Michael,

I tried it several times, however the email address is not detected. See example below.

Another problem was regarding a Web server certificate. Following the instructions from the OpenCA guide I create the RA Web server certificate and I provide email address and DNS info. However, when I generate the certificate it doesn't have the email address in it. It says email address: N/A. This causes an error when that certificate is imported in LDAP. Namely error 21.

"Certificate 9 FAILED (error 21: LDAP-add failed: mail: value #0 invalid per syntax)"


OpenCA::X509 should detect the emailaddress in the subject alternative name. Does the certificate contain the emailaddress in it's subject alternative name? (If yes, then it is a bug in OpenCA::X509 or ldap-utils.lib.)


The certificate contains the email address in the subject alternative name, as follows:
*Subject Alternative Name:* DNS:ra.ritca.edu;email:[EMAIL PROTECTED]



I also tried to put a space after the colon, but the result is the same....


*Subject Alternative Name:* DNS:ra.ritca.edu; email:[EMAIL PROTECTED]


When I click to see the certificate through OpenCA, the email address appears as n/a.


What should I do?

Nicholas



-------------------------------------------------------
This SF.Net email sponsored by: Free pre-built ASP.NET sites including
Data Reports, E-commerce, Portals, and Forums are available now.
Download today and enter to win an XBOX or Visual Studio .NET.
http://aspnet.click-url.com/go/psa00100006ave/direct;at.asp_061203_01/01
_______________________________________________
Openca-Users mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/openca-users

Reply via email to