<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<id>tag:old.nabble.com,2006:forum-3689</id>
	<title>Nabble - OpenCA</title>
	<updated>2009-11-28T18:20:48Z</updated>
	<link rel="self" type="application/atom+xml" href="http://old.nabble.com/OpenCA-f3689.xml" />
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OpenCA-f3689.html" />
	<subtitle type="html">The OpenCA PKI Development Project is a collaborative effort to develop a robust, full-featured and Open Source out-of-the-box Certification Authority implementing the most used protocols with full-strength cryptography world-wide. OpenCA home is &lt;a href=&quot;http://sourceforge.net/projects/openca/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;here&lt;/a&gt;.</subtitle>
	
<entry>
	<id>tag:old.nabble.com,2006:post-26558851</id>
	<title>Re: Expired list doesn't show</title>
	<published>2009-11-28T18:20:48Z</published>
	<updated>2009-11-28T18:20:48Z</updated>
	<author>
		<name>Samuel Rios Carvalho</name>
	</author>
	<content type="html">hello Ralf&lt;br&gt;&lt;br&gt;please, don&amp;#39;t forget to see the problem in this weekend.&lt;br&gt;&lt;br&gt;thanks.&lt;br&gt;&lt;br clear=&quot;all&quot;&gt;Samuel Rios Carvalho&lt;br&gt;
&lt;br&gt;&lt;br&gt;&lt;div class=&quot;gmail_quote&quot;&gt;On Thu, Nov 26, 2009 at 2:25 PM, Ralf Hornik Mailings &lt;span dir=&quot;ltr&quot;&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26558851&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;ralf@...&lt;/a&gt;&amp;gt;&lt;/span&gt; wrote:&lt;br&gt;&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;
&lt;div class=&quot;im&quot;&gt;Samuel Rios Carvalho &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26558851&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nhawkbr@...&lt;/a&gt;&amp;gt; wrote:&lt;br&gt;
&lt;br&gt;
&lt;/div&gt;&lt;div class=&quot;im&quot;&gt;&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;
I think that in status like should be REVOKED, but I don&amp;#39;t know where I can&lt;br&gt;
change it.&lt;br&gt;
&lt;/blockquote&gt;
&lt;br&gt;&lt;/div&gt;
The database shows EXPIERD in the status field of certificate:&lt;br&gt;
&lt;br&gt;
select status,dn,date(notafter),time(notafter) from certificate where status = &amp;#39;EXPIRED&amp;#39;;&lt;br&gt;
&lt;br&gt;
So cmdlistCerts doesn&amp;#39;t seem to do the correct query.&lt;br&gt;
I will try to fix that on this weekend.&lt;br&gt;&lt;font color=&quot;#888888&quot;&gt;
&lt;br&gt;
Ralf&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;/font&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;
&lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26558851&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/openca-users-f3692.html&quot; embed=&quot;fixTarget[3692]&quot; target=&quot;_top&quot; &gt;openca-users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Expired-list-doesn%27t-show-tp26530153p26558851.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26532831</id>
	<title>Re: Expired list doesn't show</title>
	<published>2009-11-26T09:42:50Z</published>
	<updated>2009-11-26T09:42:50Z</updated>
	<author>
		<name>Samuel Rios Carvalho</name>
	</author>
	<content type="html">yes,&lt;br&gt;&lt;br&gt;sorry, I make a mistake speaking about REVOKED, the correct is EXPIRED.&lt;br&gt;&lt;br&gt;I&amp;#39;m waiting your fix.&lt;br&gt;&lt;br&gt;thanks&lt;br&gt;&lt;br&gt;&lt;br clear=&quot;all&quot;&gt;Samuel Rios Carvalho&lt;br&gt;
&lt;br&gt;&lt;br&gt;&lt;div class=&quot;gmail_quote&quot;&gt;On Thu, Nov 26, 2009 at 2:25 PM, Ralf Hornik Mailings &lt;span dir=&quot;ltr&quot;&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26532831&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;ralf@...&lt;/a&gt;&amp;gt;&lt;/span&gt; wrote:&lt;br&gt;&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;
&lt;div class=&quot;im&quot;&gt;Samuel Rios Carvalho &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26532831&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nhawkbr@...&lt;/a&gt;&amp;gt; wrote:&lt;br&gt;
&lt;br&gt;
&lt;/div&gt;&lt;div class=&quot;im&quot;&gt;&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;
I think that in status like should be REVOKED, but I don&amp;#39;t know where I can&lt;br&gt;
change it.&lt;br&gt;
&lt;/blockquote&gt;
&lt;br&gt;&lt;/div&gt;
The database shows EXPIERD in the status field of certificate:&lt;br&gt;
&lt;br&gt;
select status,dn,date(notafter),time(notafter) from certificate where status = &amp;#39;EXPIRED&amp;#39;;&lt;br&gt;
&lt;br&gt;
So cmdlistCerts doesn&amp;#39;t seem to do the correct query.&lt;br&gt;
I will try to fix that on this weekend.&lt;br&gt;&lt;font color=&quot;#888888&quot;&gt;
&lt;br&gt;
Ralf&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;/font&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;
&lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26532831&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/openca-users-f3692.html&quot; embed=&quot;fixTarget[3692]&quot; target=&quot;_top&quot; &gt;openca-users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Expired-list-doesn%27t-show-tp26530153p26532831.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26531803</id>
	<title>Re: Expired list doesn't show</title>
	<published>2009-11-26T08:25:05Z</published>
	<updated>2009-11-26T08:25:05Z</updated>
	<author>
		<name>Ralf Hornik Mailings</name>
	</author>
	<content type="html">Samuel Rios Carvalho &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26531803&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nhawkbr@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&lt;br&gt;&amp;gt; I think that in status like should be REVOKED, but I don't know where I can
&lt;br&gt;&amp;gt; change it.
&lt;br&gt;&lt;br&gt;The database shows EXPIERD in the status field of certificate:
&lt;br&gt;&lt;br&gt;select status,dn,date(notafter),time(notafter) from certificate where &amp;nbsp;
&lt;br&gt;status = 'EXPIRED';
&lt;br&gt;&lt;br&gt;So cmdlistCerts doesn't seem to do the correct query.
&lt;br&gt;I will try to fix that on this weekend.
&lt;br&gt;&lt;br&gt;Ralf
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26531803&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/openca-users-f3692.html&quot; embed=&quot;fixTarget[3692]&quot; target=&quot;_top&quot; &gt;openca-users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Expired-list-doesn%27t-show-tp26530153p26531803.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26531567</id>
	<title>Re: Expired list doesn't show</title>
	<published>2009-11-26T08:08:59Z</published>
	<updated>2009-11-26T08:08:59Z</updated>
	<author>
		<name>Samuel Rios Carvalho</name>
	</author>
	<content type="html">I found this query in my mysql&amp;#39;s log to show REVOKED certificates&lt;br&gt;&lt;br&gt;select * from openca.certificate where (cert_key &amp;gt;= &amp;#39;0&amp;#39; ) and  (status like &amp;#39;VALID&amp;#39;) and (notafter &amp;lt; &amp;#39;20091126160813&amp;#39; ) order by cert_key LIMIT 25&lt;br&gt;
&lt;br&gt;I think that in status like should be REVOKED, but I don&amp;#39;t know where I can change it.&lt;br&gt;&lt;br&gt;&lt;br clear=&quot;all&quot;&gt;Samuel Rios Carvalho&lt;br&gt;
&lt;br&gt;&lt;br&gt;&lt;div class=&quot;gmail_quote&quot;&gt;On Thu, Nov 26, 2009 at 12:23 PM, Samuel Rios Carvalho &lt;span dir=&quot;ltr&quot;&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26531567&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nhawkbr@...&lt;/a&gt;&amp;gt;&lt;/span&gt; wrote:&lt;br&gt;&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;
Hello,&lt;br&gt;&lt;br&gt;exactly 1 year I&amp;#39;m using OpenCA.&lt;br&gt;&lt;br&gt;Then, yesterday my first certificate expired. In EXPIRED Certificate List doesn&amp;#39;t show.&lt;br&gt;&lt;br&gt;I think it a little bug, please confirm.&lt;br&gt;&lt;font color=&quot;#888888&quot;&gt;&lt;br clear=&quot;all&quot;&gt;
Samuel Rios Carvalho&lt;br&gt;

&lt;/font&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;
&lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26531567&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/openca-users-f3692.html&quot; embed=&quot;fixTarget[3692]&quot; target=&quot;_top&quot; &gt;openca-users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Expired-list-doesn%27t-show-tp26530153p26531567.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26530153</id>
	<title>Expired list doesn't show</title>
	<published>2009-11-26T06:23:14Z</published>
	<updated>2009-11-26T06:23:14Z</updated>
	<author>
		<name>Samuel Rios Carvalho</name>
	</author>
	<content type="html">Hello,&lt;br&gt;&lt;br&gt;exactly 1 year I&amp;#39;m using OpenCA.&lt;br&gt;&lt;br&gt;Then, yesterday my first certificate expired. In EXPIRED Certificate List doesn&amp;#39;t show.&lt;br&gt;&lt;br&gt;I think it a little bug, please confirm.&lt;br&gt;&lt;br clear=&quot;all&quot;&gt;Samuel Rios Carvalho&lt;br&gt;

&lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26530153&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/openca-users-f3692.html&quot; embed=&quot;fixTarget[3692]&quot; target=&quot;_top&quot; &gt;openca-users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Expired-list-doesn%27t-show-tp26530153p26530153.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26519175</id>
	<title>Fwd: IDtrust peer-reviewed paper deadline extended to Dec 20</title>
	<published>2009-11-25T11:50:26Z</published>
	<updated>2009-11-25T11:50:26Z</updated>
	<author>
		<name>Massimiliano Pala-3</name>
	</author>
	<content type="html">FYI.
