baizw wrote:

Hi, all,


I appreciate your time and answer in advance.

I installed openca 0.9.1.1 on linux 7.3 os, ca server and ra server are in different pcs.

My configuration is as following:
CA server: linux 7.3 + ca + mysql + sendmail + apache web server
dns: ca.sso.xxxxxx.com
RA server: linux 7.3 + ca + mysql + sendmail + apache web server+ openldap 2.0.23
dns:ra.sso.xxxxxxx.com

then i create a basic request, and approve it by RA, but signed it not worked,
the error message is as following:

Request Approved

Description: Certificate Request Successfully approved.

Signature: Cannot find the certificate with the matching serial in the database!

1. Please look into you mysql database on the RA and search in the table "certificate" for the certificate which you use to sign the request.


2. If the certificate is present then there is a real problem. If this is the case then please go to OPENCADIR/etc/database/DBI.conf and set DEBUG to 1. After this you can see the debugging output of the database module. Please send this output to the list. The interesting event is the KEY which getItem uses to load the certificate which was used to sign the request.

The problem is in crypto-utils.lib error 6303 and the getItem call some lines above.

Best regards

Michael
--
-------------------------------------------------------------------
Michael Bell                   Email (private): [EMAIL PROTECTED]
Rechenzentrum - Datacenter     Email:  [EMAIL PROTECTED]
Humboldt-University of Berlin  Tel.: +49 (0)30-2093 2482
Unter den Linden 6             Fax:  +49 (0)30-2093 2704
10099 Berlin
Germany                                       http://www.openca.org



-------------------------------------------------------
This SF.net email is sponsored by:Crypto Challenge is now open! Get cracking and register here for some mind boggling fun and the chance of winning an Apple iPod:
http://ads.sourceforge.net/cgi-bin/redirect.pl?thaw0031en
_______________________________________________
Openca-Users mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/openca-users

Reply via email to