You can subscribe to this list here.
| 2008 |
Jan
(1) |
Feb
(4) |
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
(4) |
Dec
|
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2009 |
Jan
(2) |
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
(1) |
Nov
(4) |
Dec
|
| 2010 |
Jan
(1) |
Feb
|
Mar
|
Apr
(4) |
May
|
Jun
(1) |
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
| 2011 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
(1) |
Jul
(1) |
Aug
|
Sep
|
Oct
|
Nov
|
Dec
(3) |
| 2012 |
Jan
(1) |
Feb
(8) |
Mar
(10) |
Apr
|
May
(12) |
Jun
(2) |
Jul
(28) |
Aug
(15) |
Sep
(12) |
Oct
(2) |
Nov
|
Dec
(16) |
| 2013 |
Jan
(30) |
Feb
(1) |
Mar
|
Apr
(11) |
May
(2) |
Jun
(11) |
Jul
(15) |
Aug
(4) |
Sep
(1) |
Oct
(10) |
Nov
(1) |
Dec
(2) |
| 2014 |
Jan
(8) |
Feb
(13) |
Mar
(12) |
Apr
(24) |
May
(2) |
Jun
(1) |
Jul
(1) |
Aug
|
Sep
(2) |
Oct
(1) |
Nov
(2) |
Dec
(1) |
| 2015 |
Jan
(3) |
Feb
(6) |
Mar
|
Apr
|
May
(7) |
Jun
(7) |
Jul
(3) |
Aug
(5) |
Sep
(1) |
Oct
(8) |
Nov
(6) |
Dec
|
| 2016 |
Jan
|
Feb
(3) |
Mar
(5) |
Apr
(9) |
May
(26) |
Jun
(8) |
Jul
|
Aug
|
Sep
(11) |
Oct
(8) |
Nov
(1) |
Dec
(2) |
| 2017 |
Jan
(4) |
Feb
(7) |
Mar
(7) |
Apr
(4) |
May
(1) |
Jun
(5) |
Jul
(3) |
Aug
(3) |
Sep
(1) |
Oct
(4) |
Nov
(5) |
Dec
(1) |
| 2018 |
Jan
(4) |
Feb
(1) |
Mar
(1) |
Apr
(1) |
May
|
Jun
(1) |
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
| 2019 |
Jan
|
Feb
(1) |
Mar
(2) |
Apr
(1) |
May
|
Jun
|
Jul
|
Aug
|
Sep
(1) |
Oct
|
Nov
(2) |
Dec
|
| 2020 |
Jan
(3) |
Feb
|
Mar
(2) |
Apr
(3) |
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
| 2021 |
Jan
|
Feb
|
Mar
|
Apr
(1) |
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
| 2022 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
(2) |
Jul
|
Aug
|
Sep
(1) |
Oct
|
Nov
|
Dec
(1) |
| 2023 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
(1) |
Aug
|
Sep
|
Oct
|
Nov
|
Dec
(1) |
| 2025 |
Jan
|
Feb
(1) |
Mar
|
Apr
(1) |
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
|
From: Markus K. <ma...@pr...> - 2015-06-01 10:01:16
|
On 06/01/2015 11:19 AM, Marcin Fabianczyk wrote: > Hello, Hello Marcin, > > When I try to sign a document timestamp gets > errors. SIGNSERVER_NODEID in the system variable is set. > > 10:59:57,754 ERROR [org.signserver.common.WorkerConfig] > (http--0.0.0.0-8080-1) Error, required environment variable > SIGNSERVER_NODEID isn't set. > 10:59:57,755 ERROR [org.signserver.common.WorkerConfig] > (http--0.0.0.0-8080-1) Error, required environment variable > SIGNSERVER_NODEID isn't set. > 10:59:57,755 ERROR [org.signserver.common.WorkerConfig] > (http--0.0.0.0-8080-1) Error, required environment variable > SIGNSERVER_NODEID isn't set. > 10:59:57,755 ERROR [org.signserver.common.WorkerConfig] > (http--0.0.0.0-8080-1) Error, required environment variable > SIGNSERVER_NODEID isn't set. > 10:59:57,756 ERROR [org.signserver.common.WorkerConfig] > (http--0.0.0.0-8080-1) Error, required environment variable > SIGNSERVER_NODEID isn't set. > 10:59:57,756 ERROR [org.signserver.common.WorkerConfig] > (http--0.0.0.0-8080-1) Error, required environment variable > SIGNSERVER_NODEID isn't set. The error about SIGNSERVER_NODEID is more of a warning. If you want to get rid of it you need to define it as an environment variable in place that is read by the application server. For instance ~/.bashrc might not work but /etc/environment or similar might depending on the system and how the application server is started. > 10:59:57,757 INFO [org.signserver.server.log.IWorkerLogger] > (http--0.0.0.0-8080-1) AUDIT; DefaultTimeStampLogger; LOG_ID: > 396652c8-edc8-4559-a969-07cc17b08283; CLIENT_IP: 10.0.0.27; > REQUEST_FULLURL: > http://tsa-01.company.local/signserver/process?workerName=TimeStampSigner; > RequestTime: 1433149197753; ResponseTime: 1; TimeStamp: 1433149197756; > TimeSource: LocalComputerTimeSource; PKIStatus: ${TSA_PKISTATUS}; > PKIFailureInfo: ${TSA_PKIFAILUREINFO}; SerialNumber: b889d6e3b9c7ea6; > TSA_POLICYID: 1.2.3; SIGNER_CERT_SERIALNUMBER: > ${SIGNER_CERT_SERIALNUMBER}; SIGNER_CERT_ISSUERDN: > ${SIGNER_CERT_ISSUERDN}; TIMESTAMPREQUEST_ENCODED: > MDECAQEwITAJBgUrDgMCGgUABBS9rHsjYWM6fCYkVPdKcSRUfwXi7wIGAU2uXXQnAQH/; > TSA_TIMESTAMPRESPONSE_ENCODED: ${TSA_TIMESTAMPRESPONSE_ENCODED}; > ARCHIVE_IDS: ${ARCHIVE_IDS}; PURCHASED: ${PURCHASED}; TSA_EXCEPTION: > ${TSA_EXCEPTION}; EXCEPTION: > org.signserver.common.CryptoTokenOfflineException: No certificate for > this signer > > The last sentence is the real issue you are facing: "No certificate for the signer". So you need to make sure the signer has a certificate configured. Best regards, Markus PrimeKey PrimeKey Solutions offers a commercial EJBCA & SignServer support subscription and training. Please see www.primekey.se or contact in...@pr... for more information. https://www.primekey.se/Services/Support/ https://www.primekey.se/Services/Training/ |
|
From: Marcin F. <mar...@en...> - 2015-06-01 09:19:48
|
Hello, When I try to sign a document timestamp gets errors. SIGNSERVER_NODEID in the system variable is set. 10:59:57,754 ERROR [org.signserver.common.WorkerConfig] (http--0.0.0.0-8080-1) Error, required environment variable SIGNSERVER_NODEID isn't set. 10:59:57,755 ERROR [org.signserver.common.WorkerConfig] (http--0.0.0.0-8080-1) Error, required environment variable SIGNSERVER_NODEID isn't set. 10:59:57,755 ERROR [org.signserver.common.WorkerConfig] (http--0.0.0.0-8080-1) Error, required environment variable SIGNSERVER_NODEID isn't set. 10:59:57,755 ERROR [org.signserver.common.WorkerConfig] (http--0.0.0.0-8080-1) Error, required environment variable SIGNSERVER_NODEID isn't set. 10:59:57,756 ERROR [org.signserver.common.WorkerConfig] (http--0.0.0.0-8080-1) Error, required environment variable SIGNSERVER_NODEID isn't set. 10:59:57,756 ERROR [org.signserver.common.WorkerConfig] (http--0.0.0.0-8080-1) Error, required environment variable SIGNSERVER_NODEID isn't set. 10:59:57,757 INFO [org.signserver.server.log.IWorkerLogger] (http--0.0.0.0-8080-1) AUDIT; DefaultTimeStampLogger; LOG_ID: 396652c8-edc8-4559-a969-07cc17b08283; CLIENT_IP: 10.0.0.27; REQUEST_FULLURL: http://tsa-01.company.local/signserver/process?workerName=TimeStampSigner; RequestTime: 1433149197753; ResponseTime: 1; TimeStamp: 1433149197756; TimeSource: LocalComputerTimeSource; PKIStatus: ${TSA_PKISTATUS}; PKIFailureInfo: ${TSA_PKIFAILUREINFO}; SerialNumber: b889d6e3b9c7ea6; TSA_POLICYID: 1.2.3; SIGNER_CERT_SERIALNUMBER: ${SIGNER_CERT_SERIALNUMBER}; SIGNER_CERT_ISSUERDN: ${SIGNER_CERT_ISSUERDN}; TIMESTAMPREQUEST_ENCODED: MDECAQEwITAJBgUrDgMCGgUABBS9rHsjYWM6fCYkVPdKcSRUfwXi7wIGAU2uXXQnAQH/; TSA_TIMESTAMPRESPONSE_ENCODED: ${TSA_TIMESTAMPRESPONSE_ENCODED}; ARCHIVE_IDS: ${ARCHIVE_IDS}; PURCHASED: ${PURCHASED}; TSA_EXCEPTION: ${TSA_EXCEPTION}; EXCEPTION: org.signserver.common.CryptoTokenOfflineException: No certificate for this signer |
|
From: Markus K. <ma...@pr...> - 2015-05-28 18:45:34
|
