You can subscribe to this list here.
| 2001 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
(1) |
Dec
(3) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2002 |
Jan
(3) |
Feb
(2) |
Mar
(8) |
Apr
(3) |
May
(6) |
Jun
(1) |
Jul
(15) |
Aug
(6) |
Sep
|
Oct
(10) |
Nov
(2) |
Dec
(4) |
| 2003 |
Jan
(1) |
Feb
(7) |
Mar
(3) |
Apr
(6) |
May
(7) |
Jun
(5) |
Jul
(5) |
Aug
(25) |
Sep
(14) |
Oct
(2) |
Nov
|
Dec
(2) |
| 2004 |
Jan
(7) |
Feb
(4) |
Mar
(12) |
Apr
(16) |
May
(43) |
Jun
(56) |
Jul
(43) |
Aug
(40) |
Sep
(66) |
Oct
(12) |
Nov
(26) |
Dec
(10) |
| 2005 |
Jan
(13) |
Feb
(33) |
Mar
(16) |
Apr
(7) |
May
(10) |
Jun
(34) |
Jul
(41) |
Aug
(8) |
Sep
(4) |
Oct
(32) |
Nov
(20) |
Dec
(25) |
| 2006 |
Jan
(30) |
Feb
(101) |
Mar
(5) |
Apr
(75) |
May
(74) |
Jun
(22) |
Jul
(6) |
Aug
(70) |
Sep
(19) |
Oct
(21) |
Nov
(31) |
Dec
(50) |
| 2007 |
Jan
(15) |
Feb
(20) |
Mar
(24) |
Apr
(33) |
May
(13) |
Jun
(18) |
Jul
(13) |
Aug
(7) |
Sep
(63) |
Oct
(68) |
Nov
(29) |
Dec
(68) |
| 2008 |
Jan
(30) |
Feb
(33) |
Mar
(30) |
Apr
(103) |
May
(78) |
Jun
(48) |
Jul
(72) |
Aug
(24) |
Sep
(62) |
Oct
(63) |
Nov
(70) |
Dec
(37) |
| 2009 |
Jan
(34) |
Feb
(35) |
Mar
(64) |
Apr
(34) |
May
(34) |
Jun
(58) |
Jul
(30) |
Aug
(30) |
Sep
(46) |
Oct
(52) |
Nov
(12) |
Dec
(23) |
| 2010 |
Jan
(121) |
Feb
(18) |
Mar
(53) |
Apr
(62) |
May
(62) |
Jun
(20) |
Jul
(33) |
Aug
(20) |
Sep
(36) |
Oct
(35) |
Nov
(44) |
Dec
(63) |
| 2011 |
Jan
(19) |
Feb
(32) |
Mar
(94) |
Apr
(41) |
May
(47) |
Jun
(25) |
Jul
(34) |
Aug
(20) |
Sep
(9) |
Oct
(41) |
Nov
(33) |
Dec
(24) |
| 2012 |
Jan
(12) |
Feb
(36) |
Mar
(48) |
Apr
(32) |
May
(20) |
Jun
(15) |
Jul
(32) |
Aug
(13) |
Sep
(33) |
Oct
(54) |
Nov
(25) |
Dec
(16) |
| 2013 |
Jan
(45) |
Feb
(39) |
Mar
(38) |
Apr
(50) |
May
(29) |
Jun
(30) |
Jul
(33) |
Aug
(12) |
Sep
(9) |
Oct
(25) |
Nov
(29) |
Dec
(20) |
| 2014 |
Jan
(25) |
Feb
(19) |
Mar
(16) |
Apr
(33) |
May
(27) |
Jun
(37) |
Jul
(29) |
Aug
(27) |
Sep
(37) |
Oct
(58) |
Nov
(109) |
Dec
(26) |
| 2015 |
Jan
(4) |
Feb
(35) |
Mar
(22) |
Apr
(35) |
May
(28) |
Jun
(20) |
Jul
(4) |
Aug
(16) |
Sep
(37) |
Oct
(13) |
Nov
(13) |
Dec
(14) |
| 2016 |
Jan
(22) |
Feb
(7) |
Mar
(23) |
Apr
(30) |
May
(10) |
Jun
(10) |
Jul
(15) |
Aug
(12) |
Sep
(22) |
Oct
(31) |
Nov
(5) |
Dec
(5) |
| 2017 |
Jan
(30) |
Feb
(25) |
Mar
(28) |
Apr
(4) |
May
(19) |
Jun
(13) |
Jul
(7) |
Aug
(1) |
Sep
(2) |
Oct
(5) |
Nov
(12) |
Dec
(2) |
| 2018 |
Jan
(7) |
Feb
|
Mar
(7) |
Apr
(2) |
May
(8) |
Jun
(18) |
Jul
(6) |
Aug
(3) |
Sep
(15) |
Oct
(33) |
Nov
(13) |
Dec
(7) |
| 2019 |
Jan
(5) |
Feb
(7) |
Mar
(30) |
Apr
(5) |
May
(4) |
Jun
(69) |
Jul
(86) |
Aug
(22) |
Sep
(6) |
Oct
(7) |
Nov
(5) |
Dec
(3) |
| 2020 |
Jan
(10) |
Feb
(12) |
Mar
(22) |
Apr
(5) |
May
(1) |
Jun
(4) |
Jul
(6) |
Aug
|
Sep
(9) |
Oct
|
Nov
|
Dec
(1) |
| 2021 |
Jan
(4) |
Feb
(11) |
Mar
(7) |
Apr
(7) |
May
|
Jun
(3) |
Jul
(10) |
Aug
(6) |
Sep
|
Oct
|
Nov
(18) |
Dec
(2) |
| 2022 |
Jan
(1) |
Feb
(1) |
Mar
|
Apr
|
May
|
Jun
(2) |
Jul
|
Aug
(4) |
Sep
|
Oct
|
Nov
|
Dec
|
| 2023 |
Jan
|
Feb
|
Mar
|
Apr
(1) |
May
(1) |
Jun
|
Jul
|
Aug
(5) |
Sep
|
Oct
|
Nov
|
Dec
|
|
From: Arshad N. <ars...@st...> - 2012-05-25 16:47:41
|
I was a little hasty; I should have clarified that since the constraint allows for more than one permitted sub-tree, there will be other permitted sub-tree besides the one for which the certificate-issuance is allowed. Arshad Noor StrongAuth, Inc. On 05/25/2012 09:33 AM, Arshad Noor wrote: > > For example, a browser checks the subjectAltName extension for the > FQDN and matches it up with the FQDN of the web-site it is connected > to. If they do not match, you get the proverbial warnings. Since the > use of SAN is universal for server SSL certificates, what would it > matter if the nameConstraint had a completely different FQDN in the > permitted sub-tree (as long as the site and the SAN FQDN matched? > |
|
From: Arshad N. <ars...@st...> - 2012-05-25 16:35:53
|
Thank you, Anders; I will give this a shot. However, once I've added the custom extension to EJBCA, will EJBCA restrict the issuance of digital certificates based on the values in the constraint? That is, will it ensure that server SSL certificates are issued only to "strongauth.com" if the permitted sub-tree has such a restriction for DNS names? Arshad Noor StrongAuth, Inc. On 05/25/2012 12:46 AM, ejbca-support wrote: > Hi Arshad, > Name Constraints have indeed gotten more attention by the PKI > community lately. EJBCA can "as is" support NCs. However, there > is *currently* no GUI support; you have to provide the data as a > DER string. Fortunately this is not overly complex to create and > here is an example of such: > > Permitted > [1]Subtrees (0..Max): > RFC822 Na...@ex... > [2]Subtrees (0..Max): > Directory Address: > O=EXAMPLE > C=US > Excluded=None > > This is a Java program that creates the DER code which must be code into hex in > a custom extension using the NC OID: > > import org.bouncycastle.asn1.ASN1EncodableVector; > import org.bouncycastle.asn1.DERObjectIdentifier; > import org.bouncycastle.asn1.DERObject; > import org.bouncycastle.asn1.DERSequence; > import org.bouncycastle.asn1.DERTaggedObject; > import org.bouncycastle.asn1.DERUTF8String; > import org.bouncycastle.asn1.x509.GeneralName; > import org.bouncycastle.asn1.x509.X509Name; > > > import java.io.FileOutputStream; > > > public class KBBC > { > static ASN1EncodableVector v = new ASN1EncodableVector(); // this is the OtherName > static ASN1EncodableVector vec = new ASN1EncodableVector(); // this is the inner data > > static void addRFC822 (String rfc822name) throws Exception > { > vec.add (new DERSequence (new GeneralName(GeneralName.rfc822Name,rfc822name))); > } > > public static void main (String[] args) throws Exception > { > addRFC822 ("@example.com"); > vec.add (new DERSequence (new GeneralName(GeneralName.directoryName,new X509Name ("O=EXAMPLE,C=US")))); > v.add (new DERTaggedObject(false, 0, new DERSequence(vec))); > DERObject gn = new DERSequence (v); > FileOutputStream fos = new FileOutputStream (args[0]); > fos.write (gn.getDEREncoded ()); > fos.close (); > } > } > > > Regards, > Anders Rundgren > tech support > > > On 2012-05-24 22:14, Arshad Noor wrote: >> Hi, >> >> Not sure if I'm reading this correctly, but does EJBCA have support >> for issuing/understanding certificates with the nameConstraints (OID >> 2.5.29.30) extension in them, so it can only issue certificates that >> conform to the constraint? I don't see any reference to this >> constraint in its documentation. >> >> I did find an old e-mail that seems to indicate that PrimeKey does >> NOT recommend this extension: >> >> http://osdir.com/ml/java.ejbca.devel/2006-02/msg00092.html >> >> Unfortunately, because of all the problems recently with CAs being >> compromised, TTP CAs are now planning to enforce the use of this >> extension to limit their liability. However, the CA software must >> be able to support the use of the constraint and check all CSRs to >> see if the constraint is satisfied before issuing the certificate. >> I'm unable to find anything in EJBCA docs that indicate this is >> supported; can someone please provide some clarification? Thanks. >> >> Arshad Noor >> StrongAuth, Inc. >> >> >> ------------------------------------------------------------------------------ >> Live Security Virtual Conference >> Exclusive live event will cover all the ways today's security and >> threat landscape has changed and how IT managers can respond. Discussions >> will include endpoint security, mobile security and the latest in malware >> threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ >> _______________________________________________ >> Ejbca-develop mailing list >> Ejb...@li... >> https://lists.sourceforge.net/lists/listinfo/ejbca-develop > |
|
From: Arshad N. <ars...@st...> - 2012-05-25 16:33:59
|
Hi Tomas,
Thanks for your response; I will look into the Custom Extensions
section of the EJBCA documentation and see how easy/difficult it is
to include the constraint in CA certificates.
