<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>subca - GoBlog</title>
	<atom:link href="https://blog.goreinnamah.com/blog/tag/subca/feed/" rel="self" type="application/rss+xml" />
	<link>https://blog.goreinnamah.com</link>
	<description>LOG ALL LOGS</description>
	<lastBuildDate>Tue, 15 May 2018 18:56:02 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://blog.goreinnamah.com/wp-content/uploads/2017/01/cropped-1-150x150.jpg</url>
	<title>subca - GoBlog</title>
	<link>https://blog.goreinnamah.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Import Certificates pada EJBCA 6.10.1.2</title>
		<link>https://blog.goreinnamah.com/blog/2018/05/16/import-certificates-pada-ejbca-6-10-1-2/</link>
		
		<dc:creator><![CDATA[Darius Go Reinnamah]]></dc:creator>
		<pubDate>Tue, 15 May 2018 18:56:02 +0000</pubDate>
				<category><![CDATA[Information Technology]]></category>
		<category><![CDATA[CA]]></category>
		<category><![CDATA[Certificates]]></category>
		<category><![CDATA[ejbca]]></category>
		<category><![CDATA[import certificates]]></category>
		<category><![CDATA[import certificates pada ejbca]]></category>
		<category><![CDATA[import certificates pada EJBCA 6.10.1.2]]></category>
		<category><![CDATA[Policy]]></category>
		<category><![CDATA[Root CA]]></category>
		<category><![CDATA[subca]]></category>
		<guid isPermaLink="false">http://blog.goreinnamah.com/?p=2547</guid>

					<description><![CDATA[<p>Okay, pada postingan kali ini saya akan coba membahas soal Import Certificates dalam EJBCA. Kalau pada postingan sebelumnya saya sudah[...]</p>
<p>The post <a href="https://blog.goreinnamah.com/blog/2018/05/16/import-certificates-pada-ejbca-6-10-1-2/">Import Certificates pada EJBCA 6.10.1.2</a> first appeared on <a href="https://blog.goreinnamah.com">GoBlog</a>.</p>]]></description>
										<content:encoded><![CDATA[<p style="text-align: justify;">Okay, pada postingan kali ini saya akan coba membahas soal <strong>Import Certificates</strong> dalam EJBCA. Kalau pada postingan sebelumnya saya sudah membahas soal <strong>Import CA</strong> dan juga <strong>Import Certificate Profiles</strong>, nah kali ini yang akan dibahas adalah cara mengimport sertifikat dari End Entity-nya. Apakah EJBCA mendukung fitur tersebut? Tentu saja.</p>
<p style="text-align: justify;">Salah satu kegunaan <strong>Import Certificates</strong> adalah untuk migrasi data. Ada 2 cara untuk melakukan Import Certificates, yang pertama adalah dengan cara satuan dan yang kedua adalah secara bersamaan.</p>
<h3 style="text-align: justify;"><strong>Import Single Certificate (satuan)</strong></h3>
<p style="text-align: justify;">Perintah yang digunakan untuk import certificates secara satuan adalah:</p>
<ul style="text-align: justify;">
<li>Mandatori</li>
</ul>
<pre><strong>bin/ejbca.sh ca importcert --username <span style="color: #ff0000;">&lt;username&gt;</span> --password <span style="color: #ff0000;">&lt;password&gt;</span> --caname <span style="color: #ff0000;">&lt;nama CA&gt;</span> -a <span style="color: #ff0000;">&lt;status&gt;</span> -f <span style="color: #ff0000;">&lt;file certificate&gt;</span></strong></pre>
<ul style="text-align: justify;">
<li>Versi lengkap (ada tambahan parameter opsional)</li>
</ul>
<div class="confbox programlisting" style="text-align: justify;">
<div class="defaultnew syntaxhighlighter scroll-html-formatted-code">
<pre class="line" style="text-align: justify;"><strong>bin/ejbca.sh ca importcert <span style="color: #ff0000;">&lt;username&gt; &lt;password&gt; &lt;Nama CA&gt; &lt;status&gt;</span> --email <span style="color: #ff0000;">&lt;email&gt; &lt;File Certificate&gt;</span> \[--eeprofile <span style="color: #ff0000;">&lt;End Entity Profile&gt;</span>\] \[--certprofile <span style="color: #ff0000;">&lt;Certificate Profile&gt;</span>\] \[--revocation-reason <span style="color: #ff0000;">&lt;Alasan Revoke&gt;</span>\] \[--revocation-time <span style="color: #ff0000;">&lt;Waktu revoke&gt;</span>\]</strong></pre>
</div>
</div>
<p style="text-align: justify;">Berikut ini penjelasan mengenai beberapa parameter yang ada pada perintah di atas:</p>
<ol style="text-align: justify;">
<li><strong>Username</strong><br />
Username dari entitas akhir yang merupakan pemilik dari sertifikat. Jika entitas akhir tersebut belum ada, maka sertifikatnya akan dibuat secara otomatis. Jika entitas akhirnya sudah ada, sertifikat yang diimport akan berasosiasi dengan yang sudah ada, dan properti-properti yang ada (subject, subject alternative names) akan di-<em>update.</em></li>
<li><strong>Password</strong><br />
Password yang akan diatur untuk entitas akhir ini. (Pada versi GUI, bagian ini biasa disebut dengan <em><strong>enrollment code</strong></em>)</li>
<li><strong>Nama CA</strong><br />
Nama dari CA yang sudah mengeluarkan sertifikat.  Signature dari CA yang mengeluarkan sertifikat ini akan diverifikasi dengan CA yang ada. Jika signaturenya tidak cocok, sertifikat tidak akan diimport. <strong>CA Certificate</strong> harus ada di dalam database (Paling tidak statusnya sebagai <strong>external CA</strong>)<strong> </strong></li>
<li><strong>Status</strong>c<strong style="font-size: 1.0625rem;">Email</strong></li>
<li>Email dari si entitas akhir. Jika email ini isinya string <em>null, </em>maka akan diambil dari email yang ada di dalam sertifikat.</li>
<li><strong>File Certificate</strong><br />
File Encoded PEM (BASE 64) dari entitas akhir (file PEM-nya).</li>
<li><strong>End Entity Profile</strong><br />
End Entity Profile yang ada di sini adalah End Entity Profile untuk sertifikat yang akan diimport, buka End Entity Profile dari CA dimana entitas akhir itu diekspor. Setiap atribut dari certificate yang akan diimport akan diverifikasi oleh End Entity Profile Existing. Jika ada atribut yang tidak terseda pada End Entity Profile, maka sertifikat tidak akan bisa diimport. Jika End Entity Profile tidak ditulis pada proses impor, maka End Entity Profile <em>EMPTY </em>(bawaan EJBCA) yang akan digunakan.</li>
<li><strong>Certificate Profile</strong><br />
Mirip seperti End Entity Profile, hanya saja profil di sini adalah untuk CA. Sekali sertifikat berhasil diimport, sertifikat tersebut akan ditandai sebagai milik dari Certificate Profile yang sudah ditetapkan. Jika tidak disertakan dalam perintah, maka Certificate Profile yang akan dipilih adalah <em>ENDUSER </em>(bawaan EJBCA).</li>
<li><strong>Alasan Revoke</strong><br />
Parameter ini ada untuk mengizinkan sertifikat yang sudah di-REVOKED tetap bisa diimport (dengan alasan pencabutannya). Gunakan perintah &#8211;help untuk melihat list alasan yang bisa digunakan. Jika tidak disertakan pada perintah di atas, UNSPECIFIED akan ditetapkan sebagai alasannya.</li>