&lt;br&gt;&lt;br&gt;&amp;nbsp; -- Max
&lt;br&gt;&lt;br&gt;&lt;br&gt;-------- Original Message --------
&lt;br&gt;Subject: IDtrust peer-reviewed paper deadline extended to Dec 20
&lt;br&gt;Date: Wed, 25 Nov 2009 10:53:04 -0700
&lt;br&gt;From: Neal McBurnett &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26519175&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;neal@...&lt;/a&gt;&amp;gt;
&lt;br&gt;To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26519175&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;MW-PKIPrgmCommittee@...&lt;/a&gt;
&lt;br&gt;&lt;br&gt;Thanks to everyone for quick responses and good conversation around
&lt;br&gt;the date extension. &amp;nbsp;Based on overwhelming support I've updated the
&lt;br&gt;web site, extending the deadline for peer-reviewed papers to Dec 20th:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://middleware.internet2.edu/idtrust/2010/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://middleware.internet2.edu/idtrust/2010/&lt;/a&gt;&lt;br&gt;&lt;br&gt;I hope you can take a moment to share that with your colleagues and
&lt;br&gt;encourage them to submit a paper, and also to propose a panel.
&lt;br&gt;&lt;br&gt;The panel proposal deadline is Jan 24 but we'd love to hear ideas
&lt;br&gt;earlier. &amp;nbsp;Radia Perlman is the panels chair. &amp;nbsp;At this point we're
&lt;br&gt;looking for folks who will step forward to gather participants and
&lt;br&gt;coordinate an interesting, relevant panel.
&lt;br&gt;&lt;br&gt;Cheers, and happy Thanksgiving!
&lt;br&gt;&lt;br&gt;Neal McBurnett &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://neal.mcburnett.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://neal.mcburnett.org/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br /&gt; &lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;OpenCA-Devel mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26519175&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;OpenCA-Devel@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-devel&lt;/a&gt;&lt;br&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;smime.p7s&lt;/strong&gt; (4K) &lt;a href=&quot;http://old.nabble.com/attachment/26519175/0/smime.p7s&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/openca-devel-f3691.html&quot; embed=&quot;fixTarget[3691]&quot; target=&quot;_top&quot; &gt;openca-devel&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Fwd%3A-IDtrust-peer-reviewed-paper-deadline-extended-to-Dec-20-tp26519175p26519175.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26519171</id>
	<title>Fwd: IDtrust peer-reviewed paper deadline extended to Dec 20</title>
	<published>2009-11-25T11:50:19Z</published>
	<updated>2009-11-25T11:50:19Z</updated>
	<author>
		<name>Massimiliano Pala-3</name>
	</author>
	<content type="html">FYI.
&lt;br&gt;&lt;br&gt;&amp;nbsp; -- Max
&lt;br&gt;&lt;br&gt;&lt;br&gt;-------- Original Message --------
&lt;br&gt;Subject: IDtrust peer-reviewed paper deadline extended to Dec 20
&lt;br&gt;Date: Wed, 25 Nov 2009 10:53:04 -0700
&lt;br&gt;From: Neal McBurnett &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26519171&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;neal@...&lt;/a&gt;&amp;gt;
&lt;br&gt;To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26519171&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;MW-PKIPrgmCommittee@...&lt;/a&gt;
&lt;br&gt;&lt;br&gt;Thanks to everyone for quick responses and good conversation around
&lt;br&gt;the date extension. &amp;nbsp;Based on overwhelming support I've updated the
&lt;br&gt;web site, extending the deadline for peer-reviewed papers to Dec 20th:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://middleware.internet2.edu/idtrust/2010/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://middleware.internet2.edu/idtrust/2010/&lt;/a&gt;&lt;br&gt;&lt;br&gt;I hope you can take a moment to share that with your colleagues and
&lt;br&gt;encourage them to submit a paper, and also to propose a panel.
&lt;br&gt;&lt;br&gt;The panel proposal deadline is Jan 24 but we'd love to hear ideas
&lt;br&gt;earlier. &amp;nbsp;Radia Perlman is the panels chair. &amp;nbsp;At this point we're
&lt;br&gt;looking for folks who will step forward to gather participants and
&lt;br&gt;coordinate an interesting, relevant panel.
&lt;br&gt;&lt;br&gt;Cheers, and happy Thanksgiving!
&lt;br&gt;&lt;br&gt;Neal McBurnett &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://neal.mcburnett.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://neal.mcburnett.org/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br /&gt; &lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26519171&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;smime.p7s&lt;/strong&gt; (4K) &lt;a href=&quot;http://old.nabble.com/attachment/26519171/0/smime.p7s&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/openca-users-f3692.html&quot; embed=&quot;fixTarget[3692]&quot; target=&quot;_top&quot; &gt;openca-users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Fwd%3A-IDtrust-peer-reviewed-paper-deadline-extended-to-Dec-20-tp26519171p26519171.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26479630</id>
	<title>Re: OCSP URL - what's it return????</title>
	<published>2009-11-23T07:05:41Z</published>
	<updated>2009-11-23T07:05:41Z</updated>
	<author>
		<name>Massimiliano Pala-3</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;&lt;br&gt;the HTTP GET support is on its way. Actually we are in the process of
&lt;br&gt;porting the OCSP server to LibPKI - it makes it easier to manage HSMs
&lt;br&gt;and it has direct support for PKCS#11 devices.
&lt;br&gt;&lt;br&gt;Once we have a stable version (0.4.0) of LibPKI we will finish the work
&lt;br&gt;on the OCSP server and publish the new version.
&lt;br&gt;&lt;br&gt;This is the first step toward the extensive use of LibPKI in all of our
&lt;br&gt;servers. Ideally we will have a single server with plugins for the different
&lt;br&gt;services that can be enabled/disabled. By using the PRQP activating and
&lt;br&gt;de-activating a service will enable clients to automatically use (or
&lt;br&gt;stop using) the specific service... that is a very useful feature!!!!
&lt;br&gt;&lt;br&gt;Cheers,
&lt;br&gt;Max
&lt;br&gt;&lt;br&gt;&lt;br&gt;On 11/20/2009 04:29 PM, &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26479630&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;blainedw@...&lt;/a&gt; wrote:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Cool. I wasn't sure if the chain should be specified as part of the
&lt;br&gt;&amp;gt; -issuer cert or the -CAcert. Your help confirmed that it is the -CAcert
&lt;br&gt;&amp;gt; that requires the concatenated chain of certs.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Also when will you support HTTP GET method in OCSP?