However, I believe you and I may have a misunderstanding about how
the nameConstraints extension is used - although this is not the first
time RFC 5280 has been misunderstood :-). Here is how I understand it:
Section 4.2.1.10 of RFC 5280 says:
The name constraints extension, which MUST be used only in a CA
certificate, indicates a name space within which all subject names
in subsequent certificates in a certification path MUST be located.
My understanding is that the constraint exists primarily for the use
of the CA software (like EJBCA) to constrain the certificates is issues
to only the permitted sub-trees.
I do not believe application software (such as browsers, e-mail, VPN
software, etc.) need care about the nameConstraints extension even
though they see it in the CA certificates of the chain. The reason is,
they have other ways of verifying the permitted subtree.
For example, a browser checks the subjectAltName extension for the
FQDN and matches it up with the FQDN of the web-site it is connected
to. If they do not match, you get the proverbial warnings. Since the
use of SAN is universal for server SSL certificates, what would it
matter if the nameConstraint had a completely different FQDN in the
permitted sub-tree (as long as the site and the SAN FQDN matched?
Similarly, Maul User Agents are able to verify the use of a digital
certificate for S/MIME against the e-mail header - which has the
sender and recipients' e-mail addresses. What would the RFC822 name
in the nameConstraint tell the MUA that it doesn't already know?
I believe the nameConstraints extension exists primarily for the use
of CA software vendors so that issuers of certificates can constrain
the issuance of digital certificates to permit or exclude sub-trees.
Am I misunderstanding this?
Arshad Noor
StrongAuth, Inc.
On 05/24/2012 11:58 PM, Tomas Gustavsson wrote:
>
> Hi Arshad,
>
> Currently you can use custom extensions to implement name constraints.
> We have done that for customers.
>
> The main responsibility is for the client, when verifying the
> certificate chain, to reject certificate violating the constraints.
> The client implementations for this is currently not perfect, with
> different flaws on various platforms, as our testing shows.
>
> I'd expect this to work better and be more widely deployed in the future
> though.
>
> Cheers,
> Tomas
>
> On 05/24/2012 10:14 PM, Arshad Noor wrote:
>> Hi,
>>
>> Not sure if I'm reading this correctly, but does EJBCA have support
>> for issuing/understanding certificates with the nameConstraints (OID
>> 2.5.29.30) extension in them, so it can only issue certificates that
>> conform to the constraint? I don't see any reference to this
>> constraint in its documentation.
>>
>> I did find an old e-mail that seems to indicate that PrimeKey does
>> NOT recommend this extension:
>>
>> http://osdir.com/ml/java.ejbca.devel/2006-02/msg00092.html
>>
>> Unfortunately, because of all the problems recently with CAs being
>> compromised, TTP CAs are now planning to enforce the use of this
>> extension to limit their liability. However, the CA software must
>> be able to support the use of the constraint and check all CSRs to
>> see if the constraint is satisfied before issuing the certificate.
>> I'm unable to find anything in EJBCA docs that indicate this is
>> supported; can someone please provide some clarification? Thanks.
>>
>> Arshad Noor
>> StrongAuth, Inc.
|
|
From: ejbca-support <ejb...@pr...> - 2012-05-25 07:46:25
|
Hi Arshad,
Name Constraints have indeed gotten more attention by the PKI
community lately. EJBCA can "as is" support NCs. However, there
is *currently* no GUI support; you have to provide the data as a
DER string. Fortunately this is not overly complex to create and
here is an example of such:
Permitted
[1]Subtrees (0..Max):
RFC822 Na...@ex...
[2]Subtrees (0..Max):
Directory Address:
O=EXAMPLE
C=US
Excluded=None
This is a Java program that creates the DER code which must be code into hex in
a custom extension using the NC OID:
import org.bouncycastle.asn1.ASN1EncodableVector;
import org.bouncycastle.asn1.DERObjectIdentifier;
import org.bouncycastle.asn1.DERObject;
import org.bouncycastle.asn1.DERSequence;
import org.bouncycastle.asn1.DERTaggedObject;
import org.bouncycastle.asn1.DERUTF8String;
import org.bouncycastle.asn1.x509.GeneralName;
import org.bouncycastle.asn1.x509.X509Name;
import java.io.FileOutputStream;
public class KBBC
{
static ASN1EncodableVector v = new ASN1EncodableVector(); // this is the OtherName
static ASN1EncodableVector vec = new ASN1EncodableVector(); // this is the inner data
static void addRFC822 (String rfc822name) throws Exception
{
vec.add (new DERSequence (new GeneralName(GeneralName.rfc822Name,rfc822name)));
}
public static void main (String[] args) throws Exception
{
addRFC822 ("@example.com");
vec.add (new DERSequence (new GeneralName(GeneralName.directoryName,new X509Name ("O=EXAMPLE,C=US"))));
v.add (new DERTaggedObject(false, 0, new DERSequence(vec)));
DERObject gn = new DERSequence (v);
FileOutputStream fos = new FileOutputStream (args[0]);
fos.write (gn.getDEREncoded ());
fos.close ();
}
}
Regards,
Anders Rundgren
tech support
On 2012-05-24 22:14, Arshad Noor wrote:
> Hi,
>
> Not sure if I'm reading this correctly, but does EJBCA have support
> for issuing/understanding certificates with the nameConstraints (OID
> 2.5.29.30) extension in them, so it can only issue certificates that
> conform to the constraint? I don't see any reference to this
> constraint in its documentation.
>
> I did find an old e-mail that seems to indicate that PrimeKey does
> NOT recommend this extension:
>
> http://osdir.com/ml/java.ejbca.devel/2006-02/msg00092.html
>
> Unfortunately, because of all the problems recently with CAs being
> compromised, TTP CAs are now planning to enforce the use of this
> extension to limit their liability. However, the CA software must
> be able to support the use of the constraint and check all CSRs to
> see if the constraint is satisfied before issuing the certificate.
> I'm unable to find anything in EJBCA docs that indicate this is
> supported; can someone please provide some clarification? Thanks.
>
> Arshad Noor
> StrongAuth, Inc.
>
>
> ------------------------------------------------------------------------------
> Live Security Virtual Conference
> Exclusive live event will cover all the ways today's security and
> threat landscape has changed and how IT managers can respond. Discussions
> will include endpoint security, mobile security and the latest in malware
> threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
> _______________________________________________
> Ejbca-develop mailing list
> Ejb...@li...
