Hello,
  I've (maybe small) problem with issuing new CRL:

I have installed Monday's cvs snap with DBI. OpenSSL snap-20020415.
I revoked successfully (some test's) certificates and tried to 'issue new CRL'.

ERROR: Cannot initialize a new CRL Object!
               256

Does somebody know what it means - what to do?

There are some more technical details:

- From apache-error_log:
        Using configuration from /usr/local/Authority/OpenCA/etc/openssl/openssl.cnf

- the tmp files, like ..._cnv.tmp and ..._data.tmp was created and are (I think) OK.

- when DEBUG on:

Debugging is activated!
Content-type: text/html
                                       CRL Issuing
                               (Please wait until operation completes)


          Generating Certificate Revocation List ... OpenCA::OpenSSL=HASH(0x8227e1c),
          /usr/local/Authority/OpenCA/var/crypto/cacerts/cacert.pem,
          /usr/local/Authority/OpenCA/var/crypto/keys/cakey.pem, 30, ,XXXXXXXX

          OpenCA::OpenSSL->dataConvert: command="/usr/local/ssl/bin/openssl crl -out
          /usr/local/Authority/OpenCA/var/tmp/2529_cnv.tmp -in
          /usr/local/Authority/OpenCA/var/tmp/2529_crl.tmp -outform PEM -inform PEM "
          OpenCA::OpenSSL->dataConvert: using infile
          OpenCA::OpenSSL->dataConvert: openssl itself successful
          OpenCA::OpenSSL->dataConvert: passphrases deleted
          OpenCA::OpenSSL->dataConvert: return result like follows
          -----BEGIN X509 CRL-----
          MIIB7DCB1TANBgkqhkiG9w0BAQQFADBoMQswCQYDVQQGEwJDWjERMA8GA1UEChMI
          Q3plY2ggQ0ExEDAOBgNVBAsTB2RldmVsb3AxETAPBgNVBAMTCEN6ZWNoIENBMSEw
          HwYJKoZIhvcNAQkBFhJjemVjaGNhQGN6ZWNoY2EuY3oXDTAyMDUwMjE2NTYzMVoX
          DTAyMDYwMTE2NTYzMVowPDASAgEBFw0wMjA0MzAxMzQyNDZaMBICAQIXDTAyMDQz
          MDE0MTkzN1owEgIBAxcNMDIwNTAyMTYyOTA0WjANBgkqhkiG9w0BAQQFAAOCAQEA
          PnsorqgYnGYil7rI0Ex+uzbwxSHTv+p9v/dRjfghMKBCg5IWCd8Sd4cqkLDrGAHQ
          9GeUo2+7oKbos/uVjgz2LSOlUbhf+krfEB0RuUGb+IiZCXs/szlWdkKpt3YOvcMV
          weymVW5ORFEOJ02ALYrvyLujTxMAigP7ZfZoLLiptrLnXIv4KJC1VabW/wEKqV4s
          +/8yorMuWxGOJ8d8y6jAUWzYYfgcW2vyKiBr4jZztqdXwzXBZYtnfn/jnkLGKDUt
          v6Np2ZEl4UVDC20A3x2KWhbvHsbMtj1y7pM7pwyk0UU77hCxzDo72oO4ouMjUbXB
          7eTXUHnl608r5OpqYYBdng== -----END X509 CRL-----

