From: marchiani jb <mar...@ya...> - 2005-03-17 08:50:56
|
Hi Sorry but I don't know how to respond directly at the precedent message. For this error you have to configure your interfaces in OpenCA/etc/access_control/ You should have ra ca node batch (more or less). Edit all .xml and set correct values for protocol and symmetric keylength. This error is about the length key usage. If you are in testing you can set: <openca> <access_control> <channel> <type>mod_ssl</type> <protocol>.*</protocol> <source>.*</source> <asymmetric_cipher>.*</asymmetric_cipher> <asymmetric_keylength>0</asymmetric_keylength> <symmetric_cipher>.*</symmetric_cipher> <symmetric_keylength>0</symmetric_keylength> </channel> For protocol you set .* in order to accept all protocol and 0 here "<symmetric_keylength>0</symmetric_keylength>" for length of keys. This permits just you to work with OpenCA. Excuse me for my bad english. I hope that's understand ... Marchiani JB Découvrez nos promotions exclusives "destination de la Tunisie, du Maroc, des Baléares et la Rép. Dominicaine sur Yahoo! Voyages : http://fr.travel.yahoo.com/promotions/mar14.html |
From: talhaoui n. <tal...@cn...> - 2007-05-04 11:01:48
|
Hi; I have installed OpenCA 0.9.3 on Fedora Core 4. When I try to use the website, I got the the Error 6251026 "Aborting connction ......." Can you help me!! Best Regards. -- Nabil Talhaoui Réseau Marwan CNRST - MAROC 52, Avenue Omar Ibn Al Khattab, B.P. 8027 Agdal - Rabat Tél: +212 37686233 / 34 - Fax: +212 37686235 |
From: Matthias A. <ti...@gm...> - 2007-05-04 22:33:26
|
On 5/4/07, talhaoui nabil <tal...@cn...> wrote: > Hi; Hi > > I have installed OpenCA 0.9.3 on Fedora Core 4. > When I try to use the website, I got the the Error 6251026 "Aborting conn= ction ......." > Can you help me!! Have a look at this link, that should help you: http://www.openca.info/docs/guide/openca-guide.html#id2524105 And if this is setup correct you have to use HTTPS to connect to openca, then you shouldn't get this error any more. Kind regards, Matthias > > > Best Regards. > > > -- > Nabil Talhaoui > R=E9seau Marwan > CNRST - MAROC > 52, Avenue Omar Ibn Al Khattab, B.P. 8027 > Agdal - Rabat > T=E9l: +212 37686233 / 34 - Fax: +212 37686235 > > > > ------------------------------------------------------------------------- > This SF.net email is sponsored by DB2 Express > Download DB2 Express C - the FREE version of DB2 express and take > control of your XML. No limits. Just data. Click to get it now. > http://sourceforge.net/powerbar/db2/ > _______________________________________________ > Openca-Users mailing list > Ope...@li... > https://lists.sourceforge.net/lists/listinfo/openca-users > |
From: <bh...@cs...> - 2005-03-18 02:17:51
|
Hi all When i try to approve a certificate request at RA i get error 700 General Error. The compilation of the command cmdViewCSR failed. Can't us= e an undefined value as a HASH reference at /usr/local/openra/openca/lib/servers/ra-node/functions/crypto-utils.lib line 1093. i generated another certificate request and i made sure that i entered al= l the values but still the problem persists. Please help. -saurabh |
From: M.-A. D. <mad...@nu...> - 2005-03-18 07:45:17
|
bh...@cs... a =E9crit : > When i try to approve a certificate request at RA i get error 700 >=20 > General Error. The compilation of the command cmdViewCSR failed. Can't = use > an undefined value as a HASH reference at > /usr/local/openra/openca/lib/servers/ra-node/functions/crypto-utils.lib= > line 1093. >=20 > i generated another certificate request and i made sure that i entered = all > the values but still the problem persists. Please help. >=20 It's very very similar to my error: Error 700 General Error The compilation of the command cmdViewCSR failed.=20 Can't use an undefined value as a HASH reference at=20 /usr/local/pki-ra/OpenCA/lib/functions/crypto-utils.lib line 1149. cf.=20 http://www.mail-archive.com/ope...@li.../msg06818.h= tml and to this one: General error trapped 700: The compilation of the command cmdViewCSR=20 failed. Can't use an undefined value as a HASH reference at=20 /usr/local/openra/openca/lib/functions/crypto-utils.lib line 1149.<br> Compilation failed in require at=20 /usr/local/openra/openca/etc/openca_start line 62. cf.