help for automatic certificate generation
by jfonfon
Hi,
We have to generate dozen certificates for devices authentication.
I've been looking for a solution with the CMCEnrollement tool.
It's working but there is a manual action required to put the signed
certificate request in the web interface.
There is also a bulkinssuance tool but for this the CSR have to be in the
CMRF format. I don't find a tool be able to convert pkcs10 to CMRF.
Any tips or help to achieve this is welcome.
regards,
Jacques
15 years, 2 months
pkiconsole cmd not available
by Rashmi Pawar
Hi,
I installed and configured all pki subsystems and started the services.
Upon starting the service for pki-ca following command was thrown on
screen " pkiconsole https://ca.cactus.com:9445/ca "
but there is no such binary pkiconsole on the server..I need to configure
profiles...please help..
Thanks in advance.
15 years, 3 months
no service page for tks
by Rashmi Pawar
After configuring all the 6 subsystems services files for all subsystem was
created except for TKS...however upon starting the service pki-tks on the CA
server a link to the serivices page (Secure Admin Port =
https://ca1.cactus.com:13445/tks/services) was displayed on screen along
with other links..
when i paste the above link in firefox browser a web page with heading
"Certificate System TKS Services Page" opens without any links on it to view
or change the settings.
Is this the default behaviour of tks subsystem or if something went wrong
while configuring the subsystem?
if the configuration went wrong how to correct it ? does it require stopping
and restarting all the subsystems?
On Fri, Sep 11, 2009 at 5:16 AM, Adewumi, Julius-p99373 <
Julius.Adewumi(a)gdc4s.com> wrote:
> I've run into that several times. By just changing the name of the
> DB .. say kra to kra1, you will see what the problem is,
> especially if you have acess to the directory server you are using for the
> repository. If the name has been created prior in the directory server,
> you have to delete it from the directory server, and then it will use the
> name. Changing the name will make it create a new instance of the DB
> with the new name.
>
>
> *From: Julius Adewumi*
> *(a)GDC4S.com*
> *Ph:480-441-6768*
> *Contract Corp:MTSI*
>
>
> ------------------------------
> *From:* pki-users-bounces(a)redhat.com [mailto:pki-users-bounces@redhat.com]
> *On Behalf Of *Rashmi Pawar
> *Sent:* Thursday, September 10, 2009 12:16 PM
> *To:* pki-users(a)redhat.com
> *Subject:* [Pki-users] PKI-TKS Internal Database Error
>
> Hi,
>
> I have installed following PKI Subsystmes:pki-ca, pki-kra, pki-ocsp,
> pki-tks
> I configured pki-ca, pki-kra and pki-ocsp withoout any error. but i
> encountered an error message while configuring pki-tks subsystem.
>
> The error is "This database has already been used. Select the checkbox
> below to remove all data and resuse this database"
>
> My concern is, if i check mark the option "Remove the existing data from
> the base DN shown above" will it remove the databases of ca,ocsp and kra?
>
> the base DN i have used here on this wepage is dc=cactus ... the same DN
> has been used while configuring ca,ocsp and kra subsystem.
>
>
>
>
15 years, 3 months
Re: [Pki-users] How to completely remove all traces of pki subsystem
by kashyap chamarthy
Rashmi Pawar wrote:
> Hi Kashyap,
>
> Thank you for the advise.
>
> I am using fedora 10 and installing dogtag1.2.0. I read the
> documentation on redhat certificate system 8.0 on RHEL 5.3.
> In the documentation fedora it has been mentioned that sqlite should be
> installed while in documentation for certificate system 8.0 on RHEL5.3
> sqlite,libsqlite rpms should be removed...
> SQLlite is installed at the time of installtion so I am confused if
> Sqlite has to be removed from FC10 or not for RA subsytem, or if the the
> prerequisites for installing the certificate system are different for
> FC10 and RHEL5.3?
IIRC, if you are trying to remove dependencies for RA(SQLite related), perl-DBI and
perl-DBD-SQLite should be OK.
/kashyap
> Rashmi
> On Tue, Sep 8, 2009 at 6:43 PM, kashyap chamarthy <kchamart(a)redhat.com
> <mailto:kchamart@redhat.com>> wrote:
>
> Rashmi Pawar wrote:
>
> Hi,
>
> I tried using firefox for configuration but was not successfull.
> As i got the error 46 on web browser and could not resolve the
> error I uninstalled all the pki subsystems, again when i
> installed the pki susbsytems say pki-ca a new instance file
> /var/log/pki-ca-install.log was not created.. Please advice me
> how to completely remove all traces, instances of
> pki-subsystems..as i tried pkiremove and pkicreate to remove and
> create the instance and log file...but was unsuccessfull.
>
>
> Though I'm not sure of the error 46 you're encountering,
>
>
> - Also try to clean-up the Directory Server instance, (and later
> create a new one)
> # remove-ds.pl -i slapd-foo
> (-f can be passed as argument to force uninstall)
>
> - Try doing a yum remove for the pki package dependencies,
>
> - After that, try removing the below files..
>
> /var/lib/pki* /var/log/pki* /etc/init.d/pki*
>
> - Create a new firefox user profile (just to avoid any old subsystem
> certs in your browser)
>
> HTH,
> kashyap
>
> Thanks.
> Regards.
> Rsahmi
>
>
>
> On Fri, Sep 4, 2009 at 6:36 PM, Chandrasekar Kannan
> <ckannan(a)redhat.com <mailto:ckannan@redhat.com>
> <mailto:ckannan@redhat.com <mailto:ckannan@redhat.com>>> wrote:
>
> On 09/04/2009 02:16 AM, Rashmi Pawar wrote:
>
> Hi when i configured subsystem pki-ca i got he error
> "Error 46
> Cerendentials not generated"
> Please find the attached file that shows the error...
>
>
> I don't believe we support IE for the administration interface.
> If possible, please try with firefox.
