > > > thanks > > > > * > *I.S.C. Noe Adahi Gutiérrez Romero* > ***Oracle® Certified Professional, Java® SE 6 Programmer* > *IBM® InfoShere® Guardium® Technical Professional v1* > > > > > ------------------------------------------------------------------------------ > Got visibility? > Most devs has no idea what their production app looks like. > Find out how fast your code is with AppDynamics Lite. > http://ad.doubleclick.net/clk;262219671;13503038;y? > http://info.appdynamics.com/FreeJavaPerformanceDownload.html > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Noe G. <noe...@gm...> - 2012-09-21 18:17:44
|
*hi * *I.S.C. Noe Adahi Gutiérrez Romero* ***Oracle® Certified Professional, Java® SE 6 Programmer* *IBM® InfoShere® Guardium® Technical Professional v1* On Fri, Sep 21, 2012 at 1:15 PM, Noe Gutierrez <noe...@gm...> wrote: > *hi: > > I have a problem when Try to install EJBCA, my database's instance is > across the Pgpool (is a postgresSQL 9.1's cluster) > > > thanks > > > > * > *I.S.C. Noe Adahi Gutiérrez Romero* > ***Oracle® Certified Professional, Java® SE 6 Programmer* > *IBM® InfoShere® Guardium® Technical Professional v1* > > > |
|
From: Tomas G. <to...@pr...> - 2012-09-10 17:55:12
|
When submitting CSRs you must use keystore type "USERGENERATED", everything else means server generated keys. Cheers, Tomas ----- PrimeKey Solutions offers commercial EJBCA and SignServer support subscriptions and training courses. Please see www.primekey.se or contact in...@pr... for more information. http://www.primekey.se/Services/Support/ http://www.primekey.se/Services/Training/ On 09/10/2012 06:04 PM, Jack D. Pond wrote: > Even more information: > 2012-09-06 17:36:09,802 INFO [org.ejbca.core.model.log.Log4jLogDevice] > (http-0.0.0.0-8443-2) 2012-09-06 17:36:09-04:00, CAId : -1724983956, CA, > EVENT_INFO_REQUESTCERTIFICATE, Administrator : PUBLICWEBUSER : IP > Address : [CA IP Addr], User : SSLVPN_wbcb1490_com, Certificate : No > certificate involved, Comment : Received certificate request for user > SSLVPN_wbcb1490_com for CA [CAId] with certificate profile [cpprofile]. > > 2012-09-06 17:36:09,956 INFO [org.ejbca.core.model.log.Log4jLogDevice] > (http-0.0.0.0-8443-2) 2012-09-06 17:36:09-04:00, CAId : [CAId], CA, > EVENT_INFO_CREATECERTIFICATE, Administrator : PUBLICWEBUSER : IP Address > : [CA IP Addr],User : SSLVPN_wbcb1490_com, Certificate : No certificate > involved, Comment : Illegal key length: 1024. > > *From:*Jack D. Pond [mailto:jac...@ps...] > *Sent:* Monday, September 10, 2012 12:25 PM > *To:* ejb...@li... > *Subject:* Re: [Ejbca-develop] CSR Request Failing in Create Certificate > from CSR, Public Web Interface > > Oh, Little more information: > > java version "1.6.0_24" > > OpenJDK Runtime Environment (IcedTea6 1.11.4) (6b24-1.11.4-1ubuntu0.12.04.1) > > OpenJDK 64-Bit Server VM (build 20.0-b12, mixed mode) > > *From:*Jack D. Pond [mailto:jac...