Hi, The cert.db and key.db file seems to be corrupted. In GUI, we can see 3 certificates, one is cloned, one is valid. The "detail" option does not work on the cloned one, whith a failure message. We tried to manipulate db with certutil : certutil -L -d ...... Certificate Name Trust Attributes server-cert u,, IRDNEW u,pu,u IRDNEW u,pu,u IRD - IRD CT,, p Valid peer P Trusted peer (implies p) c Valid CA T Trusted CA to issue client certs (implies c) C Trusted CA to certs(only server certs for ssl) (implies c) u User cert w Send warning We tried to delete the cloned one but, here is an new error message : certutil: could not find certificate named "IRDNEW": security library: bad database. What is the pb ? BR, -- =========================================Emmanuel BILLOT IRD - Orléans Délégation aux Systèmes d''Information (DSI) tél : 02 38 49 95 88 ==========================================
Emmanuel BILLOT wrote:> Hi, > > The cert.db and key.db file seems to be corrupted. > In GUI, we can see 3 certificates, one is cloned, one is valid. The > "detail" option does not work on the cloned one, whith a failure message. > > We tried to manipulate db with certutil : > > certutil -L -d ...... > Certificate Name Trust > Attributes > > server-cert u,, > IRDNEW u,pu,u > IRDNEW u,pu,u > IRD - IRD CT,, > > p Valid peer > P Trusted peer (implies p) > c Valid CA > T Trusted CA to issue client certs (implies c) > C Trusted CA to certs(only server certs for ssl) (implies c) > u User cert > w Send warning > > > We tried to delete the cloned one but, here is an new error message : > > certutil: could not find certificate named "IRDNEW": security library: > bad database. > > What is the pb ?Can you post the exact certutil command line you''re using?> > BR, >
Rich Megginson a écrit :> Emmanuel BILLOT wrote: >> Hi, >> >> The cert.db and key.db file seems to be corrupted. >> In GUI, we can see 3 certificates, one is cloned, one is valid. The >> "detail" option does not work on the cloned one, whith a failure >> message. >> >> We tried to manipulate db with certutil : >> >> certutil -L -d ...... >> Certificate Name Trust >> Attributes >> >> server-cert u,, >> IRDNEW u,pu,u >> IRDNEW u,pu,u >> IRD - IRD CT,, >> >> p Valid peer >> P Trusted peer (implies p) >> c Valid CA >> T Trusted CA to issue client certs (implies c) >> C Trusted CA to certs(only server certs for ssl) (implies c) >> u User cert >> w Send warning >> >> >> We tried to delete the cloned one but, here is an new error message : >> >> certutil: could not find certificate named "IRDNEW": security >> library: bad database. >> >> What is the pb ? > Can you post the exact certutil command line you''re using? >>certutil -L -d /etc/dirsrv/slapd-xxx -P slapd-xxx- for certs database listing (give a "ggod" result) certutil -D -d /etc/dirsrv/slapd-xxx -P slapd-xxx- "IRDNEW" for deleting a cert instance cert are p12 file generated with openssl. The only way we found was deleting/recreating the database with cert sources. BR,>> BR, >> > > ------------------------------------------------------------------------ > > -- > Fedora-directory-users mailing list > Fedora-directory-users@redhat.com > https://www.redhat.com/mailman/listinfo/fedora-directory-users >-- =========================================Emmanuel BILLOT IRD - Orléans Délégation aux Systèmes d''Information (DSI) tél : 02 38 49 95 88 ==========================================