<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<id>tag:old.nabble.com,2006:forum-3692</id>
	<title>Nabble - openca-users</title>
	<updated>2009-12-10T11:11:18Z</updated>
	<link rel="self" type="application/atom+xml" href="http://old.nabble.com/openca-users-f3692.xml" />
	<link rel="alternate" type="text/html" href="http://old.nabble.com/openca-users-f3692.html" />
	<subtitle type="html">Mailing list archive for openca-users</subtitle>
	
<entry>
	<id>tag:old.nabble.com,2006:post-26732862</id>
	<title>Bug in bpExportPIN</title>
	<published>2009-12-10T11:11:18Z</published>
	<updated>2009-12-10T11:11:18Z</updated>
	<author>
		<name>blainedw</name>
	</author>
	<content type="html">
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;Not sure if this was mentioned before
but when exporting PINs after the first time using the batch process I
would get a module error (strftime not found).&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;At the top of bpExportPIN, add to correct
this issue:&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;&amp;nbsp;use POSIX qw(strftime);&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;&lt;br&gt;
&lt;br&gt;
Dave&lt;/font&gt;&lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Return on Information:
&lt;br&gt;Google Enterprise Search pays you back
&lt;br&gt;Get the facts.
&lt;br&gt;&lt;a href=&quot;http://p.sf.net/sfu/google-dev2dev&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/google-dev2dev&lt;/a&gt;&lt;br&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26732862&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Bug-in-bpExportPIN-tp26732862p26732862.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26578762</id>
	<title>renew certificate</title>
	<published>2009-11-30T09:42:04Z</published>
	<updated>2009-11-30T09:42:04Z</updated>
	<author>
		<name>Samuel Rios Carvalho</name>
	</author>
	<content type="html">People,&lt;br&gt;&lt;br&gt;I have some certificates. This certificates are created by smartcard. Work perfeclty, but when I want renew the certificates, I renew this certificate in certificate request and after when I import this certificate to my smartcard, it isn&amp;#39;t recognized as a valid certificate.&lt;br&gt;
&lt;br clear=&quot;all&quot;&gt;Samuel Rios Carvalho&lt;br&gt;
&lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26578762&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/renew-certificate-tp26578762p26578762.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26578616</id>
	<title>Re: FIX: Expired list doesn't show</title>
	<published>2009-11-30T09:33:56Z</published>
	<updated>2009-11-30T09:33:56Z</updated>
	<author>
		<name>Samuel Rios Carvalho</name>
	</author>
	<content type="html">Ralf,&lt;br&gt;&lt;br&gt;worked perfectly&lt;br&gt;&lt;br&gt;thank you very much.&lt;br&gt;&lt;br&gt;&lt;br clear=&quot;all&quot;&gt;Samuel Rios Carvalho&lt;br&gt;
&lt;br&gt;&lt;br&gt;&lt;div class=&quot;gmail_quote&quot;&gt;On Sun, Nov 29, 2009 at 11:07 AM, Ralf Hornik Mailings &lt;span dir=&quot;ltr&quot;&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26578616&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;ralf@...&lt;/a&gt;&amp;gt;&lt;/span&gt; wrote:&lt;br&gt;&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;
Hi&lt;br&gt;
&lt;br&gt;
Samuel Rios Carvalho schrieb:&lt;br&gt;
&amp;gt;&lt;br&gt;
&amp;gt;     select status,dn,date(notafter),time(notafter) from certificate&lt;br&gt;
&amp;gt;     where status = &amp;#39;EXPIRED&amp;#39;;&lt;br&gt;
&amp;gt;&lt;br&gt;
&amp;gt;     So cmdlistCerts doesn&amp;#39;t seem to do the correct query.&lt;br&gt;
&amp;gt;     I will try to fix that on this weekend.&lt;br&gt;
&amp;gt;&lt;br&gt;
You can download the fixed version of OpenCA::DBI.pm here:&lt;br&gt;
&lt;br&gt;
&lt;a href=&quot;http://www.ralf-hornik.de/pub/patches/openca/DBI.pm&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://www.ralf-hornik.de/pub/patches/openca/DBI.pm&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
Please replace it with &amp;lt;openca_prefix&amp;gt;/modules/perl5/OpenCA/DBI.pm&lt;br&gt;
&lt;br&gt;
@Max. Since the status of expired certificates is being updated in DB,&lt;br&gt;
there is no need to use &amp;quot;handleExpiredCert&amp;quot; any more.&lt;br&gt;
I think it can be completely removed.&lt;br&gt;
&lt;br&gt;
Please test it and give a short feedback&lt;br&gt;
Regards&lt;br&gt;
&lt;br&gt;
Ralf&lt;br&gt;
&lt;br&gt;
------------------------------------------------------------------------------&lt;br&gt;
Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day&lt;br&gt;
trial. Simplify your report design, integration and deployment - and focus on&lt;br&gt;
what you do best, core application coding. Discover what&amp;#39;s new with&lt;br&gt;
Crystal Reports now.  &lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;
_______________________________________________&lt;br&gt;
Openca-Users mailing list&lt;br&gt;
&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26578616&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;&lt;br&gt;
&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;
&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;
&lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26578616&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Expired-list-doesn%27t-show-tp26530153p26578616.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26575327</id>
	<title>Re: silly question</title>
	<published>2009-11-30T05:36:22Z</published>
	<updated>2009-11-30T05:36:22Z</updated>
	<author>
		<name>Ionescu Dan</name>
	</author>
	<content type="html">&lt;!DOCTYPE html PUBLIC &quot;-//W3C//DTD HTML 4.01 Transitional//EN&quot;&gt;
&lt;html&gt;
&lt;head&gt;
  &lt;meta content=&quot;text/html;charset=ISO-8859-1&quot; http-equiv=&quot;Content-Type&quot;&gt;
  &lt;title&gt;&lt;/title&gt;
&lt;/head&gt;
&lt;body bgcolor=&quot;#ffffff&quot; text=&quot;#000000&quot;&gt;
I always wandered what was with all that files ....&amp;nbsp; :)&lt;br&gt;
&lt;br&gt;
It's clear now ... i have modified the wrong file ...&lt;br&gt;
&lt;br&gt;
Thank you all for your answers&lt;br&gt;
&lt;br&gt;
David O'Callaghan wrote:
&lt;blockquote cite=&quot;mid:4B13BCF0.8030706@cs.tcd.ie&quot; type=&quot;cite&quot;&gt;
  &lt;pre wrap=&quot;&quot;&gt;Hi,

On 29/11/09 16:53, Ionescu Dan wrote:
  &lt;/pre&gt;
  &lt;blockquote type=&quot;cite&quot;&gt;
    &lt;pre wrap=&quot;&quot;&gt;I know it's a silly question, but:
I have a problem setting the expiring date of certificates. All the
certificates I create using OpenCa, have a  365 days life span, and i
want to increase that.
I've changed the obvious setting (days)  in openssl.cnf file on the ca
machine , but nothing ...
    &lt;/pre&gt;
  &lt;/blockquote&gt;
  &lt;pre wrap=&quot;&quot;&gt;&lt;!----&gt;
This might be a silly answer, but are you sure you modified the right file?

For example, on my system (based on OpenCA 1.x) if I want to alter the 
&quot;days&quot; parameter for the Web Server certificate profile I would need to 
edit /opt/openca/etc/openca/openssl/openssl/Web_Server.conf
There is a separate OpenSSL conf file for each profile.

