The anwser is here : http://www.mail-archive.com/[EMAIL PROTECTED]/msg02502.html
It was a passphrase issue. This means everyone should check a private key's passphrase before generating a root certificate because it is asked only once... Duh ! :-) Barbara Post -----Message d'origine----- De : [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] De la part de Barbara Post Envoy� : lundi 29 d�cembre 2003 17:47 � : [EMAIL PROTECTED] Objet : [Openca-Users] getting mad with error 6751 (could not load key despite right passphrase) (...) In Apache's log I have : [Mon Dec 29 18:32:59 2003] [error] [client 192.168.1.38] Using configuration from /usr/local/openca-0.9.1-5_ca_racine/OpenCA/etc/openssl/openssl/Sub-CA.conf, referer: http://openca-ca-racine.cvs_data01.apc/cgi-bin/ca/ca?cmd=viewCSR;dataType=AP PROVED_REQUEST;key=1312 [Mon Dec 29 18:32:59 2003] [error] [client 192.168.1.38] unable to load CA private key, referer: http://openca-ca-racine.cvs_data01.apc/cgi-bin/ca/ca?cmd=viewCSR;dataType=AP PROVED_REQUEST;key=1312 [Mon Dec 29 18:32:59 2003] [error] [client 192.168.1.38] 18685:error:06065064:digital envelope routines:EVP_DecryptFinal:bad decrypt:evp_enc.c:438:, referer: http://openca-ca-racine.cvs_data01.apc/cgi-bin/ca/ca?cmd=viewCSR;dataType=AP PROVED_REQUEST;key=1312 [Mon Dec 29 18:32:59 2003] [error] [client 192.168.1.38] 18685:error:0906A065:PEM routines:PEM_do_header:bad decrypt:pem_lib.c:421:, referer: http://openca-ca-racine.cvs_data01.apc/cgi-bin/ca/ca?cmd=viewCSR;dataType=AP PROVED_REQUEST;key=1312 When prompted, I enter the passphrase of root CA private key, but error above says it could not load the key. Using openssl rsa -text -in c:\temp\cakey.pem (key is copied from /OpenCA/var/crypto/cacerts/cakey.pem) I am sure the passphrase I enter is right. Moreover, it doesn't contain exotic letters. (...) ------------------------------------------------------- This SF.net email is sponsored by: IBM Linux Tutorials. Become an expert in LINUX or just sharpen your skills. Sign up for IBM's Free Linux Tutorials. Learn everything from the bash shell to sys admin. Click now! http://ads.osdn.com/?ad_id78&alloc_id371&op=click _______________________________________________ Openca-Users mailing list [EMAIL PROTECTED] https://lists.sourceforge.net/lists/listinfo/openca-users
