Hi Til,
just submitted the update to our DNS.
Oliver
Til Obes wrote:
Hello all,
i have to move the site to a new server. So the IP address
will change. Please change it from 85.131.254.81 to
85.131.254.89. The site will be available on both hosts
from now on. I will shut down the old site som
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1
Hi Luigi,
> i'm trying to install on Debian the OpenXPKI CA, i followed this
> tutorial
> (http://wiki.openxpki.org/index.php/Best_Practices/Operating_systems/Debian/Debian_Package_Installation#How_To_Install_OpenXPKI_on_Debian),
> but after the insta
error was encountered while trying to use
an ErrorDocument to handle the request.
Apache/2.2.16 (Debian) Server at localhost Port 80"
I looked in the Apache configuration files and everything seems to be Ok.
Any suggestions??
Luigi
On Sun, Jan 29, 2012 at 4:38 PM, Oliver Welte
Hello Luigi,
as promised I prepared some debian squeeze packages with the current
development status.
The packages are available at http://packages.openxpki.org/debian
The packages feature a new (internal) certification interface, therefore
there are some limitations:
* You can use only PKC
Hi Luigi,
I published new packages yesterday.
LDAP Publishing is now working again.
Oliver
On 01.02.2012 15:44, Oliver Welter wrote:
Hello Luigi,
as promised I prepared some debian squeeze packages with the current
development status.
The packages are available at http
Hello Gaetan,
it looks like sf has problems with the ml, as my mail yesterday didnt
make it to the list.
Basically the i18n stuff should do. I am not aware of the current state
of the snapshots and the git head, but at least the debian packages at
packages.openxpki.org are working.
Anyway, t
Hello Gaetan,
basically the i18n stuff should do. I am not aware of the current state
of the snapshots and the git head, but at least the debian packages at
packages.openxpki.org are working.
The code internally uses gettext and sets the language environment to
LC_*=en_US.utf8 - can you check
Hi Gaetan,
thanks for your patience =)
The session mixing really looks weird. I know that the frontend has
problems if you work in more than one browser window and it is not
supported to have two different sessions in the same browser. If you try
to work as two roles, you need two different br
Hi Gaetan,
Am 19.06.2012 20:23, schrieb Gaëtan Minet:
>
> On 19/06/2012, at 18:35, Oliver Welter wrote:
>
>> The session mixing really looks weird. I know that the frontend has problems
>> if you work in more than one browser window and it is not supported to have
>>
Hi Gaetan,
Am 19.06.2012 21:18, schrieb Gaëtan Minet:
> Hi Oliver
>
> Well, looks like converting the secret table to MyISAM fixes it !!
> Addditionally, now the secret table is emptied upon daemon (re)start.
I use myisam here in testing, and this sounds like a problem with
transactions (myisam
Hi Gaetan,
this XML config system came directly from hell and is full of surprises.
You should not spend to much time as you will get a new, YAML based
profile config with the new packages on friday ;)
And yes , this stuff should better go to the devel list...
Oliver
On 20.06.2012 22:55, G
Dear OpenXPKI Users,
the project is making good efforts to stabilize and we still fight for
our plan to get a first stable release this year. We are currently
facing a critical decission and kindly ask for your vote.
The latest development is done on Debian Squeeze but we consider
switching
Hi Micha,
On 23.06.2012 20:09, Michael Bell wrote:
I think the comments regarding Debian are a little bit misleading. There
are two different things - development and packaging platforms.
ok you are right, so the rephrased question should be: What should be
the recommended distribution for dep
Hi
it sounds like most of our users are building their stuff from source.
@Chris - are you able and willing to help us in updating the rpm build
code?
Oliver
--
Protect your environment - close windows and adopt a penguin!
PGP-Key: 3B2C 8095 A7DF 8BB5 2CFF 8168 CAB7 B0DD 3985 1721
smim
Thats wrong! We are currently doing a rewrite of the SCEP Code, you can
see the current status on GitHub and a lot of the planned featureset on
the docs page
https://openxpki.readthedocs.org/en/latest/reference/configuration/workflows/scep.html
Note - this is development head and NOT fully work
Dear OpenXPKI Followers,
we are making good efforts on the OpenXPKI rewrite and the core team
decided its time to get a real logo for the project. We did a design
contest and got really great submissions - now we want *your opinion* on
the last two finalists.
