Hi,

I have got my RA cert, my un-passphrased RA keyfile and my dummy password
in the configuration, compiled OpenCA with openssl 0.9.7e3 (as shipped
with Ubuntu Hoary), Can retrieve the CA and RA certificates as expected,
but when i try and enroll a cert with sscep, i get:

./sscep: PKCS#7 payload size 586 bytes
./sscep: printing PEM fomatted PKCS#7
-----BEGIN PKCS7-----
-----END PKCS7-----
Segmentation fault

sscep is sometimes a bit picky. When you are using sscep to enroll
your request you should do the following:
- get ca certificates
- when running the sscep 'enroll' operation make sure you use
  the *first* certificate returned by the getcacert operation
  for the -c option.

The Cisco VPN client just gives me an 'Error 42 cannot construct
certificate request'.

Could be an incorrectly set up SCEP server. Did you generate a distinct
SCEP Server certificate? If yes, which key usage did you use?

There is no trace of openssl-0.9.7d on my system, openssl version reports:

OpenSSL 0.9.7e 25 Oct 2004

Does OpenCA's SCEP support not work with any version of OpenSSL later than 0.9.7c? And if so, it would probably be helpful to add this information to
an FAQ or something.

I tried the SCEP server successfully with 0.9.7e and g.

cheers

Martin




-------------------------------------------------------
This SF.net email is sponsored by: Splunk Inc. Do you grep through log files
for problems?  Stop!  Download the new AJAX search engine that makes
searching your log files as easy as surfing the  web.  DOWNLOAD SPLUNK!
http://ads.osdn.com/?ad_id=7637&alloc_id=16865&op=click
_______________________________________________
Openca-Users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openca-users

Reply via email to