>
>
>
> On Wed, Sep 2, 2009 at 8:57 AM, Rashmi Pawar
> <rashmeepawar(a)gmail.com <mailto:rashmeepawar@gmail.com>
> <mailto:rashmeepawar@gmail.com
> <mailto:rashmeepawar@gmail.com>>> wrote:
>
> ok..
> thanks a lot...
>
> On Wed, Sep 2, 2009 at 8:40 AM, Chandrasekar Kannan
> <ckannan(a)redhat.com <mailto:ckannan@redhat.com>
> <mailto:ckannan@redhat.com <mailto:ckannan@redhat.com>>> wrote:
>
> On 09/01/2009 07:48 PM, Rashmi Pawar wrote:
>
> Thank you
> Chandrasekar for your prompt and informative
> response.
> I asked if apache or secure
> apache is required for dogtag
> implementation because at the end of the web page
>
> http://pki.fedoraproject.org/wiki/PKI_Runtime_Environments
> it
> has been mentioned that RA and TPS subsystems
> require
> Apache web server,
> hence the question as to what all daemons and
> rpms need
> to be installed and configured before
> starting installing
> and configuring PKI subsytsems.
>
>
> ah ok. yeah apache is required. but if you do
> yum -y install pki-tps pki-ra
>
> yum will pull in and install all the dependencies
> for you.
> httpd - apache webserver is one of them.
>
> no other action is required.
>
>
>
>
> On Tue, Sep 1, 2009 at 10:43 PM,
> Chandrasekar Kannan
> <ckannan(a)redhat.com
> <mailto:ckannan@redhat.com> <mailto:ckannan@redhat.com
> <mailto:ckannan@redhat.com>>> wrote:
>
> On 09/01/2009 09:43 AM, Rashmi Pawar wrote:
>
> I
> want to install all the 6 PKI subsystems for
> dogtag implementation,
>
>
> right. yum -y install pki-ca pki-tks
> pki-tps pki-ra
> pki-ocsp pki-kra
> is all you need to do. It will pull in
> httpd,tomcat5
> etc...
>
>
> do i need to configure apache or
> secure apache.
>
>
> What is this for ?
>
>
>
> Thanks in advance.
>
>
> On Mon, Aug 31, 2009
> at 5:53 PM, Chandrasekar Kannan
> <ckannan(a)redhat.com
> <mailto:ckannan@redhat.com>
> <mailto:ckannan@redhat.com
> <mailto:ckannan@redhat.com>>> wrote:
>
> On 08/31/2009 01:20 AM, Rashmi
> Pawar wrote:
>
> Hi Chandrasekar,
> Thank you
> for your reply.
> One quick question..As you
> said i dont need to
> install and run Apache if
> pki-tps and pki-ra
> subsystems are not
> installed...My question is
> even if i am not installing
> pki-ra and pki-tps
> subsystems can i still go
> with apache?
>
>
> can u explain what you will use
> apache for .. in
> this case ?..
>
> Regards,
> Rashmi Pawar
> On Sun, Aug 30, 2009 at 9:30 PM,
> <pki-users-request(a)redhat.com
> <mailto:pki-users-request@redhat.com>
>
> <mailto:pki-users-request@redhat.com
> <mailto:pki-users-request@redhat.com>>> wrote:
>
> Send Pki-users mailing
> list submissions to
>
> pki-users(a)redhat.com <mailto:pki-users@redhat.com>
>
> <mailto:pki-users@redhat.com
> <mailto:pki-users@redhat.com>>
>
>
> To subscribe or
> unsubscribe via the World
> Wide Web, visit
>
>
> https://www.redhat.com/mailman/listinfo/pki-users
> or, via email, send a
> message with subject
> or body 'help' to
>
> pki-users-request(a)redhat.com
> <mailto:pki-users-request@redhat.com>
>
> <mailto:pki-users-request@redhat.com
> <mailto:pki-users-request@redhat.com>>
>
>
> You can reach the person
> managing the list at
>
> pki-users-owner(a)redhat.com
> <mailto:pki-users-owner@redhat.com>
>
> <mailto:pki-users-owner@redhat.com
> <mailto:pki-users-owner@redhat.com>>
>
>
> When replying, please
> edit your Subject
> line so it is more specific
> than "Re: Contents of
> Pki-users digest..."
>
>
> Today's Topics:
>
> 1. Dogtag Installation
> on FC6 (Rashmi Pawar)
> 2. Re: Dogtag
> Installation on FC6
> (Chandrasekar Kannan)
>
>
>
> ----------------------------------------------------------------------
>
> Message: 1
> Date: Sun, 30 Aug 2009
> 13:42:01 +0530
> From: Rashmi Pawar
> <rashmeepawar(a)gmail.com
> <mailto:rashmeepawar@gmail.com>
>
> <mailto:rashmeepawar@gmail.com
> <mailto:rashmeepawar@gmail.com>>>
>
> Subject: [Pki-users]
> Dogtag Installation on FC6
> To: pki-users(a)redhat.com
> <mailto:pki-users@redhat.com>
>
> <mailto:pki-users@redhat.com
> <mailto:pki-users@redhat.com>>
>
> Message-ID:
>
>
> <816962df0908300112t6ca5b2at2b79ae587ba32d98(a)mail.gmail.com
> <mailto:816962df0908300112t6ca5b2at2b79ae587ba32d98@mail.gmail.com>
>
> <mailto:816962df0908300112t6ca5b2at2b79ae587ba32d98@mail.gmail.com
> <mailto:816962df0908300112t6ca5b2at2b79ae587ba32d98@mail.gmail.com>>>
>
>
> Content-Type: text/plain;
> charset="iso-8859-1"
>
> Hi
>
> I am new to the Dogtag
> Certificate system.
> I have to install the dogtag
> certificate system on
> fedora core 6. I
> would appreciate help
> from pki-users
> who have successfully
> installed and are
> runing dogtag certificate
> system on
> linux.
