Khaled,
Important addition: for the root certificate you need to use "oic.sec.cred.trustca" value credUsage field instead of "oic.sec.cred.mfgtrustca", since cipher suite list formed by trustca certificates. "oic.sec.cred.mfgcert" and "oic.sec.cred.mfgtrustca" types used only at the otm process, and will never used then for authentication by default.
Best regards, Aleksey Volkov
--------- Original Message --------- Sender : Khaled Elsayed <khaledi...@gmail.com> Date : 2019-01-03 12:13 (GMT+2) Title : Re: Re: [dev] Certificate-based credential (DTLS fails to find cipher suite)
Thanks again. Will retry using 'oic.sec.cred.cert'. Was using "credusage": "oic.sec.cred.mfgcert" for the client own certificate and intermediate certificate and "credusage": "oic.sec.cred.mfgtrustca" for the peer certificate. I guess you meant oic.sec.cred.cert in place of the oic.sec.cred.mfgcert but the oic.sec.cred.mfgtrustca should remain the same as this is what is used to verify the peer certificate.
I attach the client and server .json files. For simplicity, I am assuming a pre-provisioned server here. As mentioned earlier no problem in getting the server provisioned via provisioningclient (of course the json file doxm entry is different for that case).
I will retry and share the logs if that change still does not work.
Best regards,
Khaled
On Thu, Jan 3, 2019 at 11:26 AM Oleksiy Volkov <a.vol...@samsung.com> wrote:
_._,_._,_
Links: You receive all messages sent to this group.
View/Reply Online (#10122) |
Reply To Sender
| Reply To Group
|
Mute This Topic
| New Topic _._,_._,_
|
client.cred.json
Description: Binary data
server.cred.json
Description: Binary data