@ps...] > <mailto:[mailto:jac...@ps...]> > *Sent:* Monday, September 10, 2012 12:09 PM > *To:* ejb...@li... > <mailto:ejb...@li...> > *Subject:* [Ejbca-develop] CSR Request Failing in Create Certificate > from CSR, Public Web Interface > > Whether asking for entity PKCS #7 or PEM, get “Invalid Key in request: > Illegal key length: 1024.. Please supply a correct request.” > > Note: If doing batch generation, no problem, generates 2048 key & cert, > so I know the 2048 part on the end entity is correct, but of course then > it’s not using the user created key from the CSR. > > I saw this bug, but assuming since closed, not relevant: > https://jira.primekey.se/browse/ECA-1613?page=com.atlassian.jira.plugin.system.issuetabpanels%3Achangehistory-tabpanel > > Debug Information: CSR: PEM, 2048 bit – obviously, I’m going to throw > this one away. > > -----BEGIN CERTIFICATE REQUEST----- > > MIIC9DCCAdwCAQAwga4xHDAaBgNVBAMTE3NzbHZwbi53YmNiMTQ5MC5jb20xKDAm > > BgkqhkiG9w0BCQEWGXN1cHBvcnRAbGV4dGVjaGF1ZGl0cy5jb20xCzAJBgNVBAYT > > AlVTMRUwEwYDVQQIEwxQZW5uc3lsdmFuaWExFzAVBgNVBAcTDkZhaXJsZXNzIEhp > > bGxzMRIwEAYDVQQKEwlXQkNCIDE0OTAxEzARBgNVBAsTClByb2R1Y3Rpb24wggEi > > MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQD5oKhG73qA8JxZNTlLpwOpHX7m > > mlKBjmVSIs8OlJRkEsAFR9WWS2pldVqA3OnANPJNodzDrQzYDeRpl6ZwNuylMcTR > > 9w32A4nobZtpuYlHTWB81dQ5O6vylte6VYr3Rv2J0caRF1S0CTdA64wh2AGl7kng > > zOD5UmGc+vUwgWNHX6buUNURJAOXNegp/0AeCV6JD3WfRfSbXoKF4eDAH/mYRqKw > > 7XXQ/WcPgHqy8HDuaN9AF1f/rEvya8nShZNsaTGgapyfkpn1GUTaIVjW0UaG9tee > > eZag0V1oZLzcBob4dkinz/7FoYB2BSAxwBPsmQlQgWub4EKagZRubTld0O3HAgMB > > AAGgADANBgkqhkiG9w0BAQUFAAOCAQEAukcNs0mkTlehUmrypwCltcEcMxWaYL/n > > xcOUel6nifqh7ulq4ioHqKRVxwdgO83EcQtUkg4OLBnD+WVfzNgANhiQjXj+1wYH > > rTJhYPFFGHQv9dbajSw6ARY77cD02JfLipGJBeEXB7B1DWTJyiaNk6po0ahCfupv > > vvb4iEag+xJO/1biXSibMsUAJkaMlm5ue2oH0lhNt+2u64pxkyRNvHx8Y8sugRBL > > 0FSK3EyBZBYSNPJtUUNQCF/N1eqDIbbnLKo6Z7ALcj/fqMgIcy7nda+mdrWSTFRM > > rfsZyWOZn7L0z1IHeCHk9Cjhc81400ph16lvkmHluy+ABelCUnFXaw== > > -----END CERTIFICATE REQUEST----- > > CSR Details (from) >openssl req -text -noout -in “CertName.csr " > > Certificate Request: > > Data: > > Version: 0 (0x0) > > Subject: > CN=sslvpn.wbcb1490.com/ema...@le... > <mailto:CN=sslvpn.wbcb1490.com/ema...@le...>, > C=US, ST=Pennsylvania, L=Fairless Hills, O=WBCB 1490, OU=Production > > Subject Public Key Info: > > Public Key Algorithm: rsaEncryption > > Public-Key: (2048 bit) > > Modulus: > > 00:f9:a0:a8:46:ef:7a:80:f0:9c:59:35:39:4b:a7: > > 03:a9:1d:7e:e6:9a:52:81:8e:65:52:22:cf:0e:94: > > 94:64:12:c0:05:47:d5:96:4b:6a:65:75:5a:80:dc: > > e9:c0:34:f2:4d:a1:dc:c3:ad:0c:d8:0d:e4:69:97: > > a6:70:36:ec:a5:31:c4:d1:f7:0d:f6:03:89:e8:6d: > > 9b:69:b9:89:47:4d:60:7c:d5:d4:39:3b:ab:f2:96: > > d7:ba:55:8a:f7:46:fd:89:d1:c6:91:17:54:b4:09: > > 37:40:eb:8c:21:d8:01:a5:ee:49:e0:cc:e0:f9:52: > > 61:9c:fa:f5:30:81:63:47:5f:a6:ee:50:d5:11:24: > > 03:97:35:e8:29:ff:40:1e:09:5e:89:0f:75:9f:45: > > f4:9b:5e:82:85:e1:e0:c0:1f:f9:98:46:a2:b0:ed: > > 75:d0:fd:67:0f:80:7a:b2:f0:70:ee:68:df:40:17: > > 57:ff:ac:4b:f2:6b:c9:d2:85:93:6c:69:31:a0:6a: > > 9c:9f:92:99:f5:19:44:da:21:58:d6:d1:46:86:f6: > > d7:9e:79:96:a0:d1:5d:68:64:bc:dc:06:86:f8:76: > > 48:a7:cf:fe:c5:a1:80:76:05:20:31:c0:13:ec:99: > > 09:50:81:6b:9b:e0:42:9a:81:94:6e:6d:39:5d:d0: > > ed:c7 > > Exponent: 65537 (0x10001) > > Attributes: > > a0:00 > > Signature Algorithm: sha1WithRSAEncryption > > ba:47:0d:b3:49:a4:4e:57:a1:52:6a:f2:a7:00:a5:b5:c1:1c: > > 33:15:9a:60:bf:e7:c5:c3:94:7a:5e:a7:89:fa:a1:ee:e9:6a: > > e2:2a:07:a8:a4:55:c7:07:60:3b:cd:c4:71:0b:54:92:0e:0e: > > 2c:19:c3:f9:65:5f:cc:d8:00:36:18:90:8d:78:fe:d7:06:07: > > ad:32:61:60:f1:45:18:74:2f:f5:d6:da:8d:2c:3a:01:16:3b: > > ed:c0:f4:d8:97:cb:8a:91:89:05:e1:17:07:b0:75:0d:64:c9: > > ca:26:8d:93:aa:68:d1:a8:42:7e:ea:6f:be:f6:f8:88:46:a0: > > fb:12:4e:ff:56:e2:5d:28:9b:32:c5:00:26:46:8c:96:6e:6e: > > 7b:6a:07:d2:58:4d:b7:ed:ae:eb:8a:71:93:24:4d:bc:7c:7c: > > 63:cb:2e:81:10:4b:d0:54:8a:dc:4c:81:64:16:12:34:f2:6d: > > 51:43:50:08:5f:cd:d5:ea:83:21:b6:e7:2c:aa:3a:67:b0:0b: > > 72:3f:df:a8:c8:08:73:2e:e7:75:af:a6:76:b5:92:4c:54:4c: > > ad:fb:19:c9:63:99:9f:b2:f4:cf:52:07:78:21:e4:f4:28:e1: > > 73:cd:78:d3:4a:61:d7:a9:6f:92:61:e5:bb:2f:80:05:e9:42: > > 52:71:57:6b > > Jack D. Pond > Description: Description: C:\Users\Jack D > Pond\AppData\Roaming\Microsoft\Signatures\JDP-PSITEX_files\image001.png > > */"Truth is the summit of being; justice is the application of it to > affairs." -- Ralph Waldo Emerson, (1803-1882)/* > > > > ------------------------------------------------------------------------------ > Live Security Virtual Conference > Exclusive live event will cover all the ways today's security and > threat landscape has changed and how IT managers can respond. Discussions > will include endpoint security, mobile security and the latest in malware > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Pallavidino L. <luc...@gm...> - 2012-09-10 15:53:53
|
Hi,
It works, I uncheck all the Approval settings, and It works fine.
Thank you for your help and your reactivity !
Cheers,
Le 10/09/2012 17:45, ejbca-support a écrit :
> Hi,
> I don't know how this happened but apparently you have created rather
> unusual profiles :-)
>
> Anyway, this time it is the *certificate profile* that is the culprit.
> Uncheck all the Approval settings in the end of the dialog.
>
> Cheers,
> Anders
>
>
> On 2012-09-10 17:39, Pallavidino Luc wrote:
>> Hi,
>>
>> It works ! But I have an other problem now. I get this error :
>>
>> WaitingForApprovalException_Exception: Add Endity Action have been added
>> for approval by authorized adminstrators.
>>
>> I don't want an other approval to add a new end entity for my CA. What I
>> need to do, to have this behaviour ?
>>
>> Thank for your reactivity !