> https://lists.sourceforge.net/lists/listinfo/ejbca-develop
|
|
From: Tomas G. <to...@pr...> - 2012-05-25 06:58:37
|
Hi Arshad, Currently you can use custom extensions to implement name constraints. We have done that for customers. The main responsibility is for the client, when verifying the certificate chain, to reject certificate violating the constraints. The client implementations for this is currently not perfect, with different flaws on various platforms, as our testing shows. I'd expect this to work better and be more widely deployed in the future though. Cheers, Tomas On 05/24/2012 10:14 PM, Arshad Noor wrote: > Hi, > > Not sure if I'm reading this correctly, but does EJBCA have support > for issuing/understanding certificates with the nameConstraints (OID > 2.5.29.30) extension in them, so it can only issue certificates that > conform to the constraint? I don't see any reference to this > constraint in its documentation. > > I did find an old e-mail that seems to indicate that PrimeKey does > NOT recommend this extension: > > http://osdir.com/ml/java.ejbca.devel/2006-02/msg00092.html > > Unfortunately, because of all the problems recently with CAs being > compromised, TTP CAs are now planning to enforce the use of this > extension to limit their liability. However, the CA software must > be able to support the use of the constraint and check all CSRs to > see if the constraint is satisfied before issuing the certificate. > I'm unable to find anything in EJBCA docs that indicate this is > supported; can someone please provide some clarification? Thanks. > > Arshad Noor > StrongAuth, Inc. > > > ------------------------------------------------------------------------------ > Live Security Virtual Conference > Exclusive live event will cover all the ways today's security and > threat landscape has changed and how IT managers can respond. Discussions > will include endpoint security, mobile security and the latest in malware > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Arshad N. <ars...@st...> - 2012-05-24 20:33:43
|
Hi, Not sure if I'm reading this correctly, but does EJBCA have support for issuing/understanding certificates with the nameConstraints (OID 2.5.29.30) extension in them, so it can only issue certificates that conform to the constraint? I don't see any reference to this constraint in its documentation. I did find an old e-mail that seems to indicate that PrimeKey does NOT recommend this extension: http://osdir.com/ml/java.ejbca.devel/2006-02/msg00092.html Unfortunately, because of all the problems recently with CAs being compromised, TTP CAs are now planning to enforce the use of this extension to limit their liability. However, the CA software must be able to support the use of the constraint and check all CSRs to see if the constraint is satisfied before issuing the certificate. I'm unable to find anything in EJBCA docs that indicate this is supported; can someone please provide some clarification? Thanks. Arshad Noor StrongAuth, Inc. |
|
From: Tomas G. <to...@pr...> - 2012-05-14 08:48:04
|
Hi Community, The latest release of EJBCA 5, not being freely downloadable has of course sparked some questions what EJBCA 5 is and what happens with EJBCA 4. In short, simplified form, EJBCA 5 is a Common Criteria certified version of EJBCA. As common criteria, and other, certifications are very expensive it is not freely downloadable, but available together with a support subscription from PrimeKey. I have written two blog posts in this topic. 1. EJBCA will always be open source, blog.ejbca.org/2012/05/ejbca-will-always-be-open-source.html 2. Enterprise EJBCA features vs Community, http://blog.ejbca.org/2012/05/new-features-in-ejbca-5.html Regards, Tomas |
|
From: <lil...@bu...> - 2012-05-07 08:11:42
|
Because it is "apparently" created. It appears on the bottom of the page, with two links : View end entity, Edit end entity, but when I click on "View end entity", II get the message "The end entity doesn't exist". -----Tomas Gustavsson <to...@pr...> a écrit : ----- A : ejb...@li... De : Tomas Gustavsson <to...@pr...> Date : 07/05/2012 10:04 Objet : Re: [Ejbca-develop] EJBCA with HSM So how do you try to visualize it? On 05/07/2012 09:59 AM, lil...@bu... wrote: > The problem is the CA. If I select the default CA (AdminCA), the End > Entity is created, if I select my CA it is not. > BR, > Liliana > > > > -----Tomas Gustavsson <to...@pr...> a écrit : ----- > > A : ejb...@li... > De : Tomas Gustavsson <to...@pr...> > Date : 07/05/2012 09:46 > Objet : Re: [Ejbca-develop] EJBCA with HSM > > That is unheard of so far. Check JBoss server log. Remember that > username is case sensitive, and don't add strange whitespace in the end. > > /Tomas > > On 05/07/2012 09:40 AM, lil...@bu... wrote: > > That's what I've done. I try to create an End Entity, there is no > error > > message, but the End Entity is not created. > > > > BR, > > Liliana > > > > > > -----Tomas Gustavsson <to...@pr...> a écrit : ----- > > > > A : ejb...@li... > > De : Tomas Gustavsson <to...@pr...> > > Date : 07/05/2012 09:11 > > Objet : Re: [Ejbca-develop] EJBCA with HSM > > > > Hi, > > > > That can only mean that you have not created the end entity. If > you go > > to "Add end entity" and add a new end entity, what happens? > > > > Cheers, > > Tomas > > ----- > > PrimeKey Solutions offers commercial EJBCA and SignServer support > > subscriptions and training courses. Please see www.primekey.se or > > contact in...@pr... for more information. > > http://www.primekey.se/Services/Support/ > > http://www.primekey.se/Services/Training/ > > > > On 05/07/2012 08:43 AM, lil...@bu... wrote: > > > > > > Hello, > > > I'm trying to integrate EJBCA with Bull HSM. I've been able to > > create a > > > RSA key-pair in the HSM, using pkcs11HSM.sh and a CA using the > > generated > > > key-pair, but I'm not able to create an End Entity with this > new CA. > > > There is no error message, but when I try to visualize the End > > Entity, I > > > get the message "The End Entity doesn't exist". > > > Can you help me ? > > > Best regards, > > > Liliana Cabalantti > > > Bull SAS > > > > > > > > > > > > ------------------------------------------------------------------------------ > > > Live Security Virtual Conference > > > Exclusive live event will cover all the ways today's security and > > > threat landscape has changed and how IT managers can respond. > > Discussions > > > will include endpoint security, mobile security and the latest in > > malware > > > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > > > > > > > > > > > > _______________________________________________ > > > Ejbca-develop mailing list > > > Ejb...@li... > > > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > > > > ------------------------------------------------------------------------------ > > Live Security Virtual Conference > > Exclusive live event will cover all the ways today's security and > > threat landscape has changed and how IT managers can respond. > > Discussions > > will include endpoint security, mobile security and the latest in > > malware > > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > > _______________________________________________ > > Ejbca-develop mailing list > > Ejb...@li... > > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > > > > > > ------------------------------------------------------------------------------ > > Live Security Virtual Conference > > Exclusive live event will cover all the ways today's security and > > threat landscape has changed and how IT managers can respond. > Discussions > > will include endpoint security, mobile security and the latest in > malware > > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > > > > > > > > _______________________________________________ > > Ejbca-develop mailing list > > Ejb...@li... > > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > ------------------------------------------------------------------------------ > Live Security Virtual Conference > Exclusive live event will cover all the ways today's security and > threat landscape has changed and how IT managers can respond. > Discussions > will include endpoint security, mobile security and the latest in > malware > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > ------------------------------------------------------------------------------ > Live Security Virtual Conference > Exclusive live event will cover all the ways today's security and > threat landscape has changed and how IT managers can respond. Discussions > will include endpoint security, mobile security and the latest in malware > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop ------------------------------------------------------------------------------ Live Security Virtual Conference Exclusive live event will cover all the ways today's security and threat landscape has changed and how IT managers can respond. Discussions will include endpoint security, mobile security and the latest in malware threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: martijn.list <mar...@gm...> - 2012-05-07 08:10:26
|
