hi,

i've just tested new cvs update and ie signing still fails:

Compilation failed in require at /usr/local/apache/cgi-bin/ra/RAServer
line 213.
General Error Trapped 6203: The request is not signed! at
/usr/local/openca_ra/lib/functions/misc-utils.lib line 38.

the request is approved alas not signed :).

martin lizner
www.anect.com
czech rep.

On Thu, 27 Jun 2002, Michael Bell wrote:

> Robson de Oliveira Albuquerque schrieb:
> >
> > Hi all !!!
> >
> > I got a problem when trying to issue the initial administrator certificate.
> >
> > I can generate the request ok, but when trying to edit the request I get the
> > following error...
> > Configuration Error. Request not present in DB or the status of the request
> > was changed!.
> >
> > but when trying to get the pending requests the certificate is there..
> >
> > Serial Submit Name Submitted On Requested Role
> > 256  [EMAIL PROTECTED],CN=Robson
> > Albuquerque,OU=Internet,O=LabRedes,C=BR  Wed Jun 26 17:16:00 2002 GMT  CA
> > Operator
> >
> > The main problem is when trying to issue the administrator certificate...the
> > error is:
> > Configuration Error. Error while opening
> > /usr/local/OpenCA/var/crypto/certs/01.pem.
> >
> > Well, the version of CA I'm working is the latests snapshot 0624...
> > Openssl version is the rpm 0.9.8.xxx in the ftp where the latest snap of ca
> > is.
> >
> > I have tried to understand the meaning of the subjectAltName in openssl and
> > *.ext files but I could not solve it. The ca_operator.conf is the default
> > file generated
> > by make install-ca.
> >
> > The error generated by openssl says:
> > Using configuration from
> > /usr/local/OpenCA/etc/openssl/openssl/CA_Operator.conf
> > Check that the request matches the signature
> > Signature ok
> > The Subject's Distinguished Name is as follows
> > countryName           :PRINTABLE:'BR'
> > organizationName      :PRINTABLE:'LabRedes'
> > organizationalUnitName:PRINTABLE:'Internet'
> > commonName            :PRINTABLE:'Robson Albuquerque'
> > emailAddress          :IA5STRING:'[EMAIL PROTECTED]'
> > serialNumber          :PRINTABLE:'01'
> > ERROR: adding extensions in section default
> > 19158:error:2206D06C:X509 V3 routines:X509V3_parse_list:invalid null
> > name:v3_utl.c:319:
> > 19158:error:2206B069:X509 V3 routines:X509V3_EXT_conf:invalid extension
> > string:v3_conf.c:138:
> > name=subjectAltName,section=
> > 19158:error:2206B080:X509 V3 routines:X509V3_EXT_conf:error in
> > extension:v3_conf.c:92:name=su
> > bjectAltName, value=
> > unable to write 'random state'
> > Error Trapped: Error while opening /usr/local/OpenCA/var/crypto/certs/01.pem
> > at /usr/local/Op
> > enCA/lib/functions/misc-utils.lib line 20.
> > Compilation failed in require at /usr/local/apache/cgi-bin/ca/ca line 193.
> >
> > I have changed the .conf files of both ca and ra to
> > DN_WITHOUT_EMAIL to N and didn't help, as said by Massimiliano
> >
> > Any Ideas ?
>
> The problem is that you must edit the certificate request and set the
> subjectAlternativeName to email:somebody@somewhere or you must remove
> the subject alternative name from the extension-file of the role
> (openca_dir/etc/openssl/extfile/role_name.ext
>
> Best Regards Michael
> --
> -------------------------------------------------------------------
> Michael Bell                   Email (private): [EMAIL PROTECTED]
> Rechenzentrum - Datacenter     Email:  [EMAIL PROTECTED]
> Humboldt-University of Berlin  Tel.: +49 (0)30-2093 2482
> Unter den Linden 6             Fax:  +49 (0)30-2093 2959
> 10099 Berlin
> Germany                                       http://www.openca.org
>
>
> -------------------------------------------------------
> Sponsored by:
> ThinkGeek at http://www.ThinkGeek.com/
> _______________________________________________
> Openca-Users mailing list
> [EMAIL PROTECTED]
> https://lists.sourceforge.net/lists/listinfo/openca-users
>



-------------------------------------------------------
This sf.net email is sponsored by: OSDN - Tired of that same old
cell phone?  Get a new here for FREE!
https://www.inphonic.com/r.asp?r=sourceforge1&refcode1=vs3390
_______________________________________________
Openca-Users mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/openca-users

Reply via email to