> I read the explanantion
> on dogtag on
>
> http://pki.fedoraproject.org/wiki/PKI_Main_Page
> yet I have some questions
> before starting the
> installation. Following
> are the questions:
>
> 1. Do I have to install
> and run Apache
> service on the system on
> which I am
> going to implement dogtag?
> 2. I am confused about
> the configuration of
> all the PKI subsystems like
> CA,RA,DRM...etc. In the
>
> http://pki.fedoraproject.org/wiki/PKI_Main_Page
> the
> configuration of all
> subsyems is given but
> I dont understand from
> where do I
> get the configuration URL
> for each subsystem.
> 3. I have to integrate
> the setup with
> Checkpoint, so need steps
> on the
> integration.
>
> I would appreciate if
> someone who has
> implemented dogtag would
> provide me
> easy steps to install
> dogtag on fedora core 6.
>
> Thanks & Regards,
> Rashmi
> -------------- next part
> --------------
> An HTML attachment was
> scrubbed...
> URL:
>
> https://www.redhat.com/archives/pki-users/attachments/20090830/86c17a72/a...
>
>
> ------------------------------
>
> Message: 2
> Date: Sun, 30 Aug 2009
> 07:30:03 -0700
> From: Chandrasekar Kannan
> <ckannan(a)redhat.com
> <mailto:ckannan@redhat.com>
>
> <mailto:ckannan@redhat.com
> <mailto:ckannan@redhat.com>>>
>
> Subject: Re: [Pki-users]
> Dogtag
> Installation on FC6
> To: Rashmi Pawar
> <rashmeepawar(a)gmail.com
> <mailto:rashmeepawar@gmail.com>
>
> <mailto:rashmeepawar@gmail.com
> <mailto:rashmeepawar@gmail.com>>>
>
> Cc: pki-users(a)redhat.com
> <mailto:pki-users@redhat.com>
>
> <mailto:pki-users@redhat.com
> <mailto:pki-users@redhat.com>>
>
> Message-ID:
> <4A9A8CEB.1080404(a)redhat.com
> <mailto:4A9A8CEB.1080404@redhat.com>
>
> <mailto:4A9A8CEB.1080404@redhat.com
> <mailto:4A9A8CEB.1080404@redhat.com>>>
>
> Content-Type: text/plain;
> charset="iso-8859-1"
>
> On 08/30/2009 01:12 AM,
> Rashmi Pawar wrote:
> > Hi
> > I am new to the Dogtag
> Certificate
> system. I have to install the
> > dogtag certificate
> system on fedora core
> 6. I would appreciate help
> > from pki-users who have
> successfully
> installed and are runing
> dogtag
> > certificate system on
> linux.
> > I read the explanantion
> on dogtag on
> >
>
> http://pki.fedoraproject.org/wiki/PKI_Main_Page
> yet I have some
> > questions before
> starting the
> installation. Following
> are the questions:
> > 1. Do I have to install
> and run Apache
> service on the system on
> > which I am going to
> implement dogtag?
>
> not unless you need
> pki-tps or pki-ra
> subsystems. For pki-ca,
> pki-tks,
> pki-ocsp, pki-kra you
> just need tomcat5.
>
> > 2. I am confused about
> the configuration
> of all the PKI subsystems
> > like CA,RA,DRM...etc.
> In the
> >
>
> http://pki.fedoraproject.org/wiki/PKI_Main_Page
> the configuration of
> > all subsyems is given
> but I dont
> understand from where do
> I get the
> > configuration URL for
> each subsystem.
>
> for example, once you run
> yum install
> pki-ca, the rpm post install
> scripts run
> /usr/bin/pkicreate utility to
> create the default instance.
> Upon creation of this
> default instance,
> pkicreate spits out the
> url for
> configuration.
>
>
> > 3. I have to integrate
> the setup with
> Checkpoint, so need steps
> on the
> > integration.
> no idea.
>
> > I would appreciate if
> someone who has
> implemented dogtag would
> provide
> > me easy steps to
> install dogtag on fedora
> core 6.
> > Thanks & Regards,
> > Rashmi
> >
>
> ------------------------------------------------------------------------
> >
> >
>
> _______________________________________________
> > Pki-users mailing list
> > Pki-users(a)redhat.com
> <mailto:Pki-users@redhat.com>
>
> <mailto:Pki-users@redhat.com
> <mailto:Pki-users@redhat.com>>
>
> >
>
> https://www.redhat.com/mailman/listinfo/pki-users
> >
>
> -------------- next part
> --------------
> An HTML attachment was
> scrubbed...
> URL:
>
> https://www.redhat.com/archives/pki-users/attachments/20090830/573d26cb/a...
>
>
> ------------------------------
>
>
> _______________________________________________
> Pki-users mailing list
> Pki-users(a)redhat.com
> <mailto:Pki-users@redhat.com>
>
> <mailto:Pki-users@redhat.com
> <mailto:Pki-users@redhat.com>>
>
>
> https://www.redhat.com/mailman/listinfo/pki-users
>
>
> End of Pki-users Digest,
> Vol 18, Issue 6
>
> ****************************************
>
>
>
>
>
>
>
>
>
>
>
>
> ------------------------------------------------------------------------
>
> _______________________________________________
> Pki-users mailing list
> Pki-users(a)redhat.com <mailto:Pki-users@redhat.com>
> https://www.redhat.com/mailman/listinfo/pki-users
>
>
>
15 years, 3 months
PKI-TKS Internal Database Error
by Rashmi Pawar
Hi,
I have installed following PKI Subsystmes:pki-ca, pki-kra, pki-ocsp, pki-tks
I configured pki-ca, pki-kra and pki-ocsp withoout any error. but i
encountered an error message while configuring pki-tks subsystem.
