LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-28-2017, 12:46 AM   #1
sario120
LQ Newbie
 
Registered: Mar 2013
Location: Karachi
Distribution: CentOS, Fedora, Ubuntu
Posts: 5
Blog Entries: 1

Rep: Reputation: Disabled
Question Signing CSR which is in PKCS10 using Openssl tool in CentOS-7


I have created my own CA in CentOS 7.

I need to sign digital certificates. I have signed SSL certs which working fine in CentOS webservers apache and nginx.

Now I need to sign a CSR which is in pkcs10 format generated from Oracle Wallet Manager for at Oracle 11 g Server. When export OWM csr to my CentOS CA, it is not being signed using openssl tool. it gives error private key not matched.

I don't get which arguments and options to use with openssl to sign pkcs10 csr. Need your help to get it done.
 
Old 08-29-2017, 07:12 AM   #2
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,679
Blog Entries: 4

Rep: Reputation: 3947Reputation: 3947Reputation: 3947Reputation: 3947Reputation: 3947Reputation: 3947Reputation: 3947Reputation: 3947Reputation: 3947Reputation: 3947Reputation: 3947
Please post the commands that you are using, and the verbatim text of the error-messages you are receiving.

Also, check the first few lines of each certificate file ... the first line is usually English descriptive text ... and show us a copy of, say, the first two lines of the file and tell us its total file-size in bytes.

Of course, do not post complete certificates, actual pass-phrases (if any), nor anything else that could be considered compromising. Just enough to let us see for ourselves, in detail, what you are actually trying to do.
 
Old 08-29-2017, 07:17 AM   #3
sario120
LQ Newbie
 
Registered: Mar 2013
Location: Karachi
Distribution: CentOS, Fedora, Ubuntu
Posts: 5

Original Poster
Blog Entries: 1

Rep: Reputation: Disabled
Quote:
Originally Posted by sundialsvcs View Post
Please post the commands that you are using, and the verbatim text of the error-messages you are receiving.

Also, check the first few lines of each certificate file ... the first line is usually English descriptive text ... and show us a copy of, say, the first two lines of the file and tell us its total file-size in bytes.

Of course, do not post complete certificates, actual pass-phrases (if any), nor anything else that could be considered compromising. Just enough to let us see for ourselves, in detail, what you are actually trying to do.
This is the command and outpu of it.
openssl ca -config openssl.cnf -extensions usr_cert -days 375 -notext -md md5 -in owm.csr -out ca/intermediate/certs/owm.cert
Using configuration from ca/intermediate/openssl.cnf
Enter pass phrase for intermediate.key.pem:
Check that the request matches the signature
Signature verification problems....

Last edited by sario120; 08-29-2017 at 07:18 AM.
 
  


Reply

Tags
centos7, openssh, oracle11g, security, ssl authentication



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
OpenSSL: Send CSR to server programatically zvivered Linux - Security 1 11-20-2016 12:09 PM
How to remove Openssl in CentOS 6.5? nkcedwin Linux - Newbie 7 01-20-2016 11:26 PM
[SOLVED] OpenSSL: Signing Client Certificate - Help Needed peridian Linux - Security 2 02-20-2011 07:32 AM
Downgrading openssl on Centos onesikgypo Linux - Newbie 2 09-27-2010 08:51 PM
Use Openssl to do signing and verification johnny.lee Programming 0 02-18-2004 09:30 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:15 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration