Hi Olivier and everybody
after putting 1 to the log.xm and config the syslog.conf here his the message i receive from syslogd
 
BICIS(config)#crypto ca authenticate certifs
Message from [EMAIL PROTECTED] at Tue Jul 19 15:59:55 2005 ...
certifs OpenCA PKI Log Message[781]: <?xml version="1.0" encoding="iso-8859-1" ?> <log_message>     <acl>         <cmd>scepgetcacert</cmd>         <length>104</length>         <list>             <module>.*</module>             <operation>crr list</operation>             <owner>.*</owner>             <role>.*</role>         </list>         <list>             <module>.*</module>             <operation>csr list</operation>             <owner>.*</owner>             <role>.*</role>         </list>         <list>             <module>3</module>             <operation>cleanup sessions</operation>             <owner>.*</owner>             <role>.*</role>         </list>         <list>             <module>0</module>             <operation>access control configure</operation>             <owner>.*</owner>             <role>.*</role>         </list>         <list>             <module>0</module>             <operation>access control show configuration</operation>             <owner>.*</owner>             <role>.*</role>
BICIS(config)#
Message from [EMAIL PROTECTED] at Tue Jul 19 15:59:55 2005 ...us = FAIL, cert length = 0
certifs OpenCA PKI Log Message[781]: <?xml version="1.0" encoding="iso-8859-1" ?> <log_message>     <class>cmd</class>     <cmd>scepgetcacert</cmd>     <id>112178879570193531147172745918341452723061</id>     <iso_timestamp>2005-07-19 15:59:55</iso_timestamp>     <level>info</level>     <message></message>     <session_id>729a592000188aedcd4909fce6f2a17d</session_id>     <timestamp>2005-jul-19 15:59:55</timestamp> </log_message>
02:53:28: %CRYPTO-3-GETCARACERT: Failed to receive RA/CA certificates.
 