>>
>> Cheers,
>>
>> Le 10/09/2012 17:25, ejbca-support a écrit :
>>> On 2012-09-10 17:18, Pallavidino Luc wrote:
>>>> Hi,
>>>>
>>>> I try with the profiles "EMPTY" and "ENDUSER", and it works. I don't
>>>> where is my error on my profile ... Have you an idea ?
>>> I think you should look into the end-entity profile and maybe clear
>>> "Revocation reason to set after certificate issuance [?]"
>>> if set.
>>>
>>> As far as I know this is the only revocation-reason-related data.
>>>
>>> Cheers,
>>> Anders
>>>
>>>> Thank you for your help.
>>>>
>>>> Le 10/09/2012 16:54, ejbca-support a écrit :
>>>>> On 2012-09-10 16:24, Pallavidino Luc wrote:
>>>>>> Hello,
>>>>>>
>>>>>> I try to use EJBCA web service to add a new End entity. But when I want
>>>>>> to add a new user with my own authority and my own end entity profile, I
>>>>>> get this error :
>>>>>>
>>>>>> Exception in thread "main"
>>>>>> org.ejbca.core.protocol.ws.client.gen.UserDoesntFullfillEndEntityProfile_Exception:
>>>>>> Issuance revocation reason 'null' does not match required value '-1'.
>>>>>>
>>>>>>
>>>>>> I don't know what is the problem. May you help me please ?
>>>>> Hi,
>>>>> I don't know for sure but it feels that there is something wrong with the
>>>>> profiles. Could you test with the EMPTY and ENDUSER profiles and see
>>>>> if you get a different result?
>>>>>
>>>>> Cheers,
>>>>> Anders
>>>>> tech support
>>>>>
>>>>>
>>>>>> This is my code :
>>>>>>
>>>>>>
>>>>>> CertTools.installBCProviderIfNotAvailable();
>>>>>> String urlstr = "https://localhost:8443/ejbca/ejbcaws/ejbcaws?wsdl";
>>>>>> System.setProperty("javax.net.ssl.trustStore","p12/cacerts.jks");
>>>>>> System.setProperty("javax.net.ssl.trustStorePassword","changeit");
>>>>>>
>>>>>> System.setProperty("javax.net.ssl.keyStoreType", "pkcs12");
>>>>>> System.setProperty("javax.net.ssl.keyStore","p12/testKs.p12");
>>>>>> System.setProperty("javax.net.ssl.keyStorePassword","PASSWORDP12");
>>>>>>
>>>>>> QName qname = new QName("http://ws.protocol.core.ejbca.org/";,
>>>>>> "EjbcaWSService");
>>>>>> EjbcaWSService service = new EjbcaWSService(new URL(urlstr),qname);
>>>>>> EjbcaWS ejbcaraws = service.getEjbcaWSPort();
>>>>>>
>>>>>> UserDataVOWS user1 = new UserDataVOWS();
>>>>>> user1.setUsername("WSTESTUSER25");
>>>>>> user1.setPassword("foo12345");
>>>>>> user1.setClearPwd(true);
>>>>>> user1.setEmail(null);
>>>>>> user1.setSubjectDN("CN=WSTESTUSER25,OU=Test,O=ACME,L=CAEN,ST=Calvados,C=FR");
>>>>>> user1.setCaName("ACME SIGN CA");
>>>>>> user1.setSubjectAltName(null);
>>>>>> user1.setStatus(UserDataVOWS.STATUS_NEW);
>>>>>> user1.setTokenType("USERGENERATED");
>>>>>> user1.setEndEntityProfileName("ACME SIGNATURE ENTITY PROFILE");
>>>>>> user1.setCertificateProfileName("ACME SIGNATURE CERTIFICATE PROFILE");
>>>>>>
>>>>>> ejbcaraws.editUser(user1);
>>>>>>
>>>>>>
>>>>>> Thank you for your help.
>>>>>>
>>>>>>
>>
--
Pallavidino Luc Ingénieur en monétique et sécurité des systèmes
Tél. : +33-6-8070-3133 Mail : luc...@yo...
|
|
From: ejbca-support <ejb...@pr...> - 2012-09-10 15:45:32
|
Hi,
I don't know how this happened but apparently you have created rather
unusual profiles :-)
Anyway, this time it is the *certificate profile* that is the culprit.
Uncheck all the Approval settings in the end of the dialog.
