[OpenXPKI-users] Need help in crl

2021-09-08 Thread Sanju Kundu
Hello, We are using openxpki version 3.12 in our environment. We are able to add revoke certificates in .crl manually using openxpki raop. But we want to run the revoke command using cron jobs per day. Please give us the command which runs the backend for revocation & add .crl list. Thanks in adva

Re: [OpenXPKI-users] Need help in crl

2021-09-08 Thread Martin Bartosch via OpenXPKI-users
Hi, > We are using openxpki version 3.12 in our environment. We are able to add > revoke certificates in .crl manually using openxpki raop. But we want to run > the revoke command using cron jobs per day. Please give us the command which > runs the backend for revocation & add .crl list. pleas

Re: [OpenXPKI-users] Upgrade from 2.x to 3.12

2021-09-08 Thread Dirk Heuvels
OK, everything working now. The name of the realm in the database deviated from the name in the filesystem. That's why I didn't see existing certificates. Thus the SQLs used for upgrading the schema seem to be correct. Only migrating the Sequences was needed an additional "+1" for hitting the

[OpenXPKI-users] How to build production openxpki?

2021-09-08 Thread Ale Ch
Could you please to advise. Where is my mistake? I have done pp 1-4 (and all previous) from this page https://github.com/openxpki/openxpki/tree/develop/core/htdocs_source I have right page at p4. (I have add ru-ru.yaml and button for switching and I do see it) I would like to create production, fo

Re: [OpenXPKI-users] directory /etc/openxpki/contrib/local missing

2021-09-08 Thread Martin Bartosch via OpenXPKI-users
Hi, > While working through the steps for a productive setup on Debian I came > across the following instruction in > https://github.com/openxpki/openxpki-config/tree/community#credentials--local-users > >> The files are already linked into the configuration layer and must >> be created before th

Re: [OpenXPKI-users] Upgrade from 2.x to 3.12

2021-09-08 Thread Martin Bartosch via OpenXPKI-users
Hi, > OK, everything working now. > > The name of the realm in the database deviated from the name in the > filesystem. That's why I didn't see existing certificates. > > Thus the SQLs used for upgrading the schema seem to be correct. Only > migrating the Sequences was needed an additional "+1

Re: [OpenXPKI-users] 4 eyes to approve/issue certificate

2021-09-08 Thread Martin Bartosch via OpenXPKI-users
Hi, > I mange to enforce policy of 2 approvals required by RA Operators (4 eyes) in > order to issue a certificate using WEBUI interface > > Is it possible! Any advice! (Almost) everything is possible with OpenXPKI ;-) For the automatic enrollment interfaces the approval policy is located in t

Re: [OpenXPKI-users] 4 eyes to approve/issue certificate

2021-09-08 Thread Montajab Saleh
Thanks Martin, Actually when I checked the mentioned file I found this sentence :), which is answer exactly my question # If you want a 4-eyes approval, just add a second "RA Operator" # e.g. "role: RA Operator, RA Operator" - you should add also # add current approval count to the ou