Kind regards,

David
  &lt;/pre&gt;
&lt;/blockquote&gt;
&lt;br&gt;
&lt;/body&gt;
&lt;/html&gt;
&lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26575327&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Generate-Requests-from-CSV-Import-tp26563544p26575327.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26574344</id>
	<title>Re: silly question</title>
	<published>2009-11-30T04:59:45Z</published>
	<updated>2009-11-30T04:59:45Z</updated>
	<author>
		<name>Ralf Hornik Mailings</name>
	</author>
	<content type="html">David O'Callaghan &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26574344&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;david.ocallaghan@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&lt;br&gt;&amp;gt; This might be a silly answer, but are you sure you modified the right file?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; For example, on my system (based on OpenCA 1.x) if I want to alter the
&lt;br&gt;&amp;gt; &amp;quot;days&amp;quot; parameter for the Web Server certificate profile I would need to
&lt;br&gt;&amp;gt; edit /opt/openca/etc/openca/openssl/openssl/Web_Server.conf
&lt;br&gt;&amp;gt; There is a separate OpenSSL conf file for each profile.
&lt;br&gt;&lt;br&gt;You'd rather want to modify Web_Server.conf.template since &amp;nbsp;
&lt;br&gt;Web_Server.conf would be rewritten on startup.
&lt;br&gt;&lt;br&gt;Also its possible to increase the lifetime by using the days field in &amp;nbsp;
&lt;br&gt;the request form.
&lt;br&gt;Regards
&lt;br&gt;&lt;br&gt;&lt;br&gt;Ralf
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26574344&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Generate-Requests-from-CSV-Import-tp26563544p26574344.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26574044</id>
	<title>Re: silly question</title>
	<published>2009-11-30T04:39:12Z</published>
	<updated>2009-11-30T04:39:12Z</updated>
	<author>
		<name>David O'Callaghan</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;&lt;br&gt;On 29/11/09 16:53, Ionescu Dan wrote:
&lt;br&gt;&amp;gt; I know it's a silly question, but:
&lt;br&gt;&amp;gt; I have a problem setting the expiring date of certificates. All the
&lt;br&gt;&amp;gt; certificates I create using OpenCa, have a &amp;nbsp;365 days life span, and i
&lt;br&gt;&amp;gt; want to increase that.
&lt;br&gt;&amp;gt; I've changed the obvious setting (days) &amp;nbsp;in openssl.cnf file on the ca
&lt;br&gt;&amp;gt; machine , but nothing ...
&lt;br&gt;&lt;br&gt;This might be a silly answer, but are you sure you modified the right file?
&lt;br&gt;&lt;br&gt;For example, on my system (based on OpenCA 1.x) if I want to alter the 
&lt;br&gt;&amp;quot;days&amp;quot; parameter for the Web Server certificate profile I would need to 
&lt;br&gt;edit /opt/openca/etc/openca/openssl/openssl/Web_Server.conf
&lt;br&gt;There is a separate OpenSSL conf file for each profile.
&lt;br&gt;&lt;br&gt;Kind regards,
&lt;br&gt;&lt;br&gt;David
&lt;br&gt;-- 
&lt;br&gt;Dr David O'Callaghan
&lt;br&gt;&amp;nbsp; Research Fellow - Grid-Ireland - e-INIS - Computer Architecture &amp; Grid
&lt;br&gt;School of Computer Science &amp; Statistics,
&lt;br&gt;Trinity College, Dublin 2, Ireland &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Telephone: +353 1 896 1536
&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26574044&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Generate-Requests-from-CSV-Import-tp26563544p26574044.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26563846</id>
	<title>Re: silly question</title>
	<published>2009-11-29T09:09:46Z</published>
	<updated>2009-11-29T09:09:46Z</updated>
	<author>
		<name>Simon P Smith-2</name>
	</author>
	<content type="html">You cannot have a certificate with an expiry date beyond the expiry of the signing (CA) certificate.  Is the expiry of the CA certificate less than 365 days?&lt;br&gt;&lt;br&gt;Si&lt;br&gt;&lt;br&gt;&lt;div class=&quot;gmail_quote&quot;&gt;2009/11/29 Ionescu Dan &lt;span dir=&quot;ltr&quot;&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26563846&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;dionescux@...&lt;/a&gt;&amp;gt;&lt;/span&gt;&lt;br&gt;
&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;Hi&lt;br&gt;
I know it&amp;#39;s a silly question, but:&lt;br&gt;
I have a problem setting the expiring date of certificates. All the&lt;br&gt;
certificates I create using OpenCa, have a  365 days life span, and i&lt;br&gt;
want to increase that.&lt;br&gt;
I&amp;#39;ve changed the obvious setting (days)  in openssl.cnf file on the ca&lt;br&gt;
machine , but nothing ...&lt;br&gt;
&lt;br&gt;
My OpenCa Chain is the following:&lt;br&gt;
- one pub machine&lt;br&gt;
-one ra machine&lt;br&gt;
-one ca machine&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
------------------------------------------------------------------------------&lt;br&gt;
Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day&lt;br&gt;
trial. Simplify your report design, integration and deployment - and focus on&lt;br&gt;
what you do best, core application coding. Discover what&amp;#39;s new with&lt;br&gt;
Crystal Reports now.  &lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;
_______________________________________________&lt;br&gt;
Openca-Users mailing list&lt;br&gt;
&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26563846&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;&lt;br&gt;
&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;
&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;
&lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26563846&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Generate-Requests-from-CSV-Import-tp26563544p26563846.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26563713</id>
	<title>silly question</title>
	<published>2009-11-29T08:53:49Z</published>
	<updated>2009-11-29T08:53:49Z</updated>
	<author>
		<name>Ionescu Dan</name>
	</author>
	<content type="html">Hi
&lt;br&gt;I know it's a silly question, but:
&lt;br&gt;I have a problem setting the expiring date of certificates. All the 
&lt;br&gt;certificates I create using OpenCa, have a &amp;nbsp;365 days life span, and i 
&lt;br&gt;want to increase that.
&lt;br&gt;I've changed the obvious setting (days) &amp;nbsp;in openssl.cnf file on the ca 
&lt;br&gt;machine , but nothing ...
&lt;br&gt;&lt;br&gt;My OpenCa Chain is the following:
&lt;br&gt;- one pub machine
&lt;br&gt;-one ra machine
&lt;br&gt;-one ca machine
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26563713&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Generate-Requests-from-CSV-Import-tp26563544p26563713.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26563544</id>
	<title>Generate Requests from CSV Import</title>
	<published>2009-11-29T08:31:56Z</published>
	<updated>2009-11-29T08:31:56Z</updated>
	<author>
		<name>Ralf Hornik Mailings</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;&lt;br&gt;I want to implement the ability to generate PKCS12 files using CSV based 
&lt;br&gt;CSR generation:
&lt;br&gt;&lt;br&gt;Name,email,role,loa,pin
&lt;br&gt;----------------------------------------------
&lt;br&gt;Ralf Hornik,&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26563544&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;ralf@...&lt;/a&gt;,User,1,ba11aba||a
&lt;br&gt;...
&lt;br&gt;-----------------------------------------------
&lt;br&gt;&lt;br&gt;Then generate the requests as advanced_csr &amp;quot;server side key generation&amp;quot;
&lt;br&gt;&lt;br&gt;Can somebody (Max?) give me a pointer, witch would be the shortest (and 
&lt;br&gt;less performance killing) &amp;nbsp;way to do it (only short hints)?
&lt;br&gt;I will then do the development.