&lt;br&gt;&lt;br&gt;&lt;br /&gt; &lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26479630&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;smime.p7s&lt;/strong&gt; (4K) &lt;a href=&quot;http://old.nabble.com/attachment/26479630/0/smime.p7s&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/openca-users-f3692.html&quot; embed=&quot;fixTarget[3692]&quot; target=&quot;_top&quot; &gt;openca-users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OCSP-URL---what%27s-it-return-----tp26337743p26479630.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26450563</id>
	<title>Re: OCSP URL - what's it return????</title>
	<published>2009-11-20T13:29:05Z</published>
	<updated>2009-11-20T13:29:05Z</updated>
	<author>
		<name>blainedw</name>
	</author>
	<content type="html">
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;Cool. I wasn't sure if the chain should
be specified as part of the -issuer cert or the -CAcert. Your help confirmed
that it is the -CAcert that requires the concatenated chain of certs.&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;Also when will you support HTTP GET
method in OCSP?&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;Dave&lt;br&gt;
&lt;/font&gt;&lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26450563&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/openca-users-f3692.html&quot; embed=&quot;fixTarget[3692]&quot; target=&quot;_top&quot; &gt;openca-users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OCSP-URL---what%27s-it-return-----tp26337743p26450563.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26447269</id>
	<title>Re: OCSP URL - what's it return????</title>
	<published>2009-11-20T09:38:57Z</published>
	<updated>2009-11-20T09:38:57Z</updated>
	<author>
		<name>Massimiliano Pala-3</name>
	</author>
	<content type="html">Yes.
&lt;br&gt;&lt;br&gt;OpenSSL needs to have the full chain of certificates. You can use the
&lt;br&gt;-CAfile &amp;lt;file&amp;gt; option for adding trusted certs to the verification
&lt;br&gt;process. You might then get the error for the root CA saying that it
&lt;br&gt;is a self-signed cert :D That will be ok... :D
&lt;br&gt;&lt;br&gt;Later,
&lt;br&gt;Max
&lt;br&gt;&lt;br&gt;&lt;br&gt;On 11/13/2009 07:26 PM, &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26447269&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;blainedw@...&lt;/a&gt; wrote:
&lt;br&gt;&amp;gt; Hi max
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Getting back to something you said earlier in the thread about the error
&lt;br&gt;&amp;gt; that isn't an error. If you see my openssl command I'm using -issuer
&lt;br&gt;&amp;gt; parameter. So doesn't this tell openssl who the issuer is? This a subca
&lt;br&gt;&amp;gt; so does this -issuer parameter require a concat of ca certs that make up
&lt;br&gt;&amp;gt; the chain?
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;&lt;br&gt;Best Regards,
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Massimiliano Pala
&lt;br&gt;&lt;br&gt;--o------------------------------------------------------------------------
&lt;br&gt;Massimiliano Pala [OpenCA Project Manager] &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26447269&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openca@...&lt;/a&gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26447269&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;project.manager@...&lt;/a&gt;
&lt;br&gt;&lt;br&gt;Dartmouth Computer Science Dept &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Home Phone: +1 (603) 369-9332
&lt;br&gt;PKI/Trust Laboratory &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Work Phone: +1 (603) 646-8734
&lt;br&gt;--o------------------------------------------------------------------------
&lt;br&gt;People who think they know everything are a great annoyance to those of us
&lt;br&gt;who do.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;-- Isaac Asimov
&lt;br&gt;&lt;br&gt;&lt;br /&gt; &lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26447269&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;smime.p7s&lt;/strong&gt; (4K) &lt;a href=&quot;http://old.nabble.com/attachment/26447269/0/smime.p7s&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/openca-users-f3692.html&quot; embed=&quot;fixTarget[3692]&quot; target=&quot;_top&quot; &gt;openca-users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OCSP-URL---what%27s-it-return-----tp26337743p26447269.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26447225</id>
	<title>Re: cross-site request forgery (XSRF)</title>
	<published>2009-11-20T09:35:28Z</published>
	<updated>2009-11-20T09:35:28Z</updated>
	<author>
		<name>Massimiliano Pala-3</name>
	</author>
	<content type="html">Hello Leo,
&lt;br&gt;&lt;br&gt;I guess you can check the OpenCA::AC module and disable the check for
&lt;br&gt;the xsrf token there. That should do the trick.
&lt;br&gt;&lt;br&gt;I am not convinced it is a good idea, though. If you have other security
&lt;br&gt;mechanisms in place.. than it might be ok.. if not, then your PKI could
&lt;br&gt;be subject to the attack.. if the OpenCA pages are accessible via the
&lt;br&gt;&amp;lt;iframe&amp;gt; element.. that means I can request them directly if I know the
&lt;br&gt;URL.. and that exposes you to all of the problems...
&lt;br&gt;&lt;br&gt;In future versions we could actually think about a configuration option
&lt;br&gt;that allows for the xsrf to be disabled.. but another protection should
&lt;br&gt;be in place...
&lt;br&gt;&lt;br&gt;Later,
&lt;br&gt;Max
&lt;br&gt;&lt;br&gt;&lt;br&gt;On 11/13/2009 11:48 AM, Leo Catalinas wrote:
&lt;div class='shrinkable-quote'&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hello,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; We use OpenCA 0.9.x in a couple of university projects and we are very
&lt;br&gt;&amp;gt; pleased with it, having issued near 700 certificates for students and
&lt;br&gt;&amp;gt; professors for e-learning in the last three years.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; We integrate many screens and forms (like the request form) in a public
&lt;br&gt;&amp;gt; web page (our pki portal) made with Joomla an its &amp;quot;wrapper&amp;quot; option
&lt;br&gt;&amp;gt; (allows to embeed an external page within the page body using the html
&lt;br&gt;&amp;gt; &amp;quot;&amp;lt;iframe&amp;gt;&amp;quot; element).
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Now, we have tried the 1.0.2 version and we have seen that the &amp;quot;wrapper&amp;quot;
&lt;br&gt;&amp;gt; option doesn't work because the new OpenCA XSRF protection.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; We need the &amp;quot;wrapper&amp;quot; option to integrate OpenCA forms with Joomla, but
&lt;br&gt;&amp;gt; tried to disable the XSRF protection and we didn't find how to do it.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; How to disable XSRF or how to make work without disabling it? Any
&lt;br&gt;&amp;gt; suggestion, please?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Thank you very much
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Regards,
&lt;br&gt;&amp;gt; Leo Catalinas,
&lt;/div&gt;&lt;/div&gt;&lt;br /&gt; &lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;OpenCA-Devel mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26447225&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;OpenCA-Devel@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-devel&lt;/a&gt;&lt;br&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;smime.p7s&lt;/strong&gt; (4K) &lt;a href=&quot;http://old.nabble.com/attachment/26447225/0/smime.p7s&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/openca-devel-f3691.html&quot; embed=&quot;fixTarget[3691]&quot; target=&quot;_top&quot; &gt;openca-devel&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/cross-site-request-forgery-%28XSRF%29-tp26339844p26447225.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26397928</id>
	<title>Batch Process Adjustments Questions</title>
	<published>2009-11-17T13:22:42Z</published>
	<updated>2009-11-17T13:22:42Z</updated>
	<author>
		<name>murphykm</name>
	</author>
	<content type="html">
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;Hello,&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;I have been tasked with adding additional
fields to our cert creation that is done via batching. I have about 15
fields or so that I need to add to the cert. &lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;Looking through the code, it appears
that create_csr.sub is the one I need to alter. The changes I have made
seem to create the field files similar to SUBJECT and such that were created
before. Each field file does have the correct data. However, when the cert
is created, none of my custom fields show up. &lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;Here are some of the changes I have
made:&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;At line 26, I define the new variables
and fields I am tracking&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;&amp;nbsp; &amp;nbsp; my @additionalfields =
(&amp;quot;EMPLOYEEID&amp;quot;,&amp;quot;USERID&amp;quot;,&amp;quot;CITIZENSHIP&amp;quot;,&amp;quot;EMAIL&amp;quot;,&amp;quot;DEPTARTMENT&amp;quot;,&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;quot;PHONE&amp;quot;,&amp;quot;APPLICATION&amp;quot;,&amp;quot;COMPANY&amp;quot;,&amp;quot;LOCATION&amp;quot;,&amp;quot;ADDRESS&amp;quot;,&amp;quot;MAILZONE&amp;quot;,&amp;quot;CITY&amp;quot;,&amp;quot;STATE&amp;quot;,&amp;quot;ZIP&amp;quot;,&amp;quot;COUNTRY&amp;quot;);&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;&amp;nbsp; &amp;nbsp; my %fields = ();&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;&amp;nbsp; &amp;nbsp; my $field = &amp;quot;&amp;quot;;&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;Around line 76 (Right below the load
subject lines)&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;&amp;nbsp; &amp;nbsp; foreach $field (@additionalfields)
{&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; $fields{$field}
= $tools-&amp;gt;getFile ($home.&amp;quot;/data/&amp;quot;.$field);&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; if (not
$fields{$field} ) {&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&amp;nbsp; &amp;nbsp; my $msg = gettext (&amp;quot;The $field of the request cannot
be loaded.&amp;quot;);&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&amp;nbsp; &amp;nbsp; $journal-&amp;gt;{message} .= $msg;&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&amp;nbsp; &amp;nbsp; $log-&amp;gt;addMessage (OpenCA::Log::Message-&amp;gt;new (HASHREF
=&amp;gt; $journal));&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&amp;nbsp; &amp;nbsp; return [ -150, $msg ];&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; }&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;&amp;nbsp; &amp;nbsp; }&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;Then right after &amp;nbsp;line 136 I added
the three lines below:&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;&amp;nbsp; &amp;nbsp; foreach $field (@additionalfields)
{&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
$tmp .= $field.&amp;quot; = &amp;quot;.$fields{$field}.&amp;quot;\n&amp;quot;;&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;&amp;nbsp; &amp;nbsp; }&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;After all that I my new fields do not
show up in the cert. Do I need to alter OpenCA::REQ or something? I am
not sure where to look next.&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;Thank you,&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;K Murphy&lt;br&gt;
Email: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26397928&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;murphykm@...&lt;/a&gt;&lt;br&gt;
&lt;/font&gt;&lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;OpenCA-Devel mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26397928&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;OpenCA-Devel@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-devel&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/openca-devel-f3691.html&quot; embed=&quot;fixTarget[3691]&quot; target=&quot;_top&quot; &gt;openca-devel&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Batch-Process-Adjustments-Questions-tp26397928p26397928.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26363601</id>
	<title>Re: Trouble with LDAP and CRL's</title>
	<published>2009-11-15T13:27:21Z</published>
	<updated>2009-11-15T13:27:21Z</updated>
	<author>
		<name>blainedw</name>
	</author>
	<content type="html">Hi ralf
&lt;br&gt;&lt;br&gt;Thanks for the response. I've been reading about ldap's alias feature and will probably use that to overcome my shortcomings. 
