Re: [OpenXPKI-users] EST renewal/reenrollment

2024-03-26 Thread Mo Be
Yes yes yes Martin... That was it ! I still don't know how to play on that renewal_period though. By default, enrolled certificates are given a validity of one year. I added in my EST .yaml an initial validity, something I found in rpc .yaml initial_validity: +01 (which translates to 1

Re: [OpenXPKI-users] EST renewal/reenrollment

2024-03-26 Thread Martin Bartosch via OpenXPKI-users
Hi, > 5- I do get authenticated through basic auth AND through the certificates i'm > passing to cURL. > But I keep getting back the same certificate. > No workflow is triggered. > And in EST.log > INF authenticated client DN: CN=same cn,DC=Test > Deployment,DC=OpenXPKI,DC=org

[OpenXPKI-users] EST renewal/reenrollment

2024-03-26 Thread Mo Be
Hello, I'd like to experiment with EST reenroll web service and I don't seem to succeed yet. 1- I have enrolled a 1st CSR and got my certificate. 2- In this forum, I also found out that it's comparing the full subject (and not just the CN part) So I just ran the same command to have the same