Cheers,
Anders
On 2012-09-10 17:39, Pallavidino Luc wrote:
> Hi,
>
> It works ! But I have an other problem now. I get this error :
>
> WaitingForApprovalException_Exception: Add Endity Action have been added
> for approval by authorized adminstrators.
>
> I don't want an other approval to add a new end entity for my CA. What I
> need to do, to have this behaviour ?
>
> Thank for your reactivity !
>
> Cheers,
>
> Le 10/09/2012 17:25, ejbca-support a écrit :
>> On 2012-09-10 17:18, Pallavidino Luc wrote:
>>> Hi,
>>>
>>> I try with the profiles "EMPTY" and "ENDUSER", and it works. I don't
>>> where is my error on my profile ... Have you an idea ?
>> I think you should look into the end-entity profile and maybe clear
>> "Revocation reason to set after certificate issuance [?]"
>> if set.
>>
>> As far as I know this is the only revocation-reason-related data.
>>
>> Cheers,
>> Anders
>>
>>> Thank you for your help.
>>>
>>> Le 10/09/2012 16:54, ejbca-support a écrit :
>>>> On 2012-09-10 16:24, Pallavidino Luc wrote:
>>>>> Hello,
>>>>>
>>>>> I try to use EJBCA web service to add a new End entity. But when I want
>>>>> to add a new user with my own authority and my own end entity profile, I
>>>>> get this error :
>>>>>
>>>>> Exception in thread "main"
>>>>> org.ejbca.core.protocol.ws.client.gen.UserDoesntFullfillEndEntityProfile_Exception:
>>>>> Issuance revocation reason 'null' does not match required value '-1'.
>>>>>
>>>>>
>>>>> I don't know what is the problem. May you help me please ?
>>>> Hi,
>>>> I don't know for sure but it feels that there is something wrong with the
>>>> profiles. Could you test with the EMPTY and ENDUSER profiles and see
>>>> if you get a different result?
>>>>
>>>> Cheers,
>>>> Anders
>>>> tech support
>>>>
>>>>
>>>>> This is my code :
>>>>>
>>>>>
>>>>> CertTools.installBCProviderIfNotAvailable();
>>>>> String urlstr = "https://localhost:8443/ejbca/ejbcaws/ejbcaws?wsdl";
>>>>> System.setProperty("javax.net.ssl.trustStore","p12/cacerts.jks");
>>>>> System.setProperty("javax.net.ssl.trustStorePassword","changeit");
>>>>>
>>>>> System.setProperty("javax.net.ssl.keyStoreType", "pkcs12");
>>>>> System.setProperty("javax.net.ssl.keyStore","p12/testKs.p12");
>>>>> System.setProperty("javax.net.ssl.keyStorePassword","PASSWORDP12");
>>>>>
>>>>> QName qname = new QName("http://ws.protocol.core.ejbca.org/";,
>>>>> "EjbcaWSService");
>>>>> EjbcaWSService service = new EjbcaWSService(new URL(urlstr),qname);
>>>>> EjbcaWS ejbcaraws = service.getEjbcaWSPort();
>>>>>
>>>>> UserDataVOWS user1 = new UserDataVOWS();
>>>>> user1.setUsername("WSTESTUSER25");
>>>>> user1.setPassword("foo12345");
>>>>> user1.setClearPwd(true);
>>>>> user1.setEmail(null);
>>>>> user1.setSubjectDN("CN=WSTESTUSER25,OU=Test,O=ACME,L=CAEN,ST=Calvados,C=FR");
>>>>> user1.setCaName("ACME SIGN CA");
>>>>> user1.setSubjectAltName(null);
>>>>> user1.setStatus(UserDataVOWS.STATUS_NEW);
>>>>> user1.setTokenType("USERGENERATED");
>>>>> user1.setEndEntityProfileName("ACME SIGNATURE ENTITY PROFILE");
>>>>> user1.setCertificateProfileName("ACME SIGNATURE CERTIFICATE PROFILE");
>>>>>
>>>>> ejbcaraws.editUser(user1);
>>>>>
>>>>>
>>>>> Thank you for your help.
>>>>>
>>>>>
>>>
>
>
|
|
From: Pallavidino L. <luc...@gm...> - 2012-09-10 15:39:16
|
Hi,
It works ! But I have an other problem now. I get this error :
WaitingForApprovalException_Exception: Add Endity Action have been added
for approval by authorized adminstrators.