&lt;br&gt;&lt;br&gt;Dave
&lt;br&gt;&amp;gt;From David Blaine's blackberry
&lt;br&gt;&lt;br&gt;&lt;br&gt;----- Original Message -----
&lt;br&gt;From: Ralf Hornik Mailings [&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26363601&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;ralf@...&lt;/a&gt;]
&lt;br&gt;Sent: 11/15/2009 07:08 PM CET
&lt;br&gt;To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26363601&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openca-users@...&lt;/a&gt;
&lt;br&gt;Subject: Re: [Openca-Users] Trouble with LDAP and CRL's
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26363601&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;blainedw@...&lt;/a&gt; wrote:
&lt;br&gt;&lt;br&gt;&amp;gt; My problem now is my root certificate LDAP CDP does not include the email
&lt;br&gt;&amp;gt; address and I cannot reissue a new one. Any magic within LDAP I can do?
&lt;br&gt;&lt;br&gt;It depends on the SSL app. Some apps use subsearch and some not for &amp;nbsp;
&lt;br&gt;retrieving CRLs. Subsearch is also not recommended because of &amp;nbsp;
&lt;br&gt;performance issues.
&lt;br&gt;&lt;br&gt;The easiest way would be to move the crl to the CDP-DN of your &amp;nbsp;
&lt;br&gt;certificates by hand and &amp;quot;patch&amp;quot; your OpenCA installation to enroll &amp;nbsp;
&lt;br&gt;any new CRL there in future.
&lt;br&gt;Regards
&lt;br&gt;&lt;br&gt;Ralf
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26363601&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26363601&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/openca-users-f3692.html&quot; embed=&quot;fixTarget[3692]&quot; target=&quot;_top&quot; &gt;openca-users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Trouble-with-LDAP-and-CRL%27s-tp26337641p26363601.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26361585</id>
	<title>Re: Trouble with LDAP and CRL's</title>
	<published>2009-11-15T10:08:11Z</published>
	<updated>2009-11-15T10:08:11Z</updated>
	<author>
		<name>Ralf Hornik Mailings</name>
	</author>
	<content type="html">&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26361585&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;blainedw@...&lt;/a&gt; wrote:
&lt;br&gt;&lt;br&gt;&amp;gt; My problem now is my root certificate LDAP CDP does not include the email
&lt;br&gt;&amp;gt; address and I cannot reissue a new one. Any magic within LDAP I can do?
&lt;br&gt;&lt;br&gt;It depends on the SSL app. Some apps use subsearch and some not for &amp;nbsp;
&lt;br&gt;retrieving CRLs. Subsearch is also not recommended because of &amp;nbsp;
&lt;br&gt;performance issues.
&lt;br&gt;&lt;br&gt;The easiest way would be to move the crl to the CDP-DN of your &amp;nbsp;
&lt;br&gt;certificates by hand and &amp;quot;patch&amp;quot; your OpenCA installation to enroll &amp;nbsp;
&lt;br&gt;any new CRL there in future.
&lt;br&gt;Regards
&lt;br&gt;&lt;br&gt;Ralf
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26361585&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/openca-users-f3692.html&quot; embed=&quot;fixTarget[3692]&quot; target=&quot;_top&quot; &gt;openca-users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Trouble-with-LDAP-and-CRL%27s-tp26337641p26361585.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26345777</id>
	<title>Re: OCSP URL - what's it return????</title>
	<published>2009-11-13T16:26:20Z</published>
	<updated>2009-11-13T16:26:20Z</updated>
	<author>
		<name>blainedw</name>
	</author>
	<content type="html">&lt;font size=&quot;2&quot;&gt;&lt;p&gt;Hi max&lt;br&gt;&lt;br&gt;Getting back to something you said earlier in the thread about the error that isn't an error. If you see my openssl command I'm using -issuer parameter. So doesn't this tell openssl who the issuer is? This a subca so does this -issuer parameter require a concat of ca certs that make up the chain? &lt;br&gt;&lt;br&gt;Just trying to understand&lt;br&gt;&lt;br&gt;Dave&lt;br&gt;From David Blaine's blackberry&lt;br&gt;&lt;/p&gt;&lt;/font&gt;&lt;hr&gt;&lt;font size=&quot;2&quot;&gt;&lt;p&gt;&lt;b&gt;&amp;nbsp; From: &lt;/b&gt;blainedw&lt;br&gt;&lt;b&gt;&amp;nbsp; Sent: &lt;/b&gt;11/13/2009 04:53 PM EST&lt;br&gt;&lt;b&gt;&amp;nbsp; To: &lt;/b&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26345777&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openca@...&lt;/a&gt;; &amp;quot;Users' Help and Suggestions&amp;quot; &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26345777&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openca-users@...&lt;/a&gt;&amp;gt;&lt;br&gt;&lt;b&gt;&amp;nbsp; Subject: &lt;/b&gt;Re: [Openca-Users] OCSP URL - what's it return????&lt;br&gt;&lt;/p&gt;&lt;/font&gt;&lt;br&gt;

&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;The OCSP is defined as an AIA location&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;&lt;br&gt;
I'll check the logs when I get a chance.&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;Dave&lt;/font&gt;&lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26345777&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;&lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26345777&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/openca-users-f3692.html&quot; embed=&quot;fixTarget[3692]&quot; target=&quot;_top&quot; &gt;openca-users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OCSP-URL---what%27s-it-return-----tp26337743p26345777.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26344158</id>
	<title>Re: OCSP URL - what's it return????</title>
	<published>2009-11-13T13:53:45Z</published>
	<updated>2009-11-13T13:53:45Z</updated>
	<author>
		<name>blainedw</name>
	</author>
	<content type="html">
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;The OCSP is defined as an AIA location&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;&lt;br&gt;
I'll check the logs when I get a chance.&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;Dave&lt;/font&gt;&lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26344158&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/openca-users-f3692.html&quot; embed=&quot;fixTarget[3692]&quot; target=&quot;_top&quot; &gt;openca-users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OCSP-URL---what%27s-it-return-----tp26337743p26344158.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26344107</id>
	<title>Re: Trouble with LDAP and CRL's</title>
	<published>2009-11-13T13:50:01Z</published>
	<updated>2009-11-13T13:50:01Z</updated>
	<author>
		<name>blainedw</name>
	</author>
	<content type="html">
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;I checked ldapsearch and thanks to Ralf
the DN does have the email address in it... OK, I downloaded and installed
libpki. Using that tool and having the email address in the DN, I was able
to retrieve something (lots of garbled characters). &lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;My problem now is my root certificate
LDAP CDP does not include the email address and I cannot reissue a new
one. Any magic within LDAP I can do?&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;&lt;br&gt;
Dave&lt;/font&gt;&lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26344107&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/openca-users-f3692.html&quot; embed=&quot;fixTarget[3692]&quot; target=&quot;_top&quot; &gt;openca-users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Trouble-with-LDAP-and-CRL%27s-tp26337641p26344107.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26344011</id>
	<title>Re: OCSP URL - what's it return????</title>
	<published>2009-11-13T13:43:20Z</published>
	<updated>2009-11-13T13:43:20Z</updated>
	<author>
		<name>Massimiliano Pala-3</name>
	</author>
	<content type="html">I guess we have 2 separate issues here. The CDP is the CRL Distribution
&lt;br&gt;Point - not the OCSP responder address. That should point to your CRL
&lt;br&gt;http location.
