Actually there is a bug in NewPKI.
I assume you added some extensions to the CRL, and one of them must be authorityKeyId. If it's the case you need to remove ":always".


Billy D'Augustine wrote:

I've done this before, but now I am having problems generating a CRL in
my CA. I am not sure what I did previously, but right now, in the CA
server, when I press "Generate CRL", an error occurs:

X509 V3 routines #114
no public key
v3_skey.c:119

I am pretty sure I've done everything I need (shortened version below
taken from the v2 NewPKI_Notes.PDF). I've taken to dropping all the
newpki databases from mysql and starting over:

Login to the admin server, create the following entities: PKI, CA
and repository (I didn't create a request auth yet, but even when I do,
it doesn't change the outcome).

Now I can login to the PKI entity and sign those requests, created in
the paragraph above.


Back in the server admin, init the entities with those newly signed
requests.


Using the PKI entity, link the CA to the repository, and configure the
CA. I configure the CA with the CA cert template, the CRL CA cert
template, and give it a 1 day CRL frequency.

Back to the CA admin. Here is where I press the generate CRL
button, and where the error occurs. In previous tests, I've been able to
do so, and suspect there is a step I am missing, but cannot remember!

Thanks :)

Billy D'Augustine

PGP signature available on my web page, URL hopefully obvious from my
address.

-- Fr�d�ric Giudicelli http://www.newpki.org _____________________________________________________________________ NewPKI http://www.newpki.org User Support Mailing List [EMAIL PROTECTED] Automated List Manager [EMAIL PROTECTED]

Reply via email to