I don't want an other approval to add a new end entity for my CA. What I
need to do, to have this behaviour ?
Thank for your reactivity !
Cheers,
Le 10/09/2012 17:25, ejbca-support a écrit :
> On 2012-09-10 17:18, Pallavidino Luc wrote:
>> Hi,
>>
>> I try with the profiles "EMPTY" and "ENDUSER", and it works. I don't
>> where is my error on my profile ... Have you an idea ?
> I think you should look into the end-entity profile and maybe clear
> "Revocation reason to set after certificate issuance [?]"
> if set.
>
> As far as I know this is the only revocation-reason-related data.
>
> Cheers,
> Anders
>
>> Thank you for your help.
>>
>> Le 10/09/2012 16:54, ejbca-support a écrit :
>>> On 2012-09-10 16:24, Pallavidino Luc wrote:
>>>> Hello,
>>>>
>>>> I try to use EJBCA web service to add a new End entity. But when I want
>>>> to add a new user with my own authority and my own end entity profile, I
>>>> get this error :
>>>>
>>>> Exception in thread "main"
>>>> org.ejbca.core.protocol.ws.client.gen.UserDoesntFullfillEndEntityProfile_Exception:
>>>> Issuance revocation reason 'null' does not match required value '-1'.
>>>>
>>>>
>>>> I don't know what is the problem. May you help me please ?
>>> Hi,
>>> I don't know for sure but it feels that there is something wrong with the
>>> profiles. Could you test with the EMPTY and ENDUSER profiles and see
>>> if you get a different result?
>>>
>>> Cheers,
>>> Anders
>>> tech support
>>>
>>>
>>>> This is my code :
>>>>
>>>>
>>>> CertTools.installBCProviderIfNotAvailable();
>>>> String urlstr = "https://localhost:8443/ejbca/ejbcaws/ejbcaws?wsdl";
>>>> System.setProperty("javax.net.ssl.trustStore","p12/cacerts.jks");
>>>> System.setProperty("javax.net.ssl.trustStorePassword","changeit");
>>>>
>>>> System.setProperty("javax.net.ssl.keyStoreType", "pkcs12");
>>>> System.setProperty("javax.net.ssl.keyStore","p12/testKs.p12");
>>>> System.setProperty("javax.net.ssl.keyStorePassword","PASSWORDP12");
>>>>
>>>> QName qname = new QName("http://ws.protocol.core.ejbca.org/";,
>>>> "EjbcaWSService");
>>>> EjbcaWSService service = new EjbcaWSService(new URL(urlstr),qname);
>>>> EjbcaWS ejbcaraws = service.getEjbcaWSPort();
>>>>
>>>> UserDataVOWS user1 = new UserDataVOWS();
>>>> user1.setUsername("WSTESTUSER25");
>>>> user1.setPassword("foo12345");
>>>> user1.setClearPwd(true);
>>>> user1.setEmail(null);
>>>> user1.setSubjectDN("CN=WSTESTUSER25,OU=Test,O=ACME,L=CAEN,ST=Calvados,C=FR");
>>>> user1.setCaName("ACME SIGN CA");
>>>> user1.setSubjectAltName(null);
>>>> user1.setStatus(UserDataVOWS.STATUS_NEW);
>>>> user1.setTokenType("USERGENERATED");
>>>> user1.setEndEntityProfileName("ACME SIGNATURE ENTITY PROFILE");
>>>> user1.setCertificateProfileName("ACME SIGNATURE CERTIFICATE PROFILE");
>>>>
>>>> ejbcaraws.editUser(user1);
>>>>
>>>>
>>>> Thank you for your help.
>>>>
>>>>
>>
--
Pallavidino Luc Ingénieur en monétique et sécurité des systèmes
Tél. : +33-6-8070-3133 Mail : luc...@yo...
|
|
From: ejbca-support <ejb...@pr...> - 2012-09-10 15:26:11
|
On 2012-09-10 17:18, Pallavidino Luc wrote:
> Hi,
>
> I try with the profiles "EMPTY" and "ENDUSER", and it works. I don't
> where is my error on my profile ... Have you an idea ?
I think you should look into the end-entity profile and maybe clear
"Revocation reason to set after certificate issuance [?]"
if set.
