Hoercher wrote: > seems to be DB_ERROR_INDEX_CLASH > Probably there's already an entry for your foo.csr (and no > no_unique_subject You're right, there is an entry for this domain because the certificate was deleted and I don't have it anymore. TXT_DB error number 2 is a

Alternatively you can also change /etc/ssl/index.txt.attr to contain the line unique_subject = no to allow multiple certificates with the same common name. This certificate was deleted and I don't have it anymore. to prevent you from issuing duplicate certificates, and this is probably what you do want. (Therefore, I do not recommend that you follow the admonition to "just turn duplicate-checking off.") HTH! Openssl Revoke Certificate Without File are all included here.

Join them; it only takes a minute: Sign up How to revoke an openssl certificate when you don't have the certificate up vote 33 down vote favorite 11 I made an Openssl Revoke Certificate openssl ca -revoke bad_crt_file -keyfile ca_key -cert ca_crt openssl automatically saves a copy of your cert at newcerts directory. I got it to occur though by setting the-subj argument on req. http://openssl.6102.n7.nabble.com/failed-to-update-database-TXT-DB-error-number-2-td6470.html This is to ensure that no certificates are issued more than once with the same Subject as this could lead to confusion if the wrong certificate is used.

Introduction to Linux - A Hands on Guide This guide was created as an overview of the Linux Operating System, geared toward new users as an exploration tour and getting started Openssl Database Please consider documentaion for details. > Where did you get the constant DB_ERROR_INDEX_CLASH from ? ./crypto/txt_db/txt_db.h ______________________________________________________________________ OpenSSL Project http://www.openssl.org User Support Mailing List [email protected] Automated List Manager [email protected] [prev in Enter another Common Name. 6 Responses to "TXT_DB error number 2 failed to update database" Feed for this Entry Trackback Address Yonni June 29, 2016 at 08:57 Thanks! Redesigned by Igor Drobot Entries Feed and Comments Feed 34 queries. 0.078 seconds.

Notices Welcome to LinuxQuestions.org, a friendly and active Linux Community. http://stackoverflow.com/questions/9496698/how-to-revoke-an-openssl-certificate-when-you-dont-have-the-certificate I have edited the ca.db.index file and removed the entry for this domain, now it's works :-) Where did you get the constant DB_ERROR_INDEX_CLASH from ? -- Thomas Carrié http://thocar.orghttp://www.gnu.org/philosophy/use-free-software.fr.htmlhttp://www.lebars.org/sec/tcpa-faq.fr.htmlhttp://aful.org/publi/articles/gilmore-copy-protection.html______________________________________________________________________ OpenSSL Failed To Update Database Txt_db Error Number 2 Openvpn Free forum by Nabble Edit this page ID's blog Linux TCP/IP, GreenIT and more… Blog About Log in « Upgrading Fedora to Schrodinger’s Cat v.19 Remote Mirroring with nc and dd Openssl Unique_subject These differ from older versions in that the following lines are included in easy-rsa/2.0/vars: export KEY_CN=changeme export KEY_NAME=changeme export KEY_OU=changeme export PKCS11_MODULE_PATH=changeme export PKCS11_PIN=1234 Commenting these lines out leads to the

sham March 9, 2014 at 17:05 Solved my issue. « Upgrading Fedora to Schrodinger’s Cat v.19 Remote Mirroring with nc and dd » Leave a Reply Cancel Reply Name (required) Mail his comment is here This occurs, if the same serial number shall be used twice. Use a text-editor to locate and remove the line for the domain, then re-save the file. Browse other questions tagged openssl certificate-revocation or ask your own question. Openssl Delete Certificate From Database

Certificate is to be certified until Oct 5 21:19:18 2022 GMT (3650 days) Sign the certificate? [y/n]:y failed to update database TXT_DB error number 2 To solve this I must do Best Regards Marcin Przysowa Attachments (1) bug_gen_cert.txt​ (4.8 KB) - added by SiB 4 years ago. Groups this user belongs to Everyone Unprivileged Reminders New reminder: Subject: Owner: Nobody in particular Andy Polyakov Ben Laurie Bodo Moeller Emilia Käsper Enoch Root Geoff Thorpe guest Jeffrey Walton Kurt this contact form Interpreting Spearman's correlation in R Are the following topics usually in an introductory Complex Analysis class: Julia sets, Fatou sets, Mandelbrot set, etc?

What early computers had excellent BASIC (or other language) at bootup? Openssl Ca Renew Certificate How can I manage with it?Best regards,Maciej Bobrowski # ThuMar2722:28:282003 Lutz Jaenicke - Correspondence added Download (untitled) / with headers text/plain 512b [[email protected] - Fri Feb 14 09:17:53 2003]: Show quoted Some applications cannot cope with a certificate in this format and become confused by the text information before the certificate data.


Visit the following links: Site Howto | Site FAQ | Sitemap | Register Now If you have any problems with the registration process or your account login, please contact us. The time now is 09:19 PM. If you have published the original certificate, revoking the old one is however the preferable solution, even if you don't run an OSCP server or provide CRLs. Openssl Updatedb Uncategorized random things Uncategorized Home » Uncategorized » openssl ca: failed to update database, TXT_DB error number 2 openssl ca: failed to update database, TXT_DB error number 2 Uncategorized certificate, debian,

To remedy the problem, go to the conf/index file in the EasyRSA directory. (There will be an index.attr file nearby.) You will find that this is simply a text file. So grep /etc/ssl/index.txt to obtain the serial number of the key to be revoked, e.g. 1013, then execute the following command: openssl ca -revoke /etc/ssl/newcerts/1013.pem #replacing the serial number The -keyfile Solving the integral of a function with modulus Why are copper cables round? navigate here Digital Hardness of Integers At what point is brevity no longer a virtue?

Worked ieio May 27, 2016 at 11:38 In case you need to sign two certificate with the same CM you can modify your database attr with unique_subject = no Manoj March Not the answer you're looking for? Thought of something like that. more hot questions question feed about us tour help blog chat data legal privacy policy work here advertising info mobile contact us feedback Technology Life / Arts Culture / Recreation Science

easy-rsa 2.x is effectively unmaintained -> closing as "wontfix".