&lt;br&gt;&lt;br&gt;I have not used the PKIVIEW on Winz... but have you checked the logs on
&lt;br&gt;the OCSP server (should be /var/log/messages).. what do they report ? It
&lt;br&gt;might be that the PKIVIEW uses the HTTP GET instead of the HTTP POST for
&lt;br&gt;the OCSP.. this is just a wild guess.. :D But since the current version
&lt;br&gt;of the software does not support GET.. you'll have to wait for the new
&lt;br&gt;version (which will support GET as well..).
&lt;br&gt;&lt;br&gt;Let us know...
&lt;br&gt;&lt;br&gt;Later,
&lt;br&gt;Max
&lt;br&gt;&lt;br&gt;&lt;br&gt;On 11/13/2009 04:10 PM, &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26344011&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;blainedw@...&lt;/a&gt; wrote:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; When I look in PKIVIEW (windows utility) to verify my AIA and CDP
&lt;br&gt;&amp;gt; locations. It states unable to download for both my LDAP CDP and my OCSP
&lt;br&gt;&amp;gt; location.
&lt;br&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;&lt;br&gt;Best Regards,
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Massimiliano Pala
&lt;br&gt;&lt;br&gt;--o------------------------------------------------------------------------
&lt;br&gt;Massimiliano Pala [OpenCA Project Manager] &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26344011&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openca@...&lt;/a&gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26344011&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;project.manager@...&lt;/a&gt;
&lt;br&gt;&lt;br&gt;Dartmouth Computer Science Dept &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Home Phone: +1 (603) 369-9332
&lt;br&gt;PKI/Trust Laboratory &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Work Phone: +1 (603) 646-8734
&lt;br&gt;--o------------------------------------------------------------------------
&lt;br&gt;People who think they know everything are a great annoyance to those of us
&lt;br&gt;who do.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;-- Isaac Asimov
&lt;br&gt;&lt;br&gt;&lt;br /&gt; &lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26344011&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;smime.p7s&lt;/strong&gt; (4K) &lt;a href=&quot;http://old.nabble.com/attachment/26344011/0/smime.p7s&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/openca-users-f3692.html&quot; embed=&quot;fixTarget[3692]&quot; target=&quot;_top&quot; &gt;openca-users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OCSP-URL---what%27s-it-return-----tp26337743p26344011.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26343631</id>
	<title>Re: OCSP URL - what's it return????</title>
	<published>2009-11-13T13:10:17Z</published>
	<updated>2009-11-13T13:10:17Z</updated>
	<author>
		<name>blainedw</name>
	</author>
	<content type="html">
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;When I look in PKIVIEW (windows utility)
to verify my AIA and CDP locations. It states unable to download for both
my LDAP CDP and my OCSP location.&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;&lt;br&gt;
Dave&lt;br&gt;
&lt;/font&gt;&lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26343631&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/openca-users-f3692.html&quot; embed=&quot;fixTarget[3692]&quot; target=&quot;_top&quot; &gt;openca-users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OCSP-URL---what%27s-it-return-----tp26337743p26343631.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26342618</id>
	<title>Re: OCSP URL - what's it return????</title>
	<published>2009-11-13T12:00:51Z</published>
	<updated>2009-11-13T12:00:51Z</updated>
	<author>
		<name>Massimiliano Pala-3</name>
	</author>
	<content type="html">Hi Dave,
&lt;br&gt;&lt;br&gt;actually that seem to work fine. The error in OpenSSL is not really an error,
&lt;br&gt;it just does not have the issuer certificate of the OCSP server's certificate
&lt;br&gt;but the response is correctly parsed (status good).
&lt;br&gt;&lt;br&gt;I do not really understand, what is the issue you are having ?
&lt;br&gt;&lt;br&gt;Later,
&lt;br&gt;Max
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;On 11/13/2009 01:17 PM, &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26342618&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;blainedw@...&lt;/a&gt; wrote:
&lt;div class='shrinkable-quote'&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Well, I hope I do ;)
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I guess the URL threw me because it had /ca/ca.html on it so I was
&lt;br&gt;&amp;gt; expecting a response.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; openssl ocsp -issuer /appl/openca-ocspd-1.5.1/etc/ocspd/certs/cacert.pem
&lt;br&gt;&amp;gt; -cert /appl/openca/openca/var/openca/crypto/certs/01.pem -url
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://host:2560/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://host:2560/&lt;/a&gt;&amp;nbsp;-resp_text -respout /tmp/ocspResp.der -CAfile
&lt;br&gt;&amp;gt; /appl/openca-ocspd-1.5.1/etc/ocspd/certs/cacert.pem &amp;lt;&lt;a href=&quot;http://host:2560/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://host:2560/&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; ....
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Response Verify Failure
&lt;br&gt;&amp;gt; 19659:error:27069065:OCSP routines:OCSP_basic_verify:certificate verify
&lt;br&gt;&amp;gt; error:ocsp_vfy.c:122:Verify error:unable to get issuer certificate
&lt;br&gt;&amp;gt; /appl/openca/openca/var/openca/crypto/certs/15.pem: good
&lt;br&gt;&amp;gt; This Update: Nov 12 18:12:01 2009 GMT
&lt;br&gt;&amp;gt; Next Update: Nov 13 16:46:03 2009 GMT
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I can eliminate this error by adding -VAoption
&lt;/div&gt;&lt;/div&gt;&lt;br /&gt; &lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26342618&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;smime.p7s&lt;/strong&gt; (4K) &lt;a href=&quot;http://old.nabble.com/attachment/26342618/0/smime.p7s&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/openca-users-f3692.html&quot; embed=&quot;fixTarget[3692]&quot; target=&quot;_top&quot; &gt;openca-users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OCSP-URL---what%27s-it-return-----tp26337743p26342618.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26341001</id>
	<title>Re: OCSP URL - what's it return????</title>
	<published>2009-11-13T10:17:11Z</published>
	<updated>2009-11-13T10:17:11Z</updated>
	<author>
		<name>blainedw</name>
	</author>
	<content type="html">
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;Well, I &amp;nbsp;hope I do ;)&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;I guess the URL threw me because it
had /ca/ca.html on it so I was expecting a response.&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;openssl ocsp -issuer /appl/openca-ocspd-1.5.1/etc/ocspd/certs/cacert.pem
-cert /appl/openca/openca/var/openca/crypto/certs/01.pem -url &lt;/font&gt;&lt;a href=http://host:2560 target=&quot;_top&quot; rel=&quot;nofollow&quot; /&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;http://host:2560/
-resp_text -respout /tmp/ocspResp.der -CAfile /appl/openca-ocspd-1.5.1/etc/ocspd/certs/cacert.pem&lt;/font&gt;&lt;/a&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;....&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;Response Verify Failure&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;19659:error:27069065:OCSP routines:OCSP_basic_verify:certificate
verify error:ocsp_vfy.c:122:Verify error:unable to get issuer certificate&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;/appl/openca/openca/var/openca/crypto/certs/15.pem:
good&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; This Update:
Nov 12 18:12:01 2009 GMT&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Next Update:
Nov 13 16:46:03 2009 GMT&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;I can eliminate this error by adding
-VAoption&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;Any help would be appreciated&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;Dave&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;&lt;br&gt;
Dave&lt;/font&gt;&lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26341001&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/openca-users-f3692.html&quot; embed=&quot;fixTarget[3692]&quot; target=&quot;_top&quot; &gt;openca-users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OCSP-URL---what%27s-it-return-----tp26337743p26341001.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26339844</id>
	<title>cross-site request forgery (XSRF)</title>
	<published>2009-11-13T08:48:04Z</published>
	<updated>2009-11-13T08:48:04Z</updated>
	<author>
		<name>Leo Catalinas</name>
	</author>
	<content type="html">Hello,
&lt;br&gt;&lt;br&gt;We use OpenCA 0.9.x in a couple of university projects and we are very
&lt;br&gt;pleased with it, having issued near 700 certificates for students and
&lt;br&gt;professors for e-learning in the last three years.