&lt;br&gt;Regards
&lt;br&gt;&lt;br&gt;Ralf
&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26563544&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Generate-Requests-from-CSV-Import-tp26563544p26563544.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26561871</id>
	<title>Re: FIX: Expired list doesn't show</title>
	<published>2009-11-29T05:07:06Z</published>
	<updated>2009-11-29T05:07:06Z</updated>
	<author>
		<name>Ralf Hornik Mailings</name>
	</author>
	<content type="html">Hi
&lt;br&gt;&lt;br&gt;Samuel Rios Carvalho schrieb:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; select status,dn,date(notafter),time(notafter) from certificate
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; where status = 'EXPIRED';
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; So cmdlistCerts doesn't seem to do the correct query.
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; I will try to fix that on this weekend.
&lt;br&gt;&amp;gt;
&lt;br&gt;You can download the fixed version of OpenCA::DBI.pm here:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.ralf-hornik.de/pub/patches/openca/DBI.pm&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.ralf-hornik.de/pub/patches/openca/DBI.pm&lt;/a&gt;&lt;br&gt;&lt;br&gt;Please replace it with &amp;lt;openca_prefix&amp;gt;/modules/perl5/OpenCA/DBI.pm
&lt;br&gt;&lt;br&gt;@Max. Since the status of expired certificates is being updated in DB, 
&lt;br&gt;there is no need to use &amp;quot;handleExpiredCert&amp;quot; any more.
&lt;br&gt;I think it can be completely removed.
&lt;br&gt;&lt;br&gt;Please test it and give a short feedback
&lt;br&gt;Regards
&lt;br&gt;&lt;br&gt;Ralf
&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26561871&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Expired-list-doesn%27t-show-tp26530153p26561871.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26558851</id>
	<title>Re: Expired list doesn't show</title>
	<published>2009-11-28T18:20:48Z</published>
	<updated>2009-11-28T18:20:48Z</updated>
	<author>
		<name>Samuel Rios Carvalho</name>
	</author>
	<content type="html">hello Ralf&lt;br&gt;&lt;br&gt;please, don&amp;#39;t forget to see the problem in this weekend.&lt;br&gt;&lt;br&gt;thanks.&lt;br&gt;&lt;br clear=&quot;all&quot;&gt;Samuel Rios Carvalho&lt;br&gt;
&lt;br&gt;&lt;br&gt;&lt;div class=&quot;gmail_quote&quot;&gt;On Thu, Nov 26, 2009 at 2:25 PM, Ralf Hornik Mailings &lt;span dir=&quot;ltr&quot;&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26558851&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;ralf@...&lt;/a&gt;&amp;gt;&lt;/span&gt; wrote:&lt;br&gt;&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;
&lt;div class=&quot;im&quot;&gt;Samuel Rios Carvalho &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26558851&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nhawkbr@...&lt;/a&gt;&amp;gt; wrote:&lt;br&gt;
&lt;br&gt;
&lt;/div&gt;&lt;div class=&quot;im&quot;&gt;&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;
I think that in status like should be REVOKED, but I don&amp;#39;t know where I can&lt;br&gt;
change it.&lt;br&gt;
&lt;/blockquote&gt;
&lt;br&gt;&lt;/div&gt;
The database shows EXPIERD in the status field of certificate:&lt;br&gt;
&lt;br&gt;
select status,dn,date(notafter),time(notafter) from certificate where status = &amp;#39;EXPIRED&amp;#39;;&lt;br&gt;
&lt;br&gt;
So cmdlistCerts doesn&amp;#39;t seem to do the correct query.&lt;br&gt;
I will try to fix that on this weekend.&lt;br&gt;&lt;font color=&quot;#888888&quot;&gt;
&lt;br&gt;
Ralf&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;/font&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;
&lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26558851&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Expired-list-doesn%27t-show-tp26530153p26558851.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26532831</id>
	<title>Re: Expired list doesn't show</title>
	<published>2009-11-26T09:42:50Z</published>
	<updated>2009-11-26T09:42:50Z</updated>
	<author>
		<name>Samuel Rios Carvalho</name>
	</author>
	<content type="html">yes,&lt;br&gt;&lt;br&gt;sorry, I make a mistake speaking about REVOKED, the correct is EXPIRED.&lt;br&gt;&lt;br&gt;I&amp;#39;m waiting your fix.&lt;br&gt;&lt;br&gt;thanks&lt;br&gt;&lt;br&gt;&lt;br clear=&quot;all&quot;&gt;Samuel Rios Carvalho&lt;br&gt;
&lt;br&gt;&lt;br&gt;&lt;div class=&quot;gmail_quote&quot;&gt;On Thu, Nov 26, 2009 at 2:25 PM, Ralf Hornik Mailings &lt;span dir=&quot;ltr&quot;&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26532831&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;ralf@...&lt;/a&gt;&amp;gt;&lt;/span&gt; wrote:&lt;br&gt;&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;
&lt;div class=&quot;im&quot;&gt;Samuel Rios Carvalho &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26532831&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nhawkbr@...&lt;/a&gt;&amp;gt; wrote:&lt;br&gt;
&lt;br&gt;
&lt;/div&gt;&lt;div class=&quot;im&quot;&gt;&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;
I think that in status like should be REVOKED, but I don&amp;#39;t know where I can&lt;br&gt;
change it.&lt;br&gt;
&lt;/blockquote&gt;
&lt;br&gt;&lt;/div&gt;
The database shows EXPIERD in the status field of certificate:&lt;br&gt;
&lt;br&gt;
select status,dn,date(notafter),time(notafter) from certificate where status = &amp;#39;EXPIRED&amp;#39;;&lt;br&gt;
&lt;br&gt;
So cmdlistCerts doesn&amp;#39;t seem to do the correct query.&lt;br&gt;
I will try to fix that on this weekend.&lt;br&gt;&lt;font color=&quot;#888888&quot;&gt;
&lt;br&gt;
Ralf&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;/font&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;
&lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26532831&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Expired-list-doesn%27t-show-tp26530153p26532831.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26531803</id>
	<title>Re: Expired list doesn't show</title>
	<published>2009-11-26T08:25:05Z</published>
	<updated>2009-11-26T08:25:05Z</updated>
	<author>
		<name>Ralf Hornik Mailings</name>
	</author>
	<content type="html">Samuel Rios Carvalho &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26531803&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nhawkbr@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&lt;br&gt;&amp;gt; I think that in status like should be REVOKED, but I don't know where I can
&lt;br&gt;&amp;gt; change it.
&lt;br&gt;&lt;br&gt;The database shows EXPIERD in the status field of certificate:
&lt;br&gt;&lt;br&gt;select status,dn,date(notafter),time(notafter) from certificate where &amp;nbsp;
&lt;br&gt;status = 'EXPIRED';
&lt;br&gt;&lt;br&gt;So cmdlistCerts doesn't seem to do the correct query.
&lt;br&gt;I will try to fix that on this weekend.