Please pick your favorite at:
ht
Dear OpenXPKI Users,
the team is happy to announce the availability of the first "stable"
release of the rewritten OpenXPKI core.
Large parts of the core system have been overhauled, the most visible
change is the new config layer based on structured (and hopefully more
readable) YaML files.
Hi Florian,
yes it is a config issue . you passed a challenge password which was wrong:
2013/09/24 18:33:59 openxpki.workflow.INFO:27491
[OpenXPKI::Server::Workflow::Activity::SCEPv2::EvaluateChallenge (76);
scep-server-1()@d569] SCEP Challenge using compare validation FAILED!
I am in charge o
Hello Sergei,
Am 26.09.2013 10:04, schrieb Sergei Vyshenski:
openxpki: core for server part
openxpki-client: base class for actual clients
openxpki-i18n: internationalization of the user interface
openxpki-client-html-mason: web interface to local OpenXPKI daemon
openxpki-client-scep: set of SC
Dear OpenXPKI fellows,
a new release 0.11.4 has been tagged and packages for debian/ubuntu have
been pushed to the repository.
The major improvement is an extension to the scep enrollment workflow,
which now allows manipulation of the csr subject. Besides a lot of bugs
have been fixed and hook
Hello Thomas,
> thanks for the fast reply!
We always try to be fast ;D
>
>> OpenXPKI supports the concept of "PKI Realms". A Realm in our
>> terminology should be considered a logical CA, for example a CA
>> that issues certificates for server systems (web server, mail
>> server etc) only. Within
Hi Thomas,
after looking at the code I can confirm that we just did not implement
nyCertType=server. As Martin already answered this extension is a bit
outdated and should not be used, but if you really need it, I compiled a
patch to add support for it:
https://github.com/openxpki/openxpki/commit
Hi Sergei,
Am 16.06.2014 20:43, schrieb Sergei Vyshenski:
> Hi Martin,
>
> On 16.06.2014 22:07, Martin Bartosch wrote:
>> I know that we are not very good when it comes to maintaining the web page.
>> http://www.openxpki.org is at least up to date in a sense that it points to
>> the current doc
Hi Sergei,
I expected Martin to jump in here as it is his area.
Anyway, we rely on git as primary control and we also publish the git
references and tags inside the packages for better debugging and
transparency. Therefore I would encourage you to use a git checkout
instead of the tarball archive
Hi Sergei,
Am 17.06.2014 20:05, schrieb Sergei Vyshenski:
> 1. I see. Then what is the reason to publish releases on the page
>
> https://github.com/openxpki/openxpki/releases
>
> if these releases are not workable?
> Looks like a very dubious adds for users.
That was not intentional, I guess that
Dear OpenXPKI users,
it finally happend - the new UI is working and useable!
We are happy to announce the availability of the 0.15 release. Beside
the usual work under the hood, we managed to get the new ui working and
ship brandnew workflows for the UI to handle request and revocation.
We also
Hello Sergei,
Am 27.06.2014 21:37, schrieb Sergei Vyshenski:
> Do you mean that with this version UI has switched from Mason to FastCGI?
Yes - Mason UI is no longer supported and the code will be removed soon.
We will also start refactoring of the API and the Workflows so the old
UI will stop w
Hello Christian,
Am 28.06.2014 14:51, schrieb Christian Huldt:
Would it suffice to check out core and build that?
I'm wanting to try it out on gentoo
"Yes, in principle" or "No" suffice as answer :-)
For the bare code, yes - but I would also recommend to build the i18n
file (or just take the
Hi Sergei,
Am 28.06.2014 22:25, schrieb Sergei Vyshenski:
Hi Oliver,
1. What are dependencies of the openxpki distribution specific to the
use of FastCGI?
If Apache module for FastCGI is needed, which version exactly do you
recommend?
We do not have any specific requirements and do not depend o
Dear Followers,
a new release is available on the package mirror for debian wheezy. Due
to some issue we had to temporarily discontinue package build for ubuntu
trusty.
This release fixes a lot of small bugs and makes improvements to the new
UI component and includes a huge change in handlin
Hello Pawel,
> I'm new to openxpki, just started to read some docs.
welcome to the project.