<li><strong>Waktu Revoke</strong><br />
Untuk mengizinkan sertifikat yang sudah di-REVOKED agar tetap bisa diimport dengan waktu pencabutan yang spesifik (format <em>yyyy.MM.dd-HH:mm</em>). Jika tidak disertakan, maka waktu sekaranglah yang akan digunakan.</li>
</ol>
<p style="text-align: justify;"> Langsung saja saya berikan contoh dari penggunaan <em>command </em><em>importcert.</em></p>
<pre><strong>sh bin/ejbca.sh ca importcert <span style="color: #ff0000;">t.mac hou1 CA ACTIVE</span> --email <span style="color: #ff0000;">t.mac@gmail.com /home/jboss/shell/Tracy\ McGrady.pem</span> --eeprofile <span style="color: #ff0000;">Person</span> --certprofile <span style="color: #ff0000;">tutorial</span></strong></pre>
<p style="text-align: justify;">Pada perintah di atas, saya mencoba untuk mengimport sertifikat bernama <span style="color: #ff0000;"><strong>Tracy Mcgrady.pem </strong><span style="color: #000000;">dengan detil:</span></span></p>
<ul style="text-align: justify;">
<li><strong>Username = <span style="color: #ff0000;">t.mac</span></strong></li>
<li><strong>Password = <span style="color: #ff0000;">hou1</span></strong></li>
<li><strong>Nama CA = <span style="color: #ff0000;">CA</span></strong></li>
<li><strong>Status = <span style="color: #ff0000;">Active</span></strong></li>
<li><strong>Email = <span style="color: #ff0000;">t.mac@gmail.com</span></strong></li>
<li><strong>File Certificate = <span style="color: #ff0000;">/home/jboss/shell/Tracy\ McGrady.pem</span></strong></li>
<li><strong>End Entity Profile = <span style="color: #ff0000;">Person</span></strong></li>
<li><strong>Certificate Profile = <span style="color: #ff0000;">tutorial</span></strong></li>
</ul>
<figure id="attachment_2554" aria-describedby="caption-attachment-2554" style="width: 1203px" class="wp-caption aligncenter"><img fetchpriority="high" decoding="async" class="wp-image-2554 size-full" src="http://blog.goreinnamah.com/wp-content/uploads/2018/05/2-1.png" alt="" width="1203" height="439" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/05/2-1.png 1203w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/2-1-300x109.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/2-1-768x280.png 768w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/2-1-1024x374.png 1024w" sizes="(max-width: 1203px) 100vw, 1203px" /><figcaption id="caption-attachment-2554" class="wp-caption-text">End Entity t.mac belum ada</figcaption></figure>
<figure id="attachment_2555" aria-describedby="caption-attachment-2555" style="width: 624px" class="wp-caption aligncenter"><img decoding="async" class="size-full wp-image-2555" src="http://blog.goreinnamah.com/wp-content/uploads/2018/05/4-1.png" alt="" width="624" height="341" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/05/4-1.png 624w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/4-1-300x164.png 300w" sizes="(max-width: 624px) 100vw, 624px" /><figcaption id="caption-attachment-2555" class="wp-caption-text">Proses Impor yang gagal sebab ada atribut pada End Entity Profile Tutorial yang belum terpenuhi</figcaption></figure>
<figure id="attachment_2556" aria-describedby="caption-attachment-2556" style="width: 637px" class="wp-caption aligncenter"><img decoding="async" class="size-full wp-image-2556" src="http://blog.goreinnamah.com/wp-content/uploads/2018/05/5-1.png" alt="" width="637" height="362" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/05/5-1.png 637w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/5-1-300x170.png 300w" sizes="(max-width: 637px) 100vw, 637px" /><figcaption id="caption-attachment-2556" class="wp-caption-text">Setelah End Entity Profile diganti menjadi Person dan semua syarat atributnya terpenuhi, proses import pun berhasil</figcaption></figure>
<figure id="attachment_2557" aria-describedby="caption-attachment-2557" style="width: 1354px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-2557" src="http://blog.goreinnamah.com/wp-content/uploads/2018/05/6-1.png" alt="" width="1354" height="453" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/05/6-1.png 1354w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/6-1-300x100.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/6-1-768x257.png 768w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/6-1-1024x343.png 1024w" sizes="auto, (max-width: 1354px) 100vw, 1354px" /><figcaption id="caption-attachment-2557" class="wp-caption-text">Bukti kalau sertifikat milik t.mac berhasil diimport</figcaption></figure>
<p style="text-align: justify;"><span style="color: #ff0000;"><strong>Catatan:</strong></span></p>
<ul style="text-align: justify;">
<li>Jika menjalankan perintah (command) di atas tanpa ada parameter apapun, maka panduan penggunaan perintah tersebutlah yang akan muncul (lengkap dengan parameternya seperti <em>caname, status, endentityprofile </em>dan <em>certificateprofile</em>).</li>
<li>Pastikan kalau Signature CA dari Cert yang akan kita impor itu sama, kalau tidak maka proses impor akan gagal.</li>
<li>Pastikan nama Profile sudah benar dan atribut-atribut yang ada di dalam profile tersebut sudah terpenuhi semua syaratnya. Jika belum sama dan terpenuhi, maka proses impor akan gagal.</li>
</ul>
<h4><strong><em>Baca juga:<a href="http://blog.goreinnamah.com/blog/2018/03/26/instalasi-ejbca-6-10-1-2/" rel="bookmark"> Instalasi EJBCA 6.10.1.2 dengan HSM Luna 7 pada CentOS 7</a> </em></strong></h4>
<h3 style="text-align: justify;"><strong>Import Certificates in Bulk (Bersamaan)</strong></h3>
<p style="text-align: justify;">Untuk mengimport banyak sertifikat secara bersamaan, jalankan perintah berikut:</p>
<ul style="text-align: justify;">
<li>Mandatory</li>
</ul>
<pre><strong>bin/ejbca.sh ca importcertdir --filter <span style="color: #ff0000;">&lt;filter&gt;</span> --caname <span style="color: #ff0000;">&lt;Nama CA&gt;</span> -a <span style="color: #ff0000;">&lt;status&gt;</span> --dir <span style="color: #ff0000;">&lt;lokasi sertifikat&gt;</span> --eeprofile <span style="color: #ff0000;">&lt;End Entity Profile&gt;</span> --certprofile <span style="color: #ff0000;">&lt;Certificate Profile&gt;</span></strong></pre>
<ul style="text-align: justify;">
<li>Versi Lengkap (ada tambahan parameter opsional)</li>
</ul>
<pre><strong>bin/ejbca.sh ca importcertdir <span style="color: #ff0000;">&lt;username-source&gt;</span> <span style="color: #ff0000;">&lt;Nama CA&gt; &lt;status&gt; &lt;lokasi sertifikat&gt;</span> --eeprofile <span style="color: #ff0000;">&lt;End Entity Profile&gt;</span> --certprofile <span style="color: #ff0000;">&lt;Certificate Profile&gt;</span> \[-resumeonerror\] \[--revocation-reason <span style="color: #ff0000;">&lt;Alasan Revoke&gt;</span>\] \[--revocation-time <span style="color: #ff0000;">&lt;Waktu Revoke&gt;</span>\]</strong></pre>
