View Single Post
Posts: 48 | Thanked: 191 times | Joined on Jan 2016 @ Münsterland, Germany
#3
Thank's for your answer. I'll give it a shot later.

Originally Posted by peterleinchen View Post
short answer:
--edit
you might do it in as root with devel-su
AND possibly in "develsh" (giving some more rights), as I do not expect you to run that device in OpenMode?
I'm running the device in OpenMode


Edit 1:
I tried without success
Code:
# acmcli -C aegis-certman-common-ca::CertCACommonAdd -lc common-ca -a 16b5321bd4c7f3e0e68ef3bdd2b03aeeb23918d1.pem

ERROR: cannot add certificates (Permission denied)

# acmcli -c common-ca -a 16b5321bd4c7f3e0e68ef3bdd2b03aeeb23918d1.pem

ERROR: cannot add certificates (Permission denied)




Edit 2: So this happens in the log:

Code:
Jan 20 21:02:57 (2016) acmcli: aegis_storage.cpp(1436): ERROR add_file: access denied
Jan 20 21:02:57 (2016) acmcli: aegis_storage.cpp(1641): ERROR add_link: access denied
Jan 20 21:02:57 (2016) acmcli: aegis_storage.cpp(1935): ERROR commit: access denied, cannot commit '/var/lib/aegis/ps/Gs/certman.common-ca'
Jan 20 21:02:57 (2016) acmcli: certman_main.cpp(1051): ERROR aegis_certman_add_certs: add certs failed (Permission denied)


Now created a "private" common-ca and removed it again, which worked...
Code:
# /usr/bin/acmcli -p common-ca -a 16b5321bd4c7f3e0e68ef3bdd2b03aeeb23918d1.pem
Added 1 certificates

# /usr/bin/acmcli -p common-ca -r 16b5321bd4c7f3e0e68ef3bdd2b03aeeb23918d1
Removed certificate '16b5321bd4c7f3e0e68ef3bdd2b03aeeb23918d1'
Now I'm out of Ideas...

Edit 3:
Installed Inception from openrepos.
Code:
/usr/sbin/pasiv
ariadne /usr/bin/acmcli -c common-ca -a 16b5321bd4c7f3e0e68ef3bdd2b03aeeb23918d1.pem
Password for 'root': 
Added 1 certificates
Well that's a start.

The log complained about a bunch of broken Certs
Code:
Jan 20 21:46:26 (2016) acmcli: certman_main.cpp(184): ERROR Invalid certificate '/C=ES/L=C/ Muntaner 244 Barcelona/CN=Autoridad de Certificacion Firmaprofesional CIF A62634068/emailA
ddress=ca@firmaprofesional.com'
Jan 20 21:46:26 (2016) acmcli: certman_main.cpp(184): ERROR Invalid certificate '/C=NO/O=Buypass AS-983163327/CN=Buypass Class 3 CA 1'
Jan 20 21:46:26 (2016) acmcli: certman_main.cpp(184): ERROR Invalid certificate '/C=NL/O=Staat der Nederlanden/CN=Staat der Nederlanden Root CA'
Jan 20 21:46:26 (2016) acmcli: certman_main.cpp(184): ERROR Invalid certificate '/CN=T\xC3\x9CRKTRUST Elektronik Sertifika Hizmet Sa\xC4\x9Flay\xC4\xB1c\xC4\xB1s\xC4\xB1/C=TR/L=ANKAR
A/O=(c) 2005 T\xC3\x9CRKTRUST Bilgi \xC4\xB0leti\xC5\x9Fim ve Bili\xC5\x9Fim G\xC3\xBCvenli\xC4\x9Fi Hizmetleri A.\xC5\x9E.'
Jan 20 21:46:26 (2016) acmcli: certman_main.cpp(184): ERROR Invalid certificate '/CN=T\xC3\x9CRKTRUST Elektronik Sertifika Hizmet Sa\xC4\x9Flay\xC4\xB1c\xC4\xB1s\xC4\xB1/C=TR/L=Ankar
a/O=T\xC3\x9CRKTRUST Bilgi \xC4\xB0leti\xC5\x9Fim ve Bili\xC5\x9Fim G\xC3\xBCvenli\xC4\x9Fi Hizmetleri A.\xC5\x9E. (c) Kas\xC4\xB1m 2005'
Jan 20 21:46:30 (2016) acmcli: certman_main.cpp(184): ERROR Invalid certificate '/C=ES/L=C/ Muntaner 244 Barcelona/CN=Autoridad de Certificacion Firmaprofesional CIF A62634068/emailA
ddress=ca@firmaprofesional.com'
Jan 20 21:46:30 (2016) acmcli: certman_main.cpp(184): ERROR Invalid certificate '/C=NO/O=Buypass AS-983163327/CN=Buypass Class 3 CA 1'
Jan 20 21:46:30 (2016) acmcli: certman_main.cpp(184): ERROR Invalid certificate '/C=NL/O=Staat der Nederlanden/CN=Staat der Nederlanden Root CA'
Jan 20 21:46:30 (2016) acmcli: certman_main.cpp(184): ERROR Invalid certificate '/CN=T\xC3\x9CRKTRUST Elektronik Sertifika Hizmet Sa\xC4\x9Flay\xC4\xB1c\xC4\xB1s\xC4\xB1/C=TR/L=ANKAR
A/O=(c) 2005 T\xC3\x9CRKTRUST Bilgi \xC4\xB0leti\xC5\x9Fim ve Bili\xC5\x9Fim G\xC3\xBCvenli\xC4\x9Fi Hizmetleri A.\xC5\x9E.'
Jan 20 21:46:30 (2016) acmcli: certman_main.cpp(184): ERROR Invalid certificate '/CN=T\xC3\x9CRKTRUST Elektronik Sertifika Hizmet Sa\xC4\x9Flay\xC4\xB1c\xC4\xB1s\xC4\xB1/C=TR/L=Ankar
a/O=T\xC3\x9CRKTRUST Bilgi \xC4\xB0leti\xC5\x9Fim ve Bili\xC5\x9Fim G\xC3\xBCvenli\xC4\x9Fi Hizmetleri A.\xC5\x9E. (c) Kas\xC4\xB1m 2005'
Now I can open Websites which are signed by withe cacert root. Without a Complaining webbrowser...

Achieved Today: Added cacert Root

Last edited by xelo; 2016-01-20 at 20:51.