&lt;br&gt;&lt;br&gt;Ralf
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26531803&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Expired-list-doesn%27t-show-tp26530153p26531803.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26531567</id>
	<title>Re: Expired list doesn't show</title>
	<published>2009-11-26T08:08:59Z</published>
	<updated>2009-11-26T08:08:59Z</updated>
	<author>
		<name>Samuel Rios Carvalho</name>
	</author>
	<content type="html">I found this query in my mysql&amp;#39;s log to show REVOKED certificates&lt;br&gt;&lt;br&gt;select * from openca.certificate where (cert_key &amp;gt;= &amp;#39;0&amp;#39; ) and  (status like &amp;#39;VALID&amp;#39;) and (notafter &amp;lt; &amp;#39;20091126160813&amp;#39; ) order by cert_key LIMIT 25&lt;br&gt;
&lt;br&gt;I think that in status like should be REVOKED, but I don&amp;#39;t know where I can change it.&lt;br&gt;&lt;br&gt;&lt;br clear=&quot;all&quot;&gt;Samuel Rios Carvalho&lt;br&gt;
&lt;br&gt;&lt;br&gt;&lt;div class=&quot;gmail_quote&quot;&gt;On Thu, Nov 26, 2009 at 12:23 PM, Samuel Rios Carvalho &lt;span dir=&quot;ltr&quot;&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26531567&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;nhawkbr@...&lt;/a&gt;&amp;gt;&lt;/span&gt; wrote:&lt;br&gt;&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;
Hello,&lt;br&gt;&lt;br&gt;exactly 1 year I&amp;#39;m using OpenCA.&lt;br&gt;&lt;br&gt;Then, yesterday my first certificate expired. In EXPIRED Certificate List doesn&amp;#39;t show.&lt;br&gt;&lt;br&gt;I think it a little bug, please confirm.&lt;br&gt;&lt;font color=&quot;#888888&quot;&gt;&lt;br clear=&quot;all&quot;&gt;
Samuel Rios Carvalho&lt;br&gt;

&lt;/font&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;
&lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26531567&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Expired-list-doesn%27t-show-tp26530153p26531567.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26530153</id>
	<title>Expired list doesn't show</title>
	<published>2009-11-26T06:23:14Z</published>
	<updated>2009-11-26T06:23:14Z</updated>
	<author>
		<name>Samuel Rios Carvalho</name>
	</author>
	<content type="html">Hello,&lt;br&gt;&lt;br&gt;exactly 1 year I&amp;#39;m using OpenCA.&lt;br&gt;&lt;br&gt;Then, yesterday my first certificate expired. In EXPIRED Certificate List doesn&amp;#39;t show.&lt;br&gt;&lt;br&gt;I think it a little bug, please confirm.&lt;br&gt;&lt;br clear=&quot;all&quot;&gt;Samuel Rios Carvalho&lt;br&gt;

&lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26530153&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Expired-list-doesn%27t-show-tp26530153p26530153.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26519171</id>
	<title>Fwd: IDtrust peer-reviewed paper deadline extended to Dec 20</title>
	<published>2009-11-25T11:50:19Z</published>
	<updated>2009-11-25T11:50:19Z</updated>
	<author>
		<name>Massimiliano Pala-3</name>
	</author>
	<content type="html">FYI.
&lt;br&gt;&lt;br&gt;&amp;nbsp; -- Max
&lt;br&gt;&lt;br&gt;&lt;br&gt;-------- Original Message --------
&lt;br&gt;Subject: IDtrust peer-reviewed paper deadline extended to Dec 20
&lt;br&gt;Date: Wed, 25 Nov 2009 10:53:04 -0700
&lt;br&gt;From: Neal McBurnett &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26519171&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;neal@...&lt;/a&gt;&amp;gt;
&lt;br&gt;To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26519171&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;MW-PKIPrgmCommittee@...&lt;/a&gt;
&lt;br&gt;&lt;br&gt;Thanks to everyone for quick responses and good conversation around
&lt;br&gt;the date extension. &amp;nbsp;Based on overwhelming support I've updated the
&lt;br&gt;web site, extending the deadline for peer-reviewed papers to Dec 20th:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://middleware.internet2.edu/idtrust/2010/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://middleware.internet2.edu/idtrust/2010/&lt;/a&gt;&lt;br&gt;&lt;br&gt;I hope you can take a moment to share that with your colleagues and
&lt;br&gt;encourage them to submit a paper, and also to propose a panel.
&lt;br&gt;&lt;br&gt;The panel proposal deadline is Jan 24 but we'd love to hear ideas
&lt;br&gt;earlier. &amp;nbsp;Radia Perlman is the panels chair. &amp;nbsp;At this point we're
&lt;br&gt;looking for folks who will step forward to gather participants and
&lt;br&gt;coordinate an interesting, relevant panel.
&lt;br&gt;&lt;br&gt;Cheers, and happy Thanksgiving!
&lt;br&gt;&lt;br&gt;Neal McBurnett &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://neal.mcburnett.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://neal.mcburnett.org/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br /&gt; &lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26519171&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;smime.p7s&lt;/strong&gt; (4K) &lt;a href=&quot;http://old.nabble.com/attachment/26519171/0/smime.p7s&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Fwd%3A-IDtrust-peer-reviewed-paper-deadline-extended-to-Dec-20-tp26519171p26519171.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26479630</id>
	<title>Re: OCSP URL - what's it return????</title>
	<published>2009-11-23T07:05:41Z</published>
	<updated>2009-11-23T07:05:41Z</updated>
	<author>
		<name>Massimiliano Pala-3</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;&lt;br&gt;the HTTP GET support is on its way. Actually we are in the process of
&lt;br&gt;porting the OCSP server to LibPKI - it makes it easier to manage HSMs
&lt;br&gt;and it has direct support for PKCS#11 devices.
&lt;br&gt;&lt;br&gt;Once we have a stable version (0.4.0) of LibPKI we will finish the work
&lt;br&gt;on the OCSP server and publish the new version.
&lt;br&gt;&lt;br&gt;This is the first step toward the extensive use of LibPKI in all of our
&lt;br&gt;servers. Ideally we will have a single server with plugins for the different
&lt;br&gt;services that can be enabled/disabled. By using the PRQP activating and
&lt;br&gt;de-activating a service will enable clients to automatically use (or
&lt;br&gt;stop using) the specific service... that is a very useful feature!!!!
&lt;br&gt;&lt;br&gt;Cheers,
&lt;br&gt;Max
&lt;br&gt;&lt;br&gt;&lt;br&gt;On 11/20/2009 04:29 PM, &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26479630&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;blainedw@...&lt;/a&gt; wrote:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Cool. I wasn't sure if the chain should be specified as part of the
&lt;br&gt;&amp;gt; -issuer cert or the -CAcert. Your help confirmed that it is the -CAcert
&lt;br&gt;&amp;gt; that requires the concatenated chain of certs.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Also when will you support HTTP GET method in OCSP?
&lt;br&gt;&lt;br&gt;&lt;br /&gt; &lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26479630&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;smime.p7s&lt;/strong&gt; (4K) &lt;a href=&quot;http://old.nabble.com/attachment/26479630/0/smime.p7s&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OCSP-URL---what%27s-it-return-----tp26337743p26479630.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26450563</id>
	<title>Re: OCSP URL - what's it return????</title>
	<published>2009-11-20T13:29:05Z</published>
	<updated>2009-11-20T13:29:05Z</updated>
	<author>
		<name>blainedw</name>
	</author>
	<content type="html">
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;Cool. I wasn't sure if the chain should
be specified as part of the -issuer cert or the -CAcert. Your help confirmed
that it is the -CAcert that requires the concatenated chain of certs.&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;Also when will you support HTTP GET
method in OCSP?&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;Dave&lt;br&gt;
&lt;/font&gt;&lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26450563&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OCSP-URL---what%27s-it-return-----tp26337743p26450563.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26447269</id>
	<title>Re: OCSP URL - what's it return????</title>
	<published>2009-11-20T09:38:57Z</published>
	<updated>2009-11-20T09:38:57Z</updated>
	<author>
		<name>Massimiliano Pala-3</name>
	</author>
	<content type="html">Yes.
