Print

Print


Hi John,

I am trying to get the email adress in the hostcert removed, that's what the whole threat is about.
I have an old certificate (in use, hence no revoking) and I am trying to get a new one (sans email address). So I can't renew (keeps the email address) and I cannot ask for a new one, because certwizard/pecr/webpage (I've tried all three now), complain (correctly) that I already have a valid hostcert for the machine in question.
I've tried it with sedsk15.grid.hep.ph.ic.ac.uk.
As Jens mentioned, I don't think certwizard is the best tool to renew/request certificates in bulk, typing in 40+ hostnames is asking for trouble.
I am the RA, so if I revoke a cert, will that not be automatically approved ?

Cheers,
Daniela




On 26 March 2013 15:08, John Kewley <[log in to unmask]> wrote:
> I just tried the cert wizard, with the same result: cannot get a new cert, the old one exists.

If we are to work out what is going on then we need a few more details. What I have stated several times on this forum is how it should work so if it doesn't then we need to be able to work out what the bugs are.

Answers to some or all of the following may help:
* Why do you want a new certificate when an old one already exists?
* Do you have possession of the old one and is it in use?
* Is it to remove an emailAddress from the DN? If not, why can't you renew?
* What is the certificate number you are using?

> It doesn't recognise it as a new DN.
> So I am relying on a revocation not being approved (I guess it would have to come
> from someone who is not me as I am the RA) and hope I can get
> the new cert before this filters through the system.

If you say to your RA Op - "Please don't approve this request" then you are relying on him/her to adhere to your requests in the same way as when applying for a renewal you are relying on him/her to approve it before your old one expires - I don't see this is an issue, unless you have reasons to be distrustful of your RA's RA Ops.

There is nothing to filter through the system - it will sit there forever if the request isn't approved.

> Some small bit in my mind wants to scream.

I feel I am repeating myself as well, so let's see if we can get some info on why it isn't working

JK
--
Scanned by iCritical.



--
Sent from the pit of despair

-----------------------------------------------------------
[log in to unmask]
HEP Group/Physics Dep
Imperial College
Tel: +44-(0)20-75947810
http://www.hep.ph.ic.ac.uk/~dbauer/