Erik Anderson wrote:

This only happens if I create a certificate after a couple weeks, I'm
guessing it's some kind of timeout with the database that isn't recognized
until a new certificate attempt is made.  This is the full error:

Hum, I'll look into this before releasing beta4.

Okay, first of all I misspelled CER/PVK, it's actually SPC/PVK, which I
think is a combination of a PKCS#7 public certificate with a small
(768byte?) PVK file.  This file format has changed with WinXP (different
keylength?), PVK files cannot be interchanged between WinXP and other
operating systems.  This certificate file pair can be imported into the
registry by a publicly available utility called "PvkImprt".

The only place I have created a PVK file is through the Thawte EE, don't
know how easy it is to write these files otherwise.

Ok, I'll have a look at this format.

"not specifying a password" in OpenSSL is "pkcs12 -nodes"
"not exporting the complete certificate chain" in OpenSSL is
"pkcs12 -clcerts"

Now, why would you want to do that ? :)

Umm, is there any way we can get a description of what changed in the
database, so that we could upgrade our (production) systems and make use of
the next version?  Eventually a utility to detect and upgrade previous
schema variants could be very useful.  A note stating that the upgrade is
not backwards compatible would also be very useful.

It's not just the databases that changed but the internal also.
There is no way to upgrade the whole PKI, this is probably another 1-2 months development just to write the upgrade routines.


I'll will put a notice in the release note to warn people the beta4 is not backward compatible.

Regards,
--
Fr�d�ric Giudicelli
http://www.newpki.org
_____________________________________________________________________
NewPKI                                          http://www.newpki.org
User Support Mailing List                     [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to