&lt;br&gt;&lt;br&gt;OpenSSL needs to have the full chain of certificates. You can use the
&lt;br&gt;-CAfile &amp;lt;file&amp;gt; option for adding trusted certs to the verification
&lt;br&gt;process. You might then get the error for the root CA saying that it
&lt;br&gt;is a self-signed cert :D That will be ok... :D
&lt;br&gt;&lt;br&gt;Later,
&lt;br&gt;Max
&lt;br&gt;&lt;br&gt;&lt;br&gt;On 11/13/2009 07:26 PM, &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26447269&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;blainedw@...&lt;/a&gt; wrote:
&lt;br&gt;&amp;gt; Hi max
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Getting back to something you said earlier in the thread about the error
&lt;br&gt;&amp;gt; that isn't an error. If you see my openssl command I'm using -issuer
&lt;br&gt;&amp;gt; parameter. So doesn't this tell openssl who the issuer is? This a subca
&lt;br&gt;&amp;gt; so does this -issuer parameter require a concat of ca certs that make up
&lt;br&gt;&amp;gt; the chain?
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;&lt;br&gt;Best Regards,
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Massimiliano Pala
&lt;br&gt;&lt;br&gt;--o------------------------------------------------------------------------
&lt;br&gt;Massimiliano Pala [OpenCA Project Manager] &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26447269&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openca@...&lt;/a&gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26447269&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;project.manager@...&lt;/a&gt;
&lt;br&gt;&lt;br&gt;Dartmouth Computer Science Dept &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Home Phone: +1 (603) 369-9332
&lt;br&gt;PKI/Trust Laboratory &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Work Phone: +1 (603) 646-8734
&lt;br&gt;--o------------------------------------------------------------------------
&lt;br&gt;People who think they know everything are a great annoyance to those of us
&lt;br&gt;who do.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;-- Isaac Asimov
&lt;br&gt;&lt;br&gt;&lt;br /&gt; &lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26447269&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;smime.p7s&lt;/strong&gt; (4K) &lt;a href=&quot;http://old.nabble.com/attachment/26447269/0/smime.p7s&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OCSP-URL---what%27s-it-return-----tp26337743p26447269.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26363601</id>
	<title>Re: Trouble with LDAP and CRL's</title>
	<published>2009-11-15T13:27:21Z</published>
	<updated>2009-11-15T13:27:21Z</updated>
	<author>
		<name>blainedw</name>
	</author>
	<content type="html">Hi ralf
&lt;br&gt;&lt;br&gt;Thanks for the response. I've been reading about ldap's alias feature and will probably use that to overcome my shortcomings. 
&lt;br&gt;&lt;br&gt;Dave
&lt;br&gt;&amp;gt;From David Blaine's blackberry
&lt;br&gt;&lt;br&gt;&lt;br&gt;----- Original Message -----
&lt;br&gt;From: Ralf Hornik Mailings [&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26363601&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;ralf@...&lt;/a&gt;]
&lt;br&gt;Sent: 11/15/2009 07:08 PM CET
&lt;br&gt;To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26363601&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openca-users@...&lt;/a&gt;
&lt;br&gt;Subject: Re: [Openca-Users] Trouble with LDAP and CRL's
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26363601&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;blainedw@...&lt;/a&gt; wrote:
&lt;br&gt;&lt;br&gt;&amp;gt; My problem now is my root certificate LDAP CDP does not include the email
&lt;br&gt;&amp;gt; address and I cannot reissue a new one. Any magic within LDAP I can do?
&lt;br&gt;&lt;br&gt;It depends on the SSL app. Some apps use subsearch and some not for &amp;nbsp;
&lt;br&gt;retrieving CRLs. Subsearch is also not recommended because of &amp;nbsp;
&lt;br&gt;performance issues.
&lt;br&gt;&lt;br&gt;The easiest way would be to move the crl to the CDP-DN of your &amp;nbsp;
&lt;br&gt;certificates by hand and &amp;quot;patch&amp;quot; your OpenCA installation to enroll &amp;nbsp;
&lt;br&gt;any new CRL there in future.
&lt;br&gt;Regards
&lt;br&gt;&lt;br&gt;Ralf
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26363601&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26363601&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Trouble-with-LDAP-and-CRL%27s-tp26337641p26363601.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26361585</id>
	<title>Re: Trouble with LDAP and CRL's</title>
	<published>2009-11-15T10:08:11Z</published>
	<updated>2009-11-15T10:08:11Z</updated>
	<author>
		<name>Ralf Hornik Mailings</name>
	</author>
	<content type="html">&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26361585&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;blainedw@...&lt;/a&gt; wrote:
&lt;br&gt;&lt;br&gt;&amp;gt; My problem now is my root certificate LDAP CDP does not include the email
&lt;br&gt;&amp;gt; address and I cannot reissue a new one. Any magic within LDAP I can do?
&lt;br&gt;&lt;br&gt;It depends on the SSL app. Some apps use subsearch and some not for &amp;nbsp;
&lt;br&gt;retrieving CRLs. Subsearch is also not recommended because of &amp;nbsp;
&lt;br&gt;performance issues.
&lt;br&gt;&lt;br&gt;The easiest way would be to move the crl to the CDP-DN of your &amp;nbsp;
&lt;br&gt;certificates by hand and &amp;quot;patch&amp;quot; your OpenCA installation to enroll &amp;nbsp;
&lt;br&gt;any new CRL there in future.
&lt;br&gt;Regards
&lt;br&gt;&lt;br&gt;Ralf
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26361585&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Trouble-with-LDAP-and-CRL%27s-tp26337641p26361585.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26345777</id>
	<title>Re: OCSP URL - what's it return????</title>
	<published>2009-11-13T16:26:20Z</published>
	<updated>2009-11-13T16:26:20Z</updated>
	<author>
		<name>blainedw</name>
	</author>
	<content type="html">&lt;font size=&quot;2&quot;&gt;&lt;p&gt;Hi max&lt;br&gt;&lt;br&gt;Getting back to something you said earlier in the thread about the error that isn't an error. If you see my openssl command I'm using -issuer parameter. So doesn't this tell openssl who the issuer is? This a subca so does this -issuer parameter require a concat of ca certs that make up the chain? &lt;br&gt;&lt;br&gt;Just trying to understand&lt;br&gt;&lt;br&gt;Dave&lt;br&gt;From David Blaine's blackberry&lt;br&gt;&lt;/p&gt;&lt;/font&gt;&lt;hr&gt;&lt;font size=&quot;2&quot;&gt;&lt;p&gt;&lt;b&gt;&amp;nbsp; From: &lt;/b&gt;blainedw&lt;br&gt;&lt;b&gt;&amp;nbsp; Sent: &lt;/b&gt;11/13/2009 04:53 PM EST&lt;br&gt;&lt;b&gt;&amp;nbsp; To: &lt;/b&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26345777&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openca@...&lt;/a&gt;; &amp;quot;Users' Help and Suggestions&amp;quot; &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26345777&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openca-users@...&lt;/a&gt;&amp;gt;&lt;br&gt;&lt;b&gt;&amp;nbsp; Subject: &lt;/b&gt;Re: [Openca-Users] OCSP URL - what's it return????&lt;br&gt;&lt;/p&gt;&lt;/font&gt;&lt;br&gt;

&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;The OCSP is defined as an AIA location&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;&lt;br&gt;
I'll check the logs when I get a chance.&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;Dave&lt;/font&gt;&lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26345777&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;&lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26345777&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OCSP-URL---what%27s-it-return-----tp26337743p26345777.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26344158</id>
	<title>Re: OCSP URL - what's it return????</title>
	<published>2009-11-13T13:53:45Z</published>
	<updated>2009-11-13T13:53:45Z</updated>
	<author>
		<name>blainedw</name>
	</author>
	<content type="html">
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;The OCSP is defined as an AIA location&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;&lt;br&gt;
I'll check the logs when I get a chance.&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;Dave&lt;/font&gt;&lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26344158&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OCSP-URL---what%27s-it-return-----tp26337743p26344158.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26344107</id>
	<title>Re: Trouble with LDAP and CRL's</title>
	<published>2009-11-13T13:50:01Z</published>
	<updated>2009-11-13T13:50:01Z</updated>
	<author>
		<name>blainedw</name>
	</author>
	<content type="html">
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;I checked ldapsearch and thanks to Ralf
the DN does have the email address in it... OK, I downloaded and installed
libpki. Using that tool and having the email address in the DN, I was able
to retrieve something (lots of garbled characters). &lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;My problem now is my root certificate
LDAP CDP does not include the email address and I cannot reissue a new
one. Any magic within LDAP I can do?&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;&lt;br&gt;
Dave&lt;/font&gt;&lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26344107&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Trouble-with-LDAP-and-CRL%27s-tp26337641p26344107.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26344011</id>
	<title>Re: OCSP URL - what's it return????</title>
	<published>2009-11-13T13:43:20Z</published>
	<updated>2009-11-13T13:43:20Z</updated>
	<author>
		<name>Massimiliano Pala-3</name>
	</author>
	<content type="html">I guess we have 2 separate issues here. The CDP is the CRL Distribution
&lt;br&gt;Point - not the OCSP responder address. That should point to your CRL
&lt;br&gt;http location.
