[Freeipa-users] Re: Issue with SCEP enrollment to sub-CA

2018-02-05 Thread Rob Crittenden via FreeIPA-users
Trevor Vaughan wrote: > Hi Rob, > > I've created the associated ticket at https://pagure.io/certmonger/issue/93 Great, thanks. I'm investigating this along with the supported cipher and digest algos. It has been pretty slow going so far. rob > > On Thu, Feb 1, 2018 at 10:41 AM, Rob Crittenden

[Freeipa-users] Re: Issue with SCEP enrollment to sub-CA

2018-02-02 Thread Trevor Vaughan via FreeIPA-users
Hi Rob, I've created the associated ticket at https://pagure.io/certmonger/issue/93 On Thu, Feb 1, 2018 at 10:41 AM, Rob Crittenden wrote: > Trevor Vaughan via FreeIPA-users wrote: > > As an update, the sscep application set works properly with the sub-CA > > so it's definitely an issue on the

[Freeipa-users] Re: Issue with SCEP enrollment to sub-CA

2018-02-01 Thread Rob Crittenden via FreeIPA-users
Trevor Vaughan via FreeIPA-users wrote: > As an update, the sscep application set works properly with the sub-CA > so it's definitely an issue on the certmonger side of things. > > sscep in AES mode throws an exception in Dogtag and, unfortunately, > sscep also doesn't support above SHA1. > > Tha

[Freeipa-users] Re: Issue with SCEP enrollment to sub-CA

2018-01-31 Thread Trevor Vaughan via FreeIPA-users
As an update, the sscep application set works properly with the sub-CA so it's definitely an issue on the certmonger side of things. sscep in AES mode throws an exception in Dogtag and, unfortunately, sscep also doesn't support above SHA1. That said, it's at least reasonable isolation of the issu

[Freeipa-users] Re: Issue with SCEP enrollment to sub-CA

2018-01-31 Thread Trevor Vaughan via FreeIPA-users
Hi Rob, Thanks for getting back to me, I have no idea how I missed this message. I dug through the CA and KRA debug logs and don't see any PKCS7 output anywhere. I've been running certmonger in debug mode connected to the foreground and haven't really gotten anywhere there either. I did determi

[Freeipa-users] Re: Issue with SCEP enrollment to sub-CA

2018-01-30 Thread Rob Crittenden via FreeIPA-users
Trevor Vaughan via FreeIPA-users wrote: > Hi All, > > I have a setup where I have a root CA and a sub CA and the sub CA is set > up with a KRA and SCEP enabled. > > I've fired up certmonger and added the SCEP CA. > > When I attempt to request a certificate, the enrollment completes > successfull