The error is "This database has already been used. Select the checkbox below
to remove all data and resuse this database"
My concern is, if i check mark the option "Remove the existing data from the
base DN shown above" will it remove the databases of ca,ocsp and kra?
the base DN i have used here on this wepage is dc=cactus ... the same DN has
been used while configuring ca,ocsp and kra subsystem.
15 years, 3 months
How to completely remove all traces of pki subsystem
by Rashmi Pawar
Hi,
I tried using firefox for configuration but was not successfull.
As i got the error 46 on web browser and could not resolve the error
I uninstalled all the pki subsystems, again when i installed the pki
susbsytems say pki-ca a new instance file /var/log/pki-ca-install.log was
not created.. Please advice me how to completely remove all traces,
instances of pki-subsystems..as i tried pkiremove and pkicreate to remove
and create the instance and log file...but was unsuccessfull.
Thanks.
Regards.
Rsahmi
On Fri, Sep 4, 2009 at 6:36 PM, Chandrasekar Kannan <ckannan(a)redhat.com>wrote:
> On 09/04/2009 02:16 AM, Rashmi Pawar wrote:
>
> Hi when i configured subsystem pki-ca i got he error "Error 46
> Cerendentials not generated"
> Please find the attached file that shows the error...
>
>
> I don't believe we support IE for the administration interface.
> If possible, please try with firefox.
>
>
>
> On Wed, Sep 2, 2009 at 8:57 AM, Rashmi Pawar <rashmeepawar(a)gmail.com>wrote:
>
>> ok..
>> thanks a lot...
>>
>> On Wed, Sep 2, 2009 at 8:40 AM, Chandrasekar Kannan <ckannan(a)redhat.com>wrote:
>>
>>> On 09/01/2009 07:48 PM, Rashmi Pawar wrote:
>>>
>>>
>>>
>>> Thank you Chandrasekar for your prompt and informative response.
>>>
>>> I asked if apache or secure apache is required for dogtag implementation
>>> because at the end of the web page
>>> http://pki.fedoraproject.org/wiki/PKI_Runtime_Environments it has been
>>> mentioned that RA and TPS subsystems require Apache web server,
>>> hence the question as to what all daemons and rpms need to be installed
>>> and configured before starting installing and configuring PKI subsytsems.
>>>
>>>
>>> ah ok. yeah apache is required. but if you do
>>> yum -y install pki-tps pki-ra
>>>
>>> yum will pull in and install all the dependencies for you.
>>> httpd - apache webserver is one of them.
>>>
>>> no other action is required.
>>>
>>>
>>>
>>>
>>>
>>>
>>> On Tue, Sep 1, 2009 at 10:43 PM, Chandrasekar Kannan <ckannan(a)redhat.com
>>> > wrote:
>>>
>>>> On 09/01/2009 09:43 AM, Rashmi Pawar wrote:
>>>>
>>>>
>>>>
>>>> I want to install all the 6 PKI subsystems for dogtag implementation,
>>>>
>>>>
>>>> right. yum -y install pki-ca pki-tks pki-tps pki-ra pki-ocsp pki-kra
>>>> is all you need to do. It will pull in httpd,tomcat5 etc...
>>>>
>>>> do i need to configure apache or secure apache.
>>>>
>>>>
>>>> What is this for ?
>>>>
>>>>
>>>>
>>>> Thanks in advance.
>>>>
>>>>
>>>>
>>>>
>>>> On Mon, Aug 31, 2009 at 5:53 PM, Chandrasekar Kannan <
>>>> ckannan(a)redhat.com> wrote:
>>>>
>>>>> On 08/31/2009 01:20 AM, Rashmi Pawar wrote:
>>>>>
>>>>> Hi Chandrasekar,
>>>>>
>>>>> Thank you for your reply.
>>>>> One quick question..As you said i dont need to install and run Apache
>>>>> if pki-tps and pki-ra subsystems are not installed...My question is even if
>>>>> i am not installing pki-ra and pki-tps subsystems can i still go with
>>>>> apache?
>>>>>
>>>>>
>>>>> can u explain what you will use apache for .. in this case ?..
>>>>>
>>>>>
>>>>> Regards,
>>>>> Rashmi Pawar
>>>>> On Sun, Aug 30, 2009 at 9:30 PM, <pki-users-request(a)redhat.com> wrote:
>>>>>
>>>>>> Send Pki-users mailing list submissions to
>>>>>> pki-users(a)redhat.com
>>>>>>
>>>>>> To subscribe or unsubscribe via the World Wide Web, visit
>>>>>> https://www.redhat.com/mailman/listinfo/pki-users
>>>>>> or, via email, send a message with subject or body 'help' to
>>>>>> pki-users-request(a)redhat.com
>>>>>>
>>>>>> You can reach the person managing the list at
>>>>>> pki-users-owner(a)redhat.com
>>>>>>
>>>>>> When replying, please edit your Subject line so it is more specific
>>>>>> than "Re: Contents of Pki-users digest..."
>>>>>>
>>>>>>
>>>>>> Today's Topics:
>>>>>>
>>>>>> 1. Dogtag Installation on FC6 (Rashmi Pawar)
>>>>>> 2. Re: Dogtag Installation on FC6 (Chandrasekar Kannan)
>>>>>>
>>>>>>
>>>>>> ----------------------------------------------------------------------
>>>>>>
>>>>>> Message: 1
>>>>>> Date: Sun, 30 Aug 2009 13:42:01 +0530
>>>>>> From: Rashmi Pawar <rashmeepawar(a)gmail.com>
>>>>>> Subject: [Pki-users] Dogtag Installation on FC6
>>>>>> To: pki-users(a)redhat.com
>>>>>> Message-ID:
>>>>>> <816962df0908300112t6ca5b2at2b79ae587ba32d98(a)mail.gmail.com>
>>>>>> Content-Type: text/plain; charset="iso-8859-1"
>>>>>>
>>>>>> Hi
>>>>>>
>>>>>> I am new to the Dogtag Certificate system. I have to install the
>>>>>> dogtag
>>>>>> certificate system on fedora core 6. I would appreciate help from
>>>>>> pki-users
>>>>>> who have successfully installed and are runing dogtag certificate
>>>>>> system on
>>>>>> linux.