On 28 May 2015 12:45:08 CEST, "Marcin Fabiańczyk" <mar...@en...> wrote: > >Hello, > >Change java connector to 5.1.30 solved the problem > >Thanks, >Martin > >----- Oryginalna wiadomość ----- >Od: "Marcin Fabiańczyk" <mar...@en...> >Do: "Markus Kilås" <ma...@pr...> >DW: sig...@li... >Wysłane: czwartek, 28 maj 2015 11:48:17 >Temat: Re: [SignServer-develop] Problem with the >implementation of Signserver. > >Hello Markus, > >I changed the timeout to 1200 seconds and it did not resolve the issue. >I used mysql-connector-java-5.1.17 > > > >----- Oryginalna wiadomość ----- >Od: "Markus Kilås" <ma...@pr...> >Do: sig...@li... >Wysłane: czwartek, 28 maj 2015 11:37:15 >Temat: Re: [SignServer-develop] Problem with the implementation >of Signserver. > >On 05/28/2015 11:29 AM, Marcin Fabiańczyk wrote: >> Hello, >> >> I installed signserver a few times accordance with >> http://signserver.org/manual/installguide.html and each time the >> deployment is stopped at the same time. >> >> Linux dist.: Centos 6.6 >> Jboss: 7.1 finall >> Signserver: 3.6.2 >> >> >------------------------------------------------------------------------ >> >> Hello, >> >> >> I try to run signserver but each time, the implementation ends like >this: >> >> >> >> 22:57:14,581 INFO [org.jboss.web] (MSC service thread 1-1) >JBAS018210: >> Registering web context: /signserver/AdminWSService >> >> 23:13:47,327 ERROR [org.jboss.as.server.deployment.scanner] >> (DeploymentScanner-threads - 2) JBAS015052: Did not receive a >response >> to the deployment operation within the allowed timeout period [1000 >> seconds]. Check the server configuration file and the server logs to >> find more about the status of the deployment. >> >> 23:13:47,328 INFO [org.jboss.as.server] (DeploymentScanner-threads - >1) >> JBAS015870: Deploy of deployment "signserver.ear" was rolled back >with >> failure message Operation cancelled >> >> 23:13:47,381 INFO [org.jboss.as.webservices] (MSC service thread >1-1) >> JBAS015540: Stopping service >> >jboss.ws.endpoint."signserver.ear"."SignServer-ejb-ClientWS.jar".ClientWS >> >> 23:13:47,386 INFO >> [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service >> thread 1-1) remove: >> jboss.ws:context=signserver/ClientWSService,endpoint=ClientWS >> >> 23:13:47,387 INFO [org.jboss.as.webservices] (MSC service thread >1-1) >> JBAS015540: Stopping service >> >jboss.ws.endpoint."signserver.ear"."SignServer-ejb-SignServerWS.jar".SignServerWS >> >> 23:13:47,389 INFO >> [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service >> thread 1-1) remove: >> jboss.ws:context=signserver/SignServerWSService,endpoint=SignServerWS >> >> 23:13:47,409 INFO [org.jboss.as.webservices] (MSC service thread >1-1) >> JBAS015540: Stopping service >> >jboss.ws.endpoint."signserver.ear"."SignServer-ejb-ValidationWS.jar".ValidationWS >> >> 23:13:47,409 INFO >> [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service >> thread 1-1) remove: >> jboss.ws:context=signserver/ValidationWSService,endpoint=ValidationWS >> >> 23:13:47,412 INFO [org.jboss.as.webservices] (MSC service thread >1-1) >> JBAS015540: Stopping service >> >jboss.ws.endpoint."signserver.ear"."SignServer-ejb-AdminWS.jar".AdminWS >> >> 23:13:47,413 INFO >> [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service >> thread 1-1) remove: >> jboss.ws:context=signserver/AdminWSService,endpoint=AdminWS >> >> 23:13:47,542 INFO [org.jboss.as.webservices] (MSC service thread >1-1) >> JBAS015540: Stopping service jboss.ws.port-component-link >> >> > >Hi Martin, > >The timeout and failure to start JBoss indicates a problem with the >configuration of JBoss. > >One cause for a situation like this is if the data source or driver has >not been properly registered in JBoss. In that case there is usually >possible to find a small error message about it somewhere in the >server.log. > > > >Regards, >Markus >PrimeKey > >PrimeKey Solutions offers a commercial EJBCA & SignServer support >subscription and training. Please see www.primekey.se or contact >in...@pr... for more information. >https://www.primekey.se/Services/Support/ >https://www.primekey.se/Services/Training/ > > > >------------------------------------------------------------------------------ >_______________________________________________ >SignServer-develop mailing list >Sig...@li... >https://lists.sourceforge.net/lists/listinfo/signserver-develop > >------------------------------------------------------------------------------ >_______________________________________________ >SignServer-develop mailing list >Sig...@li... >https://lists.sourceforge.net/lists/listinfo/signserver-develop Great, Thanks for letting us know. BR, Markus -- Sent from my Android phone with K-9 Mail. Please excuse my brevity. |
|
From: Marcin F. <mar...@en...> - 2015-05-28 10:41:20
|
Hello, Change java connector to 5.1.30 solved the problem Thanks, Martin ----- Oryginalna wiadomość ----- Od: "Marcin Fabiańczyk" <mar...@en...> Do: "Markus Kilås" <ma...@pr...> DW: sig...@li... Wysłane: czwartek, 28 maj 2015 11:48:17 Temat: Re: [SignServer-develop] Problem with the implementation of Signserver. Hello Markus, I changed the timeout to 1200 seconds and it did not resolve the issue. I used mysql-connector-java-5.1.17 ----- Oryginalna wiadomość ----- Od: "Markus Kilås" <ma...@pr...> Do: sig...@li... Wysłane: czwartek, 28 maj 2015 11:37:15 Temat: Re: [SignServer-develop] Problem with the implementation of Signserver. On 05/28/2015 11:29 AM, Marcin Fabiańczyk wrote: > Hello, > > I installed signserver a few times accordance with > http://signserver.org/manual/installguide.html and each time the > deployment is stopped at the same time. > > Linux dist.: Centos 6.6 > Jboss: 7.1 finall > Signserver: 3.6.2 > > ------------------------------------------------------------------------ > > Hello, > > > I try to run signserver but each time, the implementation ends like this: > > > > 22:57:14,581 INFO [org.jboss.web] (MSC service thread 1-1) JBAS018210: > Registering web context: /signserver/AdminWSService > > 23:13:47,327 ERROR [org.jboss.as.server.deployment.scanner] > (DeploymentScanner-threads - 2) JBAS015052: Did not receive a response > to the deployment operation within the allowed timeout period [1000 > seconds]. Check the server configuration file and the server logs to > find more about the status of the deployment. > > 23:13:47,328 INFO [org.jboss.as.server] (DeploymentScanner-threads - 1) > JBAS015870: Deploy of deployment "signserver.ear" was rolled back with > failure message Operation cancelled > > 23:13:47,381 INFO [org.jboss.as.webservices] (MSC service thread 1-1) > JBAS015540: Stopping service > jboss.ws.endpoint."signserver.ear"."SignServer-ejb-ClientWS.jar".ClientWS > > 23:13:47,386 INFO > [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service > thread 1-1) remove: > jboss.ws:context=signserver/ClientWSService,endpoint=ClientWS > > 23:13:47,387 INFO [org.jboss.as.webservices] (MSC service thread 1-1) > JBAS015540: Stopping service > jboss.ws.endpoint."signserver.ear"."SignServer-ejb-SignServerWS.jar".SignServerWS > > 23:13:47,389 INFO > [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service > thread 1-1) remove: > jboss.ws:context=signserver/SignServerWSService,endpoint=SignServerWS > > 23:13:47,409 INFO [org.jboss.as.webservices] (MSC service thread 1-1) > JBAS015540: Stopping service > jboss.ws.endpoint."signserver.ear"."SignServer-ejb-ValidationWS.jar".ValidationWS > > 23:13:47,409 INFO > [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service > thread 1-1) remove: > jboss.ws:context=signserver/ValidationWSService,endpoint=ValidationWS > > 23:13:47,412 INFO [org.jboss.as.webservices] (MSC service thread 1-1) > JBAS015540: Stopping service > jboss.ws.endpoint."signserver.ear"."SignServer-ejb-AdminWS.jar".AdminWS > > 23:13:47,413 INFO > [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service > thread 1-1) remove: > jboss.ws:context=signserver/AdminWSService,endpoint=AdminWS > > 23:13:47,542 INFO [org.jboss.as.webservices] (MSC service thread 1-1) > JBAS015540: Stopping service jboss.ws.port-component-link > > Hi Martin, The timeout and failure to start JBoss indicates a problem with the configuration of JBoss. One cause for a situation like this is if the data source or driver has not been properly registered in JBoss. In that case there is usually possible to find a small error message about it somewhere in the server.log. Regards, Markus PrimeKey PrimeKey Solutions offers a commercial EJBCA & SignServer support subscription and training. Please see www.primekey.se or contact in...@pr... for more information. https://www.primekey.se/Services/Support/ https://www.primekey.se/Services/Training/ ------------------------------------------------------------------------------ _______________________________________________ SignServer-develop mailing list Sig...@li... https://lists.sourceforge.net/lists/listinfo/signserver-develop ------------------------------------------------------------------------------ _______________________________________________ SignServer-develop mailing list Sig...@li... https://lists.sourceforge.net/lists/listinfo/signserver-develop |
|
From: Marcin F. <mar...@en...> - 2015-05-28 09:44:27
|
Hello Markus, I changed the timeout to 1200 seconds and it did not resolve the issue. I used mysql-connector-java-5.1.17 ----- Oryginalna wiadomość ----- Od: "Markus Kilås" <ma...@pr...> Do: sig...@li... Wysłane: czwartek, 28 maj 2015 11:37:15 Temat: Re: [SignServer-develop] Problem with the implementation of Signserver. On 05/28/2015 11:29 AM, Marcin Fabiańczyk wrote: > Hello, > > I installed signserver a few times accordance with > http://signserver.org/manual/installguide.html and each time the > deployment is stopped at the same time. > > Linux dist.: Centos 6.6 > Jboss: 7.1 finall > Signserver: 3.6.2 > > ------------------------------------------------------------------------ > > Hello, > > > I try to run signserver but each time, the implementation ends like this: > > > > 22:57:14,581 INFO [org.jboss.web] (MSC service thread 1-1) JBAS018210: > Registering web context: /signserver/AdminWSService > > 23:13:47,327 ERROR [org.jboss.as.server.deployment.scanner] > (DeploymentScanner-threads - 2) JBAS015052: Did not receive a response > to the deployment operation within the allowed timeout period [1000 > seconds]. Check the server configuration file and the server logs to > find more about the status of the deployment. > > 23:13:47,328 INFO [org.jboss.as.server] (DeploymentScanner-threads - 1) > JBAS015870: Deploy of deployment "signserver.ear" was rolled back with > failure message Operation cancelled > > 23:13:47,381 INFO [org.jboss.as.webservices] (MSC service thread 1-1) > JBAS015540: Stopping service > jboss.ws.endpoint."signserver.ear"."SignServer-ejb-ClientWS.jar".ClientWS > > 23:13:47,386 INFO > [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service > thread 1-1) remove: > jboss.ws:context=signserver/ClientWSService,endpoint=ClientWS > > 23:13:47,387 INFO [org.jboss.as.webservices] (MSC service thread 1-1) > JBAS015540: Stopping service > jboss.ws.endpoint."signserver.ear"."SignServer-ejb-SignServerWS.jar".SignServerWS > > 23:13:47,389 INFO > [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service > thread 1-1) remove: > jboss.ws:context=signserver/SignServerWSService,endpoint=SignServerWS > > 23:13:47,409 INFO [org.jboss.as.webservices] (MSC service thread 1-1) > JBAS015540: Stopping service > jboss.ws.endpoint."signserver.ear"."SignServer-ejb-ValidationWS.jar".ValidationWS > > 23:13:47,409 INFO > [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service > thread 1-1) remove: > jboss.ws:context=signserver/ValidationWSService,endpoint=ValidationWS > > 23:13:47,412 INFO [org.jboss.as.webservices] (MSC service thread 1-1) > JBAS015540: Stopping service > jboss.ws.endpoint."signserver.ear"."SignServer-ejb-AdminWS.jar".AdminWS > > 23:13:47,413 INFO > [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service > thread 1-1) remove: > jboss.ws:context=signserver/AdminWSService,endpoint=AdminWS > > 23:13:47,542 INFO [org.jboss.as.webservices] (MSC service thread 1-1) > JBAS015540: Stopping service jboss.ws.port-component-link > > Hi Martin, The timeout and failure to start JBoss indicates a problem with the configuration of JBoss. One cause for a situation like this is if the data source or driver has not been properly registered in JBoss. In that case there is usually possible to find a small error message about it somewhere in the server.log. Regards, Markus PrimeKey PrimeKey Solutions offers a commercial EJBCA & SignServer support subscription and training. Please see www.primekey.se or contact in...@pr... for more information. https://www.primekey.se/Services/Support/ https://www.primekey.se/Services/Training/ ------------------------------------------------------------------------------ _______________________________________________ SignServer-develop mailing list Sig...@li... https://lists.sourceforge.net/lists/listinfo/signserver-develop |
|
From: Markus K. <ma...@pr...> - 2015-05-28 09:37:27
|
On 05/28/2015 11:29 AM, Marcin Fabiańczyk wrote: > Hello, > > I installed signserver a few times accordance with > http://signserver.org/manual/installguide.html and each time the > deployment is stopped at the same time. > > Linux dist.: Centos 6.6 > Jboss: 7.1 finall > Signserver: 3.6.2 > > ------------------------------------------------------------------------ > > Hello, > > > I try to run signserver but each time, the implementation ends like this: > > > > 22:57:14,581 INFO [org.jboss.web] (MSC service thread 1-1) JBAS018210: > Registering web context: /signserver/AdminWSService > > 23:13:47,327 ERROR [org.jboss.as.server.deployment.scanner] > (DeploymentScanner-threads - 2) JBAS015052: Did not receive a response > to the deployment operation within the allowed timeout period [1000 > seconds]. Check the server configuration file and the server logs to > find more about the status of the deployment. > > 23:13:47,328 INFO [org.jboss.as.server] (DeploymentScanner-threads - 1) > JBAS015870: Deploy of deployment "signserver.ear" was rolled back with > failure message Operation cancelled > > 23:13:47,381 INFO [org.jboss.as.webservices] (MSC service thread 1-1) > JBAS015540: Stopping service > jboss.ws.endpoint."signserver.ear"."SignServer-ejb-ClientWS.jar".ClientWS > > 23:13:47,386 INFO > [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service > thread 1-1) remove: > jboss.ws:context=signserver/ClientWSService,endpoint=ClientWS > > 23:13:47,387 INFO [org.jboss.as.webservices] (MSC service thread 1-1) > JBAS015540: Stopping service > jboss.ws.endpoint."signserver.ear"."SignServer-ejb-SignServerWS.jar".SignServerWS > > 23:13:47,389 INFO > [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service > thread 1-1) remove: > jboss.ws:context=signserver/SignServerWSService,endpoint=SignServerWS > > 23:13:47,409 INFO [org.jboss.as.webservices] (MSC service thread 1-1) > JBAS015540: Stopping service > jboss.ws.endpoint."signserver.ear"."SignServer-ejb-ValidationWS.jar".ValidationWS > > 23:13:47,409 INFO > [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service > thread 1-1) remove: > jboss.ws:context=signserver/ValidationWSService,endpoint=ValidationWS > > 23:13:47,412 INFO [org.jboss.as.webservices] (MSC service thread 1-1) > JBAS015540: Stopping service > jboss.ws.endpoint."signserver.ear"."SignServer-ejb-AdminWS.jar".AdminWS > > 23:13:47,413 INFO > [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service > thread 1-1) remove: > jboss.ws:context=signserver/AdminWSService,endpoint=AdminWS > > 23:13:47,542 INFO [org.jboss.as.webservices] (MSC service thread 1-1) > JBAS015540: Stopping service jboss.ws.port-component-link > > Hi Martin, The timeout and failure to start JBoss indicates a problem with the configuration of JBoss. One cause for a situation like this is if the data source or driver has not been properly registered in JBoss. In that case there is usually possible to find a small error message about it somewhere in the server.log. Regards, Markus PrimeKey PrimeKey Solutions offers a commercial EJBCA & SignServer support subscription and training. Please see www.primekey.se or contact in...@pr... for more information. https://www.primekey.se/Services/Support/ https://www.primekey.se/Services/Training/ |
|
From: Marcin F. <mar...@en...> - 2015-05-28 09:26:03
|
Hello, I installed signserver a few times accordance with http://signserver.org/manual/installguide.html and each time the deployment is stopped at the same time . Linux dist.: Centos 6.6 Jboss: 7.1 finall Signserver: 3.6.2 Hello, I try to run signserver but each time, the implementation ends like this: 22:57:14,581 INFO [org.jboss.web] (MSC service thread 1-1) JBAS018210: Registering web context: /signserver/AdminWSService 23:13:47,327 ERROR [org.jboss.as.server.deployment.scanner] (DeploymentScanner-threads - 2) JBAS015052: Did not receive a response to the deployment operation within the allowed timeout period [1000 seconds]. Check the server configuration file and the server logs to find more about the status of the deployment. 23:13:47,328 INFO [org.jboss.as.server] (DeploymentScanner-threads - 1) JBAS015870: Deploy of deployment "signserver.ear" was rolled back with failure message Operation cancelled 23:13:47,381 INFO [org.jboss.as.webservices] (MSC service thread 1-1) JBAS015540: Stopping service jboss.ws.endpoint."signserver.ear"."SignServer-ejb-ClientWS.jar".ClientWS 23:13:47,386 INFO [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service thread 1-1) remove: jboss.ws:context=signserver/ClientWSService,endpoint=ClientWS 23:13:47,387 INFO [org.jboss.as.webservices] (MSC service thread 1-1) JBAS015540: Stopping service jboss.ws.endpoint."signserver.ear"."SignServer-ejb-SignServerWS.jar".SignServerWS 23:13:47,389 INFO [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service thread 1-1) remove: jboss.ws:context=signserver/SignServerWSService,endpoint=SignServerWS 23:13:47,409 INFO [org.jboss.as.webservices] (MSC service thread 1-1) JBAS015540: Stopping service jboss.ws.endpoint."signserver.ear"."SignServer-ejb-ValidationWS.jar".ValidationWS 23:13:47,409 INFO [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service thread 1-1) remove: jboss.ws:context=signserver/ValidationWSService,endpoint=ValidationWS 23:13:47,412 INFO [org.jboss.as.webservices] (MSC service thread 1-1) JBAS015540: Stopping service jboss.ws.endpoint."signserver.ear"."SignServer-ejb-AdminWS.jar".AdminWS 23:13:47,413 INFO [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service thread 1-1) remove: jboss.ws:context=signserver/AdminWSService,endpoint=AdminWS 23:13:47,542 INFO [org.jboss.as.webservices] (MSC service thread 1-1) JBAS015540: Stopping service jboss.ws.port-component-link Regards, Martin ------------------------------------------------------------------------------ _______________________________________________ SignServer-develop mailing list Sig...@li... https://lists.sourceforge.net/lists/listinfo/signserver-develop |
|
From: Marcin F. <mar...@en...> - 2015-05-26 21:29:08
|
Hello, I try to run signserver but each time, the implementation ends like this: 22:57:14,581 INFO [org.jboss.web] (MSC service thread 1-1) JBAS018210: Registering web context: /signserver/AdminWSService 23:13:47,327 ERROR [org.jboss.as.server.deployment.scanner] (DeploymentScanner-threads - 2) JBAS015052: Did not receive a response to the deployment operation within the allowed timeout period [1000 seconds]. Check the server configuration file and the server logs to find more about the status of the deployment. 23:13:47,328 INFO [org.jboss.as.server] (DeploymentScanner-threads - 1) JBAS015870: Deploy of deployment "signserver.ear" was rolled back with failure message Operation cancelled 23:13:47,381 INFO [org.jboss.as.webservices] (MSC service thread 1-1) JBAS015540: Stopping service jboss.ws.endpoint."signserver.ear"."SignServer-ejb-ClientWS.jar".ClientWS 23:13:47,386 INFO [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service thread 1-1) remove: jboss.ws:context=signserver/ClientWSService,endpoint=ClientWS 23:13:47,387 INFO [org.jboss.as.webservices] (MSC service thread 1-1) JBAS015540: Stopping service jboss.ws.endpoint."signserver.ear"."SignServer-ejb-SignServerWS.jar".SignSer verWS 23:13:47,389 INFO [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service thread 1-1) remove: jboss.ws:context=signserver/SignServerWSService,endpoint=SignServerWS 23:13:47,409 INFO [org.jboss.as.webservices] (MSC service thread 1-1) JBAS015540: Stopping service jboss.ws.endpoint."signserver.ear"."SignServer-ejb-ValidationWS.jar".Validat ionWS 23:13:47,409 INFO [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service thread 1-1) remove: jboss.ws:context=signserver/ValidationWSService,endpoint=ValidationWS 23:13:47,412 INFO [org.jboss.as.webservices] (MSC service thread 1-1) JBAS015540: Stopping service jboss.ws.endpoint."signserver.ear"."SignServer-ejb-AdminWS.jar".AdminWS 23:13:47,413 INFO [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service thread 1-1) remove: jboss.ws:context=signserver/AdminWSService,endpoint=AdminWS 23:13:47,542 INFO [org.jboss.as.webservices] (MSC service thread 1-1) JBAS015540: Stopping service jboss.ws.port-component-link Regards, Martin |
|
From: Marcin F. <mar...@en...> - 2015-05-26 21:27:33
|