> Looking at:
> https://openxpki.readthedocs.org/en/latest/reference/configuration/realm.html#authentication
>
> I see it's theoretically possible to use LDAP server as authentication
> backend. It loo
Hello Pawel,
> Is it possible to also add some external authenticators (perl
> scripts) to the upstream and include them in installable packages for
> Linux distros you support? If so, then I could do most of the job,
> just need some hints where to put the code and how to add it to
> packaging.
Hi Pawel,
Am 03.09.2014 um 13:16 schrieb Pawel Tomulik:
> is it possible to sort entries that appear in auth 'stack/handler
> selection' on login page? I have quite a lot of realms, and they appear
> on random order.
Not yet, it should sort simply by alphabet - if you need such a feature,
crea
Hi Pawel,
Am 03.09.2014 um 22:54 schrieb Pawel Tomulik:
> is it possible to substitute in
> /profile/I18N_OPENXPKI_PROFILE_USER.yaml
>
> the user name (uid) of the user issuing a CSR (currently logged in user)?
It is, but it would require some sort of magic. Do you want to just
preset the
Am 04.09.2014 um 15:07 schrieb Pawel Tomulik:
> W dniu 02.09.2014 20:47, Pawel Tomulik pisze:
>> W dniu 01.09.2014 15:34, Scott T. Hardin pisze:
>>> Hi Pawel,
>>>
>>> If the module you write is generic, it can be easily added to the Connector
>>> module. Just fork that repo on github and submit a
Am 04.09.2014 um 17:20 schrieb Pawel Tomulik:
> Noobs question,
>
> what secret method should I use for the vault private keys in my realms?
> For each realm I have a group of users (authenticated against LDAP) who
> should be able to easily issue CSRs (for personal certs). It looks like
> I'm n
Hi Pawel,
Am 06.09.2014 um 20:43 schrieb Pawel Tomulik:
> I want to add optional field to my profile template, but can't figure
> out how to achieve this. I'm basing on the default configuration:
By default, a field needs to be specified exactly one time, to make it
optional, add "min: 0" to th
Am 07.09.2014 um 17:21 schrieb Pawel Tomulik:
> Is it possible to perform log rotation without restarting the whole
> openxpki daemon? Log rotation is extremly useful, but if it requires
> restarts, then we're unable to preserve daemon-stored secrets and system
> becomes critical after first rot
Am 04.09.2014 um 15:04 schrieb Paweł Tomulik:
> W dniu 04.09.2014 08:09, Oliver Welter pisze:
>> Hi Pawel,
>>
>> Am 03.09.2014 um 22:54 schrieb Pawel Tomulik:
>>
>>> is it possible to substitute in
>>> /profile/I18N_OPENXPKI_PROFILE_USER.yaml
>
Dear OpenXPKI Followers,
we are happy to announce the release of version 0.22.
It fixes the problem with the watchdog dying when the database goes down
and contains several UI improvements contributed by Paweł Tomulik the
last weeks.
The code is tagged on the github repository and packages fpr d
Hi Pawel,
Am 11.09.2014 um 12:37 schrieb Pawel Tomulik:
> https://openxpki.readthedocs.org/en/latest/reference/configuration/realm.html#crypto-layer
>
> As I understand, the docs say:
>
> 1. Literal secrets provide no safety at all
You inherit the security of your operating system - with a a s
Hello Jacques,
the "core" package now comes with all components that are necessary to
run the GUI so there is no need to install/use the mason stuff any longer.
Setting up the GUI requires two things:
1) Copy the contents of core/server/htdocs/ into your document root - a
subdirectory is also fi
No Problem - to get an idea of the setup, I recommend to check the
debian postinst and preinst scripts in package/debian/core. This is what
we do for the debian package to make it move.
Oliver
Am 30.09.2014 um 16:20 schrieb Jacques MAROIN:
> Hello Olivier,
> Many thanks.
> This is really more com
Hi Christian,
1) Did you install the sample configs and use the demo setup or did you
create your own config?
2) We still habe problems with Non-ASCII / Non-Latin chars in the
subject - did you enter non-latin chars, and if so can you please try
again with latin chars only.
regards
Oliver
Am 0
schrieb Christian Huldt:
> I used sampleconfig.sh and no funny characters...