OpenCA::OpenSSL->dataConvert: create temporary infile
          /usr/local/Authority/OpenCA/var/tmp/2529_data.tmp
          OpenCA::OpenSSL->dataConvert: the data is like follows
          -----BEGIN X509 CRL-----
          MIIB7DCB1TANBgkqhkiG9w0BAQQFADBoMQswCQYDVQQGEwJDWjERMA8GA1UEChMI
          Q3plY2ggQ0ExEDAOBgNVBAsTB2RldmVsb3AxETAPBgNVBAMTCEN6ZWNoIENBMSEw
          HwYJKoZIhvcNAQkBFhJjemVjaGNhQGN6ZWNoY2EuY3oXDTAyMDUwMjE2NTYzMVoX
          DTAyMDYwMTE2NTYzMVowPDASAgEBFw0wMjA0MzAxMzQyNDZaMBICAQIXDTAyMDQz
          MDE0MTkzN1owEgIBAxcNMDIwNTAyMTYyOTA0WjANBgkqhkiG9w0BAQQFAAOCAQEA
          PnsorqgYnGYil7rI0Ex+uzbwxSHTv+p9v/dRjfghMKBCg5IWCd8Sd4cqkLDrGAHQ
          9GeUo2+7oKbos/uVjgz2LSOlUbhf+krfEB0RuUGb+IiZCXs/szlWdkKpt3YOvcMV
          weymVW5ORFEOJ02ALYrvyLujTxMAigP7ZfZoLLiptrLnXIv4KJC1VabW/wEKqV4s
          +/8yorMuWxGOJ8d8y6jAUWzYYfgcW2vyKiBr4jZztqdXwzXBZYtnfn/jnkLGKDUt
          v6Np2ZEl4UVDC20A3x2KWhbvHsbMtj1y7pM7pwyk0UU77hCxzDo72oO4ouMjUbXB
          7eTXUHnl608r5OpqYYBdng== -----END X509 CRL-----
          OpenCA::OpenSSL->dataConvert: command="/usr/local/ssl/bin/openssl crl -out
          /usr/local/Authority/OpenCA/var/tmp/2529_cnv.tmp -in
          /usr/local/Authority/OpenCA/var/tmp/2529_data.tmp -outform PEM -inform PEM "
          OpenCA::OpenSSL->dataConvert: using infile
          OpenCA::OpenSSL->dataConvert: openssl itself successful
          OpenCA::OpenSSL->dataConvert: passphrases deleted
          OpenCA::OpenSSL->dataConvert: return result like follows
          -----BEGIN X509 CRL-----
          MIIB7DCB1TANBgkqhkiG9w0BAQQFADBoMQswCQYDVQQGEwJDWjERMA8GA1UEChMI
          Q3plY2ggQ0ExEDAOBgNVBAsTB2RldmVsb3AxETAPBgNVBAMTCEN6ZWNoIENBMSEw
          HwYJKoZIhvcNAQkBFhJjemVjaGNhQGN6ZWNoY2EuY3oXDTAyMDUwMjE2NTYzMVoX
          DTAyMDYwMTE2NTYzMVowPDASAgEBFw0wMjA0MzAxMzQyNDZaMBICAQIXDTAyMDQz
          MDE0MTkzN1owEgIBAxcNMDIwNTAyMTYyOTA0WjANBgkqhkiG9w0BAQQFAAOCAQEA
          PnsorqgYnGYil7rI0Ex+uzbwxSHTv+p9v/dRjfghMKBCg5IWCd8Sd4cqkLDrGAHQ
          9GeUo2+7oKbos/uVjgz2LSOlUbhf+krfEB0RuUGb+IiZCXs/szlWdkKpt3YOvcMV
          weymVW5ORFEOJ02ALYrvyLujTxMAigP7ZfZoLLiptrLnXIv4KJC1VabW/wEKqV4s
          +/8yorMuWxGOJ8d8y6jAUWzYYfgcW2vyKiBr4jZztqdXwzXBZYtnfn/jnkLGKDUt
          v6Np2ZEl4UVDC20A3x2KWhbvHsbMtj1y7pM7pwyk0UU77hCxzDo72oO4ouMjUbXB
          7eTXUHnl608r5OpqYYBdng== -----END X509 CRL-----
          OpenCA::OpenSSL->dataConvert: create temporary infile
          /usr/local/Authority/OpenCA/var/tmp/2529_data.tmp
          OpenCA::OpenSSL->dataConvert: the data is like follows
          -----BEGIN X509 CRL-----
          MIIB7DCB1TANBgkqhkiG9w0BAQQFADBoMQswCQYDVQQGEwJDWjERMA8GA1UEChMI
          Q3plY2ggQ0ExEDAOBgNVBAsTB2RldmVsb3AxETAPBgNVBAMTCEN6ZWNoIENBMSEw
          HwYJKoZIhvcNAQkBFhJjemVjaGNhQGN6ZWNoY2EuY3oXDTAyMDUwMjE2NTYzMVoX
          DTAyMDYwMTE2NTYzMVowPDASAgEBFw0wMjA0MzAxMzQyNDZaMBICAQIXDTAyMDQz
          MDE0MTkzN1owEgIBAxcNMDIwNTAyMTYyOTA0WjANBgkqhkiG9w0BAQQFAAOCAQEA
          PnsorqgYnGYil7rI0Ex+uzbwxSHTv+p9v/dRjfghMKBCg5IWCd8Sd4cqkLDrGAHQ
          9GeUo2+7oKbos/uVjgz2LSOlUbhf+krfEB0RuUGb+IiZCXs/szlWdkKpt3YOvcMV
          weymVW5ORFEOJ02ALYrvyLujTxMAigP7ZfZoLLiptrLnXIv4KJC1VabW/wEKqV4s
          +/8yorMuWxGOJ8d8y6jAUWzYYfgcW2vyKiBr4jZztqdXwzXBZYtnfn/jnkLGKDUt
