Hi Dmitry,
On Tue, Jan 20, 2009 at 04:47:30PM +0500, Dmitry Golomolzin wrote:
> Unfortunately, we can't see CA certificate via web interface after those
> actions ("... your CA should be up and running. You can check that using the
> web interface - use the Download > CA certificates menu to see if your CA is
> listed as usable."), but we can see it via "openxpkiadm certificate list"
> command:
>
> Certificates in I18N_OPENXPKI_DEPLOYMENT_TEST_DUMMY_CA:
>
> Identifier: cQPyP2spBaYEALeKfOyimVQ6kY8
> Alias:
> CYBORG
Is this alias configured in your config.xml as well?
> When we uncomment "<!-- <required_shares>1</required_shares> -->" line, then
> "EVAL_ERROR: I18N_OPENXPKI_XML_CACHE_GET_XPATH_COUNT_NOTHING_FOUND; __XPATH__
> => pki_realm/0/common/0/secret/0/group/0/method/0/required_shares Secret"
> error will disappear... but it won't affect the presence of CA certificate in
> the web interface.
OK, so the key part looks good, I'd assume the problem is with the CA
certificate not being found on startup.
> Is it possible to check presence and validity of CA certificate in a
> different way (not via "openxpkiadm certificate list"/web interface)?
Yes, after startup you should have lines similar to these in your
openxpki.log:
2009/01/20 14:08:19 openxpki.system.INFO [OpenXPKI::Server::Init (156)] Attached
CA token for issuing CA 'testdummyca1' of PKI realm 'I18N_OPENXPKI_DEPLOYMENT_T
EST_DUMMY_CA'
2009/01/20 14:08:19 openxpki.system.INFO [OpenXPKI::Server::Init (156)] Issuing
CA testdummyca1 of PKI realm 'I18N_OPENXPKI_DEPLOYMENT_TEST_DUMMY_CA' validity i
s 2006-08-31 11:05:00 - 2011-08-30 11:05:00
2009/01/20 14:08:19 openxpki.system.INFO [OpenXPKI::Server::Init (156)] Identifi
ed 2 issuing CAs for PKI realm 'I18N_OPENXPKI_DEPLOYMENT_TEST_DUMMY_CA'
HTH,
Alex
--
Dipl.-Math. Alexander Klink | IT-Security Engineer
[email protected] | working @ urn:oid:1.3.6.1.4.1.11417
------------------------------------------------------------------------------
This SF.net email is sponsored by:
SourcForge Community
SourceForge wants to tell your story.
http://p.sf.net/sfu/sf-spreadtheword
_______________________________________________
OpenXPKI-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openxpki-users