Hi Diego,

Every time I send a SCEP request using sscep, on the shell...

./sscep: printing PEM fomatted PKCS#7
-----BEGIN PKCS7-----
-----END PKCS7-----
Segmentation fault

Are you using openssl 0.9.7d ? If so pls update to a newer version or downgrade to 0.9.7c because some scep-related stuff is broken in this version. This applies to the sscep cleint as well as to the openca server.

One last question. I'm testing OpenCA and I'm evaluating in particular
the integration with a CMS. I've read on the mailinglist that with
SCEP is possible to automate the process of certificate creation. So
from what I understand, imitating the sscep command line tool, I send
a PKCS#10 (embedded in the pkcs7s) to the OpenCA SCEP interface, the
SCEP signs this request with it's RA Operator certificate, the CA
creates the certificate and then returns it to the CMS. Is this
correct ?

Basically - but at the moment you have to approve and sign the scep-request by hand - there is no automated issue. If you have the chance to choose the requestig client consider using teh batchsystem instead of scep. This would be much easier I guess

Oliver
--
Diese Nachricht wurde digital unterschrieben
oliwel's public key: http://www.oliwel.de/oliwel.crt
Basiszertifikat: http://www.ldv.ei.tum.de/page72

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

Reply via email to