Erik Anderson wrote: > Here's a random list of issues that I have had with the client or would like > to see, some of which you've probably already fixed: > > * About half of my certificate requests fail and must be retried due to > "lost connection to MySQL" (running on the same machine as the server)
@ Hum... That's weird. I suspect the problem comes from the mysql server. @ With the beta4, I generated 300.000 profile with 2 certificates per @ profile, for a total of 600.000 certificates, I didn't have this kind of @ problem. This only happens if I create a certificate after a couple weeks, I'm guessing it's some kind of timeout with the database that isn't recognized until a new certificate attempt is made. This is the full error: Id: 11 State: Error during certification Type: PKCS#12 CA: openvpn_ca <------------------------------------------------> Error sent by SQL server: #2004 Select failed:Lost connection to MySQL server during query [SQL.cpp:60] <------------------------------------------------> Error sent by PKI server: #3026 Giving up on previous error(s) [CA_Handler.cpp:392] <------------------------------------------------> Error sent by PKI server: #3026 Giving up on previous error(s) [Entity_CA.cpp:763] <------------------------------------------------> Error sent by PKI server: #3026 Giving up on previous error(s) [Entity_CA.cpp:895] <------------------------------------------------> > * Would like to see additional certificate export formats, such as the > CER/PVK format that so many Windows tools expect and the PEM format that my > OpenVPN program requires. @ CER is the PEM encoded certificate, this is handled in NewPKI. @ As for PVK I'll look into this. @ I added the possibility to export the certificates to PKCS#7. Okay, first of all I misspelled CER/PVK, it's actually SPC/PVK, which I think is a combination of a PKCS#7 public certificate with a small (768byte?) PVK file. This file format has changed with WinXP (different keylength?), PVK files cannot be interchanged between WinXP and other operating systems. This certificate file pair can be imported into the registry by a publicly available utility called "PvkImprt". The only place I have created a PVK file is through the Thawte EE, don't know how easy it is to write these files otherwise. > Also with the option of not specifying a password > (PEM only) and the option of not exporting the complete certificate chain. @ I don't understand what you mean. "not specifying a password" in OpenSSL is "pkcs12 -nodes" "not exporting the complete certificate chain" in OpenSSL is "pkcs12 -clcerts" > * The last server upgrade required me to wipe my certificate store, as the > database format had changed and the new version refused to read the older > database. It wasn't a big deal then (the PKI was just coming into > production and the older data was obsolete), but I would like a > version-independant dump of the entire contents of the PKI (something like > what Subversion uses?) that is not tied to the MySQL database schema and > therefore cannot be rejected by any future version of the program. @ I'm afraid that you will have the same problem with beta4. @ However, this is the last not-upgradable version, the next release will @ allow to upgrade from beta4. Umm, is there any way we can get a description of what changed in the database, so that we could upgrade our (production) systems and make use of the next version? Eventually a utility to detect and upgrade previous schema variants could be very useful. A note stating that the upgrade is not backwards compatible would also be very useful. _____________________________________________________________________ NewPKI http://www.newpki.org User Support Mailing List [EMAIL PROTECTED] Automated List Manager [EMAIL PROTECTED]