&lt;br&gt;&lt;br&gt;We integrate many screens and forms (like the request form) in a public
&lt;br&gt;web page (our pki portal) made with Joomla an its &amp;quot;wrapper&amp;quot; option
&lt;br&gt;(allows to embeed an external page within the page body using the html
&lt;br&gt;&amp;quot;&amp;lt;iframe&amp;gt;&amp;quot; element).
&lt;br&gt;&lt;br&gt;Now, we have tried the 1.0.2 version and we have seen that the &amp;quot;wrapper&amp;quot;
&lt;br&gt;option doesn't work because the new OpenCA XSRF protection.
&lt;br&gt;&lt;br&gt;We need the &amp;quot;wrapper&amp;quot; option to integrate OpenCA forms with Joomla, but
&lt;br&gt;tried to disable the XSRF protection and we didn't find how to do it.
&lt;br&gt;&lt;br&gt;How to disable XSRF or how to make work without disabling it? Any
&lt;br&gt;suggestion, please?
&lt;br&gt;&lt;br&gt;Thank you very much
&lt;br&gt;&lt;br&gt;Regards,
&lt;br&gt;Leo Catalinas,
&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;OpenCA-Devel mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26339844&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;OpenCA-Devel@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-devel&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/openca-devel-f3691.html&quot; embed=&quot;fixTarget[3691]&quot; target=&quot;_top&quot; &gt;openca-devel&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/cross-site-request-forgery-%28XSRF%29-tp26339844p26339844.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26339830</id>
	<title>cross-site request forgery (XSRF)</title>
	<published>2009-11-13T08:47:09Z</published>
	<updated>2009-11-13T08:47:09Z</updated>
	<author>
		<name>Leo Catalinas</name>
	</author>
	<content type="html">Hello,
&lt;br&gt;&lt;br&gt;We use OpenCA 0.9.x in a couple of university projects and we are very
&lt;br&gt;pleased with it, having issued near 700 certificates for students and
&lt;br&gt;professors for e-learning in the last three years.
&lt;br&gt;&lt;br&gt;We integrate many screens and forms (like the request form) in a public
&lt;br&gt;web page (our pki portal) made with Joomla an its &amp;quot;wrapper&amp;quot; option
&lt;br&gt;(allows to embeed an external page within the page body using the html
&lt;br&gt;&amp;quot;&amp;lt;iframe&amp;gt;&amp;quot; element).
&lt;br&gt;&lt;br&gt;Now, we have tried the 1.0.2 version and we have seen that the &amp;quot;wrapper&amp;quot;
&lt;br&gt;option doesn't work because the new OpenCA XSRF protection.
&lt;br&gt;&lt;br&gt;We need the &amp;quot;wrapper&amp;quot; option to integrate OpenCA forms with Joomla, but
&lt;br&gt;tried to disable the XSRF protection and we didn't find how to do it.
&lt;br&gt;&lt;br&gt;How to disable XSRF or how to make work without disabling it? Any
&lt;br&gt;suggestion, please?
&lt;br&gt;&lt;br&gt;Thank you very much
&lt;br&gt;&lt;br&gt;Regards,
&lt;br&gt;Leo Catalinas,
&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26339830&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/openca-users-f3692.html&quot; embed=&quot;fixTarget[3692]&quot; target=&quot;_top&quot; &gt;openca-users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/cross-site-request-forgery-%28XSRF%29-tp26339830p26339830.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26339116</id>
	<title>Re: How to make OpenCA use OpenSSL engine?</title>
	<published>2009-11-13T08:15:03Z</published>
	<updated>2009-11-13T08:15:03Z</updated>
	<author>
		<name>Massimiliano Pala-3</name>
	</author>
	<content type="html">Hi Allen,
&lt;br&gt;&lt;br&gt;as Ralf said, check the OpenSC token in the tokens.xml configuration - it is
&lt;br&gt;quite easy to setup the Engine.
&lt;br&gt;&lt;br&gt;One small warning: if you are using the engine for accessing a P11 device, be
&lt;br&gt;careful that when you generate keys with that, the key is actually generated
&lt;br&gt;in software and then stored on the device (instead of using the PKCS11 key
&lt;br&gt;generation on hardware directly...).
&lt;br&gt;&lt;br&gt;Later,
&lt;br&gt;Max
&lt;br&gt;&lt;br&gt;&lt;br&gt;On 09/03/2009 08:39 PM, Allen Liu wrote:
&lt;br&gt;&amp;gt; No, it's not.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; OpenSSL ENGINE is a loadable module for talking to HSM (hardware Secure
&lt;br&gt;&amp;gt; Module) or smart card through PKCS 11 in order to utilize keys stored inside
&lt;br&gt;&amp;gt; as well as hardware-implementated algorithms.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I know how to use OpenSSL ENGINE to talk to HSM but don't know to make
&lt;br&gt;&amp;gt; OpenCA use ENGINE.
&lt;br&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;&lt;br&gt;Best Regards,
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Massimiliano Pala
&lt;br&gt;&lt;br&gt;--o------------------------------------------------------------------------
&lt;br&gt;Massimiliano Pala [OpenCA Project Manager] &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26339116&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openca@...&lt;/a&gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26339116&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;project.manager@...&lt;/a&gt;
&lt;br&gt;&lt;br&gt;Dartmouth Computer Science Dept &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Home Phone: +1 (603) 369-9332
&lt;br&gt;PKI/Trust Laboratory &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Work Phone: +1 (603) 646-8734
&lt;br&gt;--o------------------------------------------------------------------------
&lt;br&gt;People who think they know everything are a great annoyance to those of us
&lt;br&gt;who do.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;-- Isaac Asimov
&lt;br&gt;&lt;br&gt;&lt;br /&gt; &lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26339116&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;smime.p7s&lt;/strong&gt; (4K) &lt;a href=&quot;http://old.nabble.com/attachment/26339116/0/smime.p7s&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/openca-users-f3692.html&quot; embed=&quot;fixTarget[3692]&quot; target=&quot;_top&quot; &gt;openca-users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/How-to-make-OpenCA-use-OpenSSL-engine--tp25285745p26339116.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26339070</id>
	<title>Re: Trouble with LDAP and CRL's</title>
	<published>2009-11-13T08:12:30Z</published>
	<updated>2009-11-13T08:12:30Z</updated>
	<author>
		<name>Massimiliano Pala-3</name>
	</author>
	<content type="html">Hi Dave,
&lt;br&gt;&lt;br&gt;LDAP can be tricky, especially because if the DNs are not precise, you
&lt;br&gt;will not find what you are looking for. You might want to use one LDAP
&lt;br&gt;browsers (some time ago Mozilla had one built in.. now I don't think
&lt;br&gt;Firefox supports ldap:// urls anymore..). If you can find it for your
&lt;br&gt;system I usually use 'gq' - last version I checked was from 2006. The
&lt;br&gt;url on the 'About' is this:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.gq-project.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.gq-project.org/&lt;/a&gt;&lt;br&gt;&lt;br&gt;but that points just to an empty page.. a very simple google search
&lt;br&gt;gave me back this:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://linux.softpedia.com/get/Utilities/GQ-LDAP-Client-11212.shtml&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://linux.softpedia.com/get/Utilities/GQ-LDAP-Client-11212.shtml&lt;/a&gt;&lt;br&gt;&lt;br&gt;there are many others out there (most of them are Java, though...).
&lt;br&gt;&lt;br&gt;Also, another thing: check that the certificate CDP (CRL Distribution
&lt;br&gt;Point) is correct.