&lt;br&gt;&lt;br&gt;I have not used the PKIVIEW on Winz... but have you checked the logs on
&lt;br&gt;the OCSP server (should be /var/log/messages).. what do they report ? It
&lt;br&gt;might be that the PKIVIEW uses the HTTP GET instead of the HTTP POST for
&lt;br&gt;the OCSP.. this is just a wild guess.. :D But since the current version
&lt;br&gt;of the software does not support GET.. you'll have to wait for the new
&lt;br&gt;version (which will support GET as well..).
&lt;br&gt;&lt;br&gt;Let us know...
&lt;br&gt;&lt;br&gt;Later,
&lt;br&gt;Max
&lt;br&gt;&lt;br&gt;&lt;br&gt;On 11/13/2009 04:10 PM, &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26344011&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;blainedw@...&lt;/a&gt; wrote:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; When I look in PKIVIEW (windows utility) to verify my AIA and CDP
&lt;br&gt;&amp;gt; locations. It states unable to download for both my LDAP CDP and my OCSP
&lt;br&gt;&amp;gt; location.
&lt;br&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;&lt;br&gt;Best Regards,
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Massimiliano Pala
&lt;br&gt;&lt;br&gt;--o------------------------------------------------------------------------
&lt;br&gt;Massimiliano Pala [OpenCA Project Manager] &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26344011&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openca@...&lt;/a&gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26344011&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;project.manager@...&lt;/a&gt;
&lt;br&gt;&lt;br&gt;Dartmouth Computer Science Dept &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Home Phone: +1 (603) 369-9332
&lt;br&gt;PKI/Trust Laboratory &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Work Phone: +1 (603) 646-8734
&lt;br&gt;--o------------------------------------------------------------------------
&lt;br&gt;People who think they know everything are a great annoyance to those of us
&lt;br&gt;who do.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;-- Isaac Asimov
&lt;br&gt;&lt;br&gt;&lt;br /&gt; &lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26344011&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;smime.p7s&lt;/strong&gt; (4K) &lt;a href=&quot;http://old.nabble.com/attachment/26344011/0/smime.p7s&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OCSP-URL---what%27s-it-return-----tp26337743p26344011.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26343631</id>
	<title>Re: OCSP URL - what's it return????</title>
	<published>2009-11-13T13:10:17Z</published>
	<updated>2009-11-13T13:10:17Z</updated>
	<author>
		<name>blainedw</name>
	</author>
	<content type="html">
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;When I look in PKIVIEW (windows utility)
to verify my AIA and CDP locations. It states unable to download for both
my LDAP CDP and my OCSP location.&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;&lt;br&gt;
Dave&lt;br&gt;
&lt;/font&gt;&lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26343631&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OCSP-URL---what%27s-it-return-----tp26337743p26343631.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26342618</id>
	<title>Re: OCSP URL - what's it return????</title>
	<published>2009-11-13T12:00:51Z</published>
	<updated>2009-11-13T12:00:51Z</updated>
	<author>
		<name>Massimiliano Pala-3</name>
	</author>
	<content type="html">Hi Dave,
&lt;br&gt;&lt;br&gt;actually that seem to work fine. The error in OpenSSL is not really an error,
&lt;br&gt;it just does not have the issuer certificate of the OCSP server's certificate
&lt;br&gt;but the response is correctly parsed (status good).
&lt;br&gt;&lt;br&gt;I do not really understand, what is the issue you are having ?
&lt;br&gt;&lt;br&gt;Later,
&lt;br&gt;Max
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;On 11/13/2009 01:17 PM, &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26342618&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;blainedw@...&lt;/a&gt; wrote:
&lt;div class='shrinkable-quote'&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Well, I hope I do ;)
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I guess the URL threw me because it had /ca/ca.html on it so I was
&lt;br&gt;&amp;gt; expecting a response.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; openssl ocsp -issuer /appl/openca-ocspd-1.5.1/etc/ocspd/certs/cacert.pem
&lt;br&gt;&amp;gt; -cert /appl/openca/openca/var/openca/crypto/certs/01.pem -url
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://host:2560/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://host:2560/&lt;/a&gt;&amp;nbsp;-resp_text -respout /tmp/ocspResp.der -CAfile
&lt;br&gt;&amp;gt; /appl/openca-ocspd-1.5.1/etc/ocspd/certs/cacert.pem &amp;lt;&lt;a href=&quot;http://host:2560/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://host:2560/&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; ....
