You can subscribe to this list here.
| 2001 |
Jan
|
Feb
|
Mar
(13) |
Apr
(15) |
May
(60) |
Jun
(52) |
Jul
(103) |
Aug
(99) |
Sep
(28) |
Oct
(74) |
Nov
(106) |
Dec
(78) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2002 |
Jan
(100) |
Feb
(92) |
Mar
(188) |
Apr
(318) |
May
(143) |
Jun
(90) |
Jul
(115) |
Aug
(211) |
Sep
(288) |
Oct
(264) |
Nov
(255) |
Dec
(134) |
| 2003 |
Jan
(139) |
Feb
(98) |
Mar
(104) |
Apr
(97) |
May
(177) |
Jun
(169) |
Jul
(197) |
Aug
(72) |
Sep
(76) |
Oct
(122) |
Nov
(150) |
Dec
(218) |
| 2004 |
Jan
(214) |
Feb
(155) |
Mar
(320) |
Apr
(167) |
May
(272) |
Jun
(270) |
Jul
(214) |
Aug
(187) |
Sep
(164) |
Oct
(212) |
Nov
(133) |
Dec
(117) |
| 2005 |
Jan
(119) |
Feb
(203) |
Mar
(115) |
Apr
(154) |
May
(164) |
Jun
(146) |
Jul
(215) |
Aug
(173) |
Sep
(221) |
Oct
(173) |
Nov
(121) |
Dec
(111) |
| 2006 |
Jan
(219) |
Feb
(107) |
Mar
(56) |
Apr
(55) |
May
(68) |
Jun
(67) |
Jul
(162) |
Aug
(84) |
Sep
(108) |
Oct
(74) |
Nov
(40) |
Dec
(31) |
| 2007 |
Jan
(43) |
Feb
(54) |
Mar
(30) |
Apr
(42) |
May
(27) |
Jun
(18) |
Jul
(17) |
Aug
(13) |
Sep
(32) |
Oct
(16) |
Nov
(21) |
Dec
(23) |
| 2008 |
Jan
(5) |
Feb
(7) |
Mar
(18) |
Apr
(16) |
May
(13) |
Jun
(9) |
Jul
(12) |
Aug
(39) |
Sep
(15) |
Oct
(131) |
Nov
(80) |
Dec
(75) |
| 2009 |
Jan
(87) |
Feb
(20) |
Mar
(16) |
Apr
(20) |
May
(23) |
Jun
(45) |
Jul
(22) |
Aug
(9) |
Sep
(7) |
Oct
(19) |
Nov
(44) |
Dec
(8) |
| 2010 |
Jan
(21) |
Feb
(52) |
Mar
(104) |
Apr
(38) |
May
(23) |
Jun
(21) |
Jul
(24) |
Aug
(28) |
Sep
(24) |
Oct
(17) |
Nov
(17) |
Dec
(13) |
| 2011 |
Jan
(6) |
Feb
(23) |
Mar
(21) |
Apr
(9) |
May
(10) |
Jun
(12) |
Jul
(16) |
Aug
(21) |
Sep
(3) |
Oct
(2) |
Nov
(8) |
Dec
(21) |
| 2012 |
Jan
(4) |
Feb
(11) |
Mar
(1) |
Apr
(10) |
May
(25) |
Jun
(27) |
Jul
(9) |
Aug
(6) |
Sep
(15) |
Oct
(3) |
Nov
(10) |
Dec
(10) |
| 2013 |
Jan
|
Feb
(1) |
Mar
(6) |
Apr
(2) |
May
(7) |
Jun
(14) |
Jul
(1249) |
Aug
(7) |
Sep
(35) |
Oct
(26) |
Nov
(22) |
Dec
(5) |
| 2014 |
Jan
|
Feb
(1) |
Mar
(2) |
Apr
|
May
(2) |
Jun
(4) |
Jul
(27) |
Aug
(12) |
Sep
(6) |
Oct
(1) |
Nov
(4) |
Dec
(6) |
| 2015 |
Jan
(5) |
Feb
(1) |
Mar
(4) |
Apr
|
May
|
Jun
|
Jul
(1) |
Aug
(1) |
Sep
(7) |
Oct
(11) |
Nov
|
Dec
|
| 2016 |
Jan
(1) |
Feb
|
Mar
(1) |
Apr
|
May
(2) |
Jun
(1) |
Jul
(1) |
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
| 2018 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
(1) |
Oct
(2) |
Nov
|
Dec
|
| 2019 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
(1) |
Sep
|
Oct
|
Nov
|
Dec
|
|
From: snoop <jm...@gm...> - 2019-08-30 13:32:10
|
Hi all, I Have setup openca pki and successfully initialized the DB but am having issues configuring sign module in CA am getting this error as a result the RA can't approve a CSR request with a sign,can approve only without signing the request General Error Error Code: 740202 [initServer:314] [ Security Protection ] Because your session changed, there might be security problems with the connection with your computer. Please start a new session to continue. Even if i restart the session the error keeps on recurring. Thanks in advance for your help. |
|
From: GABRIEL T. <gtz...@pa...> - 2018-10-23 09:53:04
|
Hello, I am trying to use openCA but the insertion in the DB always fail (tested with both mysql and postgreSQL): Mysql: Tables created at the first step but insert empty or null data from the 4th step PostgreSQL: Tables created but fails during the insertion with the following error message: invalid input syntax for integer "" at /opt/openca/lib/openca/perl_modules/perl5/OpenCA/DBI.pm line 3345 The creation of certificates itself work and can be found in my local directories. With MySQL, I can also create a request via the the CA administrator interface, but once again, the inserted request is empty. Does anybody have any idea on how to solve this issue? Thank you in advance, -- Gabriel |
|
From: Sergei V. <s.v...@gm...> - 2018-10-18 13:18:23
|
Hi, Is openxpki/openca-tools-forked product a needed per-requisite for openxpki-2.2.2 ? Regards, Sergei |
|
From: H S. <tap...@gm...> - 2018-09-09 11:07:14
|
Hi I have generated some certs and using them but the list shows nothing. I can see the previous expired issued certs. Any idea? |
|
From: Steffen W. <st...@gm...> - 2016-07-05 08:51:54
|
Hi, currently I'm trying to find some information how to configure libpki and OpenCA's ocspd. I thought it is a good idea to read some manuals and documentation. So i tried http://openca.dyndns.org:4443/wiki/ but I only got a php-scipt --------------------------- <?php /** * This is the main web entry point for MediaWiki. * * If you are reading this in your web browser, your server is probably * not configured correctly to run PHP applications! * * See the README, INSTA --------------------------- Is there a slight chance to get the wiki up again? Many thanks Steffen |
|
From: Andreas K. <kri...@ho...> - 2016-05-31 11:59:40
|
Hello.
