Hi Jeff,

I pushed a fix to the development branch of github
https://github.com/openxpki/openxpki/commit/d0331232945cbeec9179876e1c1d65e6d02fba32

Please note - we are overhauling our release management strategy, I
expect a new STABLE release tagged as 3.2.0 by the end of the week.
Release Tags with odd numbers will mark development releases in the
future - the latest release that is packaged and fully tested is 3.1.3.

Oliver

Am 20.11.19 um 14:48 schrieb Jefferson Dümes:
> Hi Oliver,
> 
> no changes to the crl profile, it is exactly like that:
> https://github.com/openxpki/openxpki-config/blob/master/config.d/realm.tpl/crl/default.yaml
> thanks for your tip I was able to find the generated crl under /var/tmp.
> Here is the output of "openssl crl -noout -text -in
> openxpki1926EIKtXTgA". It is a little "anonymized", do you really need
> the original one ?
> 
>     Certificate Revocation List (CRL):
>             Version 2 (0x1)
>             Signature Algorithm: ecdsa-with-SHA256
>             Issuer: C = BR, ST = MyCity, L = MyLocation, O = MyOrg, OU =
>     Managed Services, CN = MyOrg IA SubCA1 G1, emailAddress =
>     [email protected] <mailto:[email protected]>
>             Last Update: Nov 20 13:17:06 2019 GMT
>             Next Update: Dec  4 13:17:06 2019 GMT
>             CRL extensions:
>                 X509v3 Authority Key Identifier:
>                    
>     keyid:D2:06:E0:78:DB:70:06:2D:0B:AB:7B:FB:DD:57:BD:A9:3C:F1:56:2B
>                    
>     DirName:/C=BR/ST=MyCity/L=MyLocation/O=MyOrg/OU=Managed
>     Services/CN=MyOrg IA Root G1/[email protected]
>     <mailto:[email protected]>
>                     serial:4B:53:D6:41:0C:11:69:65
> 
>                 X509v3 CRL Number:
>                     3327
>     No Revoked Certificates.
>         Signature Algorithm: ecdsa-with-SHA256
>              30:44:02:20:6a:5c:d4:3a:d8:1d:26:c1:81:0b:1b:c6:af:d8:
> 
> 
> 
> Regards,
> Jeff
> 
> On Wed, 20 Nov 2019 at 12:22, Oliver Welter <[email protected]
> <mailto:[email protected]>> wrote:
> 
>     Hi Jeff,
> 
>     can you please provide the crl profile configuration and the generated
>     CRL. To get the CRL run "openxpkictl --keep-temp-files=yes start" and
>     look into /var/tmp for the CRL file after running the workflow.
> 
>     best regards
> 
>     Oliver
> 
>     Am 20.11.19 um 11:07 schrieb Jefferson Dümes:
>     > Hi people,
>     >
>     > I've got this error trying to issue CRL with OpenXPKI v3.1.3 on
>     Debian 10:
>     >
>     > "This workflow was interrupted by an unexpected event, please contact
>     > the support team!"
>     > Workflow Context #1023
>     > ca_alias ca-signer-1
>     > creator myuser
>     > force_issue true
>     > wf_current_action global_nice_issue_crl
>     > wf_exception decode: decode error at
>     > /usr/share/perl5/Convert/ASN1/_decode.pm <http://decode.pm>
>     <http://decode.pm> line 125.
>     > Cannot handle input or missing ASN.1 definitions at
>     > /usr/lib/x86_64-linux-gnu/perl5/5.28/OpenXPKI/Crypt/CRL.pm line
>     379. at
>     >
>     
> /usr/lib/x86_64-linux-gnu/perl5/5.28/OpenXPKI/Server/API2/Plugin/Workflow/Util.pm
>     > line 293.
>     > workflow_id 102
>     >
>     > Extra Infos: This was a Debian 8 running OpenXPKI v2 which was
>     upgraded
>     > to 9 and then 10.
>     > I follow the UPGRADEv3.md and as this is a test instance I just
>     cleaned
>     > up the DB and created it again with the new scheme. Using
>     certificates I
>     > was using with OpenXPKI v2.
>     > OpenXPKI shows System Version 3.1.3
>     >
>     > Regards,
>     > Jeff
>     >
>     >
>     > _______________________________________________
>     > OpenXPKI-users mailing list
>     > [email protected]
>     <mailto:[email protected]>
>     > https://lists.sourceforge.net/lists/listinfo/openxpki-users
>     >
> 
> 
>     -- 
>     Protect your environment -  close windows and adopt a penguin!
> 
>     _______________________________________________
>     OpenXPKI-users mailing list
>     [email protected]
>     <mailto:[email protected]>
>     https://lists.sourceforge.net/lists/listinfo/openxpki-users
> 
> 
> 
> _______________________________________________
> OpenXPKI-users mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/openxpki-users
> 


-- 
Protect your environment -  close windows and adopt a penguin!

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

_______________________________________________
OpenXPKI-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/openxpki-users

Reply via email to