Hi Oliver,

Thanks for the response.
You say that after signing the CSR by the RA, I can start some automatic
processing. Could you explain me how can I automate the dataexchange
between 2 nodes on the same machine ? I saw that we can do that with "scp"
if the nodes are on 2 different machines but nothing if the nodes are on
the same machine.
And how can I automate the CSR signature by the CA to create the
certificate ?

Have you ever tried to use client side keygen with the batch process ? Or
else, as you say, I'm going to try to write a new process.
Thanks
Florent



                                                                                       
                                                            
                      Oliver Welter                                                    
                                                            
                      <[EMAIL PROTECTED]>                     Pour :    [EMAIL 
PROTECTED]                                            
                      Envoy� par :                         cc :                        
                                                            
                      [EMAIL PROTECTED]        Objet :   Re: [Openca-Users] Full 
automatic enrollment                                  
                      ceforge.net                                                      
                                                            
                                                                                       
                                                            
                                                                                       
                                                            
                      07/06/2004 15:48                                                 
                                                            
                      Veuillez r�pondre �                                              
                                                            
                      openca-users                                                     
                                                            
                                                                                       
                                                            
                                                                                       
                                                            




Hi Florent,

currently, you can start some automatic preicessing after signing the
CSR by the RA.

And yes - you can use client side keygen with the batch, but it is not
documented yet, so you have to spend some time...

AFAIK you have to pass another start-state in the batch importfile and
must import the csr/public key stuff into the Batchprocessor Directory
(var/bp) - I think Michael (Bell) has not written an import script for
taht purpose

Oliver



[EMAIL PROTECTED] wrote:
> Hi all,
>
> I've few questions about full automatic enrollment.
> I want to generate the key pair and the CSR on the client machine with a
> web browser (IE, Netscape), to send the CSR to OpenCA and to import the
> certificate signed by the CA into the browser.
> I created 2 different OpenCA (0.9.2 RC4) instances on the same machine :
a
> "CA/CA node" instance and a "RA/RA node/ldap/pub" instance.
>
> To issue a certificate, I have to :
>
> 1- request a certificate via the pub interface
> 2- approve it via the RA interface
> 3- transfer it (dataexchange) via the RA node interface
> 4- receive it (dataexchange) via the CA node interface
> 5- sign it via the CA interface
> 6- transfer the certificate (dataexchange) via the CA node interface
> 7- receive the certificate (dataexchange) via the RA node interface
> 8- retrieve the certificate via the pub interface
>
> 1] Is it possible, after creating the CSR (step 1), to do the steps 2 to
7
> full automatically without any manual action ?
> All the controls (identity, rights, ...) are made before the CSR
> generation.
>
> 2] I tried to use batch processors to generate certificates and it works.
> But, is it possible to generate key pairs on the client side instead of
> generate p12 files on the server side ?
>
> Thank you for all the answers
>
> Florent

___
Ce message est strictement confidentiel. Son int�grit� n'est pas assur�e
sur Internet. Le contenu de ce message ne peut engager la responsabilit� du
groupe Atos Origin. Si vous n'�tes pas destinataire du message, merci d'en
avertir imm�diatement l'exp�diteur et de le d�truire.
Bien que les meilleurs efforts soient faits pour maintenir cette
transmission exempte de tout virus, l'exp�diteur ne donne aucune garantie �
cet �gard et sa responsabilit� ne saurait �tre engag�e pour tout dommage
r�sultant d'un virus transmis.
This e-mail is privileged and may contain confidential information intended
only for the person(s) named above. If you receive this e-mail in error,
please notify the sender immediately by telephone or return e-mail.
Although the sender endeavours to maintain a computer virus free network,
the sender does not warrant that this transmission is virus-free and will
not be liable for any damages resulting from any virus transmitted.




-------------------------------------------------------
This SF.Net email is sponsored by the new InstallShield X.
>From Windows to Linux, servers to mobile, InstallShield X is the one
installation-authoring solution that does it all. Learn more and
evaluate today! http://www.installshield.com/Dev2Dev/0504
_______________________________________________
Openca-Users mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/openca-users

Reply via email to