There seems to be an issue with the search process.
When searching for something (doesn't matter if certificates or requests) then i get the full list of the results on the first page so MAXITEMS is somehow being ignored. When going to the 2nd, 3rd and so on page then i get a list of all available certificates.
in the search file found at ./lib/openca/cmds/ i have added the following so the parameters are almost the same like in the listCerts file:
106 } else {
107 my %para;
108 $para{'DATATYPE'} = $dataType;
109 $para{'ITEMS'} = $mayItems;
I then get a list of only 20 entries and instead of the buttons for the pages i only have the text "No Extra References".
The URL after clicking on the OK button on the search page looks like:
https://xxxxxxxx/cgi-bin/ca2-dev-152/ca/ca
when i look for valid issued certificates then the URL looks like:
https://xxxxxxxx/cgi-bin/ca2-dev-152/ca/ca?cmd=listCerts;dataType=VALID_CERTIFICATE;xsrf_protection_token=xxxx
Maybe it has something to do that the URL is not correct?
When going to the next page on the search site then the URL looks like:
https://xxxxxxxx/cgi-bin/ca2-dev-152/ca/ca?cmd=search;value_1=cita%2A;name_2=emailAddress;name_1=CN;name_3=DN;name_4=ROLE;name_5=KEY;role=;datatype=CERTIFICATE;key=;cn=cita%;emailaddress=;dn=;viewFrom=216;dataType=CERTIFICATE;xsrf_protection_token=xxx
But as i said all is shown also which don't match the search parameters.
Does someone else have this issue?
I'm using OpenCA Base 1.5.2 and OpenCA Tools 1.3.1
PostgreSQL 9.1
Debian 8
Regards
Andreas Krieger
|
|
From: Angelo R. P. <ang...@ho...> - 2016-05-19 13:15:22
|
Greetings! I have inherited a working (barely) OpenCA infrastructure, running on a mix of RHEL / FEDORA servers. I have a few issues ongoing, my main questions are these: 1. Is there any way to get oficial support for OpenCA, from the project devs, or a third party? 2. Documentation is very scarce, where I can get info to try to pinpoint issues I'm having? 3. It's ok to post here for technical help? I hope I'm not bothering someone with my stupid requests, I have experience with other CA solutions (like MS), but this is something new to me; I have moderate linux knowledge, btw. Best regards, Angelo |
|
From: Hadas, S. <San...@di...> - 2016-01-14 13:28:54
|
Hi There, I am new to this list and openca-scep as well. What I try to do is sending valid SCEP messages to iOS units and what I get is "Profile Installation Failed" "The SCEP server returned an invalid response". Actually the response is valid on OS X devices and those accept the scep response and finally install the mobileconfig files I try to put on them. Would you please look through my commands below and pinpoint any issue what might look invalid? 1. PKIOperation message is received, payload is saved as File 2. File is url decoded (from iOS only, that is not needed for OS X) 3. File is base64 decoded and saved as File.baseless 4. openssl pkcs7 -inform der -in File.baseless -outform pem -out File.pkcs7 5. openca-scep -in File.pkcs7 -print_scert -noout >File.cer 6. openca-scep -in File.pkcs7 -print_transid -noout 7. openssl smime -verify -noverify -inform pem -in File.pkcs7 -signer File.cer 8. openca-scep -in File.pkcs7 -print_msgtype -noout #checked against PKCSReq 9. openca-scep -in File.pkcs7 -print_req -noout -out File.csr -keyfile root_ca.key -passin pass:Password # CN is checked in the csr file and is correct 10. openssl x509 -req -in File.csr -CA root_ca.crt -CAkey root_ca.key -out File.signed.device.crt -days 3650 -CAcreateserial -CAserial "uuidgen-generated-serial" -passin pass:Password 11. openca-scep -in File.pkcs7 -new -signcert root_ca.crt -msgtype CertRep -status SUCCESS -outform DER -reccert File.cer -issuedcert File.signed.device.crt -out File.for.device.out -keyfile root_ca.key -passin pass:Password 12. Optionally base64 encoding the File.for.device.out (tried both, OS X accepts both versions, iOS accepts none) 13. Sending the File.for.device.out in http(s) as a "Content-Type: application/x-pki-message" Is there any obvious mistake in how I use openca-scep what might generate an invalid result? Any suggestion on how to fix it is highly appreciated. Thank you, Sandor |
|
From: Oliver G. <oli...@gm...> - 2015-10-05 14:55:44
|
Oliver Graute <oliver.graute <at> gmail.com> writes: > > Andreas Krieger <kriegerandreas <at> hotmail.com> writes: > >You also need the ra cert on the machine where the scep client is > >requesting the certs.Logs are written in the apache log and stderror.log > >of openca.In which node are you logging in, ta, ca, pub? > > I'am logging in > > http://localhost/cgi-bin/pki/ca/ca?redir=1 > > then i got redirected to > > http://localhost/cgi-bin/pki/ca/ca?cmd=getStaticPage&name=homePage > > the Websites looks a bit broken for me. I just see the basic "Welcome > Example Site" and only the "search" Button is working here "My Certs", > "MyProfile", "Notices" and "Messages" are greyed. I solved it by a deep analysis of my apache logs. Some dirs were wrong and a saw 404 in the logs. then I deleted all stuff in /var/www/ re-installed apache2, configured my DocumentRoot Path to #DocumentRoot "/var/www/WebSites/Default/htdocs/" DocumentRoot "/var/www/" rebuild openca-base make sure this htdocs dirs are used --with-htdocs-fs-prefix=/var/www/html/pki --with-htdocs-url-prefix=/html/pki now I got a working openca website with pictures and all that CA Operating stuff ;) |
|
From: Martin H. <he...@hl...> - 2015-10-05 12:10:44
|