<p style="text-align: justify;">Berikut ini penjelasan mengenai beberapa parameter yang ada pada perintah di atas:</p>
<ol style="text-align: justify;">
<li><strong>username-source atau filter<br />
</strong>Parameter ini digunakan untuk memperoleh <em>username </em>dari entitas akhir yang akan memiliki sertifikat tersebut. Karena kita akan mengimpor banyak sertifikat sekaligus, maka tidak mungkin menentukan <em>username-</em>nya satu per satu. Untuk itulah digunakan parameter ini. Nilai yang tersedia untuk parameter ini adalah <strong>FILE, DN, CN.</strong><br />
Jika CN yang dipilih<em>, username </em>akan sama dengan atribut <em>common name </em> yang ada di subjek sertifikat.<br />
Jika DN yan dipilih, <em>username </em>akan sama dengan seluruh <em>distinguished name </em>(subjek) yang ada pada sertifikat.<br />
Jika FILE yang dipilih, <em>username </em>akan sama dengan dengan nama file dari sertifikat.<br />
Jika CN yang dipilih namun CN tidak ada dalam subjek sertifikat, proses impor akan kembali ke belakang dan menggantinya dengan DN. Jika DN juga tidak tersedia, <em>username </em>akan diambil dari nama file.<br />
Jika DN yang langsung dipilih namun DN tidak ada dalam subjek sertifikat, proses impor akan mundur dan menggantinya dengan nama FILE.</li>
<li><strong>Nama CA<br />
</strong>Nama dari CA yang sudah mengeluarkan sertifikat.  Signature dari CA yang mengeluarkan sertifikat ini akan diverifikasi dengan CA yang ada. Jika signaturenya tidak cocok, sertifikat tidak akan diimport. <strong>CA Certificate</strong> harus ada di dalam database (Paling tidak statusnya sebagai <strong>external CA</strong>)<strong> </strong></li>
<li><strong>Status<br />
</strong>Nama dari CA yang sudah mengeluarkan sertifikat.  Signature dari CA yang mengeluarkan sertifikat ini akan diverifikasi dengan CA yang ada. Jika signaturenya tidak cocok, sertifikat tidak akan diimport. <strong>CA Certificate</strong> harus ada di dalam database (Paling tidak statusnya sebagai <strong>external CA</strong>)<strong> </strong></li>
<li><strong>Lokasi Sertifikat<br />
</strong><em>Path </em>dari lokasi folder yang berisi file-file sertifikat yang ingin diimport. Setiap filenya harus berisi <em>single certificate.</em> Folder tidak boleh berisi subfolder atau file yang bukan sertifikat.</li>
<li><strong>End Entity Profile</strong><br />
End Entity Profile yang ada di sini adalah End Entity Profile untuk sertifikat yang akan diimport, buka End Entity Profile dari CA dimana entitas akhir itu diekspor. Setiap atribut dari certificate yang akan diimport akan diverifikasi oleh End Entity Profile Existing. Jika ada yang subjek pada sertifikat yang tidak cocok, maka file tersebut tidak akan diimpor.</li>
<li><strong>Certificate Profile<br />
</strong>Mirip seperti End Entity Profile, hanya saja profil di sini adalah untuk CA. Sekali sertifikat berhasil diimport, sertifikat tersebut akan ditandai sebagai milik dari Certificate Profile yang sudah ditetapkan.</li>
<li><strong>Resumeonerror<br />
</strong>Opsi ini bisa digunakan untuk memaksa proses impor tetap dapat terus berjalan meskipun ada error serius yang terjadi. Secara <em>default, </em>opsi ini tidak diaktifkan. Error yang ditangani oleh opsi ini beberapa diantaranya adalah pelanggaran pada End Entity Profile, masalah dengan <em>parsing </em>sertifikat, dll.</li>
<li><strong>Alasan Revoke<br />
</strong>Parameter ini ada untuk mengizinkan sertifikat yang sudah di-REVOKED tetap bisa diimport (dengan alasan pencabutannya). Gunakan perintah &#8211;help untuk melihat list alasan yang bisa digunakan. Jika tidak disertakan pada perintah di atas, UNSPECIFIED akan ditetapkan sebagai alasannya.</li>
<li><strong>Waktu Revoke</strong><br />
Untuk mengizinkan sertifikat yang sudah di-REVOKED agar tetap bisa diimport dengan waktu pencabutan yang spesifik (format <em>yyyy.MM.dd-HH:mm</em>). Jika tidak disertakan, maka waktu sekaranglah yang akan digunakan.</li>
</ol>
<p style="text-align: justify;">Langsung saja saya berikan contoh dari penggunaan <em>command </em><em>importcertdir.</em></p>
<pre><strong>sh bin/ejbca.sh ca importcertdir --filter <span style="color: #ff0000;">FILE</span> --caname <span style="color: #ff0000;">CA</span> -a <span style="color: #ff0000;">ACTIVE</span> --dir <span style="color: #ff0000;">/home/jboss/cert</span> --eeprofile <span style="color: #ff0000;">Person</span> --certprofile <span style="color: #ff0000;">tutorial</span></strong></pre>
<p style="text-align: justify;">Pada perintah di atas, saya mencoba untuk mengimport 4 sertifikat<strong><span style="color: #ff0000;"> (s.curry.pem, k.bryant.pem, d.wade.pem, Tracy McGrady.pem)</span></strong> dari folder<strong><span style="color: #ff0000;"> /home/jboss/cert</span></strong> dengan detil:</p>
<ul style="text-align: justify;">
<li><strong>filter = <span style="color: #ff0000;">FILE</span></strong></li>
<li><strong>Nama CA = <span style="color: #ff0000;">CA</span></strong></li>
<li><strong>Status = <span style="color: #ff0000;">ACTIVE</span></strong></li>
<li><strong>Lokasi Sertifikat = <span style="color: #ff0000;">/home/jboss/cert</span></strong></li>
<li><strong>End Entity Profile = <span style="color: #ff0000;">Person</span></strong></li>
<li><strong>Certificate Profile = <span style="color: #ff0000;">tutorial</span></strong></li>
</ul>
<figure id="attachment_2569" aria-describedby="caption-attachment-2569" style="width: 1122px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-2569 size-full" src="http://blog.goreinnamah.com/wp-content/uploads/2018/05/7-1.png" alt="" width="1122" height="513" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/05/7-1.png 1122w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/7-1-300x137.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/7-1-768x351.png 768w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/7-1-1024x468.png 1024w" sizes="auto, (max-width: 1122px) 100vw, 1122px" /><figcaption id="caption-attachment-2569" class="wp-caption-text">Hanya sertifikat Tracy McGrady yang sudah ada</figcaption></figure>
<figure id="attachment_2570" aria-describedby="caption-attachment-2570" style="width: 722px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-2570 size-full" src="http://blog.goreinnamah.com/wp-content/uploads/2018/05/11-1.png" alt="" width="722" height="294" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/05/11-1.png 722w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/11-1-300x122.png 300w" sizes="auto, (max-width: 722px) 100vw, 722px" /><figcaption id="caption-attachment-2570" class="wp-caption-text">Proses Impor berhasil. 3 file sertifikat dalam folder cert berhsil diimpor sedangkan 1 nya lagi tidak diimpor (skip) karena sudah ada.</figcaption></figure>
