Re: [Bacula-users] need help (step by step) for setting up certificates

2011-07-24 Thread scar
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Mike Hobbs @ 07/24/2011 06:15 PM: > On 7/23/2011 3:56 PM, scar wrote: >> -BEGIN PGP SIGNED MESSAGE- >> i want to set up certificates for secure communication between my >> director and clients. i've read several guides including the info on

Re: [Bacula-users] need help (step by step) for setting up certificates

2011-07-24 Thread Mark
Hi, > my certs now have the following permissions: > > - -rw-r--r-- 1 root bacula 3195 2011-07-23 16:53 home1.crt > - -r 1 bacula bacula 887 2011-07-23 16:53 home1.key > - -rw-r--r-- 1 root bacula 1359 2011-07-23 16:52 myca.crt > > so bacula should be able to read them all now, yet i

Re: [Bacula-users] need help (step by step) for setting up certificates

2011-07-24 Thread Mike Hobbs
On 7/23/2011 3:56 PM, scar wrote: > -BEGIN PGP SIGNED MESSAGE- > i want to set up certificates for secure communication between my > director and clients. i've read several guides including the info on > bacula.org, but i am so confused how to do it. This is not my website, but I configur

Re: [Bacula-users] need help (step by step) for setting up certificates

2011-07-24 Thread scar
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Craig White @ 07/24/2011 10:14 AM: > On Sun, 2011-07-24 at 09:29 -0700, scar wrote: >> frankly i don't see why bconsole, which was able to be run fine under >> normal user privileges, now needs to be run as root to access the >> private key. > >

Re: [Bacula-users] need help (step by step) for setting up certificates

2011-07-24 Thread Craig White
On Sun, 2011-07-24 at 09:29 -0700, scar wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > Ben Walton @ 07/24/2011 05:22 AM: > > Excerpts from scar's message of Sun Jul 24 00:12:30 -0400 2011: > > > >> so i tried adding `TLS Allowed CN = "home1"` and still get the same > >> error. ho

Re: [Bacula-users] need help (step by step) for setting up certificates

2011-07-24 Thread scar
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Ben Walton @ 07/24/2011 05:22 AM: > Excerpts from scar's message of Sun Jul 24 00:12:30 -0400 2011: > >> so i tried adding `TLS Allowed CN = "home1"` and still get the same >> error. however, i tried using the `-d 99` switch for bconsole and >> it

Re: [Bacula-users] need help (step by step) for setting up certificates

2011-07-24 Thread scar
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Ben Walton @ 07/24/2011 05:22 AM: > Excerpts from scar's message of Sun Jul 24 00:12:30 -0400 2011: > >> so i tried adding `TLS Allowed CN = "home1"` and still get the same >> error. however, i tried using the `-d 99` switch for bconsole and >> it

Re: [Bacula-users] need help (step by step) for setting up certificates

2011-07-24 Thread Ben Walton
Excerpts from scar's message of Sun Jul 24 00:12:30 -0400 2011: > so i tried adding `TLS Allowed CN = "home1"` and still get the same > error. however, i tried using the `-d 99` switch for bconsole and > it reveals something helpful: You need to make sure that this parameter exactly matches what

Re: [Bacula-users] need help (step by step) for setting up certificates

2011-07-23 Thread scar
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Mike Hobbs @ 07/23/2011 06:32 PM: > On 7/23/2011 8:38 PM, scar wrote: >> this is what i have in home1.bacula-dir.conf: >> >> Director { >>Name = home1-dir >>DirAddress = home1.local >>... >>TLS Enable = yes >>TLS Require = yes >>

Re: [Bacula-users] need help (step by step) for setting up certificates

2011-07-23 Thread Mike Hobbs
On 7/23/2011 8:38 PM, scar wrote: > this is what i have in home1.bacula-dir.conf: > > Director { >Name = home1-dir >DirAddress = home1.local >... >TLS Enable = yes >TLS Require = yes >TLS Verify Peer = yes >TLS CA Certificate File = /etc/bacula/myca.crt >TLS Certific

Re: [Bacula-users] need help (step by step) for setting up certificates

2011-07-23 Thread scar
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Ben Walton @ 07/23/2011 02:01 PM: > Excerpts from scar's message of Sat Jul 23 15:56:53 -0400 2011: > >> i think what is confusing me the most is what to use for CN, but i >> am generally puzzled as to how to generate the certs properly in >> genera

Re: [Bacula-users] need help (step by step) for setting up certificates

2011-07-23 Thread Ben Walton
Excerpts from scar's message of Sat Jul 23 15:56:53 -0400 2011: > i think what is confusing me the most is what to use for CN, but i > am generally puzzled as to how to generate the certs properly in > general. i've got TinyCA installed and i created a CA, what's next? Generally speaking, the CN

[Bacula-users] need help (step by step) for setting up certificates

2011-07-23 Thread scar
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 i want to set up certificates for secure communication between my director and clients. i've read several guides including the info on bacula.org, but i am so confused how to do it. i currently have 4 machines i want backed up, two are at home and