>
> Oliver Welter skrev 2014-10-01 16:04:
>> Hi Christian,
>>
>> 1) Did you install the sample configs and use the demo setup or did you
>> create your own config?
>>
>> 2
Am 02.10.2014 um 17:23 schrieb Christian Huldt:
> I found the problem...
>
> I had edited the sampleconfig.sh to change all
> "/DC=ORG/DC=OpenXPKI/OU=Test CA/CN=CA ONE" (and passwords as I don't
> want it easy for others even if I'm just taking it for a spin), but the
> created csr still had those
Dear OpenXPKI Followers,
a new release is tagged on github and available as debian wheezy package.
There have been a lot of improvements under the hood, most notably the
workflow config is now also in YAML and no longer in XML format and we
also removed the "config-versioning". Upgraders must
Hi,
I just published and tagged a new release 0.25.
This is mainly for fixing issues with the tests that blocked the FreeBSD
builds. Also some improvements on the UI have been made.
Your feedback is welcome.
Oliver
--
Protect your environment - close windows and adopt a penguin!
smime.p7s
Dear OpenXPKI Followers,
the new release 0.26 is out! Source code is tagged at github, pre-build
packages for debian wheezy are on the package server.
Most notable changes:
* configurable UI Menu trees for different user roles
* Stand-Alone Publication of CA-Certificates and CRL
* Improved "Token
Dear OpenXPKI Followers,
the recently published 0.26.0 packages had an error rendering the
certificate search unusable.
Please find updated packages for debian with version 0.26.1 on the server.
best regards
Oliver
--
Protect your environment - close windows and adopt a penguin!
smime.p7s
Hi Sergei
Am 08.02.2015 um 00:25 schrieb Sergei Vyshenski:
> My make procedure breaks because of files with space in a name, like
>
> CA Operator.yaml
> RA Operator.yaml
>
> More definitely, output of "find" presents such a file as two
> (non-existent) files.
>
> Is it that necessary to have
Dear OpenXPKI Followers,
the new release 0.27 is out! Source code is tagged at github, pre-build
packages for debian wheezy are on the package server.
The main improvement was done on rendering workflow status pages and
pagination for list views. The default workflows have received an
initial
Hi Nicolas,
Am 23.04.2015 um 11:28 schrieb Nicolas Grelliere:
I try to add several options such as --config with the configuration
directory but i always have the same problem.
if you use a recent version, the loadcfg command is no longer
necessary/implemented, the config is read and parsed
Am 24.04.2015 um 08:53 schrieb Nicolas Grelliere:
I use the 0.28 version of OpenxPKI, when i restart the server, the new
configuration is not parsed. For example, I change the default lifetime
of certificates and this modification doesn't appeared when I do a
certificate request on the Web inter
Hello Nicolas,
Am 27.04.2015 um 15:26 schrieb Nicolas Grelliere:> But now i'm
encountering a problem when i try to configure an SSCEP
> client. If i follow the quick start, by generating a certificate with a
> private key and retrieving CA certificate with the sscep command, when i
> want to cl
Am 28.04.2015 um 11:00 schrieb Nicolas Grelliere:
>this indicate that the openssl command to actually create the
>certificate crashes. I have seen this some times in the past when using
>non-latin chars or special attributes in the certificate.
In order to create initials certificate, i used
Hi Nicolas,
after looking at the database dump I found the problem - your scep
client sends a request with an empty subject CN:
Version: 0 (0x0)
Subject: C=FR, ST=France, O=Internet Widgits Pty Ltd
The default workflow extracts the "CN" portion of the csr subject and
creates the new cert
Hi Nicolas,
Am 29.04.2015 um 13:40 schrieb Nicolas Grelliere:
Actually, with the CN it works, thanks for your help. The default
great to hear.
configuration for scep delivered a certificate with the TLS profile,
when i change it to I18N_OPENXPKI_USER on the /scep/default.conf file,
sscep re
Am 30.04.2015 um 09:02 schrieb Nicolas Grelliere:
An other question concerning the scep mechanism, i have enrol a client
to my PKI server. By default the renewal period is fixed to 14 days,
during this period, if one client certificate is almost out of day how
can i do to renew it ? I have just
Hello Dan,
welcome to OpenXPKI.
