Hi!
I've been trying to use x509 certificates with CheckPoint's FW-1 FP3.
I generated cerificate request using SmartDashboard (the Management GUI
of FW-1), saved it to file and then i tried to feed it to OpenCA using
public WWW interface. It appears to read request (shows screen with DN
and all other details) then when i push 'Continue' i get Error 978
Internal Request Error in the browser window. At the same time Apache
error.log shows this:
Error loading SPKAC
4335:error:0D07207B:asn1 encoding routines:ASN1_get_object:header too
long:asn1_lib.c:138:
4335:error:0D068066:asn1 encoding routines:ASN1_CHECK_TLEN:bad object
header:tasn_dec.c:928:
4335:error:0D07803A:asn1 encoding routines:ASN1_ITEM_EX_D2I:nested asn1
error:tasn_dec.c:304:Type=NETSCAPE_SPKI
Error loading SPKAC
4336:error:0D07207B:asn1 encoding routines:ASN1_get_object:header too
long:asn1_lib.c:138:
4336:error:0D068066:asn1 encoding routines:ASN1_CHECK_TLEN:bad object
header:tasn_dec.c:928:
4336:error:0D07803A:asn1 encoding routines:ASN1_ITEM_EX_D2I:nested asn1
error:tasn_dec.c:304:Type=NETSCAPE_SPKI
Signature OK
Signature OK
Error loading SPKAC
4345:error:0D07207B:asn1 encoding routines:ASN1_get_object:header too
long:asn1_lib.c:138:
4345:error:0D068066:asn1 encoding routines:ASN1_CHECK_TLEN:bad object
header:tasn_dec.c:928:
4345:error:0D07803A:asn1 encoding routines:ASN1_ITEM_EX_D2I:nested asn1
error:tasn_dec.c:304:Type=NETSCAPE_SPKI
Error loading SPKAC
4346:error:0D07207B:asn1 encoding routines:ASN1_get_object:header too
long:asn1_lib.c:138:
4346:error:0D068066:asn1 encoding routines:ASN1_CHECK_TLEN:bad object
header:tasn_dec.c:928:
4346:error:0D07803A:asn1 encoding routines:ASN1_ITEM_EX_D2I:nested asn1
error:tasn_dec.c:304:Type=NETSCAPE_SPKI
unable to load X509 request
4347:error:0906D066:PEM routines:PEM_read_bio:bad end line:pem_lib.c:731:
unable to load X509 request
4348:error:0906D066:PEM routines:PEM_read_bio:bad end line:pem_lib.c:731:
I've read on list on some problems with SPKAC but it seemed to be bit
different from this one. Will this problem be cured with 0.9.1.1 ?
Hope someone will be able to help as at this moment i'm a stuck. Thanks
in advance
Best regards
--
Robert Ramiega <[EMAIL PROTECTED]> RR282-RIPE
Security Team Leader | Systems Administrator
TDC Internet Polska SA | PDi Ltd
-------------------------------------------------------
This SF.NET email is sponsored by: FREE SSL Guide from Thawte
are you planning your Web Server Security? Click here to get a FREE
Thawte SSL guide and find the answers to all your SSL security issues.
http://ads.sourceforge.net/cgi-bin/redirect.pl?thaw0026en
_______________________________________________
Openca-Users mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/openca-users