Hi Oliver,

no changes to the crl profile, it is exactly like that:
https://github.com/openxpki/openxpki-config/blob/master/config.d/realm.tpl/crl/default.yaml
thanks for your tip I was able to find the generated crl under /var/tmp.
Here is the output of "openssl crl -noout -text -in openxpki1926EIKtXTgA".
It is a little "anonymized", do you really need the original one ?

Certificate Revocation List (CRL):
        Version 2 (0x1)
        Signature Algorithm: ecdsa-with-SHA256
        Issuer: C = BR, ST = MyCity, L = MyLocation, O = MyOrg, OU =
Managed Services, CN = MyOrg IA SubCA1 G1, emailAddress = [email protected]
        Last Update: Nov 20 13:17:06 2019 GMT
        Next Update: Dec  4 13:17:06 2019 GMT
        CRL extensions:
            X509v3 Authority Key Identifier:

keyid:D2:06:E0:78:DB:70:06:2D:0B:AB:7B:FB:DD:57:BD:A9:3C:F1:56:2B
                DirName:/C=BR/ST=MyCity/L=MyLocation/O=MyOrg/OU=Managed
Services/CN=MyOrg IA Root G1/[email protected]
                serial:4B:53:D6:41:0C:11:69:65

            X509v3 CRL Number:
                3327
No Revoked Certificates.
    Signature Algorithm: ecdsa-with-SHA256
         30:44:02:20:6a:5c:d4:3a:d8:1d:26:c1:81:0b:1b:c6:af:d8:



Regards,
Jeff

On Wed, 20 Nov 2019 at 12:22, Oliver Welter <[email protected]> wrote:

> Hi Jeff,
>
> can you please provide the crl profile configuration and the generated
> CRL. To get the CRL run "openxpkictl --keep-temp-files=yes start" and
> look into /var/tmp for the CRL file after running the workflow.
>
> best regards
>
> Oliver
>
> Am 20.11.19 um 11:07 schrieb Jefferson Dümes:
> > Hi people,
> >
> > I've got this error trying to issue CRL with OpenXPKI v3.1.3 on Debian
> 10:
> >
> > "This workflow was interrupted by an unexpected event, please contact
> > the support team!"
> > Workflow Context #1023
> > ca_alias ca-signer-1
> > creator myuser
> > force_issue true
> > wf_current_action global_nice_issue_crl
> > wf_exception decode: decode error at
> > /usr/share/perl5/Convert/ASN1/_decode.pm <http://decode.pm> line 125.
> > Cannot handle input or missing ASN.1 definitions at
> > /usr/lib/x86_64-linux-gnu/perl5/5.28/OpenXPKI/Crypt/CRL.pm line 379. at
> >
> /usr/lib/x86_64-linux-gnu/perl5/5.28/OpenXPKI/Server/API2/Plugin/Workflow/Util.pm
> > line 293.
> > workflow_id 102
> >
> > Extra Infos: This was a Debian 8 running OpenXPKI v2 which was upgraded
> > to 9 and then 10.
> > I follow the UPGRADEv3.md and as this is a test instance I just cleaned
> > up the DB and created it again with the new scheme. Using certificates I
> > was using with OpenXPKI v2.
> > OpenXPKI shows System Version 3.1.3
> >
> > Regards,
> > Jeff
> >
> >
> > _______________________________________________
> > OpenXPKI-users mailing list
> > [email protected]
> > https://lists.sourceforge.net/lists/listinfo/openxpki-users
> >
>
>
> --
> Protect your environment -  close windows and adopt a penguin!
>
> _______________________________________________
> OpenXPKI-users mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/openxpki-users
>
_______________________________________________
OpenXPKI-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openxpki-users

Reply via email to