[AG-TECH] Certificates

Randy Groves randy.groves at boeing.com
Thu Aug 28 12:29:39 CDT 2003


Actually, it's just an educated guess, based on no real hard evidence.  I 
am extrapolating from your note where you said that the cert request 
process makes a connection to your public web server.  Since I haven't 
re-run this and don't have the error message (which I remember as being 
very general), I don't have any more info that I can supply.  If I get a 
chance, I'll try to run a cert request from one of my machines and pay 
attention to the errors.

-randy

At 12:22 PM 8/28/2003 -0500, Ivan R. Judson wrote:

>We have anticipated this and are working on the mechanism by which you can
>specify your cert req service instead of ours. We believe this will be
>important moving ahead as well.
>
>--Ivan
>
>PS -- web proxy? How'd you identify that as the problem? I didn't know that
>part! :-)
>
> > -----Original Message-----
> > From: owner-ag-tech at mcs.anl.gov
> > [mailto:owner-ag-tech at mcs.anl.gov] On Behalf Of Randy Groves
> > Sent: Thursday, August 28, 2003 11:49 AM
> > To: ag-tech at mcs.anl.gov
> > Subject: Re: [AG-TECH] Certificates
> >
> >
> > I put in a bug report on this - there is a problem for people
> > like myself
> > who are behind a web proxy.  The certificate request process
> > makes the
> > assumption that there is a clear shot to the web server.
> >
> > Obviously, you folks aren't going to be in the request
> > business in the long
> > term, so the whole certificate request mechanism needs to be
> > tweaked.  And
> > in my case (and I haven't started looking at the code yet), I
> > would want to
> > hook this into our established request process.  It would be
> > nice if there
> > were hooks for that.
> >
> > -randy
> >
> > At 11:03 AM 8/28/2003 -0500, Thomas D. Uram wrote:
> > >Hi George:
> > >
> > >I know I signed one of your requests over the past couple
> > days.  If you
> > >start the CertificateRequestTool again, it should show you
> > the status of
> > >your certificate requests, and allow you to import the resulting
> > >certificate(s).  If you have any problems with this process,
> > please do let
> > >us know.
> > >
> > >As for verisign:  The transitional venue server is not supporting
> > >certificates issued by verisign at this time, so that is not
> > recommended.
> > >
> > >Tom
> > >
> > >
> > >Glover George wrote:
> > >>
> > >>Am I doing something wrong?  I have sent two requests for
> > certificates
> > >>and still havent heard a thing back on either one over the
> > past couple
> > >>weeks.  I just used the Request Certificate item in the
> > AGTk.  Should I
> > >>just get my own through verisign?
> >
> >
> >






More information about the ag-tech mailing list