I can't find the error messages you are seeing in the source. Which version of OpenCA are you using? Anyhow, the CA tries to issue another certificate for serial 00 again. So, somehow the mechanism for creating new serials is not working properly in your installation. Do you use random serials? That should be in web-interfaces/ca/ca.conf - if yes, there might be a problem with the perl module bignum, which handles the large serial numbers and converting integer to hex representation. Did you initialize the database when you could first log into your ca? Did you create the ca certificate with this installation or did you import an existing one? Do you have a file called serial in the var/crypto folder of your openca installation? if yes, what is in there, and how do the file permissions look like? Is there a backup serial.old of that file? do you have any errors logged in var/log/stderr.log? Fabricio, would you please write to the list instead of sending mails to me in person, so that others have the chance to assist you, too? On 10/05/2015 03:12 AM, Fabricio Gimenes wrote: > Martin > > I have problem a when I generate the certificate. > > You can pelase? > > > > > > > > SSBr | Strong Security Brasil | Fabricio Gimenes Porto | Dpto. Técnico | > Tel. <tel:%2B55%2011%202897-1566> +55 11 2897-1566 |Cel. +55 11 9-4558-6564 > |fgimenes <mailto:an...@st...> @strongsecurity.com.br > > As informações contidas nesta mensagem são CONFIDENCIAIS e protegidas pelo > sigilo legal. A divulgação, distribuição ou reprodução do teor deste > documento depende de autorização do emissor. Caso V. Sa. não seja o > destinatário, preposto, ou a pessoa responsável pela entrega desta mensagem, > fica, desde já, notificado que qualquer divulgação, distribuição ou > reprodução é estritamente proibida, sujeitando-se o infrator às sanções > legais. Caso esta comunicação tenha sido recebida por engano, favor nos > avisar imediatamente, respondendo esta mensagem. The information contained > in this message is CONFIDENTIAL. If the reader of this transmittal is not > the intended recipient or an agent responsible for delivering it, you are > hereby notified that you have received this communication in error, and that > any dissemination, distribution, retention or copy of this communication is > strictly prohibited. In this case, please immediately reply this message to > the sender. > > Antes de imprimir pense em seu compromisso com o Meio Ambiente. > > > > |
|
From: Oliver G. <oli...@gm...> - 2015-10-05 11:06:00
|
Andreas Krieger <kriegerandreas <at> hotmail.com> writes: > > Hi,For the config.xml .. I'm sure you have to enter the path to the > key/cert file and not the content of the files<name>SCEP_RA_CERT</name>> <value>path to ra cert</value><name>SCEP_RA_KEY</name><value>path to ra >key</value><name>SCEP_RA_PASSWD</name><value>xxxxxxx</value> thx, I entered the path there and that fixed the 100 % load issue of scep script. On the client: sscep getca -c cert -u http://localhost:80/cgi-bin/scep/scep provide me now a cert-0. >You also need the ra cert on the machine where the scep client is >requesting the certs.Logs are written in the apache log and stderror.log >of openca.In which node are you logging in, ta, ca, pub? I'am logging in http://localhost/cgi-bin/pki/ca/ca?redir=1 then i got redirected to http://localhost/cgi-bin/pki/ca/ca?cmd=getStaticPage&name=homePage the Websites looks a bit broken for me. I just see the basic "Welcome Example Site" and only the "search" Button is working here "My Certs", "MyProfile", "Notices" and "Messages" are greyed. |
|
From: Andreas K. <kri...@ho...> - 2015-10-05 10:13:43
|
Hi, For the config.xml .. I'm sure you have to enter the path to the key/cert file and not the content of the files <name>SCEP_RA_CERT</name> <value>path to ra cert</value> <name>SCEP_RA_KEY</name> <value>path to ra key</value> <name>SCEP_RA_PASSWD</name> <value>xxxxxxx</value> You also need the ra cert on the machine where the scep client is requesting the certs. Logs are written in the apache log and stderror.log of openca. In which node are you logging in, ta, ca, pub? Regards Andreas >Hello, > >how can I see if my scep server configuration is working? > >I created a certificate and a key pem file (with xca tool). >I added the crypto stuff in /opt/openca-1.3/etc/openca/config.xml > > ><name>SCEP_RA_CERT</name> ><value>-----BEGIN CERTIFICATE----- >xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx >xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx >xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx >-----END CERTIFICATE-----</value> > ><name>SCEP_RA_KEY</name> ><value>-----BEGIN RSA PRIVATE KEY----- >xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx >xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx >xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx >-----END RSA PRIVATE KEY-----</value> > ><name>SCEP_RA_PASSWD</name> ><value>xxxxxxx</value> > >after that I run > >sudo ./configure_etc.sh > >and then restart the openCA Server > >I checked /opt/openca-1.3/etc/openca/servers/scep.conf and the crypto stuff >is there. > >Now I try to access the scep script > >http://localhost/cgi-bin/scep/scep > >but nothing happens, is there some logging for scep? > >If I log into the openCA website I just see the basic "Welcome Example >Site" and only the "search" Button is working here "My Certs", "MyProfile", >"Notices" and "Messages" are greyed. > >Is here something with my installation broken? > >Best Regards, > >Oliver |
|
From: Oliver G. <oli...@gm...> - 2015-10-05 08:15:17
|