Hello, I try to run signserver but each time, the implementation ends like this: 22:57:14,581 INFO [org.jboss.web] (MSC service thread 1-1) JBAS018210: Registering web context: /signserver/AdminWSService 23:13:47,327 ERROR [org.jboss.as.server.deployment.scanner] (DeploymentScanner-threads - 2) JBAS015052: Did not receive a response to the deployment operation within the allowed timeout period [1000 seconds]. Check the server configuration file and the server logs to find more about the status of the deployment. 23:13:47,328 INFO [org.jboss.as.server] (DeploymentScanner-threads - 1) JBAS015870: Deploy of deployment "signserver.ear" was rolled back with failure message Operation cancelled 23:13:47,381 INFO [org.jboss.as.webservices] (MSC service thread 1-1) JBAS015540: Stopping service jboss.ws.endpoint."signserver.ear"."SignServer-ejb-ClientWS.jar".ClientWS 23:13:47,386 INFO [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service thread 1-1) remove: jboss.ws:context=signserver/ClientWSService,endpoint=ClientWS 23:13:47,387 INFO [org.jboss.as.webservices] (MSC service thread 1-1) JBAS015540: Stopping service jboss.ws.endpoint."signserver.ear"."SignServer-ejb-SignServerWS.jar".SignSer verWS 23:13:47,389 INFO [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service thread 1-1) remove: jboss.ws:context=signserver/SignServerWSService,endpoint=SignServerWS 23:13:47,409 INFO [org.jboss.as.webservices] (MSC service thread 1-1) JBAS015540: Stopping service jboss.ws.endpoint."signserver.ear"."SignServer-ejb-ValidationWS.jar".Validat ionWS 23:13:47,409 INFO [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service thread 1-1) remove: jboss.ws:context=signserver/ValidationWSService,endpoint=ValidationWS 23:13:47,412 INFO [org.jboss.as.webservices] (MSC service thread 1-1) JBAS015540: Stopping service jboss.ws.endpoint."signserver.ear"."SignServer-ejb-AdminWS.jar".AdminWS 23:13:47,413 INFO [org.jboss.ws.common.management.DefaultEndpointRegistry] (MSC service thread 1-1) remove: jboss.ws:context=signserver/AdminWSService,endpoint=AdminWS 23:13:47,542 INFO [org.jboss.as.webservices] (MSC service thread 1-1) JBAS015540: Stopping service jboss.ws.port-component-link Regards, Martin |
|
From: Markus K. <ma...@pr...> - 2015-02-26 13:31:55
|
On 02/26/2015 02:27 PM, Markus Kilås wrote: > On 02/26/2015 01:36 PM, Naldiello wrote: >> Hi, >> >> I was wondering if anyone can help figure out an error I'm getting on >> SignServer CE 3.6.2. >> >> I've been able to setup a Lab environment to get familiar and test both >> EJBCA and SignServer. I'm using softHSM for testing purposes and get it >> working on both servers. I got EJBCA CA and Sub-CA key store in softHSM, >> generated the CA certificates and CRLs are being issued. Just the basic >> setup. >> >> However, I have been working on setting up timestamp on SignServer and I >> keep getting the error "No signer certificate" when I run the command >> "bin/signserver getstatus complete <id>". Here are the steps I did to >> set it up: >> >> First Worker (CryptoToken) -> All Good! >> 1. Setup the configuration.properties >> bin/signserver setproperties >> $PATH/pkcs11-crypto-configuration.properties >> 2. Reload worker >> bin/signserver reload 1 >> 3. Activate CryptoToken >> bin/signserver activatecryptotoken 1 >> 4. Test CryptoToken >> bin/signserver testkey 1 >> >> First Worker (HSM KeepAlive) -> All Good! >> 1. Setup the configuration.properties >> bin/signserver setproperties >> $PATH/qs_hsmkeepalive_configuration.properties >> 2. Reload worker >> bin/signserver reload 2 >> >> First Worker (HSM KeepAlive) -> Almost Good! >> 1. Setup the configuration.properties >> bin/signserver setproperties >> $PATH/qs_timestamp_configuration.properties >> 2. Reload worker >> bin/signserver reload 3 >> 3. Upload Certificate Chain . The Chain file is PEM formated and >> contains the TSA Certificate first and then the CA Certificate. >> bin/signserver uploadsignercertificatechain 3 GLOB $PATH/Chain.pem >> 4. Reload worker >> bin/signserver reload 3 >> 5. Get Status >> bin/signserver getstatus complete 3 >> >> When I call for getstatus on the timestamp worker, these are the two (2) >> messages I'm getting: >> >> (1) Stating that there is no signer certificate installed: >> >> Error: >> - No signer certificate >> >> (2) That there is a signer certificate available. >> The current configuration use the following signer certificate : >> Subject DN: CN=softsatsap11.pilotserver.com >> Serial number: d6ce9b6c073d0f2 >> Issuer DN: CN=DevLab,OU=PKICore,O=DevLab LLC,C=COM >> Valid from: 2015-02-25 15:25:15 AST >> Valid until: 2015-06-05 15:25:15 AST >> >> The timestamp worker never becomes Active. >> >> I have also tried uploading the signer certificate directly >> (bin/signserver uploadsignercertificate 3 GLOB $PATH/tsa.pem) and I >> still get the same results. >> >> Any light on this matter will be greatly appreciated. >> >> Thank you, >> Jenner >> > > Hi Jenner, > > I think you have only run "uploadsignercertificatechain" but you also > need to run "uploadsignercertifiate" with only the signer certificate > like this: > > $ bin/signserver uploadsignercertificatechain 3 GLOB $PATH/cert.pem Doh, I wrote the same thing again :) I meant like this: $ bin/signserver uploadsignercertificate 3 GLOB $PATH/cert.pem Then do reload to activate the change: $ bin/signserver reload 3 Cheers, Markus > > > > Cheers, > Markus > PrimeKey Solutions > > > PrimeKey Solutions offers a commercial EJBCA & SignServer support > subscription and training. Please see www.primekey.se or contact > in...@pr... for more information. > https://www.primekey.se/Services/Support/ > https://www.primekey.se/Services/Training/ > > |
|
From: Naldiello <nal...@gm...> - 2015-02-26 13:30:27
|
Hi Markus, I tried that but I'm still getting the same results. Jenner On Thu, 2015-02-26 at 14:27 +0100, Markus Kilås wrote: > On 02/26/2015 01:36 PM, Naldiello wrote: > > Hi, > > > > I was wondering if anyone can help figure out an error I'm getting on > > SignServer CE 3.6.2. > > > > I've been able to setup a Lab environment to get familiar and test both > > EJBCA and SignServer. I'm using softHSM for testing purposes and get it > > working on both servers. I got EJBCA CA and Sub-CA key store in softHSM, > > generated the CA certificates and CRLs are being issued. Just the basic > > setup. > > > > However, I have been working on setting up timestamp on SignServer and I > > keep getting the error "No signer certificate" when I run the command > > "bin/signserver getstatus complete <id>". Here are the steps I did to > > set it up: > > > > First Worker (CryptoToken) -> All Good! > > 1. Setup the configuration.properties > > bin/signserver setproperties > > $PATH/pkcs11-crypto-configuration.properties > > 2. Reload worker > > bin/signserver reload 1 > > 3. Activate CryptoToken > > bin/signserver activatecryptotoken 1 > > 4. Test CryptoToken > > bin/signserver testkey 1 > > > > First Worker (HSM KeepAlive) -> All Good! > > 1. Setup the configuration.properties > > bin/signserver setproperties > > $PATH/qs_hsmkeepalive_configuration.properties > > 2. Reload worker > > bin/signserver reload 2 > > > > First Worker (HSM KeepAlive) -> Almost Good! > > 1. Setup the configuration.properties > > bin/signserver setproperties > > $PATH/qs_timestamp_configuration.properties > > 2. Reload worker > > bin/signserver reload 3 > > 3. Upload Certificate Chain . The Chain file is PEM formated and > > contains the TSA Certificate first and then the CA Certificate. > > bin/signserver uploadsignercertificatechain 3 GLOB $PATH/Chain.pem > > 4. Reload worker > > bin/signserver reload 3 > > 5. Get Status > > bin/signserver getstatus complete 3 > > > > When I call for getstatus on the timestamp worker, these are the two (2) > > messages I'm getting: > > > > (1) Stating that there is no signer certificate installed: > > > > Error: > > - No signer certificate > > > > (2) That there is a signer certificate available. > > The current configuration use the following signer certificate : > > Subject DN: CN=softsatsap11.pilotserver.com > > Serial number: d6ce9b6c073d0f2 > > Issuer DN: CN=DevLab,OU=PKICore,O=DevLab LLC,C=COM > > Valid from: 2015-02-25 15:25:15 AST > > Valid until: 2015-06-05 15:25:15 AST > > > > The timestamp worker never becomes Active. > > > > I have also tried uploading the signer certificate directly > > (bin/signserver uploadsignercertificate 3 GLOB $PATH/tsa.pem) and I > > still get the same results. > > > > Any light on this matter will be greatly appreciated. > > > > Thank you, > > Jenner > > > > Hi Jenner, > > I think you have only run "uploadsignercertificatechain" but you also > need to run "uploadsignercertifiate" with only the signer certificate > like this: > > $ bin/signserver uploadsignercertificatechain 3 GLOB $PATH/cert.pem > > > > Cheers, > Markus > PrimeKey Solutions > > > PrimeKey Solutions offers a commercial EJBCA & SignServer support > subscription and training. Please see www.primekey.se or contact > in...@pr... for more information. > https://www.primekey.se/Services/Support/ > https://www.primekey.se/Services/Training/ > > > ------------------------------------------------------------------------------ > Dive into the World of Parallel Programming The Go Parallel Website, sponsored > by Intel and developed in partnership with Slashdot Media, is your hub for all > things parallel software development, from weekly thought leadership blogs to > news, videos, case studies, tutorials and more. Take a look and join the > conversation now. http://goparallel.sourceforge.net/ > _______________________________________________ > SignServer-develop mailing list > Sig...@li... > https://lists.sourceforge.net/lists/listinfo/signserver-develop |
|
From: Markus K. <ma...@pr...> - 2015-02-26 13:28:02
|
On 02/26/2015 01:36 PM, Naldiello wrote: > Hi, > > I was wondering if anyone can help figure out an error I'm getting on > SignServer CE 3.6.2. > > I've been able to setup a Lab environment to get familiar and test both > EJBCA and SignServer. I'm using softHSM for testing purposes and get it > working on both servers. I got EJBCA CA and Sub-CA key store in softHSM, > generated the CA certificates and CRLs are being issued. Just the basic > setup. > > However, I have been working on setting up timestamp on SignServer and I > keep getting the error "No signer certificate" when I run the command > "bin/signserver getstatus complete <id>". Here are the steps I did to > set it up: > > First Worker (CryptoToken) -> All Good! > 1. Setup the configuration.properties > bin/signserver setproperties > $PATH/pkcs11-crypto-configuration.properties > 2. Reload worker > bin/signserver reload 1 > 3. Activate CryptoToken > bin/signserver activatecryptotoken 1 > 4. Test CryptoToken > bin/signserver testkey 1 > > First Worker (HSM KeepAlive) -> All Good! > 1. Setup the configuration.properties > bin/signserver setproperties > $PATH/qs_hsmkeepalive_configuration.properties > 2. Reload worker > bin/signserver reload 2 > > First Worker (HSM KeepAlive) -> Almost Good! > 1. Setup the configuration.properties > bin/signserver setproperties > $PATH/qs_timestamp_configuration.properties > 2. Reload worker > bin/signserver reload 3 > 3. Upload Certificate Chain . The Chain file is PEM formated and > contains the TSA Certificate first and then the CA Certificate. > bin/signserver uploadsignercertificatechain 3 GLOB $PATH/Chain.pem > 4. Reload worker > bin/signserver reload 3 > 5. Get Status > bin/signserver getstatus complete 3 > > When I call for getstatus on the timestamp worker, these are the two (2) > messages I'm getting: > > (1) Stating that there is no signer certificate installed: > > Error: > - No signer certificate > > (2) That there is a signer certificate available. > The current configuration use the following signer certificate : > Subject DN: CN=softsatsap11.pilotserver.com > Serial number: d6ce9b6c073d0f2 > Issuer DN: CN=DevLab,OU=PKICore,O=DevLab LLC,C=COM > Valid from: 2015-02-25 15:25:15 AST > Valid until: 2015-06-05 15:25:15 AST > > The timestamp worker never becomes Active. > > I have also tried uploading the signer certificate directly > (bin/signserver uploadsignercertificate 3 GLOB $PATH/tsa.pem) and I > still get the same results. > > Any light on this matter will be greatly appreciated. > > Thank you, > Jenner > Hi Jenner, I think you have only run "uploadsignercertificatechain" but you also need to run "uploadsignercertifiate" with only the signer certificate like this: $ bin/signserver uploadsignercertificatechain 3 GLOB $PATH/cert.pem Cheers, Markus PrimeKey Solutions PrimeKey Solutions offers a commercial EJBCA & SignServer support subscription and training. Please see www.primekey.se or contact in...@pr... for more information. https://www.primekey.se/Services/Support/ https://www.primekey.se/Services/Training/ |
|
From: Naldiello <nal...@gm...> - 2015-02-26 12:36:44
|
Hi,
I was wondering if anyone can help figure out an error I'm getting on
SignServer CE 3.6.2.
I've been able to setup a Lab environment to get familiar and test both
EJBCA and SignServer. I'm using softHSM for testing purposes and get it
working on both servers. I got EJBCA CA and Sub-CA key store in softHSM,
generated the CA certificates and CRLs are being issued. Just the basic
setup.
However, I have been working on setting up timestamp on SignServer and I
keep getting the error "No signer certificate" when I run the command
"bin/signserver getstatus complete <id>". Here are the steps I did to
set it up:
First Worker (CryptoToken) -> All Good!
1. Setup the configuration.properties
bin/signserver setproperties
$PATH/pkcs11-crypto-configuration.properties
2. Reload worker
bin/signserver reload 1
3. Activate CryptoToken
bin/signserver activatecryptotoken 1
4. Test CryptoToken
bin/signserver testkey 1
First Worker (HSM KeepAlive) -> All Good!
1. Setup the configuration.properties
bin/signserver setproperties
$PATH/qs_hsmkeepalive_configuration.properties
2. Reload worker
bin/signserver reload 2
First Worker (HSM KeepAlive) -> Almost Good!
1. Setup the configuration.properties
bin/signserver setproperties
$PATH/qs_timestamp_configuration.properties
2. Reload worker
bin/signserver reload 3
3. Upload Certificate Chain . The Chain file is PEM formated and
contains the TSA Certificate first and then the CA Certificate.
bin/signserver uploadsignercertificatechain 3 GLOB
$PATH/Chain.pem
4. Reload worker
bin/signserver reload 3
5. Get Status
bin/signserver getstatus complete 3
When I call for getstatus on the timestamp worker, these are the two (2)
messages I'm getting:
(1) Stating that there is no signer certificate installed:
Error:
- No signer certificate
(2) That there is a signer certificate available.
