Hi, > Thank you very much, how always to you Oliver! > > The only error that I detect is the openxpki.log and it is the following: > 2021/08/05 11:02:13 ERROR Could not find token alias by group; __group__ => > ca-signer, __noafter__ => 2101557733, __notbefore__ => 1628172133, > __pki_realm__ => XXXXXX > [pid=22660|sid=PLa1|wftype=certificate_signing_request_v2|wfid=327935] > 2021/08/05 11:02:13 ERROR Caught exception from action: [Generic exception]; > reset workflow to old state 'APPROVED_GLOBAL_PERSIST_CSR_0' > [pid=22660|sid=PLa1|wftype=certificate_signing_request_v2|wfid=327935] > > what should I do?
Looks very much like your system cannot find a suitable Issuing CA because the remaining validity of the current Issuing CA is not capable of issuing the requested end entity certificate validity. You should have prepared for this situation by issuing a rollover CA Certificate and configuring it in your system. This operation can be done without downtime, and the system will seamlessly roll over to the new Issuing CA if this is done properly. Cheers Martin _______________________________________________ OpenXPKI-users mailing list OpenXPKI-users@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/openxpki-users