<figure id="attachment_2571" aria-describedby="caption-attachment-2571" style="width: 724px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-2571 size-full" src="http://blog.goreinnamah.com/wp-content/uploads/2018/05/12-1.png" alt="" width="724" height="344" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/05/12-1.png 724w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/12-1-300x143.png 300w" sizes="auto, (max-width: 724px) 100vw, 724px" /><figcaption id="caption-attachment-2571" class="wp-caption-text">Contoh Impor bersamaan yang gagal.<br /> Kegagalan terjadi karena terdapat perbedaan signature antara CA dimana file yang akan diimpor dengan CA yang mengeluarkan cert tersebut</figcaption></figure>
<figure id="attachment_2572" aria-describedby="caption-attachment-2572" style="width: 686px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-2572 size-full" src="http://blog.goreinnamah.com/wp-content/uploads/2018/05/9-1.png" alt="" width="686" height="53" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/05/9-1.png 686w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/9-1-300x23.png 300w" sizes="auto, (max-width: 686px) 100vw, 686px" /><figcaption id="caption-attachment-2572" class="wp-caption-text">Contoh error lainnya dimana kegagaln terjadi karena typo pada cert profile yang mengakibatkan tidak ditemukannya cert profile tersebut</figcaption></figure>
<figure id="attachment_2573" aria-describedby="caption-attachment-2573" style="width: 1092px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-2573 size-full" src="http://blog.goreinnamah.com/wp-content/uploads/2018/05/13-1.png" alt="" width="1092" height="211" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/05/13-1.png 1092w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/13-1-300x58.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/13-1-768x148.png 768w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/13-1-1024x198.png 1024w" sizes="auto, (max-width: 1092px) 100vw, 1092px" /><figcaption id="caption-attachment-2573" class="wp-caption-text">Bukti kalau sertifikat-sertifikat tadi berhasil diimpor secara bersamaan</figcaption></figure>
<p style="text-align: justify;"><span style="color: #ff0000;"><strong>Catatan:</strong></span></p>
<ul style="text-align: justify;">
<li>Entitas akhir akan langsung terimpor apabila memang entitas tersebut belum ada. Jika Entitas akhir sudah ada, sertifikat yang diimport akan berasosiasi dengannya dan properties-nya akan diupdate.</li>
<li>Jika menjalankan perintah (command) di atas tanpa ada parameter apapun, maka panduan penggunaan perintah tersebutlah yang akan muncul (lengkap dengan parameternya seperti <em>username-source, status, endentityprofile </em>dan <em>certificateprofile</em>)</li>
<li>Sertifikat yang sudah ada di dalam database akan di-<em>skip </em>selama proses <em>import. </em></li>
<li>Sertifikat yang CA-nya berbeda dari yang dispesifikasikan akan di-<em>skip </em>juga.</li>
<li>Ketidaksesuaian lainnya seperti <em>invalid format, </em>adanya <em>subdirectory, </em>subjek yang tiak sesuai, akan menghentikan proses impor kecuali perintah &#8211;<em>resumeonerror </em>dimasukkan.</li>
<li>Sertifikat yang sudah diimpor sebelum terjadinya ketidaksesuaian pada file berikutnya akan tetap tersimpan pada <em>database. </em></li>
</ul>
<h4><em><strong>Baca juga: <a href="http://blog.goreinnamah.com/blog/2018/05/05/mengelola-ca-pada-ejbca-6-10-1-2/">Cara Mengelola CA pada EJBCA 6.10.1.2</a></strong></em></h4>
<ul style="text-align: justify;">
<li>Untuk setiap sertifikat yang di-<em>skip, </em>hasil keluaran akan menyebutkan <em>serial number </em>dan nama file-nya. Informasi file yang <em>error </em>pun akan ditampilkan juga.</li>
<li>Saat proses impor sudah selesai, rangkuman singkat mengenai sertifikat yang berhasil diimpor, sertifikat yang sudah ada (<em>redundant</em>), dan sertifikat yang ditolak (yang tidak di <em>sign </em>oleh CA yang diminta) akan muncul.</li>
<li>Tidak akan ada rangkuman yang akan ditampilkan jika <em>abnormal error </em>terjadi (seperti apapun kecuali yang sudah disebutkan di atas), kecuali kalian menyertakan paramete <em>-resumeonerror</em></li>
<li>Jika menggunakan <em>-resumeonerror, </em>import file akan berlanjut sampai semua file sertifikat dari dalam direktori diproses. Pesan <em>error </em>akan ditampilkan dan rangkuman akan berisi informasi tambahan seperti:
<ul>
<li>Jumlah sertifikat yang tidak bisa dibaca (karena salah format atau bentuknya dalam direktori lagi)</li>
<li>Jumlah sertifikat yang subjek end entity profilenya tidak sesuai (salah nilai untuk <em>non-modifiable, dll)</em></li>
<li>Jumlah sertifikat yang tidak bisa dibaca karena <em>error </em>lainnya.</li>
</ul>
</li>
</ul>
<p style="text-align: justify;">Ya, itu tadi sedikit informasi mengenai cara melakukan import certificates pada EJBCA 6.10.1.2. Semoga informasi mengenai import certificates tadi bisa bermanfaat buat kalian ya.</p>
<p style="text-align: justify;">Sampai jumpa di postingan selanjutnya <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f642.png" alt="🙂" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
<h4><em><strong>Sumber: <a href="http://ejbca.org/docs/Importing_Certificates.html">EJBCA Docs</a></strong></em></h4><p>The post <a href="https://blog.goreinnamah.com/blog/2018/05/16/import-certificates-pada-ejbca-6-10-1-2/">Import Certificates pada EJBCA 6.10.1.2</a> first appeared on <a href="https://blog.goreinnamah.com">GoBlog</a>.</p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Cara Mengelola CA pada EJBCA 6.10.1.2</title>
		<link>https://blog.goreinnamah.com/blog/2018/05/05/mengelola-ca-pada-ejbca-6-10-1-2/</link>
					<comments>https://blog.goreinnamah.com/blog/2018/05/05/mengelola-ca-pada-ejbca-6-10-1-2/#comments</comments>
		
		<dc:creator><![CDATA[Darius Go Reinnamah]]></dc:creator>
		<pubDate>Fri, 04 May 2018 18:18:50 +0000</pubDate>
				<category><![CDATA[Information Technology]]></category>
		<category><![CDATA[Certificate]]></category>
		<category><![CDATA[ejbca]]></category>
		<category><![CDATA[EJBCA 6.10.1.2]]></category>
		<category><![CDATA[key]]></category>
		<category><![CDATA[mengelola CA]]></category>
		<category><![CDATA[mengelola CA EJBCA]]></category>
		<category><![CDATA[Mengelola CA pada EJBCA]]></category>
		<category><![CDATA[Private Key]]></category>