As far as I know this is the only revocation-reason-related data.
Cheers,
Anders
>
> Thank you for your help.
>
> Le 10/09/2012 16:54, ejbca-support a écrit :
>> On 2012-09-10 16:24, Pallavidino Luc wrote:
>>> Hello,
>>>
>>> I try to use EJBCA web service to add a new End entity. But when I want
>>> to add a new user with my own authority and my own end entity profile, I
>>> get this error :
>>>
>>> Exception in thread "main"
>>> org.ejbca.core.protocol.ws.client.gen.UserDoesntFullfillEndEntityProfile_Exception:
>>> Issuance revocation reason 'null' does not match required value '-1'.
>>>
>>>
>>> I don't know what is the problem. May you help me please ?
>> Hi,
>> I don't know for sure but it feels that there is something wrong with the
>> profiles. Could you test with the EMPTY and ENDUSER profiles and see
>> if you get a different result?
>>
>> Cheers,
>> Anders
>> tech support
>>
>>
>>> This is my code :
>>>
>>>
>>> CertTools.installBCProviderIfNotAvailable();
>>> String urlstr = "https://localhost:8443/ejbca/ejbcaws/ejbcaws?wsdl";
>>> System.setProperty("javax.net.ssl.trustStore","p12/cacerts.jks");
>>> System.setProperty("javax.net.ssl.trustStorePassword","changeit");
>>>
>>> System.setProperty("javax.net.ssl.keyStoreType", "pkcs12");
>>> System.setProperty("javax.net.ssl.keyStore","p12/testKs.p12");
>>> System.setProperty("javax.net.ssl.keyStorePassword","PASSWORDP12");
>>>
>>> QName qname = new QName("http://ws.protocol.core.ejbca.org/";,
>>> "EjbcaWSService");
>>> EjbcaWSService service = new EjbcaWSService(new URL(urlstr),qname);
>>> EjbcaWS ejbcaraws = service.getEjbcaWSPort();
>>>
>>> UserDataVOWS user1 = new UserDataVOWS();
>>> user1.setUsername("WSTESTUSER25");
>>> user1.setPassword("foo12345");
>>> user1.setClearPwd(true);
>>> user1.setEmail(null);
>>> user1.setSubjectDN("CN=WSTESTUSER25,OU=Test,O=ACME,L=CAEN,ST=Calvados,C=FR");
>>> user1.setCaName("ACME SIGN CA");
>>> user1.setSubjectAltName(null);
>>> user1.setStatus(UserDataVOWS.STATUS_NEW);
>>> user1.setTokenType("USERGENERATED");
>>> user1.setEndEntityProfileName("ACME SIGNATURE ENTITY PROFILE");
>>> user1.setCertificateProfileName("ACME SIGNATURE CERTIFICATE PROFILE");
>>>
>>> ejbcaraws.editUser(user1);
>>>
>>>
>>> Thank you for your help.
>>>
>>>
>
>
|
|
From: Pallavidino L. <luc...@gm...> - 2012-09-10 15:18:56
|
Hi,
I try with the profiles "EMPTY" and "ENDUSER", and it works. I don't
where is my error on my profile ... Have you an idea ?
Thank you for your help.
Le 10/09/2012 16:54, ejbca-support a écrit :
> On 2012-09-10 16:24, Pallavidino Luc wrote:
>> Hello,
>>
>> I try to use EJBCA web service to add a new End entity. But when I want
>> to add a new user with my own authority and my own end entity profile, I
>> get this error :
>>
>> Exception in thread "main"
>> org.ejbca.core.protocol.ws.client.gen.UserDoesntFullfillEndEntityProfile_Exception:
>> Issuance revocation reason 'null' does not match required value '-1'.
>>
>>
>> I don't know what is the problem. May you help me please ?
> Hi,
> I don't know for sure but it feels that there is something wrong with the
> profiles. Could you test with the EMPTY and ENDUSER profiles and see
> if you get a different result?