The current configuration use the following signer certificate :
Subject DN: CN=softsatsap11.pilotserver.com
Serial number: d6ce9b6c073d0f2
Issuer DN: CN=DevLab,OU=PKICore,O=DevLab LLC,C=COM
Valid from: 2015-02-25 15:25:15 AST
Valid until: 2015-06-05 15:25:15 AST
The timestamp worker never becomes Active.
I have also tried uploading the signer certificate directly
(bin/signserver uploadsignercertificate 3 GLOB $PATH/tsa.pem) and I
still get the same results.
Any light on this matter will be greatly appreciated.
Thank you,
Jenner
|
|
From: Markus K. <ma...@pr...> - 2015-02-12 13:24:47
|
Hi Jean, For SignServer the recommendation is to set up multiple independent servers. You can then have some sort of load balancers in front. There is a special URL (check in the manual for Health check) that can be checked to see that a node is operational. It is also possible to have multiple nodes share the same database. You then need to make sure that database is highly available also of course. This is often the set up for EJBCA as it often not possible to have completely independent nodes (ie all CA nodes needs to share the same database with revocation information and certificate serial numbers etc). Cheers, Markus PrimeKey Solutions offers a commercial EJBCA & SignServer support subscription and training. Please see www.primekey.se or contact in...@pr... for more information. https://www.primekey.se/Services/Support/ https://www.primekey.se/Services/Training/ On 02/12/2015 02:07 PM, Jean Marc wrote: > Hi, > > > > Do you have any tips to make high availability with signserver and ejbca ? > > I am using glassfish 2.1.1 and mysql. > > I know there are some tips on the website but has someone already done > that ? > > Thanks ! > > > Jean > |
|
From: Jean M. <jm...@ya...> - 2015-02-12 13:11:24
|
Hi,
Do you have any tips to make high availability with signserver and ejbca ?
I am using glassfish 2.1.1 and mysql.
I know there are some tips on the website but has someone already done that ?
Thanks !
Jean
|
|
From: Markus K. <ma...@pr...> - 2015-01-22 13:28:24
|
(Please respond to the list so that everybody can benefit from the discussion) On 01/20/2015 10:24 AM, Mauro Fasolo wrote: > Hi Markus, > >> Not really. A worker must exist first to be able to process the request. >> You could in theory create workers using the AdminWS interface. But >> remember that workers are just configurations. They are not tied to any >> process/thread in the application server, that is completely separate >> issue. So I don't see any reason to have them automagically created. Or >> maybe you have some special use case? > > > I don’t need to configure a worker on the fly, because a worker > configuration as you said needs to be configured before it starts. > I just want to know if the whole mechanism is fully automated. Do we > need to start a worker on-demand when a WS client request is received? > Or does the WS client request needs a worker already running? No need to do anything on demand. If the worker was active since before (ie has a correct configuration) and the HSM is available it will serve the requests. > When do we need to start workers? You configure workers and give them a name. If the worker is using an HSM or keystore you need to provide that to "activate" the worker. After that the worker is fully operational. > Am asking this because otherwise i don’t really understand what is the > best way to monitor workers processes. What happens if a worker crashes? For monitoring you can call the Health check page: http://signserver.org/manual/complete.en.html#Healthcheck It will return "ALLOK" if all workers are active which typically means: - They are properly configured - The CryptoToken is accessible - The database is accessible > > I’m asking this because after this testing phase we would like to buy a > SignServer boxed solution and i would like to know if we need to monitor > the system behavior and periodically check the whole system status. Can > we let the system run with no human intervention at all? It can run mostly without intervention, except for: - Activating CryptoTokens after application starts, ie providing password (unless stored in configuration) - Renewing certificates when they expire - Restarting/re-activate it case of network issues, ie if network HSM or database is used. You can send a mail to sa...@pr... to get more details about what solutions we can offer. Cheers, Markus PrimeKey Solutions > > Greetings > Mauro > >> Il giorno 19/gen/2015, alle ore 16:32, Markus Kilås >> <ma...@pr... <mailto:ma...@pr...>> ha scritto: >> >> On 01/19/2015 12:20 PM, Mauro Fasolo wrote: >>> Hi everyone, >> >> Hi Mauro, >> >>> >>> I firstly apologize declaring that i’m a lazy guy so …. shame on me. >>> I’m trying to build a fully working production SignServer enviroment. >>> I Would like to use SignServer API to integrate with internal application >>> (http://www.signserver.org/manual/integration.html) >>> >>> Currently I had performed a fully function installation of all >>> SignServer system so using workers (starting 'em from command-line) i >>> can perform a complete signing process on document kinds handled by >>> SignServer. >>> >>> I would like to know what are*best practices* to work with workers in >>> production environment. >>> 1) Am i intended to launch them manually, for example with a particular >>> name to use in WS params ? >> >> Workers are configurations for how to perform the signing operations. >> >> You need to configure different workers to support different types of >> documents but you can also configure different works to offer signatures >> configured differently. That could be different signature algorithms, >> with or without time-stamping, using different keys/certificates etc etc. >> >> This configurations are typically statically created and then the >> clients are configured with which worker name to call, for instance in >> the WS params. >> >> >>> 2) Is it possible to automagically starts a worker during HTTP WS >>> request (so associate worker starts to a HTTP response process) ? >> >> Not really. A worker must exist first to be able to process the request. >> You could in theory create workers using the AdminWS interface. But >> remember that workers are just configurations. They are not tied to any >> process/thread in the application server, that is completely separate >> issue. So I don't see any reason to have them automagically created. Or >> maybe you have some special use case? >> >> >> >> Cheers, >> Markus >> PrimeKey Solutions >> >>> >>> As I said before i’m too lazy to find out inside huge SignServer >>> documentation (>_<) >>> I beg your pardon for my rusty english >>> >>> Thx >>> >>> >>> ------------------------------------------------------------------------------ >> >> ----- >> PrimeKey Solutions offers a commercial EJBCA & SignServer support >> subscription and training. Please see www.primekey.se >> <http://www.primekey.se/> or contact >> in...@pr... <mailto:in...@pr...> for more information. >> https://www.primekey.se/Services/Support/ >> https://www.primekey.se/Services/Training/ > |
|
From: Markus K. <ma...@pr...> - 2015-01-19 15:32:34
|
On 01/19/2015 12:20 PM, Mauro Fasolo wrote: > Hi everyone, Hi Mauro, > > I firstly apologize declaring that i’m a lazy guy so …. shame on me. > I’m trying to build a fully working production SignServer enviroment. > I Would like to use SignServer API to integrate with internal application > (http://www.signserver.org/manual/integration.html) > > Currently I had performed a fully function installation of all > SignServer system so using workers (starting 'em from command-line) i > can perform a complete signing process on document kinds handled by > SignServer. > > I would like to know what are*best practices* to work with workers in > production environment. > 1) Am i intended to launch them manually, for example with a particular > name to use in WS params ? Workers are configurations for how to perform the signing operations. You need to configure different workers to support different types of documents but you can also configure different works to offer signatures configured differently. That could be different signature algorithms, with or without time-stamping, using different keys/certificates etc etc. This configurations are typically statically created and then the clients are configured with which worker name to call, for instance in the WS params. > 2) Is it possible to automagically starts a worker during HTTP WS > request (so associate worker starts to a HTTP response process) ? Not really. A worker must exist first to be able to process the request. You could in theory create workers using the AdminWS interface. But remember that workers are just configurations. They are not tied to any process/thread in the application server, that is completely separate issue. So I don't see any reason to have them automagically created. Or maybe you have some special use case? Cheers, Markus PrimeKey Solutions > > As I said before i’m too lazy to find out inside huge SignServer > documentation (>_<) > I beg your pardon for my rusty english > > Thx > > > ------------------------------------------------------------------------------ ----- PrimeKey Solutions offers a commercial EJBCA & SignServer support subscription and training. Please see www.primekey.se or contact in...@pr... for more information. https://www.primekey.se/Services/Support/ https://www.primekey.se/Services/Training/ |