Here is the stderr.log
 
2005/07/19-15:58:24 OpenCA::Server (type Net::Server::Fork) starting! pid(773)
OpenCA::OpenSSL->_stop_shell: try to stop shell
OpenCA::OpenSSL->_stop_shell: try to stop shell
Binding to UNIX socket file /usr/local/openra/openca/var/tmp/openca_socket using SOCK_STREAM
Setting gid to "99 99"
Setting uid to "99"
initServer: BrowserSupportedLanguage(s) []
initServer: BrowserSupportedCharset(s)  []
initServer: setLanguage: setEncoding for log return iso-8859-1
initServer: setLanguage: C :: iso-8859-1
OpenCA::AC->Checking the channel ...
OpenCA::AC->    loading channel data ...
OpenCA::AC->        channel type ... mod_ssl
OpenCA::AC->    check channel data ...
OpenCA::AC->        channel type ... ok
OpenCA::AC->        security protocol ... ok
OpenCA::AC->        source ... ok
OpenCA::AC->        asymmetric cipher ... ok
OpenCA::AC->        asymmetric keylength ... ok
OpenCA::AC->        symmetric cipher ... ok
OpenCA::AC->        symmetric keylength ... ok
OpenCA::AC->Channel is ok
OpenCA::AC->Starting authentication ...
OpenCA::AC->    channel type ... mod_ssl
OpenCA::AC->    Try to get a session ...
OpenCA::AC->    Try to login ...
OpenCA::AC->        type ... none
OpenCA::AC->        identification disabled
OpenCA::AC->    checkACL ...
OpenCA::AC->    RBAC loaded
OpenCA::AC->    role loaded
OpenCA::AC->    operation loaded
OpenCA::AC->    owner loaded
OpenCA::AC->getAccess: real module: 33
OpenCA::AC->getAccess: real role:
OpenCA::AC->getAccess: real operation: ca-cert send
OpenCA::AC->getAccess: real owner:
OpenCA::AC->getAccess: module: .*
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: CRR list
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: module: .*
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: CSR list
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: module: 3
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: Cleanup Sessions
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: module: 0
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: access control configure
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: module: 0
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: access control show configuration
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: module: 0
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: access control sign configuration
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: module: 3
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: all ldap update
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: module: 32
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: all list
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: module: .*
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: all search
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: module: 3
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAc cess: operation: backup
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: module: 128
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: batchprocessor delete pin
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: module: 128
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: batchprocessor export pins
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: module: 128
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: batchprocessor import new data in compact form
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: module: 128
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: batchprocessor import new processes
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: module: 128
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: batchprocessor import new users
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: module: 128
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: batchprocessor import process data
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: module: 128
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: batchprocessor import update of user data
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: module: (0|128)
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: batchprocessor issue certificate
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: module: 128
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: batchprocessor list users
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: module: 128
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: batchprocessor recover key
OpenCA::AC->getAcces s: owner: .*
OpenCA::AC->getAccess: module: (0|128)
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: batchprocessor revoke certificate
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: module: 128
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: batchprocessor state configuration
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: module: 128
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: batchprocessor view user
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: module: .*
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: ca-cert send
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: access granted
OpenCA::AC->    access granted
OpenCA::AC->initToken: starting
OpenCA::AC->initToken: successfully finished
OpenCA::OpenSSL->_execute_command: entering function
OpenCA::OpenSSL->_start_shell: try to start shell
OpenCA::OpenSSL->_start_shell: | /usr/local/ssl/bin/openssl 1>/usr/local/openra/openca/var/tmp/775_stdout.log 2>/usr/local/openra/openca/var/tmp/775_stderr.log
OpenCA::OpenSSL->_start_shell: shell started
OpenCA::OpenSSL->_execute_command: crl2pkcs7 -nocrl -in /usr/local/openra/openca/var/tmp/775_incrl.tmp -out /usr/local/openra/openca/var/tmp/scep_authenticate_775.p7 -inform PEM -outform DER -certfile /usr/local/openra/openca/etc/scep/scep.crt
OpenCA::OpenSSL->_execute_command: executed
OpenCA::OpenSSL->_execute_command: command executed - stopping shell
OpenCA::OpenSSL->_stop_shell: try to stop shell
OpenCA::OpenSSL->_execute_command: check for error
OpenCA::OpenSSL->_execute_command: detected error log
OpenCA::OpenSSL->_execute_command: stderr:
OpenCA::OpenSSL->_execute_command: leaving successful (return: 1)
OpenCA::OpenSSL->_stop_shell: try to stop shell
OpenCA::OpenSSL->_stop_shell: try to stop shell
initServer: BrowserSupportedLanguage(s) []
initServer: BrowserSupportedCharset(s)  []
initServer: setLanguage: setEncoding for log return iso-8859-1
initServer: setLanguage: C :: iso-8859-1
OpenCA::AC->Checking the channel ...
OpenCA::AC->    loading channel data ...