Oliver Graute <oliver.graute <at> gmail.com> writes: > > Hello, > > how can I see if my scep server configuration is working? > > > http://localhost/cgi-bin/scep/scep > Now I tried to fetch a certificate from a client sscep application sscep getca -c tmp/cert -u http://localhost:80/cgi-bin/scep /scep > but nothing happens, is there some logging for scep? something is happenning now, the scep server script runs with 100% CPU load. But no certificate is provided. Best regards, Oliver |
|
From: Oliver G. <oli...@gm...> - 2015-10-02 12:45:17
|
Hello, how can I see if my scep server configuration is working? I created a certificate and a key pem file (with xca tool). I added the crypto stuff in /opt/openca-1.3/etc/openca/config.xml <name>SCEP_RA_CERT</name> <value>-----BEGIN CERTIFICATE----- xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx -----END CERTIFICATE-----</value> <name>SCEP_RA_KEY</name> <value>-----BEGIN RSA PRIVATE KEY----- xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx -----END RSA PRIVATE KEY-----</value> <name>SCEP_RA_PASSWD</name> <value>xxxxxxx</value> after that I run sudo ./configure_etc.sh and then restart the openCA Server I checked /opt/openca-1.3/etc/openca/servers/scep.conf and the crypto stuff is there. Now I try to access the scep script http://localhost/cgi-bin/scep/scep but nothing happens, is there some logging for scep? If I log into the openCA website I just see the basic "Welcome Example Site" and only the "search" Button is working here "My Certs", "MyProfile", "Notices" and "Messages" are greyed. Is here something with my installation broken? Best Regards, Oliver |
|
From: Martin H. <he...@hl...> - 2015-10-02 08:56:23
|
On 10/02/2015 10:32 AM, Oliver Graute wrote: > I solved my problem :-) I added the last pki dir in this compile > option --with-cgi-fs-prefix=/usr/lib/cgi-bin/pki then rebuild and > reconfigure everything. Then reinstall apache2 with apt-get remove > --purge apache2 apache2.2-common apt-get install --purge apache2 > apache2.2-common and now i can login to openca via the web. Best > Regards, Oliver this is of course the better solution. Please ignore my previous mail. |
|
From: Martin H. <he...@hl...> - 2015-10-02 08:50:01
|
Hello Oliver,
it seems the configure script has not properly replaced
@ca_cgi_url_prefix@, but there is no configure option
--with-ca-cgi-url-prefix. I guess it's usually generated out of the
other url-prefix settings, but for some reason not in your case.
I'd suggest to manually edit ./src/web-interfaces/ca/htdocs/index.html
and replace the above string by /cgi-bin/pki/
(or, in the already installed place it should be
/var/www/html/pki/ca/index.html if I'm not mistaken...)
Probably you have to do the same for the other web interfaces as well.
The following command should print out the files in which preprocessing
variables are left over.
find /var/www/html/pki/ -type f -exec grep -Eq '@[a-zA-Z_]*@' {} \; -print
Some of these are intentional and they are replaced at runtime, e.g.
when place holders are filled in for emails or for translation, but I
believe paths and URLs should be filled in during configure or make.
A similar thing I have already noticed is @dbmodule@, which can be
either DB, or on modern distributions it's DBI.
best regards,
Martin
On 10/01/2015 05:00 PM, Oliver Graute wrote:
> Hello,
>
> I'am trying to install openca-base-1.5.1 on Ubuntu 12.04. I struggling with
> the openca apache part. All I get on my Webserver (localhost) is:
>
> Not Found
>
> The requested URL /@ca_cgi_url_prefix@/ca was not found on this server.
> Apache/2.2.22 (Ubuntu) Server at 127.0.0.1 Port 80
>
>
> I read the Install instructions and I dig a bit through the archive,
> especially this thread helped me. But I cloudn't solve the problem above.
>
> http://thread.gmane.org/gmane.comp.security.openca.user/1304/
>
> some suggestion?
>
> here is my config part:
>
>
> ./configure --prefix=/opt/openca-1.3 --with-openca-user=openca --with-
> openca-group=openca --with-web-host=localhost --with-httpd-user=www-data --
> with-httpd-group=www-data --with-cgi-fs-prefix=/usr/lib/cgi-bin --with-
> htdocs-fs-prefix=/var/www/html/pki --with-htdocs-url-prefix="/html/pki" --
> with-cgi-url-prefix="/cgi-bin/pki" --with-openca-
> prefix=/usr/local/openca/ca --with-etc-prefix=/usr/local/openca/ca/etc --
> with-module-prefix=/usr/local/openca/ca/modules --disable-external-modules
> --enable-scep
>
>
> openca-base-1.5.1
>
>
> Installation Details:
> =====================
>
> OpenCA Server:
> * OpenCA prefix .................: /opt/openca-1.3
> * Build prefix ..................:
> * OpenCA User ...................: openca
> * OpenCA Group ..................: openca
> * OpenCA Tools prefix ...........:
>
> Web Server:
> * httpd User ....................: www-data
> * httpd Group ...................: www-data
> * httpd prefix ..................: /var/www
> * htdocs prefix .................: /var/www/html/pki
> * cgi prefix ....................: /usr/lib/cgi-bin
> * htdocs URL prefix .............: /html/pki
> * cgi URL prefix ................: /cgi-bin/pki
>
> Other:
> * OpenSSL Prefix ................: /usr
> * OpenSSL Libs ..................: -Wl,-rpath,/usr/lib -L/usr/lib -L/usr -
> lcrypto -lssl
>
> Done.
>
> System Configured for: Ubuntu 12.04.5
>
> Please now use 'make' to build the components.
> Use 'make install-offline' for the CA installation and
> use 'make install-online' for RA/Public interface installation
>
> More targets are available. Use 'make help' for a full list.
