Return-Path: <oracle-l-bounce@freelists.org>
Delivered-To: 2-oracle-l@orafaq.com
Received: (qmail 3183 invoked from network); 17 Dec 2007 13:58:58 -0600
Received: from freelists-180.iquest.net (HELO turing.freelists.org) (206.53.239.180)
  by static-ip-69-64-49-119.inaddr.intergenia.de with SMTP; 17 Dec 2007 13:58:54 -0600
Received: from localhost (localhost [127.0.0.1])
 by turing.freelists.org (Avenir Technologies Mail Multiplex) with ESMTP id D70667DAA93;
 Mon, 17 Dec 2007 14:58:48 -0500 (EST)
Received: from turing.freelists.org ([127.0.0.1])
 by localhost (turing.freelists.org [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id 26377-01; Mon, 17 Dec 2007 14:58:48 -0500 (EST)
Received: from turing (localhost [127.0.0.1])
 by turing.freelists.org (Avenir Technologies Mail Multiplex) with ESMTP id 474427DA9B8;
 Mon, 17 Dec 2007 14:58:48 -0500 (EST)
Received: with ECARTIS (v1.0.0; list oracle-l); Mon, 17 Dec 2007 14:11:23 -0500 (EST)
Received: from localhost (localhost [127.0.0.1])
 by turing.freelists.org (Avenir Technologies Mail Multiplex) with ESMTP id 80F197DAA97
 for <oracle-l@freelists.org>; Mon, 17 Dec 2007 14:11:23 -0500 (EST)
Received: from turing.freelists.org ([127.0.0.1])
 by localhost (turing.freelists.org [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id 19021-02 for <oracle-l@freelists.org>;
 Mon, 17 Dec 2007 14:11:23 -0500 (EST)
Received: from wr-out-0506.google.com (wr-out-0506.google.com [64.233.184.238])
 by turing.freelists.org (Avenir Technologies Mail Multiplex) with ESMTP id 64D167DAB75
 for <oracle-l@freelists.org>; Mon, 17 Dec 2007 14:11:20 -0500 (EST)
Received: by wr-out-0506.google.com with SMTP id c49so1341039wra.1
        for <oracle-l@freelists.org>; Mon, 17 Dec 2007 11:11:20 -0800 (PST)
Received: by 10.142.52.9 with SMTP id z9mr938389wfz.134.1197918678067;
        Mon, 17 Dec 2007 11:11:18 -0800 (PST)
Received: by 10.142.81.20 with HTTP; Mon, 17 Dec 2007 11:11:18 -0800 (PST)
Message-ID: <b32e774d0712171111u12ed8c09yfe67a5aea54b19dd@mail.gmail.com>
Date: Mon, 17 Dec 2007 13:11:18 -0600
From: "Jason Heinrich" <jheinrichdba@gmail.com>
To: mkb <mkb125@yahoo.com>, "Hameed, Amir" <Amir.Hameed@xerox.com>
Subject: Re: Renewing an SSL certificate in Advanced Security
Cc: oracle-l <oracle-l@freelists.org>
In-Reply-To: <500554.83063.qm@web58007.mail.re3.yahoo.com>
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="----=_Part_14383_3097700.1197918678044"
References: <500554.83063.qm@web58007.mail.re3.yahoo.com>
X-Google-Sender-Auth: b76ee615f1b24f15
X-archive-position: 3981
X-ecartis-version: Ecartis v1.0.0
Sender: oracle-l-bounce@freelists.org
Errors-to: oracle-l-bounce@freelists.org
X-original-sender: jheinrichdba@gmail.com
Precedence: normal
Reply-to: jheinrichdba@gmail.com
List-help: <mailto:ecartis@freelists.org?Subject=help>
List-unsubscribe: <oracle-l-request@freelists.org?Subject=unsubscribe>
List-software: Ecartis version 1.0.0
List-Id: oracle-l <oracle-l.freelists.org>
X-List-ID: oracle-l <oracle-l.freelists.org>
List-subscribe: <oracle-l-request@freelists.org?Subject=subscribe>
List-owner: <mailto:steve.adams@ixora.com.au>
List-post: <mailto:oracle-l@freelists.org>
List-archive: <http://www.freelists.org/archives/oracle-l>
X-list: oracle-l
X-Virus-Scanned: Debian amavisd-new at localhost.localdomain
------=_Part_14383_3097700.1197918678044
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

I found the Metalink document that describes the "official" way to renew a
certificate (303299.1).  Basically you export a CSR for your existing
certificate, get it signed, delete the old certificate (which leaves the CSR
behind), and import the new certificate.  Of course, this all requires OWM,
as orapki doesn't provide a way to remove certificates.  Obviously this
would be an inconvenience if X wasn't installed on the server.