		<category><![CDATA[Public Key]]></category>
		<category><![CDATA[ROOTCA]]></category>
		<category><![CDATA[subca]]></category>
		<guid isPermaLink="false">http://blog.goreinnamah.com/?p=2454</guid>

					<description><![CDATA[<p>Export dan Import CA Dalam bebarapa keadaan, melakukan backup terhadap CA Signature Keys dan Encryption Keys adalah hal yang cukup bijak. Namun ada satu hal[...]</p>
<p>The post <a href="https://blog.goreinnamah.com/blog/2018/05/05/mengelola-ca-pada-ejbca-6-10-1-2/">Cara Mengelola CA pada EJBCA 6.10.1.2</a> first appeared on <a href="https://blog.goreinnamah.com">GoBlog</a>.</p>]]></description>
										<content:encoded><![CDATA[<h2 style="text-align: justify;">Export dan Import CA</h2>
<p style="text-align: justify;">Dalam bebarapa keadaan, melakukan <em>backup </em>terhadap <strong>CA Signature Keys </strong>dan<strong> Encryption Keys </strong>adalah hal yang cukup bijak. Namun ada satu hal yang perlu diingat saat melakukan <em>backup </em><strong>CA Keys, </strong>yaitu lindungilah kunci tersebut sama seperti kita melindungi CA itu sendiri.</p>
<p style="text-align: justify;"><strong>Soft token </strong>CA bisa diekspor dan di-<em>backup</em> secara langsung melalui EJBCA,<em> </em>tapi tidak dengan CA yang menggunakan <strong>HSM (<em>Hardware Security Module). </em></strong>Untuk mengekspor<em> </em>kunci pada CA yang menggunakan HSM maka proses <em>backup </em>harus dilakukan melalui HSM.</p>
<p style="text-align: justify;">Ada 2 cara untuk mengimpor EJBCA yaitu dengan <strong>CLI <em>(Command Line Interface) </em></strong>dan <strong>GUI <em>(Graphical User Interface)</em></strong>, sementara HSM hanya bisa diimpor dengan menggunakan <strong>CLI.</strong></p>
<h3 style="text-align: justify;"><strong>Menggunakan CLI (Ekspor)</strong></h3>
<p style="text-align: justify;">Untuk mengekspor sebuah CA dengan nama <strong>imporCA </strong>menjadi file <strong>PKCS#12 </strong>bernama <strong>/home/imporCA.p12 , </strong>jalankan perintah berikut di direktori <strong>$EJBCA_HOME:</strong></p>
<pre style="text-align: justify;"><span style="color: #ff0000;"><strong>$ sh bin/ejbca.sh ca exportca imporCA /home/jboss/imporCA.p12</strong></span>
Setting SignatureKeyAlias to SignatureKeyAlias
Setting EncryptionKeyAlias to EncryptionKeyAlias
Enter keystore password:</pre>
<figure id="attachment_2457" aria-describedby="caption-attachment-2457" style="width: 732px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-2457 size-full" src="http://blog.goreinnamah.com/wp-content/uploads/2018/05/Screenshot-from-2018-05-04-16-45-39.png" alt="" width="732" height="21" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/05/Screenshot-from-2018-05-04-16-45-39.png 732w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/Screenshot-from-2018-05-04-16-45-39-300x9.png 300w" sizes="auto, (max-width: 732px) 100vw, 732px" /><figcaption id="caption-attachment-2457" class="wp-caption-text">ImporCA</figcaption></figure>
<figure id="attachment_2458" aria-describedby="caption-attachment-2458" style="width: 440px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-2458 size-full" src="http://blog.goreinnamah.com/wp-content/uploads/2018/05/Screenshot-from-2018-05-04-16-52-27.png" alt="" width="440" height="72" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/05/Screenshot-from-2018-05-04-16-52-27.png 440w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/Screenshot-from-2018-05-04-16-52-27-300x49.png 300w" sizes="auto, (max-width: 440px) 100vw, 440px" /><figcaption id="caption-attachment-2458" class="wp-caption-text">Masukkan Password</figcaption></figure>
<ul style="text-align: justify;">
<li>Jika Password belum diubah, isi dengan <strong>foo123</strong></li>
</ul>
<p style="text-align: justify;">Apabila menemukan <strong>error </strong>seperti ini, maka ada perubahan yang harus dilakukan pada <strong>crypto token </strong>yang ada pada <strong>CA Funtions</strong>:</p>
<ul style="text-align: justify;">
<li>Error ini menandakan kalau <em>private keys </em>CA tidak diizinkan untuk diekspor</li>
</ul>
<figure id="attachment_2460" aria-describedby="caption-attachment-2460" style="width: 723px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-2460" src="http://blog.goreinnamah.com/wp-content/uploads/2018/05/Screenshot-from-2018-05-04-16-25-24.png" alt="" width="723" height="130" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/05/Screenshot-from-2018-05-04-16-25-24.png 723w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/Screenshot-from-2018-05-04-16-25-24-300x54.png 300w" sizes="auto, (max-width: 723px) 100vw, 723px" /><figcaption id="caption-attachment-2460" class="wp-caption-text">Pesan Error</figcaption></figure>
<p style="text-align: justify;">Untuk membenahinya, masuk ke <strong>CA Functions →Crypto Tokens </strong>&amp; pilih Crypto Token yang digunakan oleh CA tersebut. Pada contoh kali ini, <strong>imporCA </strong>menggunakan crypto token bernama <strong>imporCA:</strong></p>
<figure id="attachment_2461" aria-describedby="caption-attachment-2461" style="width: 1086px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-2461 size-full" src="http://blog.goreinnamah.com/wp-content/uploads/2018/05/6.png" alt="" width="1086" height="119" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/05/6.png 1086w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/6-300x33.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/6-768x84.png 768w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/6-1024x112.png 1024w" sizes="auto, (max-width: 1086px) 100vw, 1086px" /><figcaption id="caption-attachment-2461" class="wp-caption-text">Crypto Token imporCA</figcaption></figure>
<p style="text-align: justify;">Kalau diperhatikan, bagian <em>check box </em>untuk <strong>allow export private keys </strong>masih belum tercentang. Untuk mengubahnya, pilih <strong>switch to edit mode:</strong></p>
<figure id="attachment_2462" aria-describedby="caption-attachment-2462" style="width: 427px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-2462 size-full" src="http://blog.goreinnamah.com/wp-content/uploads/2018/05/7.png" alt="" width="427" height="243" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/05/7.png 427w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/7-300x171.png 300w" sizes="auto, (max-width: 427px) 100vw, 427px" /><figcaption id="caption-attachment-2462" class="wp-caption-text">Pilihan ekspor belum diizinkan</figcaption></figure>
<p style="text-align: justify;">Centang <em>check box </em><strong>allow export private keys </strong>kemudian tekan tombol <strong>save:</strong></p>