On 05/07/2012 09:40 AM, lil...@bu... wrote: > That's what I've done. I try to create an End Entity, there is no error > message, but the End Entity is not created. What database are you using and which version? Are you using Postgres 9? Kind regards, Martijn Brinkers > > -----Tomas Gustavsson <to...@pr...> a écrit : ----- > > A : ejb...@li... > De : Tomas Gustavsson <to...@pr...> > Date : 07/05/2012 09:11 > Objet : Re: [Ejbca-develop] EJBCA with HSM > > Hi, > > That can only mean that you have not created the end entity. If you go > to "Add end entity" and add a new end entity, what happens? > > Cheers, > Tomas > ----- > PrimeKey Solutions offers commercial EJBCA and SignServer support > subscriptions and training courses. Please see www.primekey.se or > contact in...@pr... for more information. > http://www.primekey.se/Services/Support/ > http://www.primekey.se/Services/Training/ > > On 05/07/2012 08:43 AM, lil...@bu... wrote: > > > > Hello, > > I'm trying to integrate EJBCA with Bull HSM. I've been able to > create a > > RSA key-pair in the HSM, using pkcs11HSM.sh and a CA using the > generated > > key-pair, but I'm not able to create an End Entity with this new CA. > > There is no error message, but when I try to visualize the End > Entity, I > > get the message "The End Entity doesn't exist". > > Can you help me ? > > Best regards, > > Liliana Cabalantti > > Bull SAS > > > > > > > ------------------------------------------------------------------------------ > > Live Security Virtual Conference > > Exclusive live event will cover all the ways today's security and > > threat landscape has changed and how IT managers can respond. > Discussions > > will include endpoint security, mobile security and the latest in > malware > > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > > > > > > > > _______________________________________________ > > Ejbca-develop mailing list > > Ejb...@li... > > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > ------------------------------------------------------------------------------ > Live Security Virtual Conference > Exclusive live event will cover all the ways today's security and > threat landscape has changed and how IT managers can respond. > Discussions > will include endpoint security, mobile security and the latest in > malware > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > ------------------------------------------------------------------------------ > Live Security Virtual Conference > Exclusive live event will cover all the ways today's security and > threat landscape has changed and how IT managers can respond. Discussions > will include endpoint security, mobile security and the latest in malware > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop -- DJIGZO email encryption |
|
From: Tomas G. <to...@pr...> - 2012-05-07 08:04:03
|
So how do you try to visualize it? On 05/07/2012 09:59 AM, lil...@bu... wrote: > The problem is the CA. If I select the default CA (AdminCA), the End > Entity is created, if I select my CA it is not. > BR, > Liliana > > > > -----Tomas Gustavsson <to...@pr...> a écrit : ----- > > A : ejb...@li... > De : Tomas Gustavsson <to...@pr...> > Date : 07/05/2012 09:46 > Objet : Re: [Ejbca-develop] EJBCA with HSM > > That is unheard of so far. Check JBoss server log. Remember that > username is case sensitive, and don't add strange whitespace in the end. > > /Tomas > > On 05/07/2012 09:40 AM, lil...@bu... wrote: > > That's what I've done. I try to create an End Entity, there is no > error > > message, but the End Entity is not created. > > > > BR, > > Liliana > > > > > > -----Tomas Gustavsson <to...@pr...> a écrit : ----- > > > > A : ejb...@li... > > De : Tomas Gustavsson <to...@pr...> > > Date : 07/05/2012 09:11 > > Objet : Re: [Ejbca-develop] EJBCA with HSM > > > > Hi, > > > > That can only mean that you have not created the end entity. If > you go > > to "Add end entity" and add a new end entity, what happens? > > > > Cheers, > > Tomas > > ----- > > PrimeKey Solutions offers commercial EJBCA and SignServer support > > subscriptions and training courses. Please see www.primekey.se or > > contact in...@pr... for more information. > > http://www.primekey.se/Services/Support/ > > http://www.primekey.se/Services/Training/ > > > > On 05/07/2012 08:43 AM, lil...@bu... wrote: > > > > > > Hello, > > > I'm trying to integrate EJBCA with Bull HSM. I've been able to > > create a > > > RSA key-pair in the HSM, using pkcs11HSM.sh and a CA using the > > generated > > > key-pair, but I'm not able to create an End Entity with this > new CA. > > > There is no error message, but when I try to visualize the End > > Entity, I > > > get the message "The End Entity doesn't exist". > > > Can you help me ? > > > Best regards, > > > Liliana Cabalantti > > > Bull SAS > > > > > > > > > > > > ------------------------------------------------------------------------------ > > > Live Security Virtual Conference > > > Exclusive live event will cover all the ways today's security and > > > threat landscape has changed and how IT managers can respond. > > Discussions > > > will include endpoint security, mobile security and the latest in > > malware > > > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > > > > > > > > > > > > _______________________________________________ > > > Ejbca-develop mailing list > > > Ejb...@li... > > > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > > > > ------------------------------------------------------------------------------ > > Live Security Virtual Conference > > Exclusive live event will cover all the ways today's security and > > threat landscape has changed and how IT managers can respond. > > Discussions > > will include endpoint security, mobile security and the latest in > > malware > > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > > _______________________________________________ > > Ejbca-develop mailing list > > Ejb...@li... > > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > > > > > > ------------------------------------------------------------------------------ > > Live Security Virtual Conference > > Exclusive live event will cover all the ways today's security and > > threat landscape has changed and how IT managers can respond. > Discussions > > will include endpoint security, mobile security and the latest in > malware > > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > > > > > > > > _______________________________________________ > > Ejbca-develop mailing list > > Ejb...@li... > > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > ------------------------------------------------------------------------------ > Live Security Virtual Conference > Exclusive live event will cover all the ways today's security and > threat landscape has changed and how IT managers can respond. > Discussions > will include endpoint security, mobile security and the latest in > malware > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > ------------------------------------------------------------------------------ > Live Security Virtual Conference > Exclusive live event will cover all the ways today's security and > threat landscape has changed and how IT managers can respond. Discussions > will include endpoint security, mobile security and the latest in malware > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: <lil...@bu...> - 2012-05-07 07:59:49
|
The problem is the CA. If I select the default CA (AdminCA), the End Entity is created, if I select my CA it is not. BR, Liliana -----Tomas Gustavsson <to...@pr...> a écrit : ----- A : ejb...@li... De : Tomas Gustavsson <to...@pr...> Date : 07/05/2012 09:46 Objet : Re: [Ejbca-develop] EJBCA with HSM That is unheard of so far. Check JBoss server log. Remember that username is case sensitive, and don't add strange whitespace in the end. /Tomas On 05/07/2012 09:40 AM, lil...@bu... wrote: > That's what I've done. I try to create an End Entity, there is no error > message, but the End Entity is not created. > > BR, > Liliana > > > -----Tomas Gustavsson <to...@pr...> a écrit : ----- > > A : ejb...@li... > De : Tomas Gustavsson <to...@pr...> > Date : 07/05/2012 09:11 > Objet : Re: [Ejbca-develop] EJBCA with HSM > > Hi, > > That can only mean that you have not created the end entity. If you go > to "Add end entity" and add a new end entity, what happens? > > Cheers, > Tomas > ----- > PrimeKey Solutions offers commercial EJBCA and SignServer support > subscriptions and training courses. Please see www.primekey.se or > contact in...@pr... for more information. > http://www.primekey.se/Services/Support/ > http://www.primekey.se/Services/Training/ > > On 05/07/2012 08:43 AM, lil...@bu... wrote: > > > > Hello, > > I'm trying to integrate EJBCA with Bull HSM. I've been able to > create a > > RSA key-pair in the HSM, using pkcs11HSM.sh and a CA using the > generated > > key-pair, but I'm not able to create an End Entity with this new CA. > > There is no error message, but when I try to visualize the End > Entity, I > > get the message "The End Entity doesn't exist". > > Can you help me ? > > Best regards, > > Liliana Cabalantti > > Bull SAS > > > > > > > ------------------------------------------------------------------------------ > > Live Security Virtual Conference > > Exclusive live event will cover all the ways today's security and > > threat landscape has changed and how IT managers can respond. > Discussions > > will include endpoint security, mobile security and the latest in > malware > > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > > > > > > > > _______________________________________________ > > Ejbca-develop mailing list > > Ejb...@li... > > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > ------------------------------------------------------------------------------ > Live Security Virtual Conference > Exclusive live event will cover all the ways today's security and > threat landscape has changed and how IT managers can respond. > Discussions > will include endpoint security, mobile security and the latest in > malware > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > ------------------------------------------------------------------------------ > Live Security Virtual Conference > Exclusive live event will cover all the ways today's security and > threat landscape has changed and how IT managers can respond. Discussions > will include endpoint security, mobile security and the latest in malware > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop ------------------------------------------------------------------------------ Live Security Virtual Conference Exclusive live event will cover all the ways today's security and threat landscape has changed and how IT managers can respond. Discussions will include endpoint security, mobile security and the latest in malware threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Tomas G. <to...@pr...> - 2012-05-07 07:45:54
|
