Okay, I got it finally. Turned out I hadn't properly exported the CA cert from CA to RAServer due to a permissions problem on the RAServer directory; hence the import from RAServer to browser didn't work right, and the certificate wouldn't verify (nice of Netscape to give me a reasonable error message for that case).
It also helped when I looked at INSTALL-0.8 instead of INSTALL... There were a couple more glitches. After I signed the request, I got this in the browser: Operation Request Approved Description: Certificate Request Successfully approved and archivied. signature: Error 404 Signer's Certificate Not Present in dB Upon trying to retrieve the cert from the public interface, I got this in the error log: [Wed Oct 10 11:24:30 2001] [error] [client 140.221.16.7] malformed header from script. Bad header= defining the class parameter: /home/openca/cgi-public/getID which turned out to be a result of DEBUG=1 in the DBI.conf. HOwever, turning debug off resulted in me receiving an empty document. --bob _______________________________________________ OpenCA-Devel mailing list [EMAIL PROTECTED] https://lists.sourceforge.net/lists/listinfo/openca-devel