<figure id="attachment_2465" aria-describedby="caption-attachment-2465" style="width: 609px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-2465 size-full" src="http://blog.goreinnamah.com/wp-content/uploads/2018/05/8.png" alt="" width="609" height="343" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/05/8.png 609w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/8-300x169.png 300w" sizes="auto, (max-width: 609px) 100vw, 609px" /><figcaption id="caption-attachment-2465" class="wp-caption-text">Centang Allow export Private key</figcaption></figure>
<p style="text-align: justify;">Sekarang <strong>Private Key</strong> dari CA sudah bisa diekspor:</p>
<figure id="attachment_2466" aria-describedby="caption-attachment-2466" style="width: 390px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-2466" src="http://blog.goreinnamah.com/wp-content/uploads/2018/05/Screenshot-from-2018-05-04-16-27-14.png" alt="" width="390" height="265" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/05/Screenshot-from-2018-05-04-16-27-14.png 390w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/Screenshot-from-2018-05-04-16-27-14-300x204.png 300w" sizes="auto, (max-width: 390px) 100vw, 390px" /><figcaption id="caption-attachment-2466" class="wp-caption-text">Private Key sudah bisa diekspor</figcaption></figure>
<h3 style="text-align: justify;"><strong>Menggunakan CLI (Impor)</strong></h3>
<p style="text-align: justify;">Untuk mengimpor <em>backup key </em>yang sudah kita expor tadi ke CA lainnya, jalankan perintah berikut pada direktori <strong>$EJBCA_HOME</strong>:</p>
<pre><span style="color: #ff0000;"><strong>$ sh bin/ejbca.sh ca importca imporCA /root/imporCA.p12</strong></span> 
Importing soft token.
Enter keystore password:</pre>
<figure id="attachment_2469" aria-describedby="caption-attachment-2469" style="width: 982px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-2469 size-full" src="http://blog.goreinnamah.com/wp-content/uploads/2018/05/9.png" alt="" width="982" height="61" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/05/9.png 982w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/9-300x19.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/9-768x48.png 768w" sizes="auto, (max-width: 982px) 100vw, 982px" /><figcaption id="caption-attachment-2469" class="wp-caption-text">Proses impor CA</figcaption></figure>
<figure id="attachment_2470" aria-describedby="caption-attachment-2470" style="width: 300px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-2470 size-medium" src="http://blog.goreinnamah.com/wp-content/uploads/2018/05/Screenshot-from-2018-05-04-17-48-44-300x49.png" alt="" width="300" height="49" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/05/Screenshot-from-2018-05-04-17-48-44-300x49.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/Screenshot-from-2018-05-04-17-48-44.png 312w" sizes="auto, (max-width: 300px) 100vw, 300px" /><figcaption id="caption-attachment-2470" class="wp-caption-text">impor ca</figcaption></figure>
<p>Pada versi GUI-nya pun pasti otomatis langsung muncul:</p>
<figure id="attachment_2509" aria-describedby="caption-attachment-2509" style="width: 873px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-2509" src="http://blog.goreinnamah.com/wp-content/uploads/2018/05/ejbca.png" alt="" width="873" height="216" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/05/ejbca.png 873w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/ejbca-300x74.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/ejbca-768x190.png 768w" sizes="auto, (max-width: 873px) 100vw, 873px" /><figcaption id="caption-attachment-2509" class="wp-caption-text">imporCA sudah muncul</figcaption></figure>
<p style="text-align: justify;">Untuk bisa melakukan <strong>import</strong> <strong>CA </strong>yang mengunakan HSM. Jalankan perintah berikut:</p>
<pre><span style="color: #ff0000;"><strong>$ sh bin/ejbca.sh ca importca --help</strong></span></pre>
<figure id="attachment_2474" aria-describedby="caption-attachment-2474" style="width: 836px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-2474 size-full" src="http://blog.goreinnamah.com/wp-content/uploads/2018/05/10.jpg" alt="" width="836" height="612" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/05/10.jpg 836w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/10-300x220.jpg 300w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/10-768x562.jpg 768w" sizes="auto, (max-width: 836px) 100vw, 836px" /><figcaption id="caption-attachment-2474" class="wp-caption-text">Opsi yang bisa digunakan pada perintah importca</figcaption></figure>
<p style="text-align: justify;"><span style="color: #ff0000;"><em>*Baca deskripsi dan rajin coba ya*</em></span></p>
<h4 style="text-align: justify;"><strong><em>Baca juga: <a href="http://blog.goreinnamah.com/blog/2018/05/03/konsep-ejbca-ca/">Konsep pada EJBCA</a></em></strong></h4>
<h3 style="text-align: justify;"><strong>Menggunakan GUI</strong></h3>
<p style="text-align: justify;">Untuk bisa mengekspor dan mengimpor <strong>CA Keys </strong>dengan menggunakan <strong>admin GUI, </strong>kita terlebih dahulu harus memiliki <strong>akses superadministrator. </strong>Pastikan kalau file .p12 tidak secara otomatis tersimpan pada tempat yang diinginkan oleh <em>browser. </em></p>
<p style="text-align: justify;">Untuk mengekspor CA Keys, lakukan tahap berikut:</p>
<ul style="text-align: justify;">
<li>Pilih <strong>Certificate Authorities </strong>dari administrator menu.</li>
<li>Pada CA yang ingin diekspor, tekan <strong>edit.</strong></li>
<li>Pergi ke baris yang bertuliskan <strong>CA export requires the token authentication code.</strong></li>
<li>Masukkan <strong>keystore password </strong>tepat di dalam kotak yang disediakan kemudiakan tekan <strong>Export CA keystore</strong></li>
<li>File PKCS#12 akan terdownload oleh browser ke lokasi yang sudah kamu atur sebelumnya.</li>
</ul>
<figure id="attachment_2476" aria-describedby="caption-attachment-2476" style="width: 928px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-2476 size-full" src="http://blog.goreinnamah.com/wp-content/uploads/2018/05/11.png" alt="" width="928" height="448" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/05/11.png 928w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/11-300x145.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/11-768x371.png 768w" sizes="auto, (max-width: 928px) 100vw, 928px" /><figcaption id="caption-attachment-2476" class="wp-caption-text">Edit CA yang ingin diekspor</figcaption></figure>