Am 08.07.2015 um 13:08 schrieb Dan Rosendorf:
> I've been trying to set up openxpki for use with scep. I'm setting it up
> on Ubuntu trusty which I realize is currently not supported, but
> everything seems to be working fine except for the webgui.
What code did
Am 08.07.2015 um 14:05 schrieb Dan Rosendorf:
The webui.fcgi is called with "/cgi-bin/webui.fcgi", can you please
check if you can access the script and if it works. It should answer
with a json encoded message "goto:login".
After a couple issues with privileges (which I ended up solving by us
Am 08.07.2015 um 17:21 schrieb Dan Rosendorf:
I apologize for the rather trivial questions, but after finally fixing
the apache configuration to appropriately parse the webui.fcgi, I ended
up with a new problem. The webui now shows up and allows me to log in.
Unforuntately the only choices on the
Am 09.07.2015 um 10:24 schrieb Dan Rosendorf:
Loading page handler class OpenXPKI::Client::UI::Bootstrap, extra params $VAR1
= {};
Method is init_index
eval error during handle
Can't locate object method "init_index" via package
"OpenXPKI::Client::UI::Bootstrap" at /usr/local/lib/perl/5.18.2/Op
Hi Lukas,
Am 10.07.2015 um 00:20 schrieb Lukas Habegger:
It try to setup a scep auto-enroll environment for our cisco routers.
I did a basic setup of openxpki and i am able to get the CA cert over
scep but i can't get a cert
In /var/openxpki/openxpki.log i get the error cannot decrypt request
r code set - default to badRequest
Any suggestions?
Here the log:
>
Regards,
Lukas
On 10.07.2015 07:27, Oliver Welter wrote:
Hi Lukas,
Am 10.07.2015 um 00:20 schrieb Lukas Habegger:
It try to setup a scep auto-enroll environment for our cisco routers.
I did a basic setup of openxpki and i am ab
Hi Lukas,
Am 15.07.2015 um 22:10 schrieb Lukas Habegger:
Hi
How can i add a selection field for the signature algorithm
in the key generation form on the web ui?
I guess this is already answered by your post on SCEP - as Martin wrote,
we consider the signature algorithm to be a profile setti
Am 15.07.2015 um 20:59 schrieb Lukas Habegger:
Hi
Ok, thx. Found it.
When i comment out condition scep_signer_cert_active in
workflow/def/enrollment.yaml it works.
What scep_signer_cert_active stands for and where can i configure it?
This is a combined condition to ensure that you are eithe
Hi Kevin,
Am 22.09.2015 um 15:42 schrieb Kevin Waller:
Hello,
I just did a fresh install of openxpki on wheezy from the repos as
specified in the quickstart guide.
System version is Version (core): 0.34.1
oops - I should upload the 0.36 we did last week to the server =)
I created my own cer
Hi Kevin,
> Here is a list of the directory:
this looks fine
I was doing some thinking, to use the key files I generated, the system
would need to know the passwords that I used on them. Where do I
specify those passwords?
Right =)
Take a look at the file "config.d/realm/ca-one/crypto.yaml"
that you need to restart the daemon after changing config.
Oliver
On Tue, Sep 22, 2015 at 10:47 AM, Oliver Welter mailto:m...@oliwel.de>> wrote:
Hi Kevin,
> Here is a list of the directory:
this looks fine
I was doing some thinking, to use the key files I gener
Am 22.09.2015 um 17:49 schrieb Kevin Waller:
The answer is no and youre awesome, thanks for the help. The password in
the bottom of the config file (as well as regenerating all 4 certs so
they use the same password) made it go green. Thank you!!
You are welcome - might be you are interessted to
Am 24.09.2015 um 14:58 schrieb Kevin Waller:
Hello again!
I guess you got the servers updated, very cool. However, after the
upgrade I am unable to start openxpki:
Some things in the config changed, most notably a path to a class which
was moved and now is not found. I hope that this is one of
Hi Adnrej,
Am 09.10.2015 um 10:52 schrieb Andrej Pintar:
Are there any YT videos or any kind of documentation in more detail.