That is unheard of so far. Check JBoss server log. Remember that username is case sensitive, and don't add strange whitespace in the end. /Tomas On 05/07/2012 09:40 AM, lil...@bu... wrote: > That's what I've done. I try to create an End Entity, there is no error > message, but the End Entity is not created. > > BR, > Liliana > > > -----Tomas Gustavsson <to...@pr...> a écrit : ----- > > A : ejb...@li... > De : Tomas Gustavsson <to...@pr...> > Date : 07/05/2012 09:11 > Objet : Re: [Ejbca-develop] EJBCA with HSM > > Hi, > > That can only mean that you have not created the end entity. If you go > to "Add end entity" and add a new end entity, what happens? > > Cheers, > Tomas > ----- > PrimeKey Solutions offers commercial EJBCA and SignServer support > subscriptions and training courses. Please see www.primekey.se or > contact in...@pr... for more information. > http://www.primekey.se/Services/Support/ > http://www.primekey.se/Services/Training/ > > On 05/07/2012 08:43 AM, lil...@bu... wrote: > > > > Hello, > > I'm trying to integrate EJBCA with Bull HSM. I've been able to > create a > > RSA key-pair in the HSM, using pkcs11HSM.sh and a CA using the > generated > > key-pair, but I'm not able to create an End Entity with this new CA. > > There is no error message, but when I try to visualize the End > Entity, I > > get the message "The End Entity doesn't exist". > > Can you help me ? > > Best regards, > > Liliana Cabalantti > > Bull SAS > > > > > > > ------------------------------------------------------------------------------ > > Live Security Virtual Conference > > Exclusive live event will cover all the ways today's security and > > threat landscape has changed and how IT managers can respond. > Discussions > > will include endpoint security, mobile security and the latest in > malware > > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > > > > > > > > _______________________________________________ > > Ejbca-develop mailing list > > Ejb...@li... > > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > ------------------------------------------------------------------------------ > Live Security Virtual Conference > Exclusive live event will cover all the ways today's security and > threat landscape has changed and how IT managers can respond. > Discussions > will include endpoint security, mobile security and the latest in > malware > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > ------------------------------------------------------------------------------ > Live Security Virtual Conference > Exclusive live event will cover all the ways today's security and > threat landscape has changed and how IT managers can respond. Discussions > will include endpoint security, mobile security and the latest in malware > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: ejbca-support <ejb...@pr...> - 2012-05-07 07:45:42
|
On 2012-05-07 09:40, lil...@bu... wrote: > That's what I've done. I try to create an End Entity, there is no error message, but the End Entity is not created. Hi, You should take a look into server.log and see if it contains ERRORs etc. If you list CAs using the Admin GUI, does it show any CAs? Cheers, Anders tech support > > BR, > > Liliana > > > -----Tomas Gustavsson <to...@pr...> a écrit : ----- > > A : ejb...@li... > De : Tomas Gustavsson <to...@pr...> > Date : 07/05/2012 09:11 > Objet : Re: [Ejbca-develop] EJBCA with HSM > > Hi, > > That can only mean that you have not created the end entity. If you go > to "Add end entity" and add a new end entity, what happens? > > Cheers, > Tomas > ----- > PrimeKey Solutions offers commercial EJBCA and SignServer support > subscriptions and training courses. Please see www.primekey.se or > contact in...@pr... for more information. > http://www.primekey.se/Services/Support/ > http://www.primekey.se/Services/Training/ > > On 05/07/2012 08:43 AM, lil...@bu... wrote: > > > > Hello, > > I'm trying to integrate EJBCA with Bull HSM. I've been able to create a > > RSA key-pair in the HSM, using pkcs11HSM.sh and a CA using the generated > > key-pair, but I'm not able to create an End Entity with this new CA. > > There is no error message, but when I try to visualize the End Entity, I > > get the message "The End Entity doesn't exist". > > Can you help me ? > > Best regards, > > Liliana Cabalantti > > Bull SAS > > > > > > ------------------------------------------------------------------------------ > > Live Security Virtual Conference > > Exclusive live event will cover all the ways today's security and > > threat landscape has changed and how IT managers can respond. Discussions > > will include endpoint security, mobile security and the latest in malware > > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > > > > > > > > _______________________________________________ > > Ejbca-develop mailing list > > Ejb...@li... > > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > ------------------------------------------------------------------------------ > Live Security Virtual Conference > Exclusive live event will cover all the ways today's security and > threat landscape has changed and how IT managers can respond. Discussions > will include endpoint security, mobile security and the latest in malware > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > ------------------------------------------------------------------------------ > Live Security Virtual Conference > Exclusive live event will cover all the ways today's security and > threat landscape has changed and how IT managers can respond. Discussions > will include endpoint security, mobile security and the latest in malware > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: <lil...@bu...> - 2012-05-07 07:40:32
|
That's what I've done. I try to create an End Entity, there is no error message, but the End Entity is not created. BR, Liliana -----Tomas Gustavsson <to...@pr...> a écrit : ----- A : ejb...@li... De : Tomas Gustavsson <to...@pr...> Date : 07/05/2012 09:11 Objet : Re: [Ejbca-develop] EJBCA with HSM Hi, That can only mean that you have not created the end entity. If you go to "Add end entity" and add a new end entity, what happens? Cheers, Tomas ----- PrimeKey Solutions offers commercial EJBCA and SignServer support subscriptions and training courses. Please see www.primekey.se or contact in...@pr... for more information. http://www.primekey.se/Services/Support/ http://www.primekey.se/Services/Training/ On 05/07/2012 08:43 AM, lil...@bu... wrote: > > Hello, > I'm trying to integrate EJBCA with Bull HSM. I've been able to create a > RSA key-pair in the HSM, using pkcs11HSM.sh and a CA using the generated > key-pair, but I'm not able to create an End Entity with this new CA. > There is no error message, but when I try to visualize the End Entity, I > get the message "The End Entity doesn't exist". > Can you help me ? > Best regards, > Liliana Cabalantti > Bull SAS > > > ------------------------------------------------------------------------------ > Live Security Virtual Conference > Exclusive live event will cover all the ways today's security and > threat landscape has changed and how IT managers can respond. Discussions > will include endpoint security, mobile security and the latest in malware > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop ------------------------------------------------------------------------------ Live Security Virtual Conference Exclusive live event will cover all the ways today's security and threat landscape has changed and how IT managers can respond. Discussions will include endpoint security, mobile security and the latest in malware threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Tomas G. <to...@pr...> - 2012-05-07 07:11:02
|
Hi, That can only mean that you have not created the end entity. If you go to "Add end entity" and add a new end entity, what happens? Cheers, Tomas ----- PrimeKey Solutions offers commercial EJBCA and SignServer support subscriptions and training courses. Please see www.primekey.se or contact in...@pr... for more information. http://www.primekey.se/Services/Support/ http://www.primekey.se/Services/Training/ On 05/07/2012 08:43 AM, lil...@bu... wrote: > > Hello, > I'm trying to integrate EJBCA with Bull HSM. I've been able to create a > RSA key-pair in the HSM, using pkcs11HSM.sh and a CA using the generated > key-pair, but I'm not able to create an End Entity with this new CA. > There is no error message, but when I try to visualize the End Entity, I > get the message "The End Entity doesn't exist". > Can you help me ? > Best regards, > Liliana Cabalantti > Bull SAS > > > ------------------------------------------------------------------------------ > Live Security Virtual Conference > Exclusive live event will cover all the ways today's security and > threat landscape has changed and how IT managers can respond. Discussions > will include endpoint security, mobile security and the latest in malware > threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/ > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: <lil...@bu...> - 2012-05-07 06:43:10
|
Hello, I'm trying to integrate EJBCA with Bull HSM. I've been able to create a RSA key-pair in the HSM, using pkcs11HSM.sh and a CA using the generated key-pair, but I'm not able to create an End Entity with this new CA. There is no error message, but when I try to visualize the End Entity, I get the message "The End Entity doesn't exist". Can you help me ? Best regards, Liliana Cabalantti Bull SAS |
|
From: Tomas G. <to...@pr...> - 2012-05-03 14:23:51
|
Hi, We have released version 1.3.0 of the ePassport EAC library cert-cvc. This version is a minor release that only adds support for BouncyCastle v 1.47. Cert-cvc now work with BC 1.46 and BC 1.47. Visit the EJBCA download page for download details. http://ejbca.org/download.html Regards, PrimeKey EJBCA Team |
|
From: ejbca-support <ejb...@pr...> - 2012-04-17 09:19:02
|
On 2012-04-17 08:51, Toru Tanaka wrote: > Hi all > I maybe find little problem about public web windows. > > In publicweb window, If invalid userid is entered, EJBCA reply error message. > But, in case of adding space to the end of userid, > EJBCA authenticat user, although certificate doesn't publish. > So, I modify the source code to trim the end of space. > > If you can, please confirm the code that my modification affect other function or not. > > ataachment file include follows 3 files. > RequestInstance.java --modiyied file > RequestInstance.java.back -- original file > diff.txt --diff file > (path is "publicweb-gui/src/org/ejbca/ui/web/pub/RequestInstance.java") Hi Tanaka-San, Thanx for the update which should work. We will need to go through and find all places in EJBCA where this problem may occur. I see that you are active in this field: http://code.google.com/p/themistruct-wam Best regards, Anders tech support > > thanks in advance > Toru Tanaka > > > ------------------------------------------------------------------------------ > Better than sec? Nothing is better than sec when it comes to > monitoring Big Data applications. Try Boundary one-second > resolution app monitoring today. Free. > http://p.sf.net/sfu/Boundary-dev2dev > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Saeed <sae...@ya...> - 2012-04-16 08:51:46