>
>
> Best regards,
>
> Oliver
>
|
|
From: Oliver G. <oli...@gm...> - 2015-10-02 08:32:44
|
Oliver Graute <oliver.graute <at> gmail.com> writes: > I'am trying to install openca-base-1.5.1 on Ubuntu 12.04. I struggling with > the openca apache part. All I get on my Webserver (localhost) is: > > Not Found > > The requested URL / <at> ca_cgi_url_prefix <at> /ca was not found on this server. > Apache/2.2.22 (Ubuntu) Server at 127.0.0.1 Port 80 > > here is my config part: > > ./configure --prefix=/opt/openca-1.3 --with-openca-user=openca --with- > openca-group=openca --with-web-host=localhost --with-httpd-user=www-data -- > with-httpd-group=www-data --with-cgi-fs-prefix=/usr/lib/cgi-bin --with- > htdocs-fs-prefix=/var/www/html/pki --with-htdocs-url-prefix="/html/pki" - - > with-cgi-url-prefix="/cgi-bin/pki" --with-openca- > prefix=/usr/local/openca/ca --with-etc-prefix=/usr/local/openca/ca/etc -- > with-module-prefix=/usr/local/openca/ca/modules --disable-external- modules > --enable-scep I solved my problem :-) I added the last pki dir in this compile option --with-cgi-fs-prefix=/usr/lib/cgi-bin/pki then rebuild and reconfigure everything. Then reinstall apache2 with apt-get remove --purge apache2 apache2.2-common apt-get install --purge apache2 apache2.2-common and now i can login to openca via the web. Best Regards, Oliver |
|
From: Oliver G. <oli...@gm...> - 2015-10-01 17:25:19
|
Hello, I'am trying to install openca-base-1.5.1 on Ubuntu 12.04. I struggling with the openca apache part. All I get on my Webserver (localhost) is: Not Found The requested URL /@ca_cgi_url_prefix@/ca was not found on this server. Apache/2.2.22 (Ubuntu) Server at 127.0.0.1 Port 80 I read the Install instructions and I dig a bit through the archive, especially this thread helped me. But I cloudn't solve the problem above. http://thread.gmane.org/gmane.comp.security.openca.user/1304/ some suggestion? here is my config part: ./configure --prefix=/opt/openca-1.3 --with-openca-user=openca --with- openca-group=openca --with-web-host=localhost --with-httpd-user=www-data -- with-httpd-group=www-data --with-cgi-fs-prefix=/usr/lib/cgi-bin --with- htdocs-fs-prefix=/var/www/html/pki --with-htdocs-url-prefix="/html/pki" -- with-cgi-url-prefix="/cgi-bin/pki" --with-openca- prefix=/usr/local/openca/ca --with-etc-prefix=/usr/local/openca/ca/etc -- with-module-prefix=/usr/local/openca/ca/modules --disable-external-modules --enable-scep openca-base-1.5.1 Installation Details: ===================== OpenCA Server: * OpenCA prefix .................: /opt/openca-1.3 * Build prefix ..................: * OpenCA User ...................: openca * OpenCA Group ..................: openca * OpenCA Tools prefix ...........: Web Server: * httpd User ....................: www-data * httpd Group ...................: www-data * httpd prefix ..................: /var/www * htdocs prefix .................: /var/www/html/pki * cgi prefix ....................: /usr/lib/cgi-bin * htdocs URL prefix .............: /html/pki * cgi URL prefix ................: /cgi-bin/pki Other: * OpenSSL Prefix ................: /usr * OpenSSL Libs ..................: -Wl,-rpath,/usr/lib -L/usr/lib -L/usr - lcrypto -lssl Done. System Configured for: Ubuntu 12.04.5 Please now use 'make' to build the components. Use 'make install-offline' for the CA installation and use 'make install-online' for RA/Public interface installation More targets are available. Use 'make help' for a full list. Best regards, Oliver |
|
From: Martin H. <he...@hl...> - 2015-10-01 09:27:14
|
some of your questions might be addressed in the OpenCa Guide: https://pki.openca.org/projects/openca/docs/openca-guide.pdf However, I'm not aware of an up-to date documentation. Anyhow, basic usage questions should be addressed appropriately also in an older document. The command line tool you are looking for is openssl or one of its forks. As far as I know it is shipped with all linux distributions. There are also ports to windows. OpenCa is mostly not about the command line tool. It is a framework for handling the requests, the issued certificates, crls... - genarally speaking the input and output processed by openssl in the background on the server side. I'm not aware of any documentation which would address handling of x509 certificates in general. Questions about import/export in the browser are addressed in the browsers documentation, questions about vpn are addressed in the documentation of your vpn software/hardware, and there are many tutorials on the web on how to do a particular task with openssl. On 09/30/2015 08:45 PM, Fabricio Gimenes wrote: > Hello > > Sorry, as I am new in using OpenCA , I wonder where I can find a document to > help me get these following information . > > > > SEND CERTIFICATE REQ VIA COMMAND LINE > > . XP > > . W7 > > . RED HAT > > . SIGN COMMAND CERTIFICATION DIRECTORY > > . WEB ? > > . VIA COMMAND > > . EXPORT CONTROL CERTIFICATE IN DIRECTORY > > . WEB ? > > . VIA COMMAND > > . INSTALLING CERTIFICATE VIA COMMAND LINE > > * MAY NOT BE POSSIBLE TO EXPORT THE KEY OF THE PRIVATE > > . XP > > . W7 > > . RED HAT > > . EXPORT CERTIFICATE FOR CA GW OF VPN ( CAN TEST IN BROWSER ) > > . REVOKE CERTIFICATE > > . VIA COMMAND > > . VIA GUI > > . OCSP FOR CERTIFICATES ESPIRADOS > > . HOW TO SUBMIT ? > > . HOW TO RENEW CERTIFICATE ? > > . You HAVE TO ISSUE A NEW ? > > . CONTROL RENEW CERTIFICATE > > . DO VIA WEB > > > > > > SSBr | Strong Security Brasil | Fabricio Gimenes Porto | Dpto. Técnico | > Tel. <tel:%2B55%2011%202897-1566> +55 11 2897-1566 |Cel. +55 11 9-4558-6564 > |fgimenes <mailto:an...@st...> @strongsecurity.com.br > > As informações contidas nesta mensagem são CONFIDENCIAIS e protegidas pelo > sigilo legal. A divulgação, distribuição ou reprodução do teor deste > documento depende de autorização do emissor. Caso V. Sa. não seja o > destinatário, preposto, ou a pessoa responsável pela entrega desta mensagem, > fica, desde já, notificado que qualquer divulgação, distribuição ou > reprodução é estritamente proibida, sujeitando-se o infrator às sanções > legais. Caso esta comunicação tenha sido recebida por engano, favor nos > avisar imediatamente, respondendo esta mensagem. The information contained > in this message is CONFIDENTIAL. If the reader of this transmittal is not > the intended recipient or an agent responsible for delivering it, you are > hereby notified that you have received this communication in error, and that > any dissemination, distribution, retention or copy of this communication is > strictly prohibited. In this case, please immediately reply this message to > the sender. > > Antes de imprimir pense em seu compromisso com o Meio Ambiente. > > > > |
