Hello,
I am trying to figure out why System Status says OFFLINE.
I also noticed that YAML can be customized per use.
I am trying to make certificates for servers and services like:
apache, bacula, dovecot, postfix, mysql…
Are there any YT videos or any kind of documentation in more detail.
Also when trying to make certs i get this error in log file:
2015/10/05 23:32:19 openxpki.system.ERROR:19150
[OpenXPKI::Server::API::Object (1422); raop(RA Operator)@d3f9] Exception:
I18N_OPENXPKI_SERVER_API_OBJECT_GET_DATA_POOL_ENTRY_ENCRYPTION_KEY_UNAVAILABLE;
__PKI_REALM__ => uniline; __KEY__ => Szujbc65YKSSpYS06VVhhdzeykU; __SAFE_ID__
=> ca-one-vault-1; __NAMESPACE__ => sys.datapool.keys
If i truncate table data keys error does not happen upon creation.
Also when I finish cert request and when it needs approval it throws
same error again…
2015/10/09 10:47:42 openxpki.application.INFO:20943 [OpenXPKI::Server::Workflow
(128); raop(RA Operator)@b18d] Execute action csr_load_key_password on workflow
#6143 2015/10/09 10:47:42 openxpki.system.ERROR:20943 [OpenXPKI::Crypto::CLI
(/usr/lib/perl5/OpenXPKI/Crypto/CLI.pm:435); raop(RA Operator)@b18d] OpenSSL
error: unable to load signing key file 139807952742056:error:06065064:digital
envelope routines:EVP_DecryptFinal_ex:bad decrypt:evp_enc.c:539:
139807952742056:error:23077074:PKCS12 routines:PKCS12_pbe_crypt:pkcs12
cipherfinal error:p12_decr.c:104: 139807952742056:error:2306A075:PKCS12
routines:PKCS12_item_decrypt_d2i:pkcs12 pbe crypt error:p12_decr.c:130:
139807952742056:error:0907B00D:PEM routines:PEM_READ_BIO_PRIVATEKEY:ASN1
lib:pem_pkey.c:132: 2015/10/09 10:47:42 openxpki.system.ERROR:20943
[OpenXPKI::Server::API::Object (1422); raop(RA Operator)@b18d] Exception:
I18N_OPENXPKI_SERVER_API_OBJECT_GET_DATA_POOL_ENTRY_ENCRYPTION_KEY_UNAVAILABLE;
__PKI_REALM__ => uniline; __KEY__ => IRMAHsPkPIIxqxxss1gkbX8o/wQ; __SAFE_ID__
=> ca-one-vault-1; __NAMESPACE__ => sys.datapool.keys
I did an installation on debian 7. Modified the shell script to create
CA and other keys, certs. Install went smooth.
Also created separate realm. All certs install in ssl. Copied ca-one
into realm name.
Not sure what is causing this. Still trying to debug and see what went
wrong…
thank you.
Andrej Pintar
IRC: api984, freenode.net <http://freenode.net/>
::Software is like sex: it's better when it's free::
------------------------------------------------------------------------------
_______________________________________________
OpenXPKI-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openxpki-users