&lt;br&gt;&lt;br&gt;Another possibility is to download the new LibPKI - there is a tool
&lt;br&gt;there that allows you to download data from different URLs, and in
&lt;br&gt;particular from LDAP by using something like:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; $ url-tool &amp;quot;ldap://ldap.dartmouth.edu:389/cn=Dartmouth CertAuth1, o=Dartmouth College, 
&lt;br&gt;C=US, dc=dartmouth, dc=edu?cACertificate;binary&amp;quot;
&lt;br&gt;&lt;br&gt;You can find the libpki here:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://ftp.openca.org/libpki/releases/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://ftp.openca.org/libpki/releases/&lt;/a&gt;&lt;br&gt;&lt;br&gt;The version 0.4.0 is on its way...
&lt;br&gt;&lt;br&gt;Later,
&lt;br&gt;Max
&lt;br&gt;&lt;br&gt;&lt;br&gt;On 11/13/2009 09:41 AM, &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26339070&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;blainedw@...&lt;/a&gt; wrote:
&lt;div class='shrinkable-quote'&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Hi all,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Unlike most folks, I was able to publish my certificates and CRL's in
&lt;br&gt;&amp;gt; LDAP using Openca 1.0.2. My problem exists with check for it in LDAP.
&lt;br&gt;&amp;gt; Using PKIVIEW in Windows it mentions that it is &amp;quot;Unable to download&amp;quot; the
&lt;br&gt;&amp;gt; CRL from the LDAP CDP. It reports &amp;quot;OK&amp;quot; for the http one.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I used an ldap search command to check the existance of the CRL in LDAP
&lt;br&gt;&amp;gt; and that it was not expired. Here is the command I used:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; ./ldapsearch -x -h host -b &amp;quot;cn=Root CA,ou=Trustcenter,dc=domain,dc=com&amp;quot;
&lt;br&gt;&amp;gt; certificateRevocationList
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I am also able to use IE to at least contact the LDAP server via this
&lt;br&gt;&amp;gt; method (unsure how to download CRL using this method):
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; ldap://host/cn=Root CA,ou=Trustcenter,dc=domain,dc=com
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Any help appreciated!!!!
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Dave
&lt;/div&gt;&lt;/div&gt;&lt;br&gt;-- 
&lt;br&gt;&lt;br&gt;Best Regards,
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Massimiliano Pala
&lt;br&gt;&lt;br&gt;--o------------------------------------------------------------------------
&lt;br&gt;Massimiliano Pala [OpenCA Project Manager] &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26339070&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openca@...&lt;/a&gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26339070&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;project.manager@...&lt;/a&gt;
&lt;br&gt;&lt;br&gt;Dartmouth Computer Science Dept &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Home Phone: +1 (603) 369-9332
&lt;br&gt;PKI/Trust Laboratory &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Work Phone: +1 (603) 646-8734
&lt;br&gt;--o------------------------------------------------------------------------
&lt;br&gt;People who think they know everything are a great annoyance to those of us
&lt;br&gt;who do.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;-- Isaac Asimov
&lt;br&gt;&lt;br&gt;&lt;br /&gt; &lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26339070&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;smime.p7s&lt;/strong&gt; (4K) &lt;a href=&quot;http://old.nabble.com/attachment/26339070/0/smime.p7s&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/openca-users-f3692.html&quot; embed=&quot;fixTarget[3692]&quot; target=&quot;_top&quot; &gt;openca-users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Trouble-with-LDAP-and-CRL%27s-tp26337641p26339070.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26338861</id>
	<title>Re: OCSP URL - what's it return????</title>
	<published>2009-11-13T07:59:21Z</published>
	<updated>2009-11-13T07:59:21Z</updated>
	<author>
		<name>Massimiliano Pala-3</name>
	</author>
	<content type="html">Hi Dave,
&lt;br&gt;&lt;br&gt;I assume you have installed and configured the OCSP server ... :D If not,
&lt;br&gt;you have to download it as it is a separate package (that I am going to
&lt;br&gt;update quite soon... :D).
&lt;br&gt;&lt;br&gt;The OCSP server returns an OCSP response.. so it is not viewable with the
&lt;br&gt;browser. You can use the `openssl ocsp' to view the response (check the
&lt;br&gt;command line syntax by using `openssl ocsp -'.
&lt;br&gt;&lt;br&gt;Or you can just use wget (`wget &lt;a href=&quot;http://...'&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://...'&lt;/a&gt;) and then parse the contents
&lt;br&gt;of the saved data with `openssl asn1parse -inform DER -in &amp;lt;filename&amp;gt;'. Or,
&lt;br&gt;last but not least, just use the telnet command:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; $ telnet host 2560
&lt;br&gt;&lt;br&gt;then hit a couple of returns.. you'll see the response.. with the full
&lt;br&gt;headers.
&lt;br&gt;&lt;br&gt;I hope this helps,
&lt;br&gt;&lt;br&gt;Cheers,
&lt;br&gt;Max
&lt;br&gt;&lt;br&gt;&lt;br&gt;On 11/13/2009 09:49 AM, &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26338861&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;blainedw@...&lt;/a&gt; wrote:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I have a OCSP URL similar to the default one as an AIA location
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://host:2560/ca/ca.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://host:2560/ca/ca.html&lt;/a&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; If I copy and paste into a browser, it returns a 0
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; What is that supposed to return????
&lt;br&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;&lt;br&gt;Best Regards,
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Massimiliano Pala
&lt;br&gt;&lt;br&gt;--o------------------------------------------------------------------------
&lt;br&gt;Massimiliano Pala [OpenCA Project Manager] &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26338861&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openca@...&lt;/a&gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26338861&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;project.manager@...&lt;/a&gt;
&lt;br&gt;&lt;br&gt;Dartmouth Computer Science Dept &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Home Phone: +1 (603) 369-9332
&lt;br&gt;PKI/Trust Laboratory &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Work Phone: +1 (603) 646-8734
&lt;br&gt;--o------------------------------------------------------------------------
&lt;br&gt;People who think they know everything are a great annoyance to those of us
&lt;br&gt;who do.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;-- Isaac Asimov
&lt;br&gt;&lt;br&gt;&lt;br /&gt; &lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26338861&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;smime.p7s&lt;/strong&gt; (4K) &lt;a href=&quot;http://old.nabble.com/attachment/26338861/0/smime.p7s&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/openca-users-f3692.html&quot; embed=&quot;fixTarget[3692]&quot; target=&quot;_top&quot; &gt;openca-users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OCSP-URL---what%27s-it-return-----tp26337743p26338861.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26337743</id>
	<title>OCSP URL - what's it return????</title>
	<published>2009-11-13T06:49:11Z</published>
	<updated>2009-11-13T06:49:11Z</updated>
	<author>
		<name>blainedw</name>
	</author>
	<content type="html">
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;I have a OCSP URL similar to the default
one as an AIA location&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;a href=http://host:2560/ca/ca.html target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;http://host:2560/ca/ca.html&lt;/font&gt;&lt;/a&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;If I copy and paste into a browser,
it returns a 0&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;What is that supposed to return????&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;Dave&lt;br&gt;
&lt;/font&gt;&lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26337743&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/openca-users-f3692.html&quot; embed=&quot;fixTarget[3692]&quot; target=&quot;_top&quot; &gt;openca-users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OCSP-URL---what%27s-it-return-----tp26337743p26337743.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26337715</id>
	<title>Re: Trouble with LDAP and CRL's</title>
	<published>2009-11-13T06:47:59Z</published>
	<updated>2009-11-13T06:47:59Z</updated>
	<author>
		<name>Ralf Hornik Mailings</name>
	</author>
	<content type="html">&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26337715&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;blainedw@...&lt;/a&gt; wrote:
&lt;br&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; ldap://host/cn=Root CA,ou=Trustcenter,dc=domain,dc=com
&lt;br&gt;&lt;br&gt;Is this the full DN or is there an emailAddess too?
&lt;br&gt;&lt;br&gt;Some Applications need the full DN to find the CRL:
&lt;br&gt;&lt;br&gt;ldap://&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26337715&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;host/emailAdress=root@...&lt;/a&gt;, cn=Root &amp;nbsp;
&lt;br&gt;CA,ou=Trustcenter,dc=domain,dc=com
&lt;br&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;alles bleibt anders...