=20 http://www.mail-archive.com/ope...@li.../msg06688.h= tml I haven't had time yet to finish the steps needed to test the solution nicely suggested by Alexei Chetroi. What he suggested was that I shouldn't use the DB backend, but use an SQL backend instead. I have just compiled, installed and configured the CA and RA with PostgreSQL yet. I haven't had time to test certificate approval. Are you using a DB backend or an SQL one? Anyway I would be very interested in knowing when you have a solution for this problem. Cheers, --=20 Marc-Aur=E8le DARCHE NUXEO (Paris, France) http://nuxeo.com/ Nuxeo Collaborative Portal Server (CPS) http://www.cps-project.org/ Gestion de contenu web / portail collaboratif / logiciel libre |
From: Ives S. <da...@da...> - 2005-03-18 11:18:39
|
bh...@cs... wrote: > Hi all > i generated another certificate request and i made sure that i entered all > the values but still the problem persists. Please help. what exaclty did you do to generate the request when exaclty does the error occurs (which action gets performed) how does the request look, if there is no sensitive data in you may be able to provide a screenshot or something? (somewhere in the net, not of the error, of the request if it shows up before approving or something...) what system are you using os, browser, perl, openssl and so on greetings dalini |
From: <bh...@cs...> - 2005-03-19 15:55:41
|
Hi I am using red hat 9 and i installed openca using openca-0.9.2-RC4.tar.gz , i suppose it installs everythimg that is required for openca like openssl, perl etc. I am using mySQL as database. To request a certificate i did: User->Request a Certificate->Request a certificate with automatic browserdetection after doing that i got serial number 288. then i logged into RA and did: Active CSRs->New->search it showed me the certificate request. i cliked on the serial number link and it gave me a screen that had just the follwing error: Error 700 General Error. The compilation of the command cmdViewCS= R failed. Can't use an undefined value as a HASH reference at /usr/local/openra/openca/lib/servers/ra-node/functions/crypto-utils.lib line 1093. If i try to search CSR from RA node by: Utilities->search CSR-> enter name i get the certificate request, but when i click on it i get same error 70= 0. Please help. Thanking you all in anticipation Saurabh > bh...@cs... wrote: >> Hi all > >> i generated another certificate request and i made sure that i entered >> all >> the values but still the problem persists. Please help. > > what exaclty did you do to generate the request > when exaclty does the error occurs (which action gets performed) > how does the request look, if there is no sensitive data in > you may be able to provide a screenshot or something? > (somewhere in the net, not of the error, of the request if it > shows up before approving or something...) > > what system are you using > os, browser, perl, openssl and so on > > > greetings > dalini > > > ------------------------------------------------------- > SF email is sponsored by - The IT Product Guide > Read honest & candid reviews on hundreds of IT Products from real users= . > Discover which products truly live up to the hype. Start reading now. > http://ads.osdn.com/?ad_id=3D6595&alloc_id=3D14396&op=3Dclick > _______________________________________________ > Openca-Users mailing list > Ope...@li... > https://lists.sourceforge.net/lists/listinfo/openca-users > |
From: Ives S. <da...@da...> - 2005-03-20 21:04:21
|
bh...@cs... wrote: > Hi > I am using red hat 9 and i installed openca using > openca-0.9.2-RC4.tar.gz , i suppose it installs everythimg that is > required for openca like openssl, perl etc. I am using mySQL as > database. > first suggestion would be to use 0.9.2.1 or better 0.9.2.2 if there are still the same problem - tell us ;) greetings dalini |
From: Ives S. <da...@da...> - 2005-03-21 13:13:03
|