|
From: Martin H. <he...@hl...> - 2015-09-28 08:33:28
|
The Error Code: 740201 [initServer:314] No login appears when the login mechanism has failed. Which type did you configure? It's in the web-interfaces/*/access_control.xml files in the login section of access_control. For each web-interface (ra, ca, ldap, scep, pub, batch, node) there is a separate configuration file. Also, I think there should be a message in the xml logs which tells you more about what failed in the login procedure On 09/25/2015 09:42 PM, Fabricio Gimenes wrote: > Hi Martin, > > > > Can you help. > > > > > > > > Please. > > > > SSBr | Strong Security Brasil | Fabricio Gimenes Porto | Dpto. Técnico | > Tel. <tel:%2B55%2011%202897-1566> +55 11 2897-1566 |Cel. +55 11 9-4558-6564 > |fgimenes <mailto:an...@st...> @strongsecurity.com.br > > As informações contidas nesta mensagem são CONFIDENCIAIS e protegidas pelo > sigilo legal. A divulgação, distribuição ou reprodução do teor deste > documento depende de autorização do emissor. Caso V. Sa. não seja o > destinatário, preposto, ou a pessoa responsável pela entrega desta mensagem, > fica, desde já, notificado que qualquer divulgação, distribuição ou > reprodução é estritamente proibida, sujeitando-se o infrator às sanções > legais. Caso esta comunicação tenha sido recebida por engano, favor nos > avisar imediatamente, respondendo esta mensagem. The information contained > in this message is CONFIDENTIAL. If the reader of this transmittal is not > the intended recipient or an agent responsible for delivering it, you are > hereby notified that you have received this communication in error, and that > any dissemination, distribution, retention or copy of this communication is > strictly prohibited. In this case, please immediately reply this message to > the sender. > > Antes de imprimir pense em seu compromisso com o Meio Ambiente. |
|
From: Fabricio G. <fgi...@st...> - 2015-09-25 16:54:07
|
Thanks, Resolved problem. /usr/sbin/setenforce 0 Disable selinux. Martin SSBr | Strong Security Brasil | Fabricio Gimenes Porto | Dpto. Técnico | Tel. +55 11 2897-1566 |Cel. +55 11 9-4558-6564 |fgi...@st... As informações contidas nesta mensagem são CONFIDENCIAIS e protegidas pelo sigilo legal. A divulgação, distribuição ou reprodução do teor deste documento depende de autorização do emissor. Caso V. Sa. não seja o destinatário, preposto, ou a pessoa responsável pela entrega desta mensagem, fica, desde já, notificado que qualquer divulgação, distribuição ou reprodução é estritamente proibida, sujeitando-se o infrator às sanções legais. Caso esta comunicação tenha sido recebida por engano, favor nos avisar imediatamente, respondendo esta mensagem. The information contained in this message is CONFIDENTIAL. If the reader of this transmittal is not the intended recipient or an agent responsible for delivering it, you are hereby notified that you have received this communication in error, and that any dissemination, distribution, retention or copy of this communication is strictly prohibited. In this case, please immediately reply this message to the sender. Antes de imprimir pense em seu compromisso com o Meio Ambiente. -----Mensagem original----- De: Martin Hecht [mailto:he...@hl...] Enviada em: Friday, September 25, 2015 5:53 AM Para: fgi...@st... Cc: Users' Help and Suggestions <ope...@li...> Assunto: Re: [Openca-Users] RES: Openca Socket error Hi Fabricio, hmm... next I would check step by step what's happening. The error message sais that the server is not online and it mentions the path to the socket. So, if you try to restart the server, do you see the process, and does it stay alive? Just after start you should see some runs of configure_etc.sh and later there should be at least one process of perl running with the argument of openca_start (prepended by its full path). If the process is not there, we have to find out why it doesn't come up. Maybe there are other hints in the openca-start.log? If the process is there and there are no other log messages that would help, check if the socket exists, and if it is accessible by apache (file permissions, all down the path, group membership, maybe you have to add apache to the openca group or vice versa)? Does the time stamp of the socket fit to your latest openca server restart? If it is much older, remove it manually and try to restart the server again. If this should all be ok, is apparmor or selinux running? Did you change something in this area recently, or did the change come in by a security update of the OS? Maybe a more restrictive apparmor profile was distributed by an update and you have to add a few more lines to allow apache to access this socket. If this all does not give you a clue I would start reading the openca source and search for the place where the error message appears. Maybe there are some explaining comments in that region, or you get a hint from the code itself. BTW, which version of OpenCa do you use? Ehm... the server used to work before, and you didn't change anything just before you noticed the error, right? best, Martin On 09/24/2015 08:41 PM, Fabricio Gimenes wrote: > Martin, > > My server with this clear, ran the xml cleaning procedure and yet the > problem has not been resolved . > We can do some more procedure. > > Fabricio > > SSBr | Strong Security Brasil | Fabricio Gimenes Porto | Dpto. Técnico | > Tel. +55 11 2897-1566 |Cel. +55 11 9-4558-6564 > |fgi...