>>>>>> I read the explanantion on dogtag on
>>>>>> http://pki.fedoraproject.org/wiki/PKI_Main_Page yet I have some
>>>>>> questions
>>>>>> before starting the installation. Following are the questions:
>>>>>>
>>>>>> 1. Do I have to install and run Apache service on the system on which
>>>>>> I am
>>>>>> going to implement dogtag?
>>>>>> 2. I am confused about the configuration of all the PKI subsystems
>>>>>> like
>>>>>> CA,RA,DRM...etc. In the
>>>>>> http://pki.fedoraproject.org/wiki/PKI_Main_Page the
>>>>>> configuration of all subsyems is given but I dont understand from
>>>>>> where do I
>>>>>> get the configuration URL for each subsystem.
>>>>>> 3. I have to integrate the setup with Checkpoint, so need steps on the
>>>>>> integration.
>>>>>>
>>>>>> I would appreciate if someone who has implemented dogtag would provide
>>>>>> me
>>>>>> easy steps to install dogtag on fedora core 6.
>>>>>>
>>>>>> Thanks & Regards,
>>>>>> Rashmi
>>>>>> -------------- next part --------------
>>>>>> An HTML attachment was scrubbed...
>>>>>> URL:
>>>>>> https://www.redhat.com/archives/pki-users/attachments/20090830/86c17a72/a...
>>>>>>
>>>>>> ------------------------------
>>>>>>
>>>>>> Message: 2
>>>>>> Date: Sun, 30 Aug 2009 07:30:03 -0700
>>>>>> From: Chandrasekar Kannan <ckannan(a)redhat.com>
>>>>>> Subject: Re: [Pki-users] Dogtag Installation on FC6
>>>>>> To: Rashmi Pawar <rashmeepawar(a)gmail.com>
>>>>>> Cc: pki-users(a)redhat.com
>>>>>> Message-ID: <4A9A8CEB.1080404(a)redhat.com>
>>>>>> Content-Type: text/plain; charset="iso-8859-1"
>>>>>>
>>>>>> On 08/30/2009 01:12 AM, Rashmi Pawar wrote:
>>>>>> > Hi
>>>>>> > I am new to the Dogtag Certificate system. I have to install the
>>>>>> > dogtag certificate system on fedora core 6. I would appreciate help
>>>>>> > from pki-users who have successfully installed and are runing dogtag
>>>>>> > certificate system on linux.
>>>>>> > I read the explanantion on dogtag on
>>>>>> > http://pki.fedoraproject.org/wiki/PKI_Main_Page yet I have some
>>>>>> > questions before starting the installation. Following are the
>>>>>> questions:
>>>>>> > 1. Do I have to install and run Apache service on the system on
>>>>>> > which I am going to implement dogtag?
>>>>>>
>>>>>> not unless you need pki-tps or pki-ra subsystems. For pki-ca, pki-tks,
>>>>>> pki-ocsp, pki-kra you just need tomcat5.
>>>>>>
>>>>>> > 2. I am confused about the configuration of all the PKI subsystems
>>>>>> > like CA,RA,DRM...etc. In the
>>>>>> > http://pki.fedoraproject.org/wiki/PKI_Main_Page the configuration
>>>>>> of
>>>>>> > all subsyems is given but I dont understand from where do I get the
>>>>>> > configuration URL for each subsystem.
>>>>>>
>>>>>> for example, once you run yum install pki-ca, the rpm post install
>>>>>> scripts run /usr/bin/pkicreate utility to create the default instance.
>>>>>> Upon creation of this default instance, pkicreate spits out the url
>>>>>> for
>>>>>> configuration.
>>>>>>
>>>>>>
>>>>>> > 3. I have to integrate the setup with Checkpoint, so need steps on
>>>>>> the
>>>>>> > integration.
>>>>>> no idea.
>>>>>>
>>>>>> > I would appreciate if someone who has implemented dogtag would
>>>>>> provide
>>>>>> > me easy steps to install dogtag on fedora core 6.
>>>>>> > Thanks & Regards,
>>>>>> > Rashmi
>>>>>> >
>>>>>> ------------------------------------------------------------------------
>>>>>> >
>>>>>> > _______________________________________________
>>>>>> > Pki-users mailing list
>>>>>> > Pki-users(a)redhat.com
>>>>>> > https://www.redhat.com/mailman/listinfo/pki-users
>>>>>> >
>>>>>>
>>>>>> -------------- next part --------------
>>>>>> An HTML attachment was scrubbed...
>>>>>> URL:
>>>>>> https://www.redhat.com/archives/pki-users/attachments/20090830/573d26cb/a...
>>>>>>
>>>>>> ------------------------------
>>>>>>
>>>>>> _______________________________________________
>>>>>> Pki-users mailing list
>>>>>> Pki-users(a)redhat.com
>>>>>> https://www.redhat.com/mailman/listinfo/pki-users
>>>>>>
>>>>>>
>>>>>> End of Pki-users Digest, Vol 18, Issue 6
>>>>>> ****************************************
>>>>>>
>>>>>
>>>>>
>>>>>
>>>>
>>>>
>>>
>>>
>>
>
>
15 years, 3 months
Re: Error 46 Credentials not generated
by Chandrasekar Kannan
On 09/04/2009 02:16 AM, Rashmi Pawar wrote:
> Hi when i configured subsystem pki-ca i got he error "Error 46
> Cerendentials not generated"
> Please find the attached file that shows the error...
I don't believe we support IE for the administration interface.
If possible, please try with firefox.
