Maybe you are missing one of those property values in the
CA declaration? Yes, that was the problem. Thanks.
# There is an option in the NewPKI system to generate the certificate on a "Hardware key". How can I set the PIN code for this smartcard?
This is independant from the PKI, you need to see with the utilities provided whith your SmartCard.
Actually, it kind of will; when the next CRL will be generated on the CA, it will include the revoked certificate.# What happens if someone has an active certificate and in the CA (Admin) I revoke it? It won't send anything to the RA…
Let's say that you request, on the RA, a new certificate from this CA, when the response comes back to the RA, it will include the CRL, and the previously revoked certificate will be marked as revoked in the RA.
And what happens if I revoke someone in the RA, I can't get the certificate back from him. Is there a way to stop a user from using his/her certificate?
That's the role of CRLs.
# Is there an option to manually allow each certification request in the CA admin. So if the RA requests a certificate it won't be automatically accepted just when the CA says so. And in an option it could be blocked as well.
No, the RA Operators must be trusted, they're the most important people on the PKI...
# Can you name some (free, open-source) programs that I can use this PKI certificate with. I know this PKI is a standard and the certificate can be used in any PKI based application, but I couldn’t find free software for it (There are a bunch of expensive, although). I would like to find programs that I can sign and encrypt files in the Windows Explorer with this certificate.
You can use outlook or firefox to sign or encrypt emails.
-- Frédéric Giudicelli http://www.newpki.org _____________________________________________________________________ NewPKI http://www.newpki.org User Support Mailing List [EMAIL PROTECTED] Automated List Manager [EMAIL PROTECTED]