I've submitted an SR, so we'll see what Oracle says.

On 12/14/07, mkb <mkb125@yahoo.com> wrote:
>
> ----- Original Message ----
> From: Jason Heinrich <jheinrichdba@gmail.com>
> To: mkb <mkb125@yahoo.com>
> Cc: oracle-l <oracle-l@freelists.org>
> Sent: Friday, December 14, 2007 5:17:55 PM
> Subject: Re: Renewing an SSL certificate in Advanced Security
>
> Yes, I have the initial certificate installed via orapki, and SSL works
> beautifully.  It's obtaining a new certificate when the original expires
> that I'm having trouble with.  I tried the process with OWM as you
> suggested, and that seemed to work.  It seems that orapki was something of
> an afterthought to Oracle.  It's too bad: I really wanted to script the
> whole process, but this is the second activity I've run into that requires
> OWM (the first was removing unused trusted certificates).  Unless, as Amir
> suggested, I create a new wallet and replace the old one.
>
> On 12/14/07, mkb <mkb125@yahoo.com> wrote:
> >
> > I'm not sure I quite follow.  I assume you generated a certificate
> > request (something like this perhaps? orapki wallet add -wallet
> > wallet_location -dn user_dn -keySize 512|1024|2048)
> >
> > Then you exported the certificate request and got it signed from your
> > CA, right?
> >
> > You should have gotten back a root certificate from your CA and a signed
> > user certificate.  The root cert would have been imported into the wallet
> > with something like this:
> > orapki wallet add -wallet . -trusted_cert -cert cacert.pem
> >
> > The signed user certificate would have been imported into the wallet
> > using something like this:
> > orapki wallet add -wallet . -user_cert -cert newcert.pem
> >
> > If you want to create a new signed user certificate, you will need to
> > create a user certificate request, export the request and then submit it to
> > the CA and get it signed.  Once it is signed, you only need to import the
> > user signed certificate and not the root chain (assuming you got it signed
> > from the same CA).
> >
> > I think I had some problems with the orapki utility when trying to
> > import certs but when I used the GUI it seemed to work fine.  You might try
> > using the GUI first (owm) and see if that solves the problem.
> >
> > --
> > mohammed
> >
> >
> > You then created a certificate request
> >
> > ------------------------------
> > Be a better friend, newshound, and know-it-all with Yahoo! Mobile. Try
> > it now.<http://us.rd.yahoo.com/evt=51733/*http://mobile.yahoo.com/;_ylt=Ahu06i62sR8HDtDypao8Wcj9tAcJ+>
> >
>
> Ok, so that basically confirms it for me also that the orapki utility is
> half-baked.  I also was going in the same direction that you were (wanting
> it to script it out), but I guess that's not going to be the case until
> Oracle fixes it.
>
> Time to open a ticket on this one I suppose.
>
> --
> mohammed
>
> ------------------------------
> Be a better friend, newshound, and know-it-all with Yahoo! Mobile. Try it
> now.<http://us.rd.yahoo.com/evt=51733/*http://mobile.yahoo.com/;_ylt=Ahu06i62sR8HDtDypao8Wcj9tAcJ+>
>



-- 
Jason Heinrich

------=_Part_14383_3097700.1197918678044
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