@st... > As informações contidas nesta mensagem são CONFIDENCIAIS e protegidas pelo > sigilo legal. A divulgação, distribuição ou reprodução do teor deste > documento depende de autorização do emissor. Caso V. Sa. não seja o > destinatário, preposto, ou a pessoa responsável pela entrega desta mensagem, > fica, desde já, notificado que qualquer divulgação, distribuição ou > reprodução é estritamente proibida, sujeitando-se o infrator às sanções > legais. Caso esta comunicação tenha sido recebida por engano, favor nos > avisar imediatamente, respondendo esta mensagem. The information contained > in this message is CONFIDENTIAL. If the reader of this transmittal is not > the intended recipient or an agent responsible for delivering it, you are > hereby notified that you have received this communication in error, and that > any dissemination, distribution, retention or copy of this communication is > strictly prohibited. In this case, please immediately reply this message to > the sender. > Antes de imprimir pense em seu compromisso com o Meio Ambiente. > > -----Mensagem original----- > De: Martin Hecht [mailto:he...@hl...] > Enviada em: Thursday, September 24, 2015 1:36 PM > Para: fgi...@st... > Cc: Users' Help and Suggestions <ope...@li...> > Assunto: Re: [Openca-Users] Openca Socket error > > Hi Fabricio, > > this looks like the openca daemon has crashed or is in some kind of > deadlock. > Usually, you just have to stop the openca service in order to clean up > things, and start it again. > > It may take a while to become responsive again (in a VM running on old > hardware it may well be a minute and more), but as soon as the service > has finished its startup, you should be able to connect via browser again. > > However, if the reason for the crash is a full disk (or a file system > which ran out of inodes), then you first have to clean up e.g. the xml > log directory (I usually put everything into a tgz and remove all the > xml files and the directories of the current and the past year(s). A > proper logrotate mechanism would be useful here... > > Martin > > On 09/24/2015 02:53 PM, Fabricio Gimenes wrote: >> Hi, >> >> >> >> My name is Fabricio. >> >> >> >> I'm a problem in openca_socket , which access the apache web presents >> seguitne message. >> >> >> >> OpenCA Error: Server is not online or does not accept requests >> (//var/openca/tmp/openca_socket - //var/openca/tmp/openca_socket). 0 >> >> |
|
From: Martin H. <he...@hl...> - 2015-09-25 08:53:20
|
Hi Fabricio, hmm... next I would check step by step what's happening. The error message sais that the server is not online and it mentions the path to the socket. So, if you try to restart the server, do you see the process, and does it stay alive? Just after start you should see some runs of configure_etc.sh and later there should be at least one process of perl running with the argument of openca_start (prepended by its full path). If the process is not there, we have to find out why it doesn't come up. Maybe there are other hints in the openca-start.log? If the process is there and there are no other log messages that would help, check if the socket exists, and if it is accessible by apache (file permissions, all down the path, group membership, maybe you have to add apache to the openca group or vice versa)? Does the time stamp of the socket fit to your latest openca server restart? If it is much older, remove it manually and try to restart the server again. If this should all be ok, is apparmor or selinux running? Did you change something in this area recently, or did the change come in by a security update of the OS? Maybe a more restrictive apparmor profile was distributed by an update and you have to add a few more lines to allow apache to access this socket. If this all does not give you a clue I would start reading the openca source and search for the place where the error message appears. Maybe there are some explaining comments in that region, or you get a hint from the code itself. BTW, which version of OpenCa do you use? Ehm... the server used to work before, and you didn't change anything just before you noticed the error, right? best, Martin On 09/24/2015 08:41 PM, Fabricio Gimenes wrote: > Martin, > > My server with this clear, ran the xml cleaning procedure and yet the > problem has not been resolved . > We can do some more procedure. > > Fabricio > > SSBr | Strong Security Brasil | Fabricio Gimenes Porto | Dpto. Técnico | > Tel. +55 11 2897-1566 |Cel. +55 11 9-4558-6564 > |fgi...@st... > As informações contidas nesta mensagem são CONFIDENCIAIS e protegidas pelo > sigilo legal. A divulgação, distribuição ou reprodução do teor deste > documento depende de autorização do emissor. Caso V. Sa. não seja o > destinatário, preposto, ou a pessoa responsável pela entrega desta mensagem, > fica, desde já, notificado que qualquer divulgação, distribuição ou > reprodução é estritamente proibida, sujeitando-se o infrator às sanções > legais. Caso esta comunicação tenha sido recebida por engano, favor nos > avisar imediatamente, respondendo esta mensagem. The information contained > in this message is CONFIDENTIAL. If the reader of this transmittal is not > the intended recipient or an agent responsible for delivering it, you are > hereby notified that you have received this communication in error, and that > any dissemination, distribution, retention or copy of this communication is > strictly prohibited. In this case, please immediately reply this message to > the sender. > Antes de imprimir pense em seu compromisso com o Meio Ambiente. > > -----Mensagem original----- > De: Martin Hecht [mailto:he...@hl...] > Enviada em: Thursday, September 24, 2015 1:36 PM > Para: fgi...@st... > Cc: Users' Help and Suggestions <ope...@li...> > Assunto: Re: [Openca-Users] Openca Socket error > > Hi Fabricio, > > this looks like the openca daemon has crashed or is in some kind of > deadlock. > Usually, you just have to stop the openca service in order to clean up > things, and start it again. > > It may take a while to become responsive again (in a VM running on old > hardware it may well be a minute and more), but as soon as the service > has finished its startup, you should be able to connect via browser again. > > However, if the reason for the crash is a full disk (or a file system > which ran out of inodes), then you first have to clean up e.g. the xml > log directory (I usually put everything into a tgz and remove all the > xml files and the directories of the current and the past year(s). A > proper logrotate mechanism would be useful here... > > Martin > > On 09/24/2015 02:53 PM, Fabricio Gimenes wrote: >> Hi, >> >> >> >> My name is Fabricio. >> >> >> >> I'm a problem in openca_socket , which access the apache web presents >> seguitne message. >> >> >> >> OpenCA Error: Server is not online or does not accept requests >> (//var/openca/tmp/openca_socket - //var/openca/tmp/openca_socket). 0 >> >> |