          v6Np2ZEl4UVDC20A3x2KWhbvHsbMtj1y7pM7pwyk0UU77hCxzDo72oO4ouMjUbXB
          7eTXUHnl608r5OpqYYBdng== -----END X509 CRL-----
          OpenCA::OpenSSL->dataConvert: command="/usr/local/ssl/bin/openssl crl -out
          /usr/local/Authority/OpenCA/var/tmp/2529_cnv.tmp -in
          /usr/local/Authority/OpenCA/var/tmp/2529_data.tmp -outform DER -inform PEM "
          OpenCA::OpenSSL->dataConvert: using infile
          OpenCA::OpenSSL->dataConvert: openssl itself successful
          OpenCA::OpenSSL->dataConvert: passphrases deleted
          OpenCA::OpenSSL->dataConvert: return result like follows
          0,?0??0  *?H?÷
          OpenCA::OpenSSL->dataConvert: create temporary infile
          /usr/local/Authority/OpenCA/var/tmp/2529_data.tmp
          OpenCA::OpenSSL->dataConvert: the data is like follows
          -----BEGIN X509 CRL-----
          MIIB7DCB1TANBgkqhkiG9w0BAQQFADBoMQswCQYDVQQGEwJDWjERMA8GA1UEChMI
          Q3plY2ggQ0ExEDAOBgNVBAsTB2RldmVsb3AxETAPBgNVBAMTCEN6ZWNoIENBMSEw
          HwYJKoZIhvcNAQkBFhJjemVjaGNhQGN6ZWNoY2EuY3oXDTAyMDUwMjE2NTYzMVoX
          DTAyMDYwMTE2NTYzMVowPDASAgEBFw0wMjA0MzAxMzQyNDZaMBICAQIXDTAyMDQz
          MDE0MTkzN1owEgIBAxcNMDIwNTAyMTYyOTA0WjANBgkqhkiG9w0BAQQFAAOCAQEA
          PnsorqgYnGYil7rI0Ex+uzbwxSHTv+p9v/dRjfghMKBCg5IWCd8Sd4cqkLDrGAHQ
          9GeUo2+7oKbos/uVjgz2LSOlUbhf+krfEB0RuUGb+IiZCXs/szlWdkKpt3YOvcMV
          weymVW5ORFEOJ02ALYrvyLujTxMAigP7ZfZoLLiptrLnXIv4KJC1VabW/wEKqV4s
          +/8yorMuWxGOJ8d8y6jAUWzYYfgcW2vyKiBr4jZztqdXwzXBZYtnfn/jnkLGKDUt
          v6Np2ZEl4UVDC20A3x2KWhbvHsbMtj1y7pM7pwyk0UU77hCxzDo72oO4ouMjUbXB
          7eTXUHnl608r5OpqYYBdng== -----END X509 CRL-----
          OpenCA::OpenSSL->dataConvert: command="/usr/local/ssl/bin/openssl crl -out
          /usr/local/Authority/OpenCA/var/tmp/2529_cnv.tmp -in
          /usr/local/Authority/OpenCA/var/tmp/2529_data.tmp -text -noout -inform PEM "
          OpenCA::OpenSSL->dataConvert: using infile
          OpenCA::OpenSSL->dataConvert: openssl itself successful
          OpenCA::OpenSSL->dataConvert: passphrases deleted


          ERROR: Cannot initialize a new CRL Object!

               256


OpenCA::DBI automatic commit by destructor DESTROY
call finish on all statement handles to avoid warnings by DBI

- the last $? in modules/perl5/OpenCA/OpenSSL.pm line cca 787 return: 256
  then:
        if( $? != 0 ) {
        $self->setError (7722073, "OpenCA::OpenSSL->dataConvert: OpenSSL failed 
(".$?.").");
                return undef;
        }

  and OpenCA/lib/cmds/genCRL exit on:

if ( not $CRL ) {
        print addErrorLog("ERROR: Cannot initialize a new CRL Object!");
        print addPreLogLine( $CRL );
        closePage();
        exit 0;
 }


THANK YOU.

--mh

-- 
---------------------------------------------
               Miroslav Hrad
mobil: +420 606 703435, email: [EMAIL PROTECTED]


_______________________________________________________________

Have big pipes? SourceForge.net is looking for download mirrors. We supply
the hardware. You get the recognition. Email Us: [EMAIL PROTECTED]
_______________________________________________
Openca-Users mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/openca-users

Reply via email to