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Response Verify Failure
&lt;br&gt;&amp;gt; 19659:error:27069065:OCSP routines:OCSP_basic_verify:certificate verify
&lt;br&gt;&amp;gt; error:ocsp_vfy.c:122:Verify error:unable to get issuer certificate
&lt;br&gt;&amp;gt; /appl/openca/openca/var/openca/crypto/certs/15.pem: good
&lt;br&gt;&amp;gt; This Update: Nov 12 18:12:01 2009 GMT
&lt;br&gt;&amp;gt; Next Update: Nov 13 16:46:03 2009 GMT
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I can eliminate this error by adding -VAoption
&lt;/div&gt;&lt;/div&gt;&lt;br /&gt; &lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26342618&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;smime.p7s&lt;/strong&gt; (4K) &lt;a href=&quot;http://old.nabble.com/attachment/26342618/0/smime.p7s&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OCSP-URL---what%27s-it-return-----tp26337743p26342618.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26341001</id>
	<title>Re: OCSP URL - what's it return????</title>
	<published>2009-11-13T10:17:11Z</published>
	<updated>2009-11-13T10:17:11Z</updated>
	<author>
		<name>blainedw</name>
	</author>
	<content type="html">
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;Well, I &amp;nbsp;hope I do ;)&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;I guess the URL threw me because it
had /ca/ca.html on it so I was expecting a response.&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;openssl ocsp -issuer /appl/openca-ocspd-1.5.1/etc/ocspd/certs/cacert.pem
-cert /appl/openca/openca/var/openca/crypto/certs/01.pem -url &lt;/font&gt;&lt;a href=http://host:2560 target=&quot;_top&quot; rel=&quot;nofollow&quot; /&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;http://host:2560/
-resp_text -respout /tmp/ocspResp.der -CAfile /appl/openca-ocspd-1.5.1/etc/ocspd/certs/cacert.pem&lt;/font&gt;&lt;/a&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;....&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;Response Verify Failure&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;19659:error:27069065:OCSP routines:OCSP_basic_verify:certificate
verify error:ocsp_vfy.c:122:Verify error:unable to get issuer certificate&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;/appl/openca/openca/var/openca/crypto/certs/15.pem:
good&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; This Update:
Nov 12 18:12:01 2009 GMT&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Next Update:
Nov 13 16:46:03 2009 GMT&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;I can eliminate this error by adding
-VAoption&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;Any help would be appreciated&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;Dave&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;&lt;br&gt;
Dave&lt;/font&gt;&lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26341001&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OCSP-URL---what%27s-it-return-----tp26337743p26341001.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26339830</id>
	<title>cross-site request forgery (XSRF)</title>
	<published>2009-11-13T08:47:09Z</published>
	<updated>2009-11-13T08:47:09Z</updated>
	<author>
		<name>Leo Catalinas</name>
	</author>
	<content type="html">Hello,
&lt;br&gt;&lt;br&gt;We use OpenCA 0.9.x in a couple of university projects and we are very
&lt;br&gt;pleased with it, having issued near 700 certificates for students and
&lt;br&gt;professors for e-learning in the last three years.
&lt;br&gt;&lt;br&gt;We integrate many screens and forms (like the request form) in a public
&lt;br&gt;web page (our pki portal) made with Joomla an its &amp;quot;wrapper&amp;quot; option
&lt;br&gt;(allows to embeed an external page within the page body using the html
&lt;br&gt;&amp;quot;&amp;lt;iframe&amp;gt;&amp;quot; element).
&lt;br&gt;&lt;br&gt;Now, we have tried the 1.0.2 version and we have seen that the &amp;quot;wrapper&amp;quot;
&lt;br&gt;option doesn't work because the new OpenCA XSRF protection.
&lt;br&gt;&lt;br&gt;We need the &amp;quot;wrapper&amp;quot; option to integrate OpenCA forms with Joomla, but
&lt;br&gt;tried to disable the XSRF protection and we didn't find how to do it.
&lt;br&gt;&lt;br&gt;How to disable XSRF or how to make work without disabling it? Any
&lt;br&gt;suggestion, please?
&lt;br&gt;&lt;br&gt;Thank you very much
&lt;br&gt;&lt;br&gt;Regards,
&lt;br&gt;Leo Catalinas,
&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26339830&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/cross-site-request-forgery-%28XSRF%29-tp26339830p26339830.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26339116</id>
	<title>Re: How to make OpenCA use OpenSSL engine?</title>
	<published>2009-11-13T08:15:03Z</published>
	<updated>2009-11-13T08:15:03Z</updated>
	<author>
		<name>Massimiliano Pala-3</name>
	</author>
	<content type="html">Hi Allen,
&lt;br&gt;&lt;br&gt;as Ralf said, check the OpenSC token in the tokens.xml configuration - it is
&lt;br&gt;quite easy to setup the Engine.
&lt;br&gt;&lt;br&gt;One small warning: if you are using the engine for accessing a P11 device, be
&lt;br&gt;careful that when you generate keys with that, the key is actually generated
&lt;br&gt;in software and then stored on the device (instead of using the PKCS11 key
&lt;br&gt;generation on hardware directly...).
&lt;br&gt;&lt;br&gt;Later,
&lt;br&gt;Max
&lt;br&gt;&lt;br&gt;&lt;br&gt;On 09/03/2009 08:39 PM, Allen Liu wrote:
&lt;br&gt;&amp;gt; No, it's not.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; OpenSSL ENGINE is a loadable module for talking to HSM (hardware Secure
&lt;br&gt;&amp;gt; Module) or smart card through PKCS 11 in order to utilize keys stored inside
&lt;br&gt;&amp;gt; as well as hardware-implementated algorithms.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I know how to use OpenSSL ENGINE to talk to HSM but don't know to make
&lt;br&gt;&amp;gt; OpenCA use ENGINE.
&lt;br&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;&lt;br&gt;Best Regards,
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Massimiliano Pala
&lt;br&gt;&lt;br&gt;--o------------------------------------------------------------------------
&lt;br&gt;Massimiliano Pala [OpenCA Project Manager] &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26339116&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openca@...&lt;/a&gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26339116&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;project.manager@...&lt;/a&gt;
&lt;br&gt;&lt;br&gt;Dartmouth Computer Science Dept &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Home Phone: +1 (603) 369-9332
&lt;br&gt;PKI/Trust Laboratory &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Work Phone: +1 (603) 646-8734
&lt;br&gt;--o------------------------------------------------------------------------
&lt;br&gt;People who think they know everything are a great annoyance to those of us
&lt;br&gt;who do.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;-- Isaac Asimov
&lt;br&gt;&lt;br&gt;&lt;br /&gt; &lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26339116&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;smime.p7s&lt;/strong&gt; (4K) &lt;a href=&quot;http://old.nabble.com/attachment/26339116/0/smime.p7s&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/How-to-make-OpenCA-use-OpenSSL-engine--tp25285745p26339116.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26339070</id>
	<title>Re: Trouble with LDAP and CRL's</title>
	<published>2009-11-13T08:12:30Z</published>
	<updated>2009-11-13T08:12:30Z</updated>
	<author>
		<name>Massimiliano Pala-3</name>
	</author>
	<content type="html">Hi Dave,
&lt;br&gt;&lt;br&gt;LDAP can be tricky, especially because if the DNs are not precise, you
&lt;br&gt;will not find what you are looking for. You might want to use one LDAP
&lt;br&gt;browsers (some time ago Mozilla had one built in.. now I don't think
&lt;br&gt;Firefox supports ldap:// urls anymore..). If you can find it for your
&lt;br&gt;system I usually use 'gq' - last version I checked was from 2006. The
&lt;br&gt;url on the 'About' is this:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.gq-project.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.gq-project.org/&lt;/a&gt;&lt;br&gt;&lt;br&gt;but that points just to an empty page.. a very simple google search
&lt;br&gt;gave me back this:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://linux.softpedia.com/get/Utilities/GQ-LDAP-Client-11212.shtml&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://linux.softpedia.com/get/Utilities/GQ-LDAP-Client-11212.shtml&lt;/a&gt;&lt;br&gt;&lt;br&gt;there are many others out there (most of them are Java, though...).
&lt;br&gt;&lt;br&gt;Also, another thing: check that the certificate CDP (CRL Distribution
&lt;br&gt;Point) is correct.
&lt;br&gt;&lt;br&gt;Another possibility is to download the new LibPKI - there is a tool
&lt;br&gt;there that allows you to download data from different URLs, and in
&lt;br&gt;particular from LDAP by using something like:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; $ url-tool &amp;quot;ldap://ldap.dartmouth.edu:389/cn=Dartmouth CertAuth1, o=Dartmouth College, 
&lt;br&gt;C=US, dc=dartmouth, dc=edu?cACertificate;binary&amp;quot;
&lt;br&gt;&lt;br&gt;You can find the libpki here:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://ftp.openca.org/libpki/releases/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://ftp.openca.org/libpki/releases/&lt;/a&gt;&lt;br&gt;&lt;br&gt;The version 0.4.0 is on its way...