<figure id="attachment_2477" aria-describedby="caption-attachment-2477" style="width: 677px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-2477" src="http://blog.goreinnamah.com/wp-content/uploads/2018/05/Screenshot-from-2018-05-04-23-17-25.png" alt="" width="677" height="117" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/05/Screenshot-from-2018-05-04-23-17-25.png 677w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/Screenshot-from-2018-05-04-23-17-25-300x52.png 300w" sizes="auto, (max-width: 677px) 100vw, 677px" /><figcaption id="caption-attachment-2477" class="wp-caption-text">Masukkan Keystore Password untuk mengunduh file .p12</figcaption></figure>
<figure id="attachment_2478" aria-describedby="caption-attachment-2478" style="width: 499px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-2478 size-full" src="http://blog.goreinnamah.com/wp-content/uploads/2018/05/12.png" alt="" width="499" height="222" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/05/12.png 499w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/12-300x133.png 300w" sizes="auto, (max-width: 499px) 100vw, 499px" /><figcaption id="caption-attachment-2478" class="wp-caption-text">FIle p12 siap diunduh</figcaption></figure>
<p style="text-align: justify;">Untuk melakukan impor, lakukan tahap berikut:</p>
<ul style="text-align: justify;">
<li>Pilih <strong>Certificate Authorities </strong>dari administrator menu.</li>
<li>Pilih tombol <strong>import CA keystore</strong></li>
<li>Isi Form yang muncul. Beberapa hal yang harus diisi adalah nama CA yang akan diimpor, path file PKCS#12, keystore password.</li>
<li>Isi <strong>Alias of signature key </strong>dengan <strong>SignatureKeyAlias</strong></li>
<li>Isi <strong>Alias of encryption key </strong>dengan <strong>EncryptionKeyAlias</strong></li>
<li>Kalau sudah, tekan tombol <strong>Import CA keystore</strong></li>
</ul>
<figure id="attachment_2480" aria-describedby="caption-attachment-2480" style="width: 920px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-2480 size-full" src="http://blog.goreinnamah.com/wp-content/uploads/2018/05/13.png" alt="" width="920" height="418" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/05/13.png 920w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/13-300x136.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/13-768x349.png 768w" sizes="auto, (max-width: 920px) 100vw, 920px" /><figcaption id="caption-attachment-2480" class="wp-caption-text">Impor CA Keystore</figcaption></figure>
<figure id="attachment_2481" aria-describedby="caption-attachment-2481" style="width: 949px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-2481 size-full" src="http://blog.goreinnamah.com/wp-content/uploads/2018/05/Screenshot-from-2018-05-04-23-29-00.png" alt="" width="949" height="306" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/05/Screenshot-from-2018-05-04-23-29-00.png 949w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/Screenshot-from-2018-05-04-23-29-00-300x97.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/Screenshot-from-2018-05-04-23-29-00-768x248.png 768w" sizes="auto, (max-width: 949px) 100vw, 949px" /><figcaption id="caption-attachment-2481" class="wp-caption-text">Isi form sesuai dengan yang saya tuliskan di atas</figcaption></figure>
<figure id="attachment_2482" aria-describedby="caption-attachment-2482" style="width: 685px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-2482 size-full" src="http://blog.goreinnamah.com/wp-content/uploads/2018/05/14.png" alt="" width="685" height="326" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/05/14.png 685w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/14-300x143.png 300w" sizes="auto, (max-width: 685px) 100vw, 685px" /><figcaption id="caption-attachment-2482" class="wp-caption-text">Setelah menekan tombol import CA keystore, CA pun akan muncul</figcaption></figure>
<h3 style="text-align: justify;"><strong>Renew CA</strong></h3>
<p style="text-align: justify;">Kita bisa me-<em>renew </em>CA dengan 2 cara yaitu:</p>
<ul style="text-align: justify;">
<li>Hanya me-<em>renew </em>sertifikatnya saja, menggunakan <em>key </em>yang sama.</li>
<li>me-<em>renew </em>sertifikat dan key-nya.</li>
</ul>
<p style="text-align: justify;">Untuk me-<em>renew </em>hanya sertifikat CA dengan menggunakan <em>key </em>yang sama, cukup tekan <strong>Renew CA. </strong>CA harus dalam keadaan <em>on-line </em>sehingga CA bisa memberi <em>sign </em>atas terbitnya sertifikat baru tersebut jika CA tersebut merupakan <em>self signed </em>atau CA bisa menandatangani permintaan sertifikat baru jika itu adalah <strong>SUBCA. </strong></p>
<p style="text-align: justify;">Jika permintaan sertifikat ini adalah untuk SUBCA dengan ROOTCA yang berada dalam satu EJBCA, ROOTCA harus dalam keadaan <em>on-line.</em></p>
<figure id="attachment_2484" aria-describedby="caption-attachment-2484" style="width: 685px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-2484 size-full" src="http://blog.goreinnamah.com/wp-content/uploads/2018/05/15.png" alt="" width="685" height="326" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/05/15.png 685w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/15-300x143.png 300w" sizes="auto, (max-width: 685px) 100vw, 685px" /><figcaption id="caption-attachment-2484" class="wp-caption-text">Pilih CA yang ingin di renew sertifikatnya</figcaption></figure>
<figure id="attachment_2485" aria-describedby="caption-attachment-2485" style="width: 635px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-2485" src="http://blog.goreinnamah.com/wp-content/uploads/2018/05/Screenshot-from-2018-05-04-23-43-24.png" alt="" width="635" height="202" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/05/Screenshot-from-2018-05-04-23-43-24.png 635w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/Screenshot-from-2018-05-04-23-43-24-300x95.png 300w" sizes="auto, (max-width: 635px) 100vw, 635px" /><figcaption id="caption-attachment-2485" class="wp-caption-text">Biarkan Next CA Key berisi Key yang lama dan tekan renew CA</figcaption></figure>
<figure id="attachment_2486" aria-describedby="caption-attachment-2486" style="width: 702px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-2486" src="http://blog.goreinnamah.com/wp-content/uploads/2018/05/16.png" alt="" width="702" height="317" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/05/16.png 702w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/16-300x135.png 300w" sizes="auto, (max-width: 702px) 100vw, 702px" /><figcaption id="caption-attachment-2486" class="wp-caption-text">Renew Sertifikat CA berhasil</figcaption></figure>
