Hi Martin,

thx for the hint.

Martin Bartosch wrote:

Hi,

again a question concerning german TCOS cards. There are 3 keypairs on
the card but enough space for 3 or more certificates per keypair. But if
I issue a certificate for onee keypair, I cannot issue another one for
the same keypar cause of the following error :

Since there is no possibility to generate a new keypair on the card and
I'like to use the space offered, can anyone tell me how to disable the
feature of keychecking ?

it is not possible to disable the check without modifying the code
(as of 0.9.2.4). However, if you have got three key pairs and space
for three certs, why not use all three keys for requesting the certs?

... maybe I wished to install more than 3 certificates beside the SigG one. Tharts the reason why I'm asking. I think, this "problem" is worth thinking about it. With the M$-CA (which i really dont like :o)) it's possible to issue several certs for the same keypair.

Maybe in the future it could be a nice feature to mark all certificates in the database which were given out on smartcards and disable the keycheck if someone requests a new certificate with the same keypair.

Imagine the situation I give out a certificate for testing reason with a validity of only 30 days. And after that persiod of time this user wants me to issue another certificate ... and I can't.

But I understand .... major changes needs majopr amounts of time. I will have a look at the code, think, have some nice perl skills myself, can you point me to the right files ?

Would be enough info to fix this for my case.

Thx in advance.
Jan Rösner
[EMAIL PROTECTED]



-------------------------------------------------------
This SF.Net email is sponsored by:
Power Architecture Resource Center: Free content, downloads, discussions,
and more. http://solutions.newsforge.com/ibmarch.tmpl
_______________________________________________
Openca-Users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openca-users

Reply via email to