>
> On Wed, Sep 2, 2009 at 8:57 AM, Rashmi Pawar <rashmeepawar(a)gmail.com
> <mailto:rashmeepawar@gmail.com>> wrote:
>
> ok..
> thanks a lot...
>
> On Wed, Sep 2, 2009 at 8:40 AM, Chandrasekar Kannan
> <ckannan(a)redhat.com <mailto:ckannan@redhat.com>> wrote:
>
> On 09/01/2009 07:48 PM, Rashmi Pawar wrote:
>> Thank you Chandrasekar for your prompt and informative response.
>> I asked if apache or secure apache is required for dogtag
>> implementation because at the end of the web page
>> http://pki.fedoraproject.org/wiki/PKI_Runtime_Environments it
>> has been mentioned that RA and TPS subsystems require Apache
>> web server,
>> hence the question as to what all daemons and rpms need to be
>> installed and configured before starting installing and
>> configuring PKI subsytsems.
>
> ah ok. yeah apache is required. but if you do
> yum -y install pki-tps pki-ra
>
> yum will pull in and install all the dependencies for you.
> httpd - apache webserver is one of them.
>
> no other action is required.
>
>
>
>>
>> On Tue, Sep 1, 2009 at 10:43 PM, Chandrasekar Kannan
>> <ckannan(a)redhat.com <mailto:ckannan@redhat.com>> wrote:
>>
>> On 09/01/2009 09:43 AM, Rashmi Pawar wrote:
>>> I want to install all the 6 PKI subsystems for dogtag
>>> implementation,
>>
>> right. yum -y install pki-ca pki-tks pki-tps pki-ra
>> pki-ocsp pki-kra
>> is all you need to do. It will pull in httpd,tomcat5 etc...
>>
>>
>>> do i need to configure apache or secure apache.
>>
>> What is this for ?
>>
>>
>>
>>> Thanks in advance.
>>>
>>>
>>> On Mon, Aug 31, 2009 at 5:53 PM, Chandrasekar Kannan
>>> <ckannan(a)redhat.com <mailto:ckannan@redhat.com>> wrote:
>>>
>>> On 08/31/2009 01:20 AM, Rashmi Pawar wrote:
>>>> Hi Chandrasekar,
>>>> Thank you for your reply.
>>>> One quick question..As you said i dont need to
>>>> install and run Apache if pki-tps and pki-ra
>>>> subsystems are not installed...My question is even
>>>> if i am not installing pki-ra and pki-tps
>>>> subsystems can i still go with apache?
>>>
>>> can u explain what you will use apache for .. in
>>> this case ?..
>>>
>>>> Regards,
>>>> Rashmi Pawar
>>>> On Sun, Aug 30, 2009 at 9:30 PM,
>>>> <pki-users-request(a)redhat.com
>>>> <mailto:pki-users-request@redhat.com>> wrote:
>>>>
>>>> Send Pki-users mailing list submissions to
>>>> pki-users(a)redhat.com <mailto:pki-users@redhat.com>
>>>>
>>>> To subscribe or unsubscribe via the World Wide
>>>> Web, visit
>>>> https://www.redhat.com/mailman/listinfo/pki-users
>>>> or, via email, send a message with subject or
>>>> body 'help' to
>>>> pki-users-request(a)redhat.com
>>>> <mailto:pki-users-request@redhat.com>
>>>>
>>>> You can reach the person managing the list at
>>>> pki-users-owner(a)redhat.com
>>>> <mailto:pki-users-owner@redhat.com>
>>>>
>>>> When replying, please edit your Subject line so
>>>> it is more specific
>>>> than "Re: Contents of Pki-users digest..."
>>>>
>>>>
>>>> Today's Topics:
>>>>
>>>> 1. Dogtag Installation on FC6 (Rashmi Pawar)
>>>> 2. Re: Dogtag Installation on FC6
>>>> (Chandrasekar Kannan)
>>>>
>>>>
>>>> ----------------------------------------------------------------------
>>>>
>>>> Message: 1
>>>> Date: Sun, 30 Aug 2009 13:42:01 +0530
>>>> From: Rashmi Pawar <rashmeepawar(a)gmail.com
>>>> <mailto:rashmeepawar@gmail.com>>
>>>> Subject: [Pki-users] Dogtag Installation on FC6
>>>> To: pki-users(a)redhat.com
>>>> <mailto:pki-users@redhat.com>
>>>> Message-ID:
>>>> <816962df0908300112t6ca5b2at2b79ae587ba32d98(a)mail.gmail.com
>>>> <mailto:816962df0908300112t6ca5b2at2b79ae587ba32d98@mail.gmail.com>>
>>>> Content-Type: text/plain; charset="iso-8859-1"
>>>>
>>>> Hi
>>>>
>>>> I am new to the Dogtag Certificate system. I
>>>> have to install the dogtag
>>>> certificate system on fedora core 6. I would
>>>> appreciate help from pki-users
>>>> who have successfully installed and are runing
>>>> dogtag certificate system on
>>>> linux.
>>>> I read the explanantion on dogtag on
>>>> http://pki.fedoraproject.org/wiki/PKI_Main_Page
>>>> yet I have some questions
>>>> before starting the installation. Following are
>>>> the questions:
>>>>
>>>> 1. Do I have to install and run Apache service
>>>> on the system on which I am
>>>> going to implement dogtag?
>>>> 2. I am confused about the configuration of all
>>>> the PKI subsystems like
>>>> CA,RA,DRM...etc. In the
>>>> http://pki.fedoraproject.org/wiki/PKI_Main_Page the
>>>> configuration of all subsyems is given but I
>>>> dont understand from where do I
>>>> get the configuration URL for each subsystem.
>>>> 3. I have to integrate the setup with
>>>> Checkpoint, so need steps on the
>>>> integration.
>>>>
>>>> I would appreciate if someone who has
>>>> implemented dogtag would provide me
>>>> easy steps to install dogtag on fedora core 6.