>
> Cheers,
> Anders
> tech support
>
>
>> This is my code :
>>
>>
>> CertTools.installBCProviderIfNotAvailable();
>> String urlstr = "https://localhost:8443/ejbca/ejbcaws/ejbcaws?wsdl";
>> System.setProperty("javax.net.ssl.trustStore","p12/cacerts.jks");
>> System.setProperty("javax.net.ssl.trustStorePassword","changeit");
>>
>> System.setProperty("javax.net.ssl.keyStoreType", "pkcs12");
>> System.setProperty("javax.net.ssl.keyStore","p12/testKs.p12");
>> System.setProperty("javax.net.ssl.keyStorePassword","PASSWORDP12");
>>
>> QName qname = new QName("http://ws.protocol.core.ejbca.org/";,
>> "EjbcaWSService");
>> EjbcaWSService service = new EjbcaWSService(new URL(urlstr),qname);
>> EjbcaWS ejbcaraws = service.getEjbcaWSPort();
>>
>> UserDataVOWS user1 = new UserDataVOWS();
>> user1.setUsername("WSTESTUSER25");
>> user1.setPassword("foo12345");
>> user1.setClearPwd(true);
>> user1.setEmail(null);
>> user1.setSubjectDN("CN=WSTESTUSER25,OU=Test,O=ACME,L=CAEN,ST=Calvados,C=FR");
>> user1.setCaName("ACME SIGN CA");
>> user1.setSubjectAltName(null);
>> user1.setStatus(UserDataVOWS.STATUS_NEW);
>> user1.setTokenType("USERGENERATED");
>> user1.setEndEntityProfileName("ACME SIGNATURE ENTITY PROFILE");
>> user1.setCertificateProfileName("ACME SIGNATURE CERTIFICATE PROFILE");
>>
>> ejbcaraws.editUser(user1);
>>
>>
>> Thank you for your help.
>>
>>
--
Pallavidino Luc Ingénieur en monétique et sécurité des systèmes
Tél. : +33-6-8070-3133 Mail : luc...@yo...
|
|
From: ejbca-support <ejb...@pr...> - 2012-09-10 14:54:59
|
On 2012-09-10 16:24, Pallavidino Luc wrote:
> Hello,
>
> I try to use EJBCA web service to add a new End entity. But when I want
> to add a new user with my own authority and my own end entity profile, I
> get this error :
>
> Exception in thread "main"
> org.ejbca.core.protocol.ws.client.gen.UserDoesntFullfillEndEntityProfile_Exception:
> Issuance revocation reason 'null' does not match required value '-1'.
>
>
> I don't know what is the problem. May you help me please ?
Hi,
I don't know for sure but it feels that there is something wrong with the
profiles. Could you test with the EMPTY and ENDUSER profiles and see
if you get a different result?
Cheers,
Anders
tech support
>
> This is my code :
>
>
> CertTools.installBCProviderIfNotAvailable();
> String urlstr = "https://localhost:8443/ejbca/ejbcaws/ejbcaws?wsdl";
> System.setProperty("javax.net.ssl.trustStore","p12/cacerts.jks");
> System.setProperty("javax.net.ssl.trustStorePassword","changeit");
>
> System.setProperty("javax.net.ssl.keyStoreType", "pkcs12");
> System.setProperty("javax.net.ssl.keyStore","p12/testKs.p12");
> System.setProperty("javax.net.ssl.keyStorePassword","PASSWORDP12");
>
> QName qname = new QName("http://ws.protocol.core.ejbca.org/";,
> "EjbcaWSService");
> EjbcaWSService service = new EjbcaWSService(new URL(urlstr),qname);
> EjbcaWS ejbcaraws = service.getEjbcaWSPort();
>
> UserDataVOWS user1 = new UserDataVOWS();
> user1.setUsername("WSTESTUSER25");
> user1.setPassword("foo12345");
> user1.setClearPwd(true);
> user1.setEmail(null);
> user1.setSubjectDN("CN=WSTESTUSER25,OU=Test,O=ACME,L=CAEN,ST=Calvados,C=FR");
> user1.setCaName("ACME SIGN CA");
> user1.setSubjectAltName(null);
> user1.setStatus(UserDataVOWS.STATUS_NEW);
> user1.setTokenType("USERGENERATED");
> user1.setEndEntityProfileName("ACME SIGNATURE ENTITY PROFILE");
> user1.setCertificateProfileName("ACME SIGNATURE CERTIFICATE PROFILE");
>
> ejbcaraws.editUser(user1);
>
>
> Thank you for your help.
>
>
|