Hello,

        I am trying to figure out why System Status says OFFLINE. 
        I also noticed that YAML can be customized per use.
        
        I am trying to make certificates for servers and services like:
        apache, bacula, dovecot, postfix, mysql…

        Are there any YT videos or any kind of documentation in more detail. 

        Also when trying to make certs i get this error in log file:

        2015/10/05 23:32:19 openxpki.system.ERROR:19150 
[OpenXPKI::Server::API::Object (1422); raop(RA Operator)@d3f9] Exception: 
I18N_OPENXPKI_SERVER_API_OBJECT_GET_DATA_POOL_ENTRY_ENCRYPTION_KEY_UNAVAILABLE; 
__PKI_REALM__ => uniline; __KEY__ => Szujbc65YKSSpYS06VVhhdzeykU; __SAFE_ID__ 
=> ca-one-vault-1; __NAMESPACE__ => sys.datapool.keys

        If i truncate table data keys error does not happen upon creation.
        
        Also when I finish cert request and when it needs approval it throws 
same error again… 

2015/10/09 10:47:42 openxpki.application.INFO:20943 [OpenXPKI::Server::Workflow 
(128); raop(RA Operator)@b18d] Execute action csr_load_key_password on workflow 
#6143 2015/10/09 10:47:42 openxpki.system.ERROR:20943 [OpenXPKI::Crypto::CLI 
(/usr/lib/perl5/OpenXPKI/Crypto/CLI.pm:435); raop(RA Operator)@b18d] OpenSSL 
error: unable to load signing key file 139807952742056:error:06065064:digital 
envelope routines:EVP_DecryptFinal_ex:bad decrypt:evp_enc.c:539: 
139807952742056:error:23077074:PKCS12 routines:PKCS12_pbe_crypt:pkcs12 
cipherfinal error:p12_decr.c:104: 139807952742056:error:2306A075:PKCS12 
routines:PKCS12_item_decrypt_d2i:pkcs12 pbe crypt error:p12_decr.c:130: 
139807952742056:error:0907B00D:PEM routines:PEM_READ_BIO_PRIVATEKEY:ASN1 
lib:pem_pkey.c:132: 2015/10/09 10:47:42 openxpki.system.ERROR:20943 
[OpenXPKI::Server::API::Object (1422); raop(RA Operator)@b18d] Exception: 
I18N_OPENXPKI_SERVER_API_OBJECT_GET_DATA_POOL_ENTRY_ENCRYPTION_KEY_UNAVAILABLE; 
__PKI_REALM__ => uniline; __KEY__ => IRMAHsPkPIIxqxxss1gkbX8o/wQ; __SAFE_ID__ 
=> ca-one-vault-1; __NAMESPACE__ => sys.datapool.keys

        I did an installation on debian 7. Modified the shell script to create 
CA and other keys, certs. Install went smooth.
        Also created separate realm. All certs install in ssl. Copied ca-one 
into realm name. 

        Not sure what is causing this. Still trying to debug and see what went 
wrong… 

thank you.

Andrej Pintar

IRC: api984, freenode.net <http://freenode.net/>
::Software is like sex: it's better when it's free::




------------------------------------------------------------------------------
_______________________________________________
OpenXPKI-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openxpki-users

Reply via email to