LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 06-11-2003, 03:32 AM   #1
mantat
LQ Newbie
 
Registered: Jun 2003
Distribution: RedHat8.0
Posts: 12

Rep: Reputation: 0
question about OpenSSL


Hello,

after i have created a digital certificate (.p12 format) using OpenSSL and import the cert into MS outlook express,
when i clicked the signed/encrypt button and sent the mail,
it was not prompt to ask me to type the password(private key),
the purpose and the function of using signed mail is vanished...

i have made a search from Microsoft web site about how to make it prompt for the password before sending the signed/encrypted mail, i found the following messages:

"When you obtain a certificate (or digital ID) from a public certification authority (CA) such as VeriSign, you can request additional security to protect your private key (or digital ID). If you request additional security to protect your private key, you are prompted for a password when you send a digitally signed message. If you do not type your private key password but instead click Cancel, your private key is not used to digitally sign the message when it is sent, and the message is sent unsigned. "


anybody know how to generate the cert using OpenSSL so that it will prompt me to type the password?
or, how to set it in Outlook express or Netscape/mozilla??

Thanks a lot.
 
Old 06-11-2003, 02:19 PM   #2
nxny
Member
 
Registered: May 2002
Location: AK - The last frontier.
Distribution: Red Hat 8.0, Slackware 8.1, Knoppix 3.7, Lunar 1.3, Sorcerer
Posts: 771

Rep: Reputation: 30
Are you sure that your gave your certificate a password during creation?

The following URL may help:
http://www.fz-juelich.de/zam/unicore...rtificates.htm
 
Old 06-11-2003, 08:06 PM   #3
mantat
LQ Newbie
 
Registered: Jun 2003
Distribution: RedHat8.0
Posts: 12

Original Poster
Rep: Reputation: 0
You mean given the password while creating the .p12 cert with
the "-password pass:MyUserPass" parameter??
yes, i haven't, can password be type in interactive mode instead of typing it inline?
 
Old 06-11-2003, 08:45 PM   #4
nxny
Member
 
Registered: May 2002
Location: AK - The last frontier.
Distribution: Red Hat 8.0, Slackware 8.1, Knoppix 3.7, Lunar 1.3, Sorcerer
Posts: 771

Rep: Reputation: 30
Try it, it wont hurt. If not, you can always exit the shell, log back in and delete the specific command from ~/.bash_history .
 
Old 06-11-2003, 09:33 PM   #5
mantat
LQ Newbie
 
Registered: Jun 2003
Distribution: RedHat8.0
Posts: 12

Original Poster
Rep: Reputation: 0
But i need to generate certs for my colleagues, for internal use only.
For security issue, it is impossible to see the other's passphase.
 
Old 06-12-2003, 07:23 PM   #6
nxny
Member
 
Registered: May 2002
Location: AK - The last frontier.
Distribution: Red Hat 8.0, Slackware 8.1, Knoppix 3.7, Lunar 1.3, Sorcerer
Posts: 771

Rep: Reputation: 30
And you can't let them create their own certs with their own passphrases because you dont want them to have access to your priv pem file? How many colleagues are we talking about?
 
Old 06-12-2003, 08:11 PM   #7
mantat
LQ Newbie
 
Registered: Jun 2003
Distribution: RedHat8.0
Posts: 12

Original Poster
Rep: Reputation: 0
Around 50+ peoples..
they don't know the password of the CA,
I will let them key in there private key while generating the cert request, and while generating the .p12 file,
i will ask them to type their key again, at the same time,
i hope them to key in the password for the certificate,
but no one should see the plain text of what they are typing, including me.
 
Old 06-12-2003, 09:06 PM   #8
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Maybe a little "expect" scripting could help, else you gotta type in your CA passwd +50 times...
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Openssl velan Programming 1 05-16-2005 12:28 AM
OpenSSL question depdiver Linux - Security 1 03-28-2005 04:15 PM
OpenSSL Chiel Linux - Newbie 1 09-03-2004 04:52 PM
OpenSSL 0.9.6k kojiroh Solaris / OpenSolaris 2 10-09-2003 10:51 AM
Question about openssl update ?? chuck77 Linux - General 3 11-21-2002 04:11 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:21 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration