Hello

I have the follwoing problem:

The ca certificate is not getting online in the openxpki.

For the private key I used the same Password as DataVault and saved it to the 
crypto.yaml

The import of the certificate looks good:
Input:
openxpkiadm alias --realm docscf --token certsign --file ca/subca.cert -key 
ca/privkey_subca.pem
Output:
Successfully wrote key to datapool with key 'ca-signer-1'
Successfully wrote alias:
  Alias     : ca-signer-1
  Identifier: -VqlqCwcePkgAk_gbWmQN4EL6A0
  NotBefore : 2021-06-08 13:43:49
  NotAfter  : 2027-06-07 13:43:49


Token is certsign, looking for root...
Creating alias for root ca:
  Alias     : root-1
  Identifier: -VqlqCwcePkgAk_gbWmQN4EL6A0
  NotBefore : 2021-06-08 13:43:49
  NotAfter  : 2027-06-07 13:43:49

But:
openxpkicli is_token_usable --realm=democa --arg alias=ca-signer-1

returns <undef>

As I understand the privat key will be saved in de vault and has not to be at 
local/keys/docscf/ but sure I also tried this.

Is there a step I miss?

Elias




Elias Steiner

SBB AG
Informatik / CYBER
Poststrasse 6 - Ostermundigen, 3000 Bern 65
Mobil +41 77 257 07 03
[email protected] / www.sbb.ch


_______________________________________________
OpenXPKI-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openxpki-users

Reply via email to