OpenCA::AC->        channel type ... mod_ssl
OpenCA::AC->    check channel data ...
OpenCA::AC->        channel type ... ok
OpenCA::AC->        security protocol ... ok
OpenCA::AC->        source ... ok
OpenCA::AC->        asymmetric cipher ... ok
OpenCA::AC->        asymmetric keylength ... ok
OpenCA::AC->        symmetric cipher ... ok
OpenCA::AC->        symmetric keylength ... ok
OpenCA::AC->Channel is ok
OpenCA::AC->Starting authentication ...
OpenCA::AC->    channel type ... mod_ssl
OpenCA::AC->    Try to get a session ...
OpenCA::AC->    Try to login ...
OpenCA::AC->        type ... none
OpenCA::AC->        identification disabled
OpenCA::AC->    checkACL ...
OpenCA::AC->    RBAC loaded
OpenCA::AC->    role loaded
OpenCA::AC->    operation loaded
OpenCA::AC->    owner loaded
OpenCA::AC->getAccess: real module: 33
OpenCA::AC->getAccess: real role:
OpenCA::AC->getAccess: real operation: ca-cert send
OpenCA::AC->getAccess: real owner:
OpenCA::AC->getAccess: module: .*
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: CRR list
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: module: .*
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: CSR list
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: module: 3
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: Cleanup Sessions
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getA ccess: module: 0
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: access control configure
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: module: 0
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: access control show configuration
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: module: 0
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: access control sign configuration
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: module: 3
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: all ldap update
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: module: 32
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: all list
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: module: .*
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: a ll search
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: module: 3
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: backup
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: module: 128
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: batchprocessor delete pin
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: module: 128
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: batchprocessor export pins
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: module: 128
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: batchprocessor import new data in compact form
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: module: 128
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: batchprocessor import new processes
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: module: 128
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: batchprocessor import new users
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: module: 128
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: batchprocessor import process data
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: module: 128
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: batchprocessor import update of user data
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: module: (0|128)
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: batchprocessor issue certificate
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: module: 128
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: batchprocessor list users
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAcc ess: module: 128
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: batchprocessor recover key
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: module: (0|128)
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: batchprocessor revoke certificate
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: module: 128
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: batchprocessor state configuration
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: module: 128
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: batchprocessor view user
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: module: .*
OpenCA::AC->getAccess: role: .*
OpenCA::AC->getAccess: operation: ca-cert send
OpenCA::AC->getAccess: owner: .*
OpenCA::AC->getAccess: access granted
OpenCA::AC->    access granted
OpenCA::AC->initToken: starting
OpenCA::AC->initToken: successfully finished
OpenCA::OpenSSL->_execute_command: entering function
OpenCA::OpenSSL->_start_shell: try to start shell
OpenCA::OpenSSL->_start_shell: | /usr/local/ssl/bin/openssl 1>/usr/local/openra/openca/var/tmp/781_stdout.log 2>/usr/local/openra/openca/var/tmp/781_stderr.log
OpenCA::OpenSSL->_start_shell: shell started
OpenCA::OpenSSL->_execute_command: crl2pkcs7 -nocrl -in /usr/local/openra/openca/var/tmp/781_incrl.tmp -out /usr/local/openra/openca/var/tmp/scep_authenticate_781.p7 -inform PEM -outform DER -certfile /usr/local/openra/openca/etc/scep/scep.crt
OpenCA::OpenSSL->_execute_command: executed
OpenCA::OpenSSL->_execute_command: command executed - stopping shell
OpenCA::OpenSSL->_stop_shell: try to stop shell
OpenCA::OpenSSL->_execute_command: check for error
OpenCA::OpenSSL->_execute_command: detected error log
OpenCA::OpenSSL->_execute_command: stderr:
OpenCA::OpenSSL->_execute_command: leaving successful (return: 1)
OpenCA::OpenSSL->_stop_shell: try to stop shell
OpenCA::OpenSSL->_stop_shell: try to stop shell
Hope it will be usefull. Thanks a lot

Oliver Welter <[EMAIL PROTECTED]> a écrit :
>>> 01:49:20: CRYPTO_PKI: http connection opened % Error in receiving Certificate Authority certificate: status = FAIL, cert length = 0
>
>> The submitted PKCS7 structure is empty - normally this indicated problems with openssl (0.9.7d was broken)
>
> i think that the request don't use the protocol PKCS7 but the HHTP protocol. Because i am requesting the ca certificate and not a user certificate. Am i right ?
> in the HTTP response i can see Content type indicates we have received CA and RA certificates. But there is no thing.

HTTPis the transportprotocol but all SCEP data is encapsulated in pkcs7
containers, something on the OpenCA side is going wrong, is there
anything in the openca logs?


Appel audio GRATUIT partout dans le monde avec le nouveau Yahoo! Messenger
Téléchargez le ici !

Reply via email to