Well, no - setting up a PKI is nothing you should do with a YT Tutorial.
Also when trying to make certs i get this error in log file:
2015/10/05 23:32:19 openxpki.s
Hi Marian,
Am 08.11.2015 um 22:54 schrieb Marian Thieme:
I followed the Quickstart Guide until the step using the WebUI:
http://openxpki.readthedocs.org/en/stable/quickstart.html#adding-the-webclient
When visiting the website:
http://localhost/openxpki
the following webresource is loaded:
htt
Marian
On 11/08/15 23:35, Oliver Welter wrote:
Hi Marian,
Am 08.11.2015 um 22:54 schrieb Marian Thieme:
I followed the Quickstart Guide until the step using the WebUI:
http://openxpki.readthedocs.org/en/stable/quickstart.html#adding-the-webclient
When visiting the website:
http://localhost/ope
Hi Marian,
might it be the case that you forgot to activate the fastcgi module?
I saw the same error here due to it not working.
Oliver
Am 09.11.2015 um 08:04 schrieb Oliver Welter:
Hi Marian,
the jessie package has some issues with the apache config as debian has
changed some details on the
run fine.
We wont continue wheezy - I got the jessie packages working yesterday, I
will do some more tests and - if no problems occur - will publish them
today.
Oli
Marian
On 11/09/15 11:40, Oliver Welter wrote:
Hi Marian,
might it be the case that you forgot to activate the fastcgi module
Hi Matteo,
Am 10.11.2015 um 10:47 schrieb Matteo Cazzador:
Hi, i test you system with web interface and i'm really impress.
Thanks for the compliment 0)
I've a question , is it possible to have api like webservices/SOAP to
create client certificate from Openxpki CA?
It is on the roadmap but
Am 10.11.2015 um 11:15 schrieb Matteo Cazzador:
Thank's a lot, i explain better, i need to create many client
certificate *.pk12 (not simultaneus) to use with apache reverse proxy
access list.
Every users request and obtain a *.pk12 certificate (with personal
password), users will install pk1
Am 11.11.2015 um 09:58 schrieb Matteo Cazzador:
O, thanks a lot I have have some other request/info:
1 -
Possibility to search certificates
in expiring like give me the next month certificates in expiring.
It is possible to active this feautures? A more powerfull search criteria.
We need to know
Dear OpenXPKI Fellows,
we are very proud to announce the availability of the first stable
release. We decided to move to Debian Jessie as our primary operating
system, so if you already have an install you need to upgrade your
debian first.
The packages are available on the mirror, the quick
Hi David,
very strange - I just tried on a fresh checkout and it works. Do you
have the lastest revision (Version 1.1?) - the vagrant setup was broken
before.
If so, can you please run 'vagrant ssh test --command "locale -a | grep
en_US"' - you should see the "en_US.utf8" locale installed, i
Am 15.11.2015 um 12:04 schrieb David Lais:
Hi Oliver,
I checkout tag v1.1.0 and I do have en_US.utf8 installed on the
system. Vagrant version 1.7.4 with Virtualbox 5.0.2r102096.
I run VBox 4.3 but this shouldnt be a problem - can you check the
version of your debian base box? I have 8.2.1, pe
Hello Gerco,
Am 18.11.2015 um 17:18 schrieb Gerco Dries:
I'm trying to run a test instance of OpenXPKI on CentOS 7.1. I installed the package from
source and it seems to have worked ok (Web UI comes up, I can log in, text on the UI
looks fine, etc). Whenever I try to do anything real (request
Hi Sergey,
Am 22.11.2015 um 11:18 schrieb Sergey Zakharchenko:
I'm having issues trying to get OpenXPKI 0.28 (or 1.2.0, for that
matter) to run on FreeBSD (tried in 3 different setups). In short, it
doesn't work at all. I'm OK with having to install the web UI
manually, but even the command lin
Am 22.11.2015 um 14:23 schrieb Sergey Zakharchenko:
> Dont use foreground - it is just a development option and should be
removed from the manpage. In older versions, we terminated the process
on each "end of command", so we what you see here is what I expect.
