>this indicate that the openssl command to actually create the 
>certificate crashes. I have seen this some times in the past when using 
>non-latin chars or special attributes in the certificate.

In order to create initials certificate, i used the script named 
sampleconfig.sh. The only modification that i've done is the validity of the 
ROOT certificate and the CA ONE certificate.
I don't use special characters or attributes


>Can you provide me access to your database or just di a mysqldump and 
>send it by private mail or but it somewhere to download (I assume you 
>are not running that PKI in production already)

I  redo the configuration on OpenxPKI following the QuickStart without 
modification of the sampleconfig script. I have the same error, can you send me 
a private address in order to send you the database ?

 > Is it possible to use a certificate with his private key generate by my
> PKI server instead of using  an unsigned certificate generated on the
> "client" ? I try to do that but when i do the sscep command, i have an
> error :
 
>What certificate are you talking about?

In order to enrol my client on the PKI server, i want to use enrol-certificates 
delivered by the OpenxPKI server. So it avoid to use unsigned certificates 
generated on the client.





Hello Nicolas,
 
Am 27.04.2015 um 15:26 schrieb Nicolas Grelliere:> But now i'm 
encountering a problem when i try to configure an SSCEP
 > client. If i follow the quick start, by generating a certificate with a
 > private key and retrieving CA certificate with the sscep command, when i
 > want to click on "Add Authentification" on the web interface, the
 > following message appeared : "I18N_OPENXPKI_TOOLKIT_COMMAND_FAILED;
 > __COMMAND__ => OpenXPKI::Crypto::Backend::OpenSSL::Command::issue_cert;
 > __ERRVAL__ => I18N_OPENXPKI_CRYPTO_CLI_EXECUTE_FAILED; __EXIT_STATUS__
 > => 256"
 >
 
this indicate that the openssl command to actually create the 
certificate crashes. I have seen this some times in the past when using 
non-latin chars or special attributes in the certificate.
 
Can you provide me access to your database or just di a mysqldump and 
send it by private mail or but it somewhere to download (I assume you 
are not running that PKI in production already)
 
 > Is it possible to use a certificate with his private key generate by my
> PKI server instead of using  an unsigned certificate generated on the
> "client" ? I try to do that but when i do the sscep command, i have an
> error :
 
What certificate are you talking about?
 
Oliver
-- 
Protect your environment -  close windows and adopt a penguin!
 

------------------------------------------------------------------------------
One dashboard for servers and applications across Physical-Virtual-Cloud 
Widest out-of-the-box monitoring support with 50+ applications
Performance metrics, stats and reports that give you Actionable Insights
Deep dive visibility with transaction tracing using APM Insight.
http://ad.doubleclick.net/ddm/clk/290420510;117567292;y
_______________________________________________
OpenXPKI-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openxpki-users                     
                  
------------------------------------------------------------------------------
One dashboard for servers and applications across Physical-Virtual-Cloud 
Widest out-of-the-box monitoring support with 50+ applications
Performance metrics, stats and reports that give you Actionable Insights
Deep dive visibility with transaction tracing using APM Insight.
http://ad.doubleclick.net/ddm/clk/290420510;117567292;y
_______________________________________________
OpenXPKI-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openxpki-users

Reply via email to