Tiago,

You will need to import the KRA Transport Cert into the CA's nssdb.  Then configure the CS.cfg with the nickname used for SS Keygen.

https://www.dogtagpki.org/wiki/PKI_10.9_Server-side_Keygen_Enrollment_for_EE

Hope that helps,

Chris Zinda

Senior Platform Technical Account Manager 

Red Hat

Global Customer Success

czinda@redhat.com     T: 212.510.4102     M: 717.360.1923    

Partnering with you to help achieve your business goals




On Mon, Jun 14, 2021 at 1:37 PM Tiago Magalhães <leopardpresis@gmail.com> wrote:
Hi, I installed ca and kra in the same tomcat instance, but when I try to enroll a certificate using server-side Key generation, the following message appears: "KRA Transport Certificate needs to be imported into the CA nssdb for Server-Side Kegen Enrollment". Do you know how I can i fix this?

Thanks for your attention
_______________________________________________
Pki-users mailing list -- users@lists.dogtagpki.org
To unsubscribe send an email to users-leave@lists.dogtagpki.org
%(web_page_url)slistinfo%(cgiext)s/%(_internal_name)s