Hi Martin,

   example: are OpenSSL changes (private key generation, serial number
   etc) properly rolled back on error, or does it result in an
   inconsistant state after a DB rollback?

If you look into crypto-utils.lib then you see that we make a backup of the index.txt and serial files. If anything fails until the certificate is in the database then we copy the old index.txt and serial files over the perhaps damaged ones. The rest is handled by the SQL database.


I think this is an issue for a review but perhaps we should wait for some design decisions before starting coding in this area.

Michael
--
-------------------------------------------------------------------
Michael Bell                   Email: [EMAIL PROTECTED]
ZE Computer- und Medienservice            Tel.: +49 (0)30-2093 2482
(Computing Centre)                        Fax:  +49 (0)30-2093 2704
Humboldt-University of Berlin
Unter den Linden 6
10099 Berlin                   Email (private): [EMAIL PROTECTED]
Germany                                       http://www.openca.org


------------------------------------------------------- SF.Net email is sponsored by Shop4tech.com-Lowest price on Blank Media 100pk Sonic DVD-R 4x for only $29 -100pk Sonic DVD+R for only $33 Save 50% off Retail on Ink & Toner - Free Shipping and Free Gift. http://www.shop4tech.com/z/Inkjet_Cartridges/9_108_r285 _______________________________________________ OpenCA-Devel mailing list [EMAIL PROTECTED] https://lists.sourceforge.net/lists/listinfo/openca-devel

Reply via email to