I think I have found the error: I used the role CA-Operator (am I stupid?) when approving the CSR on the root ca. Now I have tried the following:

- renew archived request
- changing of role to Sub-CA
- approving the CSR
- upload

When issuning certificate I got after entering the passphrase only a white screen - there ist something wrong.

Then I tried to revoke the wrong certificate on ra, got some errors on uploading (saying: we have this stuff already in our db) thus I deleted the wrong certificate on the ca, enrolled all, imported all on ra and then renewed the archived request again, changed it and uploaded it again.

Then I had no errors on upload or import on ca anymore, but I get the same white frame-screen on issuing the certificate...

???

Regards,
Gottfried

------------------------

Hi all,

I'm using openca.0.9.1.3 for root- and sub-ca and after doing the
export/signing stuff as described by Pierre Scholtes (Subject: get a
cert for a Sub-CA)

1) Initialize the SubCA ( initialize database, generate secret key, generate request)
2) export request
3) untar the export (to get the careq.pem)
4)Point to the RootCA public interface, ->request a certificate, ->server request, 
browse for the careq.pem and submit the request
5)Point to the RootCA ra interface and approuve the request, upload to the RootCA CA; 
point to CA interface, issue the certificate, download to the RA.
6)Untar the export from RootCA CA to RootCA RA to get the new certificate: 5.pem.
7)Rename 5.pem to cacert.pem and manually make a new tar.
6)Point my browser to the SubCA CA interface. ->import CA certificate approuved by 
Root CA

I get on importing the signed cert on the sub-ca the error:


- error 690: Missing configuration keyword: UnpackArchive

Then I remembered there was a answer from Michael to Pierre's mail with
a attached importCACert and I tried thisone:

- import into filesystem is ok
- import into db: error 690 - error (1) while convertig certificate

So, has anybody some idea? What can I do?

Regards,
Gottfried





-------------------------------------------------------
This SF.net email is sponsored by: The SF.net Donation Program.
Do you like what SourceForge.net is doing for the Open
Source Community?  Make a contribution, and help us add new
features and functionality. Click here: http://sourceforge.net/donate/
_______________________________________________
Openca-Users mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/openca-users

Reply via email to