Re: [Pki-users] PKI RA cannot find Security Modules
by Bob Lord
What's the bug number?
/B
On Wed, Aug 20, 2008 at 9:54 AM, Jack Magne <jmagne(a)redhat.com> wrote:
> Ognyan:
>
> We have a bug for this that we are working on.
>
> As a quick workaround, you might try downgrading the package that contains
> "modutil" to an earlier version. This would be "nss-tools".
>
> Ognyan Kulev wrote:
>>
>> Hi,
>>
>> In PKI RA installation wizard, no supported security modules are found:
>>
>> NSS Internal PKCS #11 Module Not Found nCipher's nFast
>> Token Hardware Module Not Found SafeNet's LunaSA Token Hardware
>> Module Not Found
>>
>> How to fix that?
>>
>> Regards,
>> Ognyan Kulev
>>
>> _______________________________________________
>> Pki-users mailing list
>> Pki-users(a)redhat.com
>> https://www.redhat.com/mailman/listinfo/pki-users
>
> _______________________________________________
> Pki-users mailing list
> Pki-users(a)redhat.com
> https://www.redhat.com/mailman/listinfo/pki-users
>
>
16 years, 3 months
Modifying the caUserCert Profile to cause Firefox to generate certificate requests with EC keys?
by Price, Bill
I would like to modify the caUserCert profile to so that the resulting
certificate requests are for EC keys. The existing profile appears to
be hardwired for an RSA key. I didn't find any documentation for EC
keys. I would appreciate any information regarding how to cause a
firefox browser to generate an ECC pair and submit it to the CA. If
anyone has succeeded and would share the profile config file, I'd
appreciate it. Some questions I have are: what is the keytype? (EC,
ECC, ECDSA); What keylengths should be used (ECC lengths -256 or RSA
equivalents)? Should the signing algorithm be changed? If so, what are
the allowable names? Does anything else have to be changed such as the
html templates or class files?
Thanks.
Bill Price
16 years, 4 months
PKI RA cannot find Security Modules
by Ognyan Kulev
Hi,
In PKI RA installation wizard, no supported security modules are found:
NSS Internal PKCS #11 Module Not Found
nCipher's nFast Token Hardware Module Not Found
SafeNet's LunaSA Token Hardware Module Not Found
How to fix that?
Regards,
Ognyan Kulev
16 years, 4 months
PKI RA doesn't starts and wants password
by Ognyan Kulev
Hi,
I've successfully installed and configured PKI CA and PKI OCSP on CentOS
5.2. But trying to run PKI RA gives wants password:
Starting pki-ra: Please enter password for "internal" token:
I tried the passwords that I use for FDS or PKI CA, or the PIN of PKI RA
but nothing works. If I just hit Enter, message indicates success:
PKI service(s) are available at https://<host>:12889
But this URL doesn't connect and there is no PKI RA process.
The only other clue is the following error in /var/log/pki-ra/error_log
[Wed Aug 20 13:48:40 2008] [info] Init: Initializing NSS library
[Wed Aug 20 13:48:57 2008] [error] Unable to read from pin store for
slot: internal APR err: 0
So what can be the problem and how can be fixed?
Regards,
Ognyan Kulev
16 years, 4 months