&lt;br&gt;&lt;br&gt;Later,
&lt;br&gt;Max
&lt;br&gt;&lt;br&gt;&lt;br&gt;On 11/13/2009 09:41 AM, &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26339070&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;blainedw@...&lt;/a&gt; wrote:
&lt;div class='shrinkable-quote'&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Hi all,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Unlike most folks, I was able to publish my certificates and CRL's in
&lt;br&gt;&amp;gt; LDAP using Openca 1.0.2. My problem exists with check for it in LDAP.
&lt;br&gt;&amp;gt; Using PKIVIEW in Windows it mentions that it is &amp;quot;Unable to download&amp;quot; the
&lt;br&gt;&amp;gt; CRL from the LDAP CDP. It reports &amp;quot;OK&amp;quot; for the http one.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I used an ldap search command to check the existance of the CRL in LDAP
&lt;br&gt;&amp;gt; and that it was not expired. Here is the command I used:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; ./ldapsearch -x -h host -b &amp;quot;cn=Root CA,ou=Trustcenter,dc=domain,dc=com&amp;quot;
&lt;br&gt;&amp;gt; certificateRevocationList
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I am also able to use IE to at least contact the LDAP server via this
&lt;br&gt;&amp;gt; method (unsure how to download CRL using this method):
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; ldap://host/cn=Root CA,ou=Trustcenter,dc=domain,dc=com
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Any help appreciated!!!!
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Dave
&lt;/div&gt;&lt;/div&gt;&lt;br&gt;-- 
&lt;br&gt;&lt;br&gt;Best Regards,
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Massimiliano Pala
&lt;br&gt;&lt;br&gt;--o------------------------------------------------------------------------
&lt;br&gt;Massimiliano Pala [OpenCA Project Manager] &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26339070&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openca@...&lt;/a&gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26339070&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;project.manager@...&lt;/a&gt;
&lt;br&gt;&lt;br&gt;Dartmouth Computer Science Dept &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Home Phone: +1 (603) 369-9332
&lt;br&gt;PKI/Trust Laboratory &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Work Phone: +1 (603) 646-8734
&lt;br&gt;--o------------------------------------------------------------------------
&lt;br&gt;People who think they know everything are a great annoyance to those of us
&lt;br&gt;who do.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;-- Isaac Asimov
&lt;br&gt;&lt;br&gt;&lt;br /&gt; &lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26339070&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;smime.p7s&lt;/strong&gt; (4K) &lt;a href=&quot;http://old.nabble.com/attachment/26339070/0/smime.p7s&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Trouble-with-LDAP-and-CRL%27s-tp26337641p26339070.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26338861</id>
	<title>Re: OCSP URL - what's it return????</title>
	<published>2009-11-13T07:59:21Z</published>
	<updated>2009-11-13T07:59:21Z</updated>
	<author>
		<name>Massimiliano Pala-3</name>
	</author>
	<content type="html">Hi Dave,
&lt;br&gt;&lt;br&gt;I assume you have installed and configured the OCSP server ... :D If not,
&lt;br&gt;you have to download it as it is a separate package (that I am going to
&lt;br&gt;update quite soon... :D).
&lt;br&gt;&lt;br&gt;The OCSP server returns an OCSP response.. so it is not viewable with the
&lt;br&gt;browser. You can use the `openssl ocsp' to view the response (check the
&lt;br&gt;command line syntax by using `openssl ocsp -'.
&lt;br&gt;&lt;br&gt;Or you can just use wget (`wget &lt;a href=&quot;http://...'&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://...'&lt;/a&gt;) and then parse the contents
&lt;br&gt;of the saved data with `openssl asn1parse -inform DER -in &amp;lt;filename&amp;gt;'. Or,
&lt;br&gt;last but not least, just use the telnet command:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; $ telnet host 2560
&lt;br&gt;&lt;br&gt;then hit a couple of returns.. you'll see the response.. with the full
&lt;br&gt;headers.
&lt;br&gt;&lt;br&gt;I hope this helps,
&lt;br&gt;&lt;br&gt;Cheers,
&lt;br&gt;Max
&lt;br&gt;&lt;br&gt;&lt;br&gt;On 11/13/2009 09:49 AM, &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26338861&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;blainedw@...&lt;/a&gt; wrote:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I have a OCSP URL similar to the default one as an AIA location
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://host:2560/ca/ca.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://host:2560/ca/ca.html&lt;/a&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; If I copy and paste into a browser, it returns a 0
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; What is that supposed to return????
&lt;br&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;&lt;br&gt;Best Regards,
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Massimiliano Pala
&lt;br&gt;&lt;br&gt;--o------------------------------------------------------------------------
&lt;br&gt;Massimiliano Pala [OpenCA Project Manager] &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26338861&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openca@...&lt;/a&gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26338861&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;project.manager@...&lt;/a&gt;
&lt;br&gt;&lt;br&gt;Dartmouth Computer Science Dept &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Home Phone: +1 (603) 369-9332
&lt;br&gt;PKI/Trust Laboratory &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Work Phone: +1 (603) 646-8734
&lt;br&gt;--o------------------------------------------------------------------------
&lt;br&gt;People who think they know everything are a great annoyance to those of us
&lt;br&gt;who do.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;-- Isaac Asimov
&lt;br&gt;&lt;br&gt;&lt;br /&gt; &lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26338861&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;smime.p7s&lt;/strong&gt; (4K) &lt;a href=&quot;http://old.nabble.com/attachment/26338861/0/smime.p7s&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OCSP-URL---what%27s-it-return-----tp26337743p26338861.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26337743</id>
	<title>OCSP URL - what's it return????</title>
	<published>2009-11-13T06:49:11Z</published>
	<updated>2009-11-13T06:49:11Z</updated>
	<author>
		<name>blainedw</name>
	</author>
	<content type="html">
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;I have a OCSP URL similar to the default
one as an AIA location&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;a href=http://host:2560/ca/ca.html target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;http://host:2560/ca/ca.html&lt;/font&gt;&lt;/a&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;If I copy and paste into a browser,
it returns a 0&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;What is that supposed to return????&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;sans-serif&quot;&gt;Dave&lt;br&gt;
&lt;/font&gt;&lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26337743&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OCSP-URL---what%27s-it-return-----tp26337743p26337743.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26337715</id>
	<title>Re: Trouble with LDAP and CRL's</title>
	<published>2009-11-13T06:47:59Z</published>
	<updated>2009-11-13T06:47:59Z</updated>
	<author>
		<name>Ralf Hornik Mailings</name>
	</author>
	<content type="html">&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26337715&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;blainedw@...&lt;/a&gt; wrote:
&lt;br&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; ldap://host/cn=Root CA,ou=Trustcenter,dc=domain,dc=com
&lt;br&gt;&lt;br&gt;Is this the full DN or is there an emailAddess too?
&lt;br&gt;&lt;br&gt;Some Applications need the full DN to find the CRL:
&lt;br&gt;&lt;br&gt;ldap://&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26337715&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;host/emailAdress=root@...&lt;/a&gt;, cn=Root &amp;nbsp;
&lt;br&gt;CA,ou=Trustcenter,dc=domain,dc=com
&lt;br&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;alles bleibt anders...
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Openca-Users mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26337715&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Openca-Users@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/openca-users&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/openca-users&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Trouble-with-LDAP-and-CRL%27s-tp26337641p26337715.html" />
</entry>

</feed>
