Tim Bouwer wrote:
> 
> Hi Massimiliano

Hi,

> I have given up trying to get OpenCA working with OpenLDAP and Perl 5.6.0.
> I have eventually decided to start on a fresh linux box with Perl 5.0003 and
> Michigan LDAP.

Needed steps are not so hard:

        perl 5.005
        OpenLDAP 1.2
        Net-LDAPApi

if you install them in this order you should get them working fine. I had
them working either on Solaris (Ultra Sparc 5).


> When I try to approve a pending request on the RA server I get asked: Please
> select the certificate you are using - I select the one that I imported,
> click on ok and get "Sign is needed to proceed".
> 
> 1.  Is there somewhere that I can see a log of what is going wrong here...
> my error log on the web server is silent at this point
> 2.  Do you have any idea of how I can proceed?

You should check:

        1. The certificate you are using get correctly verified
           within Netscape ?

        2. BEFORE importing the certificate into Netscape (.p12)
           have you imported the CA certificate ? If not delete
           the root certificates db and import the CA certificate
           as well as the Operator's certificate.

        3. Check the Javascript to be enabled.

        4. Check the Netscape's version (should be 4.06+).

        5. Check your Netscape's capabilities (you may require the usage of
           Fortify to support certificates with longer keys).

These are the only things I can think of that could generate the error when
trying to sign the form...

Let me know.

-- 

C'you,

        Massimiliano Pala

--o-------------------------------------------------------------------------
Massimiliano Pala [OpenCA Project Manager]                [EMAIL PROTECTED]
                                                     [EMAIL PROTECTED]
http://www.openca.org                            Tel.:   +39 (0)59  270  094
http://openca.sourceforge.net                    Mobile: +39 (0)347 7222 365

S/MIME Cryptographic Signature

Reply via email to