I found the Metalink document that describes the &quot;official&quot; way to renew a certificate (<font size="2">303299.1).&nbsp; Basically you export a CSR for your existing certificate, get it signed, delete the old certificate (which leaves the CSR behind), and import the new certificate.&nbsp; Of course, this all requires OWM, as orapki doesn&#39;t provide a way to remove certificates.&nbsp; Obviously this would be an inconvenience if X wasn&#39;t installed on the server.
<br><br>I&#39;ve submitted an SR, so we&#39;ll see what Oracle says.<br></font><br><div><span class="gmail_quote">On 12/14/07, <b class="gmail_sendername">mkb</b> &lt;<a href="mailto:mkb125@yahoo.com">mkb125@yahoo.com</a>
&gt; wrote:</span><blockquote class="gmail_quote" style="border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;"><div><div style="font-family: times new roman,new york,times,serif; font-size: 12pt;">
<div style="font-family: times new roman,new york,times,serif; font-size: 12pt;">----- Original Message ----<br><div style="font-family: times new roman,new york,times,serif; font-size: 12pt;"><span class="q">From: Jason Heinrich &lt;
<a href="mailto:jheinrichdba@gmail.com" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">jheinrichdba@gmail.com</a>&gt;<br></span><div><span class="e" id="q_116dac45fa160d5a_2">To: mkb &lt;<a href="mailto:mkb125@yahoo.com" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">
mkb125@yahoo.com</a>&gt;<br>Cc: oracle-l &lt;<a href="mailto:oracle-l@freelists.org" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">oracle-l@freelists.org</a>&gt;<br>Sent: Friday, December 14, 2007 5:17:55 PM
<br>Subject: Re: Renewing an SSL certificate in Advanced Security<br><br>
Yes, I have the initial certificate installed via orapki, and SSL works beautifully.&nbsp; It&#39;s obtaining a new certificate when the original expires that I&#39;m having trouble with.&nbsp; I tried the process with OWM as you suggested, and that seemed to work.&nbsp; It seems that orapki was something of an afterthought to Oracle.&nbsp; It&#39;s too bad: I really wanted to script the whole process, but this is the second activity I&#39;ve run into that requires OWM (the first was removing unused trusted certificates).&nbsp; Unless, as Amir suggested, I create a new wallet and replace the old one.
<br><br><div><span class="gmail_quote">On 12/14/07, <b class="gmail_sendername">mkb</b> &lt;<a rel="nofollow" href="mailto:mkb125@yahoo.com" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">mkb125@yahoo.com
</a>&gt; wrote:</span><blockquote class="gmail_quote" style="border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">
<div><div style="font-family: times new roman,new york,times,serif; font-size: 12pt;"><div style="font-family: times new roman,new york,times,serif; font-size: 12pt;"><span></span>I&#39;m not sure I quite follow.&nbsp; I assume you generated a certificate request (something like this perhaps? orapki wallet add -wallet wallet_location -dn user_dn -keySize 512|1024|2048)
<br><br>Then you exported the certificate request and got it signed from your CA, right?<br><br>You should have gotten back a root certificate from your CA and a signed user certificate.&nbsp; The root cert would have been imported into the wallet with something like this:
<br>orapki wallet add -wallet . -trusted_cert -cert cacert.pem<br><br>The signed user certificate would have been imported into the wallet using something like this:<br>orapki wallet add -wallet . -user_cert -cert newcert.pem

<br><br>If you want to create a new signed user certificate, you will need to create a user certificate request, export the request and then submit it to the CA and get it signed.&nbsp; Once it is signed, you only need to import the
 user signed certificate and not the root chain (assuming you got it signed from the same CA).&nbsp; <br><br>I think I had some problems with the orapki utility when trying to import certs but when I used the GUI it seemed to work fine.&nbsp; You might try using the GUI first (owm) and see if that solves the problem.
<br><span><br>--<br>mohammed<br><br><br>You then created a certificate request<br></span></div></div><span><br>
      <hr size="1">Be a better friend, newshound, and 
know-it-all with Yahoo! Mobile. <a rel="nofollow" href="http://us.rd.yahoo.com/evt=51733/*http://mobile.yahoo.com/;_ylt=Ahu06i62sR8HDtDypao8Wcj9tAcJ+" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">
 Try it now.</a>
</span></div></blockquote></div><br></span></div></div>Ok, so that basically confirms it for me also that the orapki utility is half-baked.&nbsp; I also was going in the same direction that you were (wanting it to script it out), but I guess that&#39;s not going to be the case until Oracle fixes it.
<br><br>Time to open a ticket on this one I suppose.<br><span class="sg"><br>--<br>mohammed<br></span></div></div><span class="q"><br>
      <hr size="1">Be a better friend, newshound, and 
know-it-all with Yahoo! Mobile. <a href="http://us.rd.yahoo.com/evt=51733/*http://mobile.yahoo.com/;_ylt=Ahu06i62sR8HDtDypao8Wcj9tAcJ+" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)"> Try it now.</a>
</span></div></blockquote></div><br><br clear="all"><br>-- <br>Jason Heinrich

------=_Part_14383_3097700.1197918678044--
--
http://www.freelists.org/webpage/oracle-l