OK, so I guess I'm the only one n
Am 22.11.2015 um 14:57 schrieb Sergey Zakharchenko:
Oliver,
> If you can tell me more about your problems, I am happy to try to
help you. It would help a lot when you share the docker image somewhere
or make it accessible for us.
Thanks for the offer; you likeky wouldn't be able to run it unde
Hi Marian,
sorry if this question sounds to stupid, but: Is the OpenXPKI daemon
running?
If so, can you please check the openxpki.log and check on the WebUI ->
Workflow Search if a workflow of type "enrollment" was created.
Oliver
Am 10.12.2015 um 23:44 schrieb Marian Thieme:
Dear openxpk
n 12/11/15 08:27, Oliver Welter wrote:
Hi Marian,
sorry if this question sounds to stupid, but: Is the OpenXPKI daemon
running?
If so, can you please check the openxpki.log and check on the WebUI ->
Workflow Search if a workflow of type "enrollment" was created.
Oliver
Am 10.1
Hi,
Am 12.12.2015 um 14:52 schrieb Marian Thieme:
Afterwards I manually approved it but for some reason I cannot finish
it. It keeps in state PREPARED (Paused) with reason: "Certificate
signing token is not online"
Will reconsult the SCEP docs and revise what I did so far.
This is not scep re
l/examples/sampleconfig.sh
The System Status page lists 2 tokens with status online:
certsign and datasafe
I noticed, on the top of that page there is a warning saying: your
system status is critical !
On 12/13/15 09:37, Oliver Welter wrote:
Hi,
Am 12.12.2015 um 14:52 schrieb Marian Thieme:
Afterwards
Hi,
Am 20.01.2016 um 13:48 schrieb Ronny Scheffler:
Is it possible to import a certificate over the web-frontend? Or is it
planed? I´ve got a couple of old certs with I want to import.
The intended use of OpenXPKI is to run a CA to issue the certs yourself,
so "importing" certificates via the
Hi Arie,
to be honest - postgres was introduces years ago by a former developer
but never really tested with the new releases. We just did not remove it
as we *planned* to test and get it working when time allows.
Please have a look for any "obvious" hints in the openxpki.log, it might
also
Hi Stefano,
glad to hear that it works for you and thank you very much for the offer.
There are still some artefacts that are hardcoded but if you translate
the items in the gettext files, you should be able to cover 90+%.
What to do:
* grab the english language file from
https://github.com/
'm brave enough (lol!) but if I can be of any help,
it'll be a pleasure to give something back to the team, so send me the
hints, I'll try to do my best.
Best regards,
Stefano.
2016-03-14 13:23 GMT+01:00 Oliver Welter mailto:m...@oliwel.de>>:
Hi Stefano,
glad to hear
o you have any suggestion?
Just let me know, I'll follow them!
Best regards,
Stefano
2016-03-14 17:40 GMT+01:00 Oliver Welter mailto:m...@oliwel.de>>:
Hi Stefano,
I really appreciate your help!
Have a look at the files in core/server/OpenXPKI/Client/UI/.
Especially the
Hi Bhagyashree,
first, I would appreciate if you can create a new mail for each problem.
To your problem: This soungs like your apache config is incomplete, the
SCEP service is provided by a script in cgi-bin and you need a proper
Alias definition:
ScriptAlias /scep /usr/lib/cgi-bin/sce
Am 18.05.2016 um 15:49 schrieb Martin Bartosch:
A rudimentary PKCS#11 driver exists and AFAIR works with OpenSC (however, I did
not test this myself).
I can confirm this - I had a PoC install using a Feitian USB token with
PCSC/OpenSC.
Oliver
--
Protect your environment - close windows an
Hi,
the path to the repo was wrong and is now corrected in the docs, it
should be "deb http://packages.openxpki.org/ubuntu/
trusty/release/binary-amd64/" (mind the space!).
If you fix this, you should be able to find the packages. The gpg error
is unfortunatly "known" - we have problems with
Hi Renaud,
first - this looks like you are using Ubutnu 16.04:
> Get: 3 http://fr.archive.ubuntu.com/ubuntu xenial/main amd64
We support packages for Trusty (14.04 LTS) for the moment, so you either
need to build the packages yourself (a make in package/debian MIGHT
work) or use Trusty.
The
1 - 100 of 925 matches
Mail list logo