[Freeipa-users] Re: ECC keypair generation failed with `ipa-server-instal` on HSM

2019-05-28 Thread チョーチュアン via FreeIPA-users
Thanks for the feed, and yes, I have the RSA CA working apart from a negotiation error. On Wed, May 29, 2019 at 12:11 AM Alexander Bokovoy wrote: > On ti, 28 touko 2019, Rob Crittenden via FreeIPA-users wrote: > >チョーチュアン via FreeIPA-users wrote: > >> Hello, > >&

[Freeipa-users] ECC keypair generation failed with `ipa-server-instal` on HSM

2019-05-27 Thread チョーチュアン via FreeIPA-users
Hello, Recently I've been experimenting on HSM with FreeIPA, I got stuck at the CA generation, but it's a separate issue. I somehow achieve a successful key generation on HSM with default key_algorimth/size/ settings. RSA 3072/2048 keys showed up on the HSM even after a failed CA installation but

[Freeipa-users] Statues of the HSM support?

2019-05-24 Thread チョーチュアン via FreeIPA-users
Hi all, I just bought a Nitrokey HSM and trying to set it up with the Freeipa; I'm not sure it's quite supported yet. `ipa-server-install` aborted everytime during CA configuration, reported error was "pkihelper : ERRORServer unreachable due to SSL error: [SSL: SSLV3_ALERT_HANDSHAKE_FAILU