[OpenXPKI-users] automatically enable openxpki on reboot

2019-06-14 Thread Stefan Goeman
Hello, I have openxpki installed in Debian 8. When I reboot the system, openxpki is not started automatically. I have to start it manually using “openxpkictl start” Isn’t there a way to enable it by default? Using something like “systemctl enable ”? Greetings, Stefan Goeman. Verzonden vanuit

[OpenXPKI-users] scep: pkcs7 signature verification error

2019-06-21 Thread Stefan Goeman
Hello, I am using an “out of the box” installation of openxpki on Debian 8. I also compiled the last version of the scep client. When I run scep with: ./sscep_dyn enroll -d -c ca.crt-1 -r testcsr.csr -u http://127.0.0.1/scep -l testcert.crt -k privatekey.key I get a HTTP 200 OK message back con

[OpenXPKI-users] Second realm, certsign and datasafe tokens offline

2019-06-25 Thread Stefan Goeman
Hello, I tried to create a second realm and upload my own certificates in this realm. This upload is OK when I verify this with “openxpkiadm alias –realm ca-two” However, when I login into this second realm with the web interface, I see that my tokens are offline, as can be seen in the screensho

Re: [OpenXPKI-users] Second realm, certsign and datasafe tokens offline

2019-06-26 Thread Stefan Goeman
-users@lists.sourceforge.net Onderwerp: Re: [OpenXPKI-users] Second realm, certsign and datasafe tokens offline Hi, very likely the server can not find or read your keyfiles due to wrong path or permissions. Oliver Am 25.06.19 um 18:22 schrieb Stefan Goeman: > Hello, > > I tried to create a s

[OpenXPKI-users] Installing mariadb schema

2024-04-08 Thread Stefan Goeman
Hi I am trying to install openxpki on Debian 12 When I run this command: cat /usr/share/doc/libopenxpki-perl/examples/schema-mariadb.sql | \ mysql -u root --password --database openxpki I get the following error message: ERROR 1068 (42000) at line 201: Multiple primary key defined I thin

Re: [OpenXPKI-users] Installing mariadb schema

2024-04-18 Thread Stefan Goeman
| int(10) unsigned | YES | | NULL| | ++--+--+-+-+---+ Oli On 08.04.24 17:50, Stefan Goeman wrote: Hi I am trying to install openxpki on Debian 12 When I run this command: cat /usr/share/doc/libopenxpki-perl/examples/schema-mariadb.sql | \ mysql -u root --

Re: [OpenXPKI-users] Installing mariadb schema

2024-04-18 Thread Stefan Goeman
ists.sourceforge.net Onderwerp: Re: [OpenXPKI-users] Installing mariadb schema Hello Stefan, did you enable the SSL module (a2enmod ssl) ? Oliver On 18.04.24 14:00, Stefan Goeman wrote: Hi Yes, maybe that is possible. Now, I just started from scratch again. Meaning, I have de-installed

[OpenXPKI-users] web page not loading

2024-04-19 Thread Stefan Goeman
Hi I did a fresh install of openxpki following the quicstart guide, and the sample/demo configuration (with the script sampleconfig.sh) When I try to open the web page. It starts loading. But, it stays in this state. (i.e. in the upper right corner of my web browser I have this turning wheel sa

Re: [OpenXPKI-users] web page not loading

2024-04-30 Thread Stefan Goeman
config, writing the logfiles or building the database connection for the session (DB config in webui/default.conf). In any case check the logfiles including the one from the apache server. Oliver On 19.04.24 19:23, Stefan Goeman wrote: Hi I did a fresh install of openxpki following the qui

Re: [OpenXPKI-users] web page not loading

2024-04-30 Thread Stefan Goeman
my problem. Greetings, Stefan. Van: James B. Byrne via OpenXPKI-users Verzonden: dinsdag 30 april 2024 16:55 Aan: openxpki-users@lists.sourceforge.net CC: James B. Byrne Onderwerp: Re: [OpenXPKI-users] web page not loading On Tue, April 30, 2024 09:58, Stefan Go

[OpenXPKI-users] Allow additional Elliptic Curves

2024-05-08 Thread Stefan Goeman
Hello I have a default installation on Debian 12 with the democa I have created a csr using the elliptic curve secp256k1. When I copy this csr in the web interface and try to request a certificate, I get this error: "Used key parameter is not allowed by policy (curve_name: 1.3.132.0.10)" When I

[OpenXPKI-users] format of the .../.well-known/est/cacerts response

2024-06-12 Thread Stefan Goeman
Hello I want to use the following commands to get my ca files in a nicely fomated pem-file: * curl -k --connect-timeout 10 -s https://my_est_server/.well-known/est/cacerts -o cacerts.p7 * openssl base64 -d -in cacerts.p7 | openssl pkcs7 -inform DER -outform PEM -print_certs -out cacerts.pe

Re: [OpenXPKI-users] format of the .../.well-known/est/cacerts response

2024-06-12 Thread Stefan Goeman
hile the EST test server does and it looks like the openssl base64 is not able to handle this encoding. I have looked around a bit and did not really find a normative reference if OpenXPKI is doing it wrong or if this is just a glitch in OpenSSL but I will add this as an RFE so we will implement

[OpenXPKI-users] EST enrollment - use subject name from CSR

2024-07-18 Thread Stefan Goeman
Hello I am using the default configuration from the demoCA. I want to enroll certificates via EST. The certificates contain in the subject name "DC=Test Deployment, DC=OpenXPKI, DC=org" I would prefer to have in the subject name of the certificate the same fields that were provided in the CSR;