|
From: Mauro F. <fa...@co...> - 2015-01-19 11:36:02
|
Hi everyone, I firstly apologize declaring that i’m a lazy guy so …. shame on me. I’m trying to build a fully working production SignServer enviroment. I Would like to use SignServer API to integrate with internal application (http://www.signserver.org/manual/integration.html) Currently I had performed a fully function installation of all SignServer system so using workers (starting 'em from command-line) i can perform a complete signing process on document kinds handled by SignServer. I would like to know what are best practices to work with workers in production environment. 1) Am i intended to launch them manually, for example with a particular name to use in WS params ? 2) Is it possible to automagically starts a worker during HTTP WS request (so associate worker starts to a HTTP response process) ? As I said before i’m too lazy to find out inside huge SignServer documentation (>_<) I beg your pardon for my rusty english Thx |
|
From: Tomas G. <to...@pr...> - 2014-12-22 10:54:48
|
Perhaps this has been said already but... There is a new blog post out describing improved crypto token configuration in SignServer 3.6. http://blog.ejbca.org/2014/12/improved-crypto-token-configuration-and.html Cheers, Tomas |
|
From: Markus K. <ma...@pr...> - 2014-11-28 08:48:50
|
XML processing workers in SignServer has been discovered to be vulnerable to an XML External Entity attack. Systems configured with the affected modules could allow an attacker to access local files, bypass certain protection mechanisms or cause high CPU usage. Users using any of the following workers are recommended to upgrade to the latest version of SignServer or to disable access to those workers from untrusted users: - XML signer and validator - XAdES signer and validator - OOXML signer - ODF signer Note that installations where those workers are not configured are not affected by this vulnerability. This issue has been resolved in SignServer 3.6.2 by disallowing document type definitions in user supplied XML documents. For upgrade instructions, please see doc/UPGRADE.txt. Regards, PrimeKey SignServer Team |
|
From: Markus K. <ma...@pr...> - 2014-11-28 08:41:18
|
The PrimeKey SignServer team is happy to announce the release of SignServer 3.6.2 community and enterprise editions! This maintenance release resolves two bugs including one security fix. In total 5 issues were resolved, of which the most noteworthy are: Bug fixes: - Security issue in XML workers - Regression: Menu command for activating workers not working properly in GUI Improvements: - TimeMonitor now honours rate limiting messages - Updated list of 3rd party dependencies and licenses Read the changelog in our issue tracker for full details: https://jira.primekey.se/browse/DSS Further information regarding the security issue will be available shortly in a separate mail to this mailing list. Regards, PrimeKey SignServer Team |
|
From: Markus K. <ma...@pr...> - 2014-10-30 15:46:02
|
The PrimeKey SignServer team is happy to announce the release of SignServer 3.6.1 community and enterprise editions! This maintenance release resolves several minor issues and introduces one new feature. In total 20 issues were resolved, of which the most noteworthy are: New features and improvements: - Added detached signature option to CMSSigner (contributed by Pablo Ruiz García) - Improved documentation on how to specify issuer DN for clients and administrators - Improved error checking for signer certificate extended key usage at configuration time for TimeStampSigner and MSAuthCodeTimeStampSigner Bug fixes: - Serial numbers for clients and administrators can now be entered with leading zeros and either letter-case for hexadecimal letters - Client certificate authorizer can now handle issuer DN with characters that need escaping - Fixed an issue where timestamp responses were double base64-encoded in the log - Fixed KeyStoreCryptoToken to initialize key usage counter when no password is specified in configuration Read the changelog in our issue tracker for full details: https://jira.primekey.se/browse/DSS Regards, PrimeKey SignServer Team |
|
From: Markus K. <ma...@pr...> - 2014-09-30 13:28:48
|
The PrimeKey SignServer team is happy to announce the release of SignServer 3.6.0 community and enterprise editions! This release brings exciting new features such as independent worker and crypto token configuration and support for querying the database archive from the GUI. This is a major release with 25 issues resolved, the most noteworthy of which are: New features and improvements: - Independent worker and crypto token configuration - Querying of database archive from WS and GUI - Support for specifying HSM slot by label - HSM keep alive service - Underlying CESeCore library upgraded - Separation between community and enterprise editions - New application: SignServer TimeMonitor (enterprise edition only) Read the full changelog in our issue tracker for full details: https://jira.primekey.se/browse/DSS Regards, PrimeKey SignServer Team |
|
From: Antoine L. <ant...@yo...> - 2014-09-19 17:16:28
|
Hi Markus, To close this discussion, you were right and I can not change it because it is a Java Security Class. Have a nice day ! Antoine Le 04/06/2014 10:16, Markus Kilås a écrit : > On 2014-05-29 21:35, Antoine Louiset wrote: >> Hi Markus ! >> >> It works now. Thanks a lot, when the keys are already generated, the >> signatures are immediate. >> >> The key generation is quite long and it seems that it depends to the >> number of keys present in the HSM. In the case of PKCS11Cryptotoken, the >> key generation is done by Cesecore. >> >> Do you know if I could accelerate this process ? Do you know if keys are >> reload systematically just for generation ? Could the shared library >> responsible of that ? > I made a quick look through the code, see below some of the noteworthy > methods called. The only think I discovered that would cause the time to > increase with an increased number of keys is in > P11KeyStore.engineSetEntry where it iterates over existing keys to check > that the new key alias does not already exist. Not sure if this could be > the reason though. I could also have missed something. > > --- > cesecore.PKCS11CryptoToken.generateKeyPair(keySpec,alias) > -> cesecore.KeyStoreTools.generateKeyPair(keySpec, alias); > KeyPairGenerator.getInstance(algorithm, this.providerName) > kpg.initialize(spec); > -> generateKeyPair(kpg, keyEntryName, sigAlg); > KeyPair keyPair = kpg.generateKeyPair() > -> setKeyEntry(keyEntryName, keyPair.getPrivate(),chain); > KeyStore.setKeyEntry(alias, key, null, chain); > -> keyStoreSpi.engineSetKeyEntry(alias,key,password,chain); > -> P11KeyStore.engineSetEntry(alias, entry, PasswordProt); > Iterates over existing aliases. > -> storePkey(alias, pke) > -> storeChain(alias, X509Certificate[]); > --- > > Let me know if you make some more progress. > > > Cheers, > Markus > >> Thanks ! >> >> >> Antoine >> >> Le 29/04/2014 11:48, Antoine Louiset a écrit : >>> Call activation method of the cryptotoken > > |
|
From: Markus K. <ma...@pr...> - 2014-07-08 11:38:27
|
We are pleased to announce the release of SignServer 3.5.0. This release resolves several minor issues and brings improved performance in some areas as well as adds some new features such as SHA-2 support in the PDF signer. This is a maintenance release with 17 issues resolved, the most noteworthy of which are: New features and improvements: - Support for SHA-2 hash algorithms in PDF Signer. - Support for using the worker servlet when running the stress test tool. - Checksums using SHA256 are now available for the releases. - System tests are now included in the binary distribution. Bug fixes: - PDF and XAdES signers could cause deadlocks under high load when using a local TSA. - Ant target for copying modules was not working for custom sub modules. - Updated Apache Santuario (XML Security) for a security and a performance issue. The security issue might open up the server for a possible denial of service attack if the XML Validator is configured and exposed on a public network. Users running the XML Validator are recommended to upgrade to SignServer 3.5.2 and to see the included release notes for further details. Read the full changelog for details (https://jira.primekey.se/browse/DSS?report=com.atlassian.jira.plugin.system.project:changelog-panel#selectedTab=com.atlassian.jira.plugin.system.project%3Achangelog-panel). Regards, PrimeKey SignServer Team |