|
----- Forwarded Message ----- From: Saeed <sae...@ya...> To: "ejb...@pr..." <ejb...@pr...>; ejbca primekey <ejb...@li...> Sent: Tuesday, April 10, 2012 9:49 AM Subject: [Ejbca-develop] OpenVPN suitable profile Hi I would like to ask what is the suitable settings for certificate profile that will be used with OpenVPN server and OpenVPN client. Thanks Saeed ------------------------------------------------------------------------------ Better than sec? Nothing is better than sec when it comes to monitoring Big Data applications. Try Boundary one-second resolution app monitoring today. Free. http://p.sf.net/sfu/Boundary-dev2dev _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Saeed <sae...@ya...> - 2012-04-16 06:22:18
|
I do not think the problem is the HSM. Because I was running cluster with two nodes using the same network HSM using master-slave mysql replication. This problem has happened only in the master but the slave is working fine. I can edit the CA normally and I can issue certificates from the slave for this CA and the token is active. There is a Key map database locally in each node that is used by ejbca to access the keys in the HSM. I replaced that one in the master by the one on the slave but I am still having this problem in the master. I think may be there is something crashed in ejbca or jboss in the master node. regards, Mohamed Saeed ________________________________ From: ejbca-support <ejb...@pr...> To: Saeed <sae...@ya...> Cc: ejbca primekey <ejb...@li...> Sent: Sunday, April 15, 2012 2:53 PM Subject: Re: Fw: [Ejbca-develop] Problem Activating CA On 2012-04-15 13:46, Saeed wrote: > > ----- Forwarded Message ----- > *From:* Saeed <sae...@ya...> > *To:* ejbca-support <ejb...@pr...>; "ejb...@li..." <ejb...@li...> > *Sent:* Thursday, April 12, 2012 2:57 PM > *Subject:* Re: [Ejbca-develop] Problem Activating CA > > > I replaced my database with a working database but the problem still there: > my CA token can not be activated and I can not edit the CA. If that's the case I guess there is something seriously wrong with the HSM. The key must have been deleted or so. The following is probably the best next step: ./ejbcaClientToolBox.sh PKCS11HSMKeyTool Anders tech support > > -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- > *From:* ejbca-support <ejb...@pr...> > *To:* Saeed <sae...@ya...>; ejb...@li... > *Sent:* Wednesday, April 11, 2012 11:17 AM > *Subject:* Re: [Ejbca-develop] Problem Activating CA > > On 2012-04-11 10:10, Saeed wrote: >> I tried with clientToolBox to create crl for this CA but it responds with an error message. >> >> I think when I imported the CA certificate it made a problem, that always the imported CA is considered external >> and it has no private keys exists in ejbca. and since the imported CA certificate was the same as the CA that >> exists in ejbca, ejbca considered my CA has no keys here, I guess. >> I do not wont to remove the CA how this could be handled. > > If you have a database backup your import should be nullified. > Otherwise an option is repairing the database manually. > This is done by comparing working CAs with the non-working. > CAData seems to be the table... > > You could also backup the current system, load in a working old copy and save > the configuration data. > > There may be a better way doing this but this is the one I know of :-| > > Anders > tech support > >> >> Saeed >> >> -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- >> *From:* ejbca-support <ejb...@pr... <mailto:ejb...@pr...>> >> *To:* Saeed <sae...@ya... <mailto:sae...@ya...>> >> *Cc:* ejbca primekey <ejb...@li... <mailto:ejb...@li...>> >> *Sent:* Tuesday, April 10, 2012 2:27 PM >> *Subject:* Re: Problem Activating CA >> >> On 2012-04-10 13:20, Saeed wrote: >> >> It sounds like you have destroyed the key or something like that. >> Could you try the clientToolBox and see if you get any contact? >> If it doesn't work in clientToolBox it won't work in EJBCA. >> >> The problem with edit CA is new for me. >> >> I would consider removing the CA if possible. >> >> Anders >> >>> >>> No I have not upgrade. >>> >>> What I did before this problem happens, I was testing how to import CA certificate >>> Then I imported this CA certificate which is already exists. It gave me a red error message >>> of something like "primary key already exist" after that I found the CA token is inactive. >>> When I activate it it says CA Activation Successful. >>> >>> When I restarted the JBOSS it says "activated CA token of type PKCS11" but when I log to the GUI >>> it is still inactive. >>> >>> I also wonder that I can not edit the CA properties and that error appear. >>> >>> Regards, >>> Saeed >>> >>> -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- >>> *From:* Tham Wickenberg <ejb...@pr... <mailto:ejb...@pr...> <mailto:ejb...@pr... <mailto:ejb...@pr...>>> >>> *To:* Saeed <sae...@ya... <mailto:sae...@ya...> <mailto:sae...@ya... <mailto:sae...@ya...>>> >>> *Cc:* ejbca primekey <ejb...@li... <mailto:ejb...@li...> <mailto:ejb...@li... <mailto:ejb...@li...>>> >>> *Sent:* Tuesday, April 10, 2012 12:53 PM >>> *Subject:* Re: Problem Activating CA >>> >>> Hello, >>> >>> There is a problem with your configuration. It must have stopped working when you changed the configuration. >>> >>> It is strange that you would get a CA Activation Successful message though. >>> >>> Regards, >>> Tham Wickenberg - PrimeKey Support Team >>> >>> On 4/10/12 11:48 AM, Saeed wrote: >>>> Pleeeease Help >>>> >>>> My CA was working properly with Hardtoken HSM. Then suddenly the CA Token Status became offline >>>> When I try to activate it, it says CA Activation Successful. But when I check the status again it is still inactive >>>> The problem is not with the hardtoken because I have other CA's that uses the same token and working correctly. >>>> When I try to Edit this CA the Edit page does not show up it gives the following error: >>>> >>>> >>>> An exception has occurred >>>> >>>> >>>> HardCAToken is not used, configuration error. >>>> >>>> >>>> java.lang.Exception: HardCAToken is not used, configuration error. >>>> at org.apache.jsp.ca.editcas.editcas_jsp._jspService(editcas_jsp.java:1924) >>>> at org.apache.jasper.runtime.HttpJspBase.service(HttpJspBase.java:70) >>>> at javax.servlet.http.HttpServlet.service(HttpServlet.java:803) >>>> at org.apache.jasper.servlet.JspServletWrapper.service(JspServletWrapper.java:373) >>>> at org.apache.jasper.servlet.JspServlet.serviceJspFile(JspServlet.java:336) >>>> at org.apache.jasper.servlet.JspServlet.service(JspServlet.java:265) >>>> at javax.servlet.http.HttpServlet.service(HttpServlet.java:803) >>>> at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:290) >>>> at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:206) >>>> at org.jboss.web.tomcat.filters.ReplyHeaderFilter.doFilter(ReplyHeaderFilter.java:96) >>>> at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:235) >>>> at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:206) >>>> at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:230) >>>> at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:175) >>>> at org.jboss.web.tomcat.security.SecurityAssociationValve.invoke(SecurityAssociationValve.java:182) >>>> at org.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:524) >>>> at org.jboss.web.tomcat.security.JaccContextValve.invoke(JaccContextValve.java:84) >>>> at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:127) >>>> at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:102) >>>> at org.jboss.web.tomcat.service.jca.CachedConnectionValve.invoke(CachedConnectionValve.java:157) >>>> at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:109) >>>> at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:262) >>>> at org.apache.coyote.http11.Http11Processor.process(Http11Processor.java:844) >>>> at org.apache.coyote.http11.Http11Protocol$Http11ConnectionHandler.process(Http11Protocol.java:583) >>>> at org.apache.tomcat.util.net.JIoEndpoint$Worker.run(JIoEndpoint.java:446) >>>> at java.lang.Thread.run(Thread.java:636) >>>> >>>> >>>> >>> >>> >>> >> >> >> >> >> >> ------------------------------------------------------------------------------ >> Better than sec? Nothing is better than sec when it comes to >> monitoring Big Data applications. Try Boundary one-second >> resolution app monitoring today. Free. >> http://p.sf.net/sfu/Boundary-dev2dev >> >> >> >> _______________________________________________ >> Ejbca-develop mailing list >> Ejb...@li... <mailto:Ejb...@li...> >> https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > > ------------------------------------------------------------------------------ > For Developers, A Lot Can Happen In A Second. > Boundary is the first to Know...and Tell You. > Monitor Your Applications in Ultra-Fine Resolution. Try it FREE! > http://p.sf.net/sfu/Boundary-d2dvs2 > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... <mailto:Ejb...@li...> > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > |
|
From: ejbca-support <ejb...@pr...> - 2012-04-15 12:29:05
|
