Hi,

> Thank you very much, how always to you Oliver!
> 
> The only error that I detect is the openxpki.log and it is the following:
> 2021/08/05 11:02:13 ERROR Could not find token alias by group; __group__ => 
> ca-signer, __noafter__ => 2101557733, __notbefore__ => 1628172133, 
> __pki_realm__ => XXXXXX 
> [pid=22660|sid=PLa1|wftype=certificate_signing_request_v2|wfid=327935]
> 2021/08/05 11:02:13 ERROR Caught exception from action: [Generic exception]; 
> reset workflow to old state 'APPROVED_GLOBAL_PERSIST_CSR_0' 
> [pid=22660|sid=PLa1|wftype=certificate_signing_request_v2|wfid=327935]
> 
> what should I do?


Looks very much like your system cannot find a suitable Issuing CA because the 
remaining validity of the current Issuing CA is not capable of issuing the 
requested end entity certificate validity. You should have prepared for this 
situation by issuing a rollover CA Certificate and configuring it in your 
system. This operation can be done without downtime, and the system will 
seamlessly roll over to the new Issuing CA if this is done properly.

Cheers

Martin



_______________________________________________
OpenXPKI-users mailing list
OpenXPKI-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/openxpki-users

Reply via email to