Hi Piotr,

Using openca latest from cvs on debian sarge i386, installed
without major problems (all minor already discussed).

Please never delete this line.

In first step in Phase II (Create new request
- https://(myhostname)/cgi-bin/ca/ca?cmd=setupInitialCert&dest=basic_csr)

Should I reinstall ASN1::Convert or try something else?

No, this is a configuration issue.

Note1: When I put 192.168.0.32 in IP address field, form was rejected with
message that 15 characters are required in IP address.

This is a bug. The configurations ca.conf and pub.conf in etc/servers/ contain options which define the minimum length of the data in a field. If you search for DN_TYPE_*_SUBJECTALTNAME or simply for a "15" then you will find the places with the wrong length. The correct length is 7. I fixed it in CVS.


Note2: I guess that some at least one link or button should be available
to proceed to default next step for CA initialization. Or at lease for
proceed to initialization first phase screen on which phase 1 steps are
listed - for now I need to manually navigate to Initialization > 1st Phase
and then select. I think absence of this button can make people proceed
to the Phase II instead of next step in phase I. Yes, this phase II step
will be probably impossible complete, however.. :)

This is really problematical for us. We use normal standard functions for the intialization only. You can theoretically ignore Phase II and III completely if you want and perform the steps via the normal interfaces. So this is only a help to start more quickly and clean. Perhaps we can change this in the future but today this is nearly impossible. Sorry :(


from original. Only one polish letter was used on request creating page,
and it as in form fieldname "Unit" which is in PL "Dzia\??", however
I don't think this matters.

The only result should be some unreadable stuff in the certificate.

PS2. Where can I find some error descriptions? Are they available?

Yes, we collect them in our FAQ. Especially your problem is described there ;) Your entered data is correct.


Error 7211021
General error. Cannot create request!

(OpenCA::REQ->new: unable to create new request, background returns error
7712071: OpenCA::OpenSSL->genReq: Cannot execute command (7777067).
problems making Certificate Request
4433:error:0D07A097:asn1 encoding routines:ASN1_mbstring_copy:string too
long:a_mbstr.c:154:maxsize=2
error in req
).

Please check your configuration ca.conf, public.conf and config.xml. It looks like you entered somewhere more than three characters for the country. Usually the people entering "com" or "Poland" as the CA country but the ISO country code is required at this position. I added a new comment in config.xml to make it more clear.


Michael
--
-------------------------------------------------------------------
Michael Bell                   Email: [EMAIL PROTECTED]
ZE Computer- und Medienservice            Tel.: +49 (0)30-2093 2482
(Computing Centre)                        Fax:  +49 (0)30-2093 2704
Humboldt-University of Berlin
Unter den Linden 6
10099 Berlin                   Email (private): [EMAIL PROTECTED]
Germany                                       http://www.openca.org


------------------------------------------------------- This SF.Net email is sponsored by BEA Weblogic Workshop FREE Java Enterprise J2EE developer tools! Get your free copy of BEA WebLogic Workshop 8.1 today. http://ads.osdn.com/?ad_id=5047&alloc_id=10808&op=click _______________________________________________ OpenCA-Devel mailing list [EMAIL PROTECTED] https://lists.sourceforge.net/lists/listinfo/openca-devel

Reply via email to