On 2012-04-15 13:46, Saeed wrote: > > ----- Forwarded Message ----- > *From:* Saeed <sae...@ya...> > *To:* ejbca-support <ejb...@pr...>; "ejb...@li..." <ejb...@li...> > *Sent:* Thursday, April 12, 2012 2:57 PM > *Subject:* Re: [Ejbca-develop] Problem Activating CA > > > I replaced my database with a working database but the problem still there: > my CA token can not be activated and I can not edit the CA. If that's the case I guess there is something seriously wrong with the HSM. The key must have been deleted or so. The following is probably the best next step: ./ejbcaClientToolBox.sh PKCS11HSMKeyTool Anders tech support > > -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- > *From:* ejbca-support <ejb...@pr...> > *To:* Saeed <sae...@ya...>; ejb...@li... > *Sent:* Wednesday, April 11, 2012 11:17 AM > *Subject:* Re: [Ejbca-develop] Problem Activating CA > > On 2012-04-11 10:10, Saeed wrote: >> I tried with clientToolBox to create crl for this CA but it responds with an error message. >> >> I think when I imported the CA certificate it made a problem, that always the imported CA is considered external >> and it has no private keys exists in ejbca. and since the imported CA certificate was the same as the CA that >> exists in ejbca, ejbca considered my CA has no keys here, I guess. >> I do not wont to remove the CA how this could be handled. > > If you have a database backup your import should be nullified. > Otherwise an option is repairing the database manually. > This is done by comparing working CAs with the non-working. > CAData seems to be the table... > > You could also backup the current system, load in a working old copy and save > the configuration data. > > There may be a better way doing this but this is the one I know of :-| > > Anders > tech support > >> >> Saeed >> >> -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- >> *From:* ejbca-support <ejb...@pr... <mailto:ejb...@pr...>> >> *To:* Saeed <sae...@ya... <mailto:sae...@ya...>> >> *Cc:* ejbca primekey <ejb...@li... <mailto:ejb...@li...>> >> *Sent:* Tuesday, April 10, 2012 2:27 PM >> *Subject:* Re: Problem Activating CA >> >> On 2012-04-10 13:20, Saeed wrote: >> >> It sounds like you have destroyed the key or something like that. >> Could you try the clientToolBox and see if you get any contact? >> If it doesn't work in clientToolBox it won't work in EJBCA. >> >> The problem with edit CA is new for me. >> >> I would consider removing the CA if possible. >> >> Anders >> >>> >>> No I have not upgrade. >>> >>> What I did before this problem happens, I was testing how to import CA certificate >>> Then I imported this CA certificate which is already exists. It gave me a red error message >>> of something like "primary key already exist" after that I found the CA token is inactive. >>> When I activate it it says CA Activation Successful. >>> >>> When I restarted the JBOSS it says "activated CA token of type PKCS11" but when I log to the GUI >>> it is still inactive. >>> >>> I also wonder that I can not edit the CA properties and that error appear. >>> >>> Regards, >>> Saeed >>> >>> -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- >>> *From:* Tham Wickenberg <ejb...@pr... <mailto:ejb...@pr...> <mailto:ejb...@pr... <mailto:ejb...@pr...>>> >>> *To:* Saeed <sae...@ya... <mailto:sae...@ya...> <mailto:sae...@ya... <mailto:sae...@ya...>>> >>> *Cc:* ejbca primekey <ejb...@li... <mailto:ejb...@li...> <mailto:ejb...@li... <mailto:ejb...@li...>>> >>> *Sent:* Tuesday, April 10, 2012 12:53 PM >>> *Subject:* Re: Problem Activating CA >>> >>> Hello, >>> >>> There is a problem with your configuration. It must have stopped working when you changed the configuration. >>> >>> It is strange that you would get a CA Activation Successful message though. >>> >>> Regards, >>> Tham Wickenberg - PrimeKey Support Team >>> >>> On 4/10/12 11:48 AM, Saeed wrote: >>>> Pleeeease Help >>>> >>>> My CA was working properly with Hardtoken HSM. Then suddenly the CA Token Status became offline >>>> When I try to activate it, it says CA Activation Successful. But when I check the status again it is still inactive >>>> The problem is not with the hardtoken because I have other CA's that uses the same token and working correctly. >>>> When I try to Edit this CA the Edit page does not show up it gives the following error: >>>> >>>> >>>> An exception has occurred >>>> >>>> >>>> HardCAToken is not used, configuration error. >>>> >>>> >>>> java.lang.Exception: HardCAToken is not used, configuration error. >>>> at org.apache.jsp.ca.editcas.editcas_jsp._jspService(editcas_jsp.java:1924) >>>> at org.apache.jasper.runtime.HttpJspBase.service(HttpJspBase.java:70) >>>> at javax.servlet.http.HttpServlet.service(HttpServlet.java:803) >>>> at org.apache.jasper.servlet.JspServletWrapper.service(JspServletWrapper.java:373) >>>> at org.apache.jasper.servlet.JspServlet.serviceJspFile(JspServlet.java:336) >>>> at org.apache.jasper.servlet.JspServlet.service(JspServlet.java:265) >>>> at javax.servlet.http.HttpServlet.service(HttpServlet.java:803) >>>> at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:290) >>>> at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:206) >>>> at org.jboss.web.tomcat.filters.ReplyHeaderFilter.doFilter(ReplyHeaderFilter.java:96) >>>> at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:235) >>>> at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:206) >>>> at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:230) >>>> at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:175) >>>> at org.jboss.web.tomcat.security.SecurityAssociationValve.invoke(SecurityAssociationValve.java:182) >>>> at org.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:524) >>>> at org.jboss.web.tomcat.security.JaccContextValve.invoke(JaccContextValve.java:84) >>>> at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:127) >>>> at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:102) >>>> at org.jboss.web.tomcat.service.jca.CachedConnectionValve.invoke(CachedConnectionValve.java:157) >>>> at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:109) >>>> at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:262) >>>> at org.apache.coyote.http11.Http11Processor.process(Http11Processor.java:844) >>>> at org.apache.coyote.http11.Http11Protocol$Http11ConnectionHandler.process(Http11Protocol.java:583) >>>> at org.apache.tomcat.util.net.JIoEndpoint$Worker.run(JIoEndpoint.java:446) >>>> at java.lang.Thread.run(Thread.java:636) >>>> >>>> >>>> >>> >>> >>> >> >> >> >> >> >> ------------------------------------------------------------------------------ >> Better than sec? Nothing is better than sec when it comes to >> monitoring Big Data applications. Try Boundary one-second >> resolution app monitoring today. Free. >> http://p.sf.net/sfu/Boundary-dev2dev >> >> >> >> _______________________________________________ >> Ejbca-develop mailing list >> Ejb...@li... <mailto:Ejb...@li...> >> https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > > > > ------------------------------------------------------------------------------ > For Developers, A Lot Can Happen In A Second. > Boundary is the first to Know...and Tell You. > Monitor Your Applications in Ultra-Fine Resolution. Try it FREE! > http://p.sf.net/sfu/Boundary-d2dvs2 > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... <mailto:Ejb...@li...> > https://lists.sourceforge.net/lists/listinfo/ejbca-develop > > |
|
From: ejbca-support <ejb...@pr...> - 2012-04-15 12:01:28
|
On 2012-04-15 13:52, Saeed wrote: > Hi all > > I would like to know how to empty publishing queue ? If you have a non-working publisher, I guess the following table http://www.ejbca.org/library/tables/PublisherQueueData.html holds the queue. Note: working at the DB-level in EJBCA using SQL is a bit like manipulating the Registry in Windows... You do it on your own risk. Anders tech support > > Thanks > Saeed > > > ------------------------------------------------------------------------------ > For Developers, A Lot Can Happen In A Second. > Boundary is the first to Know...and Tell You. > Monitor Your Applications in Ultra-Fine Resolution. Try it FREE! > http://p.sf.net/sfu/Boundary-d2dvs2 > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Saeed <sae...@ya...> - 2012-04-15 11:54:42
|
----- Forwarded Message ----- From: Saeed <sae...@ya...> To: ejbca-support <ejb...@pr...>; "ejb...@li..." <ejb...@li...> Sent: Thursday, April 12, 2012 2:57 PM Subject: Re: [Ejbca-develop] Problem Activating CA I replaced my database with a working database but the problem still there: my CA token can not be activated and I can not edit the CA. ________________________________ From: ejbca-support <ejb...@pr...> To: Saeed <sae...@ya...>; ejb...@li... Sent: Wednesday, April 11, 2012 11:17 AM Subject: Re: [Ejbca-develop] Problem Activating CA On 2012-04-11 10:10, Saeed wrote: > I tried with clientToolBox to create crl for this CA but it responds with an error message. > > I think when I imported the CA certificate it made a problem, that always the imported CA is considered external > and it has no private keys exists in ejbca. and since the imported CA certificate was the same as the CA that > exists in ejbca, ejbca considered my CA has no keys here, I guess. > I do not wont to remove the CA how this could be handled. If you have a database backup your import should be nullified. Otherwise an option is repairing the database manually. This is done by comparing working CAs with the non-working. CAData seems to be the table... You could also backup the current system, load in a working old copy and save the configuration data. There may be a better way doing this but this is the one I know of :-| Anders tech support > > Saeed > > -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- > *From:* ejbca-support <ejb...@pr...> > *To:* Saeed <sae...@ya...> > *Cc:* ejbca primekey <ejb...@li...> > *Sent:* Tuesday, April 10, 2012 2:27 PM > *Subject:* Re: Problem Activating CA > > On 2012-04-10 13:20, Saeed wrote: > > It sounds like you have destroyed the key or something like that. > Could you try the clientToolBox and see if you get any contact? > If it doesn't work in clientToolBox it won't work in EJBCA. > > The problem with edit CA is new for me. > > I would consider removing the CA if possible. > > Anders > >> >> No I have not upgrade. >> >> What I did before this problem happens, I was testing how to import CA certificate >> Then I imported this CA certificate which is already exists. It gave me a red error message >> of something like "primary key already exist" after that I found the CA token is inactive. >> When I activate it it says CA Activation Successful. >> >> When I restarted the JBOSS it says "activated CA token of type PKCS11" but when I log to the GUI >> it is still inactive. >> >> I also wonder that I can not edit the CA properties and that error appear. >> >> Regards, >> Saeed >> >> -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- >> *From:* Tham Wickenberg <ejb...@pr... <mailto:ejb...@pr...>> >> *To:* Saeed <sae...@ya... <mailto:sae...@ya...>> >> *Cc:* ejbca primekey <ejb...@li... <mailto:ejb...@li...