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26337715&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/openca-users-f3692.html&quot; embed=&quot;fixTarget[3692]&quot; target=&quot;_top&quot; &gt;openca-users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Trouble-with-LDAP-and-CRL%27s-tp26337641p26337715.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26337641</id>
	<title>Trouble with LDAP and CRL's</title>
	<published>2009-11-13T06:41:21Z</published>
	<updated>2009-11-13T06:41:21Z</updated>
	<author>
		<name>blainedw</name>
	</author>
	<content type="html">
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;Hi all,&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;Unlike most folks, I was able to publish
my certificates and CRL's in LDAP using Openca 1.0.2. My problem exists
with check for it in LDAP. Using PKIVIEW in Windows it mentions that it
is &amp;quot;Unable to download&amp;quot; the CRL from the LDAP CDP. It reports
&amp;quot;OK&amp;quot; for the http one.&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;I used an ldap search command to check
the existance of the CRL in LDAP and that it was not expired. Here is the
command I used:&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;./ldapsearch -x -h host -b &amp;quot;cn=Root
CA,ou=Trustcenter,dc=domain,dc=com&amp;quot; certificateRevocationList&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;I am also able to use IE to at least
contact the LDAP server via this method (unsure how to download CRL using
this method):&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;ldap://host/cn=Root CA,ou=Trustcenter,dc=domain,dc=com&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;&lt;br&gt;
Any help appreciated!!!!&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;Dave&lt;/font&gt;&lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26337641&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/openca-users-f3692.html&quot; embed=&quot;fixTarget[3692]&quot; target=&quot;_top&quot; &gt;openca-users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Trouble-with-LDAP-and-CRL%27s-tp26337641p26337641.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26326883</id>
	<title>Smartcard and Trust Chain</title>
	<published>2009-11-12T13:22:44Z</published>
	<updated>2009-11-12T13:22:44Z</updated>
	<author>
		<name>blainedw</name>
	</author>
	<content type="html">
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;&lt;br&gt;
&lt;br&gt;
Hi all,&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;I am having a &amp;nbsp;problem with Windows
2003 authentication using a Smartcard with a certificate generated from
OpenCA. It won't allow logon saying &amp;quot;the smartcard used for authentication
was not trusted&amp;quot;. I am using a HID global card and with their utilities
I double checked the chain and verified the certificate ok. The CRL's on
both the offline and online CA are current and good.&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;This setup worked beautifully in development
but in my dev lab their is just the online root CA. &lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;In production, however, their is a offline
and an online root CA so a little more complicated. Using OpenCA 1.0.2
with patches.&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;Any information you need to assist with
this dilemna just let me know.&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;Dave&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;Dave &lt;/font&gt;
&lt;br&gt;&lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26326883&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/openca-users-f3692.html&quot; embed=&quot;fixTarget[3692]&quot; target=&quot;_top&quot; &gt;openca-users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Smartcard-and-Trust-Chain-tp26326883p26326883.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26259032</id>
	<title>Openca-sv docs</title>
	<published>2009-11-08T15:05:14Z</published>
	<updated>2009-11-08T15:05:14Z</updated>
	<author>
		<name>Javier Sarmiento-3</name>
	</author>
	<content type="html">Hello,&lt;br&gt;&lt;br&gt;&lt;div id=&quot;result_box&quot; dir=&quot;ltr&quot;&gt;where can I get the documentation of OpenCA-sv (README-SV)?, I don&amp;#39;t know where to find it, &lt;br&gt;&lt;br&gt; thanks for your attention&lt;/div&gt;&lt;br&gt;
&lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26259032&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/openca-users-f3692.html&quot; embed=&quot;fixTarget[3692]&quot; target=&quot;_top&quot; &gt;openca-users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Openca-sv-docs-tp26259032p26259032.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26207348</id>
	<title>Re: Better docs for Batch system and examples needed</title>
	<published>2009-11-04T14:59:37Z</published>
	<updated>2009-11-04T14:59:37Z</updated>
	<author>
		<name>blainedw</name>
	</author>
	<content type="html">
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;OK I learned some things on my own.&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;I created the following batch_data_process.txt&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;USER user1&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;PROCESS gen_certs_2&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;SET_STATE new_process&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;ROLE Smartcard&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;SUBJECT_ALT_NAME_1 email:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26207348&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;user1@...&lt;/a&gt;,otherName:1.3.6.1.4.311.20.2.3;UTF8:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26207348&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;user1@...&lt;/a&gt;&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;SUBJECT UID=user1,CN=Joe Blow,OU=Employees,DC=gdls,DC=com&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;LOA_MODE NORMAL&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;LOA 4&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;and added it to my dataexchange tar
file&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;Then selected &amp;quot;QuickImport&amp;quot;
which slurped up the dataexchange file. At this point, if I tried to reimport
the same user I would get an error so I found that I could reset things
by deleting the contents of file $OPENCADIR/var/openca/bp/users.txt and
delete the contents of directory $OPENCADIR/var/openca/bp/users. Of course,
this only works if your just in test dealing with one user ;)&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;And then I selected &amp;quot;Do one step
for all workflows&amp;quot; Yes for both CA and BP key certificates. It then
asked for the CA key twice (since I didn't create a seperate BP certificate).&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;I noticed that in the RA interface that
it doesn't have any options to download the PKCS#12 file. Is this normal
for the UI? Never fear, though, these files are located in $OPENCADIR/var/openca/bp/dataexchange
directory. &lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;My next problem was to determine the
PIN assigned. This can be done in the Batch UI by selecting Export PIN.
I found that if you want to issue Export PIN more than once you will get
an error. To clear the error, you have to delete the file $OPENCADIR/var/openca/bp/dataexchange/pin_list
(BTW, this is the list of PINs exported).&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;My remaining issue is that our normal
requests have extra fields like phone number, etc that aren't in the DN
of the certificate. They are just additional request attributes. How can
those be accomodated????&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;Dave&lt;/font&gt;

This is an e-mail from General Dynamics Land Systems. It is for the intended recipient only and may contain confidential and privileged information.  No one else may read, print, store, copy, forward or act in reliance on it or its attachments.  If you are not the intended recipient, please return this message to the sender and delete the message and any attachments from your computer. Your cooperation is appreciated.
&lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26207348&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/openca-users-f3692.html&quot; embed=&quot;fixTarget[3692]&quot; target=&quot;_top&quot; &gt;openca-users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Better-docs-for-Batch-system-and-examples-needed-tp26201568p26207348.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26201568</id>
	<title>Better docs for Batch system and examples needed</title>
	<published>2009-11-04T09:59:13Z</published>
	<updated>2009-11-04T09:59:13Z</updated>
	<author>
		<name>blainedw</name>
	</author>
	<content type="html">
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;I have several 1000 certs to create
and was looking at the batch system to do this. But there is so little
documentation on it (will the 0.9.2+ docs work for 1.0.2?) and I am very
confused.&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;To test it out, I can just use the CA
cert or am I required to create a BP cert?&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;Then I create a batch_process_data.txt
file that contains the info and tar it up into a dataexchange file.&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;I think I can use QuickImport... So
if that is the case, can someone give me examples of their batch_process_data.txt?&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;Dave&lt;br&gt;
&lt;/font&gt;&lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26201568&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/openca-users-f3692.html&quot; embed=&quot;fixTarget[3692]&quot; target=&quot;_top&quot; &gt;openca-users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Better-docs-for-Batch-system-and-examples-needed-tp26201568p26201568.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26199386</id>
	<title>Re: Upgrade from OpenCA 0.8x to 1.02</title>
	<published>2009-11-04T08:16:42Z</published>
	<updated>2009-11-04T08:16:42Z</updated>
	<author>
		<name>Ralf Hornik Mailings</name>
	</author>
	<content type="html">Hi Max,
&lt;br&gt;&lt;br&gt;Massimiliano Pala &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26199386&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Massimiliano.Pala@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&lt;br&gt;&amp;gt; AFAIK, the upgrade should work.
&lt;br&gt;&lt;br&gt;Thank you for the quick answer. So I will try that and give a short &amp;nbsp;
&lt;br&gt;conclusion if necsessary.
&lt;br&gt;Regards
&lt;br&gt;&lt;br&gt;Ralf
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26199386&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/openca-users-f3692.html&quot; embed=&quot;fixTarget[3692]&quot; target=&quot;_top&quot; &gt;openca-users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Upgrade-from-OpenCA-0.8x-to-1.02-tp26197876p26199386.html" />
</entry>

</feed>
