hi, i've just tested new cvs update and ie signing still fails:
Compilation failed in require at /usr/local/apache/cgi-bin/ra/RAServer line 213. General Error Trapped 6203: The request is not signed! at /usr/local/openca_ra/lib/functions/misc-utils.lib line 38. the request is approved alas not signed :). martin lizner www.anect.com czech rep. On Thu, 27 Jun 2002, Michael Bell wrote: > Robson de Oliveira Albuquerque schrieb: > > > > Hi all !!! > > > > I got a problem when trying to issue the initial administrator certificate. > > > > I can generate the request ok, but when trying to edit the request I get the > > following error... > > Configuration Error. Request not present in DB or the status of the request > > was changed!. > > > > but when trying to get the pending requests the certificate is there.. > > > > Serial Submit Name Submitted On Requested Role > > 256 [EMAIL PROTECTED],CN=Robson > > Albuquerque,OU=Internet,O=LabRedes,C=BR Wed Jun 26 17:16:00 2002 GMT CA > > Operator > > > > The main problem is when trying to issue the administrator certificate...the > > error is: > > Configuration Error. Error while opening > > /usr/local/OpenCA/var/crypto/certs/01.pem. > > > > Well, the version of CA I'm working is the latests snapshot 0624... > > Openssl version is the rpm 0.9.8.xxx in the ftp where the latest snap of ca > > is. > > > > I have tried to understand the meaning of the subjectAltName in openssl and > > *.ext files but I could not solve it. The ca_operator.conf is the default > > file generated > > by make install-ca. > > > > The error generated by openssl says: > > Using configuration from > > /usr/local/OpenCA/etc/openssl/openssl/CA_Operator.conf > > Check that the request matches the signature > > Signature ok > > The Subject's Distinguished Name is as follows > > countryName :PRINTABLE:'BR' > > organizationName :PRINTABLE:'LabRedes' > > organizationalUnitName:PRINTABLE:'Internet' > > commonName :PRINTABLE:'Robson Albuquerque' > > emailAddress :IA5STRING:'[EMAIL PROTECTED]' > > serialNumber :PRINTABLE:'01' > > ERROR: adding extensions in section default > > 19158:error:2206D06C:X509 V3 routines:X509V3_parse_list:invalid null > > name:v3_utl.c:319: > > 19158:error:2206B069:X509 V3 routines:X509V3_EXT_conf:invalid extension > > string:v3_conf.c:138: > > name=subjectAltName,section= > > 19158:error:2206B080:X509 V3 routines:X509V3_EXT_conf:error in > > extension:v3_conf.c:92:name=su > > bjectAltName, value= > > unable to write 'random state' > > Error Trapped: Error while opening /usr/local/OpenCA/var/crypto/certs/01.pem > > at /usr/local/Op > > enCA/lib/functions/misc-utils.lib line 20. > > Compilation failed in require at /usr/local/apache/cgi-bin/ca/ca line 193. > > > > I have changed the .conf files of both ca and ra to > > DN_WITHOUT_EMAIL to N and didn't help, as said by Massimiliano > > > > Any Ideas ? > > The problem is that you must edit the certificate request and set the > subjectAlternativeName to email:somebody@somewhere or you must remove > the subject alternative name from the extension-file of the role > (openca_dir/etc/openssl/extfile/role_name.ext > > Best Regards Michael > -- > ------------------------------------------------------------------- > Michael Bell Email (private): [EMAIL PROTECTED] > Rechenzentrum - Datacenter Email: [EMAIL PROTECTED] > Humboldt-University of Berlin Tel.: +49 (0)30-2093 2482 > Unter den Linden 6 Fax: +49 (0)30-2093 2959 > 10099 Berlin > Germany http://www.openca.org > > > ------------------------------------------------------- > Sponsored by: > ThinkGeek at http://www.ThinkGeek.com/ > _______________________________________________ > Openca-Users mailing list > [EMAIL PROTECTED] > https://lists.sourceforge.net/lists/listinfo/openca-users > ------------------------------------------------------- This sf.net email is sponsored by: OSDN - Tired of that same old cell phone? Get a new here for FREE! https://www.inphonic.com/r.asp?r=sourceforge1&refcode1=vs3390 _______________________________________________ Openca-Users mailing list [EMAIL PROTECTED] https://lists.sourceforge.net/lists/listinfo/openca-users