>>>>
>>>> Thanks & Regards,
>>>> Rashmi
>>>> -------------- next part --------------
>>>> An HTML attachment was scrubbed...
>>>> URL:
>>>> https://www.redhat.com/archives/pki-users/attachments/20090830/86c17a72/a...
>>>>
>>>> ------------------------------
>>>>
>>>> Message: 2
>>>> Date: Sun, 30 Aug 2009 07:30:03 -0700
>>>> From: Chandrasekar Kannan <ckannan(a)redhat.com
>>>> <mailto:ckannan@redhat.com>>
>>>> Subject: Re: [Pki-users] Dogtag Installation on FC6
>>>> To: Rashmi Pawar <rashmeepawar(a)gmail.com
>>>> <mailto:rashmeepawar@gmail.com>>
>>>> Cc: pki-users(a)redhat.com
>>>> <mailto:pki-users@redhat.com>
>>>> Message-ID: <4A9A8CEB.1080404(a)redhat.com
>>>> <mailto:4A9A8CEB.1080404@redhat.com>>
>>>> Content-Type: text/plain; charset="iso-8859-1"
>>>>
>>>> On 08/30/2009 01:12 AM, Rashmi Pawar wrote:
>>>> > Hi
>>>> > I am new to the Dogtag Certificate system. I
>>>> have to install the
>>>> > dogtag certificate system on fedora core 6. I
>>>> would appreciate help
>>>> > from pki-users who have successfully
>>>> installed and are runing dogtag
>>>> > certificate system on linux.
>>>> > I read the explanantion on dogtag on
>>>> >
>>>> http://pki.fedoraproject.org/wiki/PKI_Main_Page
>>>> yet I have some
>>>> > questions before starting the installation.
>>>> Following are the questions:
>>>> > 1. Do I have to install and run Apache
>>>> service on the system on
>>>> > which I am going to implement dogtag?
>>>>
>>>> not unless you need pki-tps or pki-ra
>>>> subsystems. For pki-ca, pki-tks,
>>>> pki-ocsp, pki-kra you just need tomcat5.
>>>>
>>>> > 2. I am confused about the configuration of
>>>> all the PKI subsystems
>>>> > like CA,RA,DRM...etc. In the
>>>> >
>>>> http://pki.fedoraproject.org/wiki/PKI_Main_Page
>>>> the configuration of
>>>> > all subsyems is given but I dont understand
>>>> from where do I get the
>>>> > configuration URL for each subsystem.
>>>>
>>>> for example, once you run yum install pki-ca,
>>>> the rpm post install
>>>> scripts run /usr/bin/pkicreate utility to
>>>> create the default instance.
>>>> Upon creation of this default instance,
>>>> pkicreate spits out the url for
>>>> configuration.
>>>>
>>>>
>>>> > 3. I have to integrate the setup with
>>>> Checkpoint, so need steps on the
>>>> > integration.
>>>> no idea.
>>>>
>>>> > I would appreciate if someone who has
>>>> implemented dogtag would provide
>>>> > me easy steps to install dogtag on fedora core 6.
>>>> > Thanks & Regards,
>>>> > Rashmi
>>>> >
>>>> ------------------------------------------------------------------------
>>>> >
>>>> > _______________________________________________
>>>> > Pki-users mailing list
>>>> > Pki-users(a)redhat.com
>>>> <mailto:Pki-users@redhat.com>
>>>> > https://www.redhat.com/mailman/listinfo/pki-users
>>>> >
>>>>
>>>> -------------- next part --------------
>>>> An HTML attachment was scrubbed...
>>>> URL:
>>>> https://www.redhat.com/archives/pki-users/attachments/20090830/573d26cb/a...
>>>>
>>>> ------------------------------
>>>>
>>>> _______________________________________________
>>>> Pki-users mailing list
>>>> Pki-users(a)redhat.com <mailto:Pki-users@redhat.com>
>>>> https://www.redhat.com/mailman/listinfo/pki-users
>>>>
>>>>
>>>> End of Pki-users Digest, Vol 18, Issue 6
>>>> ****************************************
>>>>
>>>>
>>>
>>>
>>
>>
>
>
>
15 years, 3 months
Apache for Dogtag
by Rashmi Pawar
Thank you Chandrasekar for your prompt and informative response.
I asked if apache or secure apache is required for dogtag implementation
because at the end of the web page
http://pki.fedoraproject.org/wiki/PKI_Runtime_Environments it has been
mentioned that RA and TPS subsystems require Apache web server,
hence the question as to what all daemons and rpms need to be installed and
configured before starting installing and configuring PKI subsytsems.
On Tue, Sep 1, 2009 at 10:43 PM, Chandrasekar Kannan <ckannan(a)redhat.com>wrote:
> On 09/01/2009 09:43 AM, Rashmi Pawar wrote:
>
>
>
> I want to install all the 6 PKI subsystems for dogtag implementation,
>
>
> right. yum -y install pki-ca pki-tks pki-tps pki-ra pki-ocsp pki-kra
> is all you need to do. It will pull in httpd,tomcat5 etc...
>
> do i need to configure apache or secure apache.
>
>
> What is this for ?
>
>
>
>
> Thanks in advance.
>
>
>
>
> On Mon, Aug 31, 2009 at 5:53 PM, Chandrasekar Kannan <ckannan(a)redhat.com>wrote:
>
>> On 08/31/2009 01:20 AM, Rashmi Pawar wrote:
>>
>> Hi Chandrasekar,
>>
>> Thank you for your reply.
>> One quick question..As you said i dont need to install and run Apache
>> if pki-tps and pki-ra subsystems are not installed...My question is even if
>> i am not installing pki-ra and pki-tps subsystems can i still go with
>> apache?
>>
>>
>> can u explain what you will use apache for .. in this case ?..