>> >> *Sent:* Tuesday, April 10, 2012 12:53 PM >> *Subject:* Re: Problem Activating CA >> >> Hello, >> >> There is a problem with your configuration. It must have stopped working when you changed the configuration. >> >> It is strange that you would get a CA Activation Successful message though. >> >> Regards, >> Tham Wickenberg - PrimeKey Support Team >> >> On 4/10/12 11:48 AM, Saeed wrote: >>> Pleeeease Help >>> >>> My CA was working properly with Hardtoken HSM. Then suddenly the CA Token Status became offline >>> When I try to activate it, it says CA Activation Successful. But when I check the status again it is still inactive >>> The problem is not with the hardtoken because I have other CA's that uses the same token and working correctly. >>> When I try to Edit this CA the Edit page does not show up it gives the following error: >>> >>> >>> An exception has occurred >>> >>> >>> HardCAToken is not used, configuration error. >>> >>> >>> java.lang.Exception: HardCAToken is not used, configuration error. >>> at org.apache.jsp.ca.editcas.editcas_jsp._jspService(editcas_jsp.java:1924) >>> at org.apache.jasper.runtime.HttpJspBase.service(HttpJspBase.java:70) >>> at javax.servlet.http.HttpServlet.service(HttpServlet.java:803) >>> at org.apache.jasper.servlet.JspServletWrapper.service(JspServletWrapper.java:373) >>> at org.apache.jasper.servlet.JspServlet.serviceJspFile(JspServlet.java:336) >>> at org.apache.jasper.servlet.JspServlet.service(JspServlet.java:265) >>> at javax.servlet.http.HttpServlet.service(HttpServlet.java:803) >>> at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:290) >>> at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:206) >>> at org.jboss.web.tomcat.filters.ReplyHeaderFilter.doFilter(ReplyHeaderFilter.java:96) >>> at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:235) >>> at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:206) >>> at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:230) >>> at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:175) >>> at org.jboss.web.tomcat.security.SecurityAssociationValve.invoke(SecurityAssociationValve.java:182) >>> at org.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:524) >>> at org.jboss.web.tomcat.security.JaccContextValve.invoke(JaccContextValve.java:84) >>> at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:127) >>> at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:102) >>> at org.jboss.web.tomcat.service.jca.CachedConnectionValve.invoke(CachedConnectionValve.java:157) >>> at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:109) >>> at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:262) >>> at org.apache.coyote.http11.Http11Processor.process(Http11Processor.java:844) >>> at org.apache.coyote.http11.Http11Protocol$Http11ConnectionHandler.process(Http11Protocol.java:583) >>> at org.apache.tomcat.util.net.JIoEndpoint$Worker.run(JIoEndpoint.java:446) >>> at java.lang.Thread.run(Thread.java:636) >>> >>> >>> >> >> >> > > > > > > ------------------------------------------------------------------------------ > Better than sec? Nothing is better than sec when it comes to > monitoring Big Data applications. Try Boundary one-second > resolution app monitoring today. Free. > http://p.sf.net/sfu/Boundary-dev2dev > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop ------------------------------------------------------------------------------ For Developers, A Lot Can Happen In A Second. Boundary is the first to Know...and Tell You. Monitor Your Applications in Ultra-Fine Resolution. Try it FREE! http://p.sf.net/sfu/Boundary-d2dvs2 _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Saeed <sae...@ya...> - 2012-04-15 11:53:55
|
----- Forwarded Message ----- From: Saeed <sae...@ya...> To: ejbca-support <ejb...@pr...>; "ejb...@li..." <ejb...@li...> Sent: Thursday, April 12, 2012 2:57 PM Subject: Re: [Ejbca-develop] Problem Activating CA I replaced my database with a working database but the problem still there: my CA token can not be activated and I can not edit the CA. ________________________________ From: ejbca-support <ejb...@pr...> To: Saeed <sae...@ya...>; ejb...@li... Sent: Wednesday, April 11, 2012 11:17 AM Subject: Re: [Ejbca-develop] Problem Activating CA On 2012-04-11 10:10, Saeed wrote: > I tried with clientToolBox to create crl for this CA but it responds with an error message. > > I think when I imported the CA certificate it made a problem, that always the imported CA is considered external > and it has no private keys exists in ejbca. and since the imported CA certificate was the same as the CA that > exists in ejbca, ejbca considered my CA has no keys here, I guess. > I do not wont to remove the CA how this could be handled. If you have a database backup your import should be nullified. Otherwise an option is repairing the database manually. This is done by comparing working CAs with the non-working. CAData seems to be the table... You could also backup the current system, load in a working old copy and save the configuration data. There may be a better way doing this but this is the one I know of :-| Anders tech support > > Saeed > > -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- > *From:* ejbca-support <ejb...@pr...> > *To:* Saeed <sae...@ya...> > *Cc:* ejbca primekey <ejb...@li...> > *Sent:* Tuesday, April 10, 2012 2:27 PM > *Subject:* Re: Problem Activating CA > > On 2012-04-10 13:20, Saeed wrote: > > It sounds like you have destroyed the key or something like that. > Could you try the clientToolBox and see if you get any contact? > If it doesn't work in clientToolBox it won't work in EJBCA. > > The problem with edit CA is new for me. > > I would consider removing the CA if possible. > > Anders > >> >> No I have not upgrade. >> >> What I did before this problem happens, I was testing how to import CA certificate >> Then I imported this CA certificate which is already exists. It gave me a red error message >> of something like "primary key already exist" after that I found the CA token is inactive. >> When I activate it it says CA Activation Successful. >> >> When I restarted the JBOSS it says "activated CA token of type PKCS11" but when I log to the GUI >> it is still inactive. >> >> I also wonder that I can not edit the CA properties and that error appear. >> >> Regards, >> Saeed >> >> -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- >> *From:* Tham Wickenberg <ejb...@pr... <mailto:ejb...@pr...>> >> *To:* Saeed <sae...@ya... <mailto:sae...@ya...>> >> *Cc:* ejbca primekey <ejb...@li... <mailto:ejb...@li...>> >> *Sent:* Tuesday, April 10, 2012 12:53 PM >> *Subject:* Re: Problem Activating CA >> >> Hello, >> >> There is a problem with your configuration. It must have stopped working when you changed the configuration. >> >> It is strange that you would get a CA Activation Successful message though. >> >> Regards, >> Tham Wickenberg - PrimeKey Support Team >> >> On 4/10/12 11:48 AM, Saeed wrote: >>> Pleeeease Help >>> >>> My CA was working properly with Hardtoken HSM. Then suddenly the CA Token Status became offline >>> When I try to activate it, it says CA Activation Successful. But when I check the status again it is still inactive >>> The problem is not with the hardtoken because I have other CA's that uses the same token and working correctly. >>> When I try to Edit this CA the Edit page does not show up it gives the following error: >>> >>> >>> An exception has occurred >>> >>> >>> HardCAToken is not used, configuration error. >>> >>> >>> java.lang.Exception: HardCAToken is not used, configuration error. >>> at org.apache.jsp.ca.editcas.editcas_jsp._jspService(editcas_jsp.java:1924) >>> at org.apache.jasper.runtime.HttpJspBase.service(HttpJspBase.java:70) >>> at javax.servlet.http.HttpServlet.service(HttpServlet.java:803) >>> at org.apache.jasper.servlet.JspServletWrapper.service(JspServletWrapper.java:373) >>> at org.apache.jasper.servlet.JspServlet.serviceJspFile(JspServlet.java:336) >>> at org.apache.jasper.servlet.JspServlet.service(JspServlet.java:265) >>> at javax.servlet.http.HttpServlet.service(HttpServlet.java:803) >>> at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:290) >>> at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:206) >>> at org.jboss.web.tomcat.filters.ReplyHeaderFilter.doFilter(ReplyHeaderFilter.java:96) >>> at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:235) >>> at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:206) >>> at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:230) >>> at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:175) >>> at org.jboss.web.tomcat.security.SecurityAssociationValve.invoke(SecurityAssociationValve.java:182) >>> at org.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:524) >>> at org.jboss.web.tomcat.security.JaccContextValve.invoke(JaccContextValve.java:84) >>> at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:127) >>> at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:102) >>> at org.jboss.web.tomcat.service.jca.CachedConnectionValve.invoke(CachedConnectionValve.java:157) >>> at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:109) >>> at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:262) >>> at org.apache.coyote.http11.Http11Processor.process(Http11Processor.java:844) >>> at org.apache.coyote.http11.Http11Protocol$Http11ConnectionHandler.process(Http11Protocol.java:583) >>> at org.apache.tomcat.util.net.JIoEndpoint$Worker.run(JIoEndpoint.java:446) >>> at java.lang.Thread.run(Thread.java:636) >>> >>> >>> >> >> >> > > > > > > ------------------------------------------------------------------------------ > Better than sec? Nothing is better than sec when it comes to > monitoring Big Data applications. Try Boundary one-second > resolution app monitoring today. Free. > http://p.sf.net/sfu/Boundary-dev2dev > > > > _______________________________________________ > Ejbca-develop mailing list > Ejb...@li... > https://lists.sourceforge.net/lists/listinfo/ejbca-develop ------------------------------------------------------------------------------ For Developers, A Lot Can Happen In A Second. Boundary is the first to Know...and Tell You. Monitor Your Applications in Ultra-Fine Resolution. Try it FREE! http://p.sf.net/sfu/Boundary-d2dvs2 _______________________________________________ Ejbca-develop mailing list Ejb...@li... https://lists.sourceforge.net/lists/listinfo/ejbca-develop |
|
From: Saeed <sae...@ya...> - 2012-04-15 11:52:40
|
Hi all I would like to know how to empty publishing queue ? Thanks Saeed |