Hi Florent,
currently, you can start some automatic preicessing after signing the CSR by the RA.
And yes - you can use client side keygen with the batch, but it is not documented yet, so you have to spend some time...
AFAIK you have to pass another start-state in the batch importfile and must import the csr/public key stuff into the Batchprocessor Directory (var/bp) - I think Michael (Bell) has not written an import script for taht purpose
Oliver
[EMAIL PROTECTED] wrote:
Hi all,
I've few questions about full automatic enrollment. I want to generate the key pair and the CSR on the client machine with a web browser (IE, Netscape), to send the CSR to OpenCA and to import the certificate signed by the CA into the browser. I created 2 different OpenCA (0.9.2 RC4) instances on the same machine : a "CA/CA node" instance and a "RA/RA node/ldap/pub" instance.
To issue a certificate, I have to :
1- request a certificate via the pub interface 2- approve it via the RA interface 3- transfer it (dataexchange) via the RA node interface 4- receive it (dataexchange) via the CA node interface 5- sign it via the CA interface 6- transfer the certificate (dataexchange) via the CA node interface 7- receive the certificate (dataexchange) via the RA node interface 8- retrieve the certificate via the pub interface
1] Is it possible, after creating the CSR (step 1), to do the steps 2 to 7 full automatically without any manual action ? All the controls (identity, rights, ...) are made before the CSR generation.
2] I tried to use batch processors to generate certificates and it works. But, is it possible to generate key pairs on the client side instead of generate p12 files on the server side ?
Thank you for all the answers
Florent ___ Ce message est strictement confidentiel. Son int�grit� n'est pas assur�e sur Internet. Le contenu de ce message ne peut engager la responsabilit� du groupe Atos Origin. Si vous n'�tes pas destinataire du message, merci d'en avertir imm�diatement l'exp�diteur et de le d�truire. Bien que les meilleurs efforts soient faits pour maintenir cette transmission exempte de tout virus, l'exp�diteur ne donne aucune garantie � cet �gard et sa responsabilit� ne saurait �tre engag�e pour tout dommage r�sultant d'un virus transmis. This e-mail is privileged and may contain confidential information intended only for the person(s) named above. If you receive this e-mail in error, please notify the sender immediately by telephone or return e-mail. Although the sender endeavours to maintain a computer virus free network, the sender does not warrant that this transmission is virus-free and will not be liable for any damages resulting from any virus transmitted.
------------------------------------------------------- This SF.Net email is sponsored by the new InstallShield X. From Windows to Linux, servers to mobile, InstallShield X is the one installation-authoring solution that does it all. Learn more and evaluate today! http://www.installshield.com/Dev2Dev/0504 _______________________________________________ Openca-Users mailing list [EMAIL PROTECTED] https://lists.sourceforge.net/lists/listinfo/openca-users
-- Diese Nachricht wurde digital unterschrieben oliwel's public key: http://www.oliwel.de/oliwel.crt Basiszertifikat: http://www.ldv.ei.tum.de/page72
smime.p7s
Description: S/MIME Cryptographic Signature