>>
>>
>> Regards,
>> Rashmi Pawar
>> On Sun, Aug 30, 2009 at 9:30 PM, <pki-users-request(a)redhat.com> wrote:
>>
>>> Send Pki-users mailing list submissions to
>>> pki-users(a)redhat.com
>>>
>>> To subscribe or unsubscribe via the World Wide Web, visit
>>> https://www.redhat.com/mailman/listinfo/pki-users
>>> or, via email, send a message with subject or body 'help' to
>>> pki-users-request(a)redhat.com
>>>
>>> You can reach the person managing the list at
>>> pki-users-owner(a)redhat.com
>>>
>>> When replying, please edit your Subject line so it is more specific
>>> than "Re: Contents of Pki-users digest..."
>>>
>>>
>>> Today's Topics:
>>>
>>> 1. Dogtag Installation on FC6 (Rashmi Pawar)
>>> 2. Re: Dogtag Installation on FC6 (Chandrasekar Kannan)
>>>
>>>
>>> ----------------------------------------------------------------------
>>>
>>> Message: 1
>>> Date: Sun, 30 Aug 2009 13:42:01 +0530
>>> From: Rashmi Pawar <rashmeepawar(a)gmail.com>
>>> Subject: [Pki-users] Dogtag Installation on FC6
>>> To: pki-users(a)redhat.com
>>> Message-ID:
>>> <816962df0908300112t6ca5b2at2b79ae587ba32d98(a)mail.gmail.com>
>>> Content-Type: text/plain; charset="iso-8859-1"
>>>
>>> Hi
>>>
>>> I am new to the Dogtag Certificate system. I have to install the dogtag
>>> certificate system on fedora core 6. I would appreciate help from
>>> pki-users
>>> who have successfully installed and are runing dogtag certificate system
>>> on
>>> linux.
>>> I read the explanantion on dogtag on
>>> http://pki.fedoraproject.org/wiki/PKI_Main_Page yet I have some
>>> questions
>>> before starting the installation. Following are the questions:
>>>
>>> 1. Do I have to install and run Apache service on the system on which I
>>> am
>>> going to implement dogtag?
>>> 2. I am confused about the configuration of all the PKI subsystems like
>>> CA,RA,DRM...etc. In the http://pki.fedoraproject.org/wiki/PKI_Main_Pagethe
>>> configuration of all subsyems is given but I dont understand from where
>>> do I
>>> get the configuration URL for each subsystem.
>>> 3. I have to integrate the setup with Checkpoint, so need steps on the
>>> integration.
>>>
>>> I would appreciate if someone who has implemented dogtag would provide me
>>> easy steps to install dogtag on fedora core 6.
>>>
>>> Thanks & Regards,
>>> Rashmi
>>> -------------- next part --------------
>>> An HTML attachment was scrubbed...
>>> URL:
>>> https://www.redhat.com/archives/pki-users/attachments/20090830/86c17a72/a...
>>>
>>> ------------------------------
>>>
>>> Message: 2
>>> Date: Sun, 30 Aug 2009 07:30:03 -0700
>>> From: Chandrasekar Kannan <ckannan(a)redhat.com>
>>> Subject: Re: [Pki-users] Dogtag Installation on FC6
>>> To: Rashmi Pawar <rashmeepawar(a)gmail.com>
>>> Cc: pki-users(a)redhat.com
>>> Message-ID: <4A9A8CEB.1080404(a)redhat.com>
>>> Content-Type: text/plain; charset="iso-8859-1"
>>>
>>> On 08/30/2009 01:12 AM, Rashmi Pawar wrote:
>>> > Hi
>>> > I am new to the Dogtag Certificate system. I have to install the
>>> > dogtag certificate system on fedora core 6. I would appreciate help
>>> > from pki-users who have successfully installed and are runing dogtag
>>> > certificate system on linux.
>>> > I read the explanantion on dogtag on
>>> > http://pki.fedoraproject.org/wiki/PKI_Main_Page yet I have some
>>> > questions before starting the installation. Following are the
>>> questions:
>>> > 1. Do I have to install and run Apache service on the system on
>>> > which I am going to implement dogtag?
>>>
>>> not unless you need pki-tps or pki-ra subsystems. For pki-ca, pki-tks,
>>> pki-ocsp, pki-kra you just need tomcat5.
>>>
>>> > 2. I am confused about the configuration of all the PKI subsystems
>>> > like CA,RA,DRM...etc. In the
>>> > http://pki.fedoraproject.org/wiki/PKI_Main_Page the configuration of
>>> > all subsyems is given but I dont understand from where do I get the
>>> > configuration URL for each subsystem.
>>>
>>> for example, once you run yum install pki-ca, the rpm post install
>>> scripts run /usr/bin/pkicreate utility to create the default instance.
>>> Upon creation of this default instance, pkicreate spits out the url for
>>> configuration.
>>>
>>>
>>> > 3. I have to integrate the setup with Checkpoint, so need steps on the
>>> > integration.
>>> no idea.
>>>
>>> > I would appreciate if someone who has implemented dogtag would provide
>>> > me easy steps to install dogtag on fedora core 6.
>>> > Thanks & Regards,
>>> > Rashmi
>>> >
>>> ------------------------------------------------------------------------
>>> >
>>> > _______________________________________________
>>> > Pki-users mailing list
>>> > Pki-users(a)redhat.com
>>> > https://www.redhat.com/mailman/listinfo/pki-users
>>> >
>>>
>>> -------------- next part --------------
>>> An HTML attachment was scrubbed...
>>> URL:
>>> https://www.redhat.com/archives/pki-users/attachments/20090830/573d26cb/a...
>>>
>>> ------------------------------
>>>
>>> _______________________________________________
>>> Pki-users mailing list
>>> Pki-users(a)redhat.com
>>> https://www.redhat.com/mailman/listinfo/pki-users
>>>
>>>
>>> End of Pki-users Digest, Vol 18, Issue 6
>>> ****************************************
>>>
>>
>>
>>
>
>
15 years, 3 months