bh...@cs... wrote: > Hi all > When i try to approve a certificate request at RA i get error 700 > > General Error. The compilation of the command cmdViewCSR failed. Can't use > an undefined value as a HASH reference at > /usr/local/openra/openca/lib/servers/ra-node/functions/crypto-utils.lib > line 1093. > > i generated another certificate request and i made sure that i entered all > the values but still the problem persists. Please help. > so, since we got very close to the problem of mr darche, we may get close to yours to: things to check: - what dataexchange did you initate from ca to ra? if only configuration you may use dataexchange and then ALL instead of Configuration only, since this only exports the rbac settings and roles and opensslfiles - check the size of the cacert files in var/crypto/cacerts it should be more then 0 bytes ;) greetings dalini |
From: <bh...@cs...> - 2005-03-21 14:08:41
|
Thanks a lot for your help Ives. It works fine now. /var/crypto/cacerts was empty. I moved certificates from ca to ra, tried again and it worked. I would have never figured that out on my own. thanks again. regards saurabh > bh...@cs... wrote: >> Hi all >> When i try to approve a certificate request at RA i get error 700 >> >> General Error. The compilation of the command cmdViewCSR failed. Can't >> use >> an undefined value as a HASH reference at >> /usr/local/openra/openca/lib/servers/ra-node/functions/crypto-utils.li= b >> line 1093. >> >> i generated another certificate request and i made sure that i entered >> all >> the values but still the problem persists. Please help. >> > so, since we got very close to the problem of mr darche, we may get > close to yours to: > > things to check: > > - what dataexchange did you initate from ca to ra? > if only configuration you may use dataexchange and then > ALL instead of Configuration only, since this only exports > the rbac settings and roles and opensslfiles > > - check the size of the cacert files in var/crypto/cacerts > it should be more then 0 bytes ;) > > > greetings > dalini > > > ------------------------------------------------------- > SF email is sponsored by - The IT Product Guide > Read honest & candid reviews on hundreds of IT Products from real users= . > Discover which products truly live up to the hype. Start reading now. > http://ads.osdn.com/?ad_id=3D6595&alloc_id=3D14396&op=3Dclick > _______________________________________________ > Openca-Users mailing list > Ope...@li... > https://lists.sourceforge.net/lists/listinfo/openca-users > |
From: Ives S. <da...@da...> - 2005-03-21 16:51:20
|
bh...@cs... wrote: > Thanks a lot for your help Ives. It works fine now. /var/crypto/cacerts > was empty. I moved certificates from ca to ra, tried again and it worked. > I would have never figured that out on my own. thanks again. > Fine, but it should work 'automatical' through the import/export functions, if its not, it means there is a setup problem like at mr. darche's case - have you configured the dataexchange section of the config.xml file correct for each system (ca/ra+pub and so on)? otherwise requests and/or certificates won't get exchanged correctly between the two systems greetings dalini |
From: <bh...@cs...> - 2005-03-21 20:21:01
|
my import/export functions were not configured properly before. Intially = i was using config.xml but that gave me some problems. i configured import/export functions in *.conf.template and certificates get exchanged correctly now. -saurabh > bh...@cs... wrote: >> Thanks a lot for your help Ives. It works fine now. /var/crypto/cacert= s >> was empty. I moved certificates from ca to ra, tried again and it >> worked. >> I would have never figured that out on my own. thanks again. >> > Fine, but it should work 'automatical' through the import/export > functions, if its not, it means there is a setup problem > > like at mr. darche's case - have you configured the dataexchange sectio= n > of the config.xml file correct for each system (ca/ra+pub and so on)? > > otherwise requests and/or certificates won't get exchanged correctly > between the two systems > > > greetings > dalini > > > ------------------------------------------------------- > SF email is sponsored by - The IT Product Guide > Read honest & candid reviews on hundreds of IT Products from real users= . > Discover which products truly live up to the hype. Start reading now. > http://ads.osdn.com/?ad_id=3D6595&alloc_id=3D14396&op=3Dclick > _______________________________________________ > Openca-Users mailing list > Ope...@li... > https://lists.sourceforge.net/lists/listinfo/openca-users > |