|
From: Fabricio G. <fgi...@st...> - 2015-09-24 18:41:35
|
Martin, My server with this clear, ran the xml cleaning procedure and yet the problem has not been resolved . We can do some more procedure. Fabricio SSBr | Strong Security Brasil | Fabricio Gimenes Porto | Dpto. Técnico | Tel. +55 11 2897-1566 |Cel. +55 11 9-4558-6564 |fgi...@st... As informações contidas nesta mensagem são CONFIDENCIAIS e protegidas pelo sigilo legal. A divulgação, distribuição ou reprodução do teor deste documento depende de autorização do emissor. Caso V. Sa. não seja o destinatário, preposto, ou a pessoa responsável pela entrega desta mensagem, fica, desde já, notificado que qualquer divulgação, distribuição ou reprodução é estritamente proibida, sujeitando-se o infrator às sanções legais. Caso esta comunicação tenha sido recebida por engano, favor nos avisar imediatamente, respondendo esta mensagem. The information contained in this message is CONFIDENTIAL. If the reader of this transmittal is not the intended recipient or an agent responsible for delivering it, you are hereby notified that you have received this communication in error, and that any dissemination, distribution, retention or copy of this communication is strictly prohibited. In this case, please immediately reply this message to the sender. Antes de imprimir pense em seu compromisso com o Meio Ambiente. -----Mensagem original----- De: Martin Hecht [mailto:he...@hl...] Enviada em: Thursday, September 24, 2015 1:36 PM Para: fgi...@st... Cc: Users' Help and Suggestions <ope...@li...> Assunto: Re: [Openca-Users] Openca Socket error Hi Fabricio, this looks like the openca daemon has crashed or is in some kind of deadlock. Usually, you just have to stop the openca service in order to clean up things, and start it again. It may take a while to become responsive again (in a VM running on old hardware it may well be a minute and more), but as soon as the service has finished its startup, you should be able to connect via browser again. However, if the reason for the crash is a full disk (or a file system which ran out of inodes), then you first have to clean up e.g. the xml log directory (I usually put everything into a tgz and remove all the xml files and the directories of the current and the past year(s). A proper logrotate mechanism would be useful here... Martin On 09/24/2015 02:53 PM, Fabricio Gimenes wrote: > Hi, > > > > My name is Fabricio. > > > > I'm a problem in openca_socket , which access the apache web presents > seguitne message. > > > > OpenCA Error: Server is not online or does not accept requests > (//var/openca/tmp/openca_socket - //var/openca/tmp/openca_socket). 0 > > |
|
From: Martin H. <he...@hl...> - 2015-09-24 16:36:13
|
Hi Fabricio, this looks like the openca daemon has crashed or is in some kind of deadlock. Usually, you just have to stop the openca service in order to clean up things, and start it again. It may take a while to become responsive again (in a VM running on old hardware it may well be a minute and more), but as soon as the service has finished its startup, you should be able to connect via browser again. However, if the reason for the crash is a full disk (or a file system which ran out of inodes), then you first have to clean up e.g. the xml log directory (I usually put everything into a tgz and remove all the xml files and the directories of the current and the past year(s). A proper logrotate mechanism would be useful here... Martin On 09/24/2015 02:53 PM, Fabricio Gimenes wrote: > Hi, > > > > My name is Fabricio. > > > > I'm a problem in openca_socket , which access the apache web presents > seguitne message. > > > > OpenCA Error: Server is not online or does not accept requests > (//var/openca/tmp/openca_socket - //var/openca/tmp/openca_socket). 0 > > |
|
From: Fabricio G. <fgi...@st...> - 2015-09-24 13:12:08
|
Hi, My name is Fabricio. I'm a problem in openca_socket , which access the apache web presents seguitne message. OpenCA Error: Server is not online or does not accept requests (//var/openca/tmp/openca_socket - //var/openca/tmp/openca_socket). 0 SSBr | Strong Security Brasil | Fabricio Gimenes Porto | Dpto. Técnico | Tel. <tel:%2B55%2011%202897-1566> +55 11 2897-1566 |Cel. +55 11 9-4558-6564 |fgimenes <mailto:an...@st...> @strongsecurity.com.br As informações contidas nesta mensagem são CONFIDENCIAIS e protegidas pelo sigilo legal. A divulgação, distribuição ou reprodução do teor deste documento depende de autorização do emissor. Caso V. Sa. não seja o destinatário, preposto, ou a pessoa responsável pela entrega desta mensagem, fica, desde já, notificado que qualquer divulgação, distribuição ou reprodução é estritamente proibida, sujeitando-se o infrator às sanções legais. Caso esta comunicação tenha sido recebida por engano, favor nos avisar imediatamente, respondendo esta mensagem. The information contained in this message is CONFIDENTIAL. If the reader of this transmittal is not the intended recipient or an agent responsible for delivering it, you are hereby notified that you have received this communication in error, and that any dissemination, distribution, retention or copy of this communication is strictly prohibited. In this case, please immediately reply this message to the sender. Antes de imprimir pense em seu compromisso com o Meio Ambiente. |