Giter Site home page Giter Site logo

Comments (9)

petkivim avatar petkivim commented on May 19, 2024 1

Hi @bmalila

What does your Security Server's diagnostics view say? If it shows red for the OCSP responder, please take a look at the /var/log/xroad/signer.log log file.

You can also try to empty the OCSP cache by following these instructions.

Regards,
Petteri

from x-road.

AWfaw avatar AWfaw commented on May 19, 2024 1

@petkivim

I checked twice the keys. It seems like something was wrong with AUTH key. I deleted a key and generated a new one. At the following moment it works.

from x-road.

AWfaw avatar AWfaw commented on May 19, 2024

Hi @petkivim

Yes your are right, The OCSP responder is read and shows that test-ca.lxd:8888 is unable to connect to the OSCP responder. Also the time-stamping is read with message that test-ca:lxd:8899 having the internal error.

from x-road.

petkivim avatar petkivim commented on May 19, 2024

Hi @AWfaw

That explains the problem. Have you tried to restart the test-ca container and/ or OCSP + TSA services running inside of it? Instructions for restarting the services can be found at:

https://github.com/nordic-institute/X-Road/blob/develop/ansible/TESTCA.md#4-restart-nginx-ocsp-and-tsa-services

Regards,
Petteri

from x-road.

petkivim avatar petkivim commented on May 19, 2024

If restarting the container or the services does not help, try to use the internal IP address of the test-ca container in the X-Road configuration instead of test-ca.lxd DNS name. Please note, that after updating the TSA URL on the Central Server, you must first remove the TSA configuration on the Security Server and then add the TSA again to apply the new TSA URL.

from x-road.

AWfaw avatar AWfaw commented on May 19, 2024

@petkivim
Thanks, yours second recommendation helped me lot. Right now the OCSP response from SIGN has a status "good" and AUTH in status "registration in progress"

from x-road.

petkivim avatar petkivim commented on May 19, 2024

@AWfaw
That's great! Next you must complete the steps described in section 3.6:

https://confluence.niis.org/pages/viewpage.action?pageId=6783483#HowtoConfigureCentralServer?-3.6Registeringtheauthenticationcertificate

Please note, that some of the steps must be completed on the Central Server, not on the Security Server.

from x-road.

AWfaw avatar AWfaw commented on May 19, 2024

@petkivim

Okay, I'm in the central server. The AUTH key had been added to the "Owned Servers", but if I going to the "management requests" the certificate registration has a status "waiting" not "submitted or approved".

from x-road.

petkivim avatar petkivim commented on May 19, 2024

@AWfaw

Are there one or two requests in the management requests queue on the Central Server? And are you sure that you imported the auth certificate (not sign certificate or auth key - as you wrote above)?

from x-road.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.