<p style="text-align: justify;">Untuk me-<em>renew </em>CA keys, atur <strong>Next CA key </strong>dengan <strong>Generate new key using KeySequence. </strong>kalau sudah, maka kita hanya perlu menekan tombol <strong>Renew CA. </strong>Proses <em>renew key </em>ini tidak selalu berhasil jika kita menggunakan HSM. Bisa saja cara ini berguna bagi suatu HSM tapi tidak dengan yang lainnya. (silahkan melapor ke EJBCA kalau terjadi kegagalan).</p>
<p style="text-align: justify;">Ketika menggunakan HSM, kita bisa me-<em>renew key </em>secara manual. Caranya cukup men-<em>generate </em>key baru di HSM dengan menggunakan <em>tools apapun </em>yang kita gunakan di awal (lebih baik menggunakan <strong>EJBCA CLI Tools</strong>) dan memilih <em>key </em>baru sebagai <strong>Next CA Key. </strong>Tekan tombol <strong>Renew CA </strong>untuk men-generate sertifikat CA yang baru.</p>
<figure id="attachment_2488" aria-describedby="caption-attachment-2488" style="width: 601px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-2488 size-full" src="http://blog.goreinnamah.com/wp-content/uploads/2018/05/Screenshot-from-2018-05-05-00-15-17.png" alt="" width="601" height="202" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/05/Screenshot-from-2018-05-05-00-15-17.png 601w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/Screenshot-from-2018-05-05-00-15-17-300x101.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/Screenshot-from-2018-05-05-00-15-17-600x202.png 600w" sizes="auto, (max-width: 601px) 100vw, 601px" /><figcaption id="caption-attachment-2488" class="wp-caption-text">Pilih Generate Key Using new Sequence</figcaption></figure>
<figure id="attachment_2486" aria-describedby="caption-attachment-2486" style="width: 702px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-2486 size-full" src="http://blog.goreinnamah.com/wp-content/uploads/2018/05/16.png" alt="" width="702" height="317" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/05/16.png 702w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/16-300x135.png 300w" sizes="auto, (max-width: 702px) 100vw, 702px" /><figcaption id="caption-attachment-2486" class="wp-caption-text">Renew Key CA berhasil</figcaption></figure>
<figure id="attachment_2489" aria-describedby="caption-attachment-2489" style="width: 592px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-2489 size-full" src="http://blog.goreinnamah.com/wp-content/uploads/2018/05/Screenshot-from-2018-05-05-00-15-42.png" alt="" width="592" height="130" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/05/Screenshot-from-2018-05-05-00-15-42.png 592w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/Screenshot-from-2018-05-05-00-15-42-300x66.png 300w" sizes="auto, (max-width: 592px) 100vw, 592px" /><figcaption id="caption-attachment-2489" class="wp-caption-text">Sekarang CA sudah menggunakan Key baru</figcaption></figure>
<h3 class="heading " style="text-align: justify;">Remove and Restore CA Soft Keystore</h3>
<p style="text-align: justify;"><em>Soft Token CA </em>bisa dihapus dari <em>database. </em>Ketika <em>keystore </em>dihapus, CA tidak bisa mengeluarkan sertifikat dan status CA Token menjadi <strong>offline.</strong></p>
<p style="text-align: justify;">Untuk menghapus catoken keys dari CA i<strong>mporCA, </strong>jalankan perintah berikut pada direktori <strong>$EJBCA_HOME:</strong></p>
<pre><span style="color: #ff0000;"><strong>$ sh bin/ejbca.sh ca removekeystore imporCA</strong></span></pre>
<figure id="attachment_2493" aria-describedby="caption-attachment-2493" style="width: 586px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-2493" src="http://blog.goreinnamah.com/wp-content/uploads/2018/05/Screenshot-from-2018-05-05-00-25-53.png" alt="" width="586" height="42" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/05/Screenshot-from-2018-05-05-00-25-53.png 586w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/Screenshot-from-2018-05-05-00-25-53-300x22.png 300w" sizes="auto, (max-width: 586px) 100vw, 586px" /><figcaption id="caption-attachment-2493" class="wp-caption-text">remove keystore</figcaption></figure>
<figure id="attachment_2494" aria-describedby="caption-attachment-2494" style="width: 703px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-2494 size-full" src="http://blog.goreinnamah.com/wp-content/uploads/2018/05/17.png" alt="" width="703" height="328" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/05/17.png 703w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/17-300x140.png 300w" sizes="auto, (max-width: 703px) 100vw, 703px" /><figcaption id="caption-attachment-2494" class="wp-caption-text">Status CA berubah offline</figcaption></figure>
<p style="text-align: justify;">Untuk me<em>-restore </em>catoken key kembali, dengan menggunakan file .p12 yang sudah diekspor sebelumnya, jalankan perintah berikut pada direktori <strong>$EJBCA_HOME:</strong></p>
<pre><span style="color: #ff0000;"><strong>$ sh bin/ejbca.sh ca restorekeystore imporCA /home/jboss/imporCA.p12 -s SignatureKeyAlias -e EncryptionKeyAlias</strong></span></pre>
<figure id="attachment_2495" aria-describedby="caption-attachment-2495" style="width: 1015px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-2495 size-full" src="http://blog.goreinnamah.com/wp-content/uploads/2018/05/Screenshot-from-2018-05-05-00-38-44.png" alt="" width="1015" height="41" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/05/Screenshot-from-2018-05-05-00-38-44.png 1015w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/Screenshot-from-2018-05-05-00-38-44-300x12.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/Screenshot-from-2018-05-05-00-38-44-768x31.png 768w" sizes="auto, (max-width: 1015px) 100vw, 1015px" /><figcaption id="caption-attachment-2495" class="wp-caption-text">restore keystore</figcaption></figure>
<figure id="attachment_2496" aria-describedby="caption-attachment-2496" style="width: 886px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-2496 size-full" src="http://blog.goreinnamah.com/wp-content/uploads/2018/05/18.png" alt="" width="886" height="222" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/05/18.png 886w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/18-300x75.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/18-768x192.png 768w" sizes="auto, (max-width: 886px) 100vw, 886px" /><figcaption id="caption-attachment-2496" class="wp-caption-text">Untuk mengaktifkan kembali status yang offline, centang keepactive dan healthcheck lalu tekan apply</figcaption></figure>
<h3 style="text-align: justify;"><strong>Revoke CA</strong></h3>
<p style="text-align: justify;">Jika kita ingin me-<em>revoke </em>sebuah CA, kita hanya perlu mengaahkan kursor ke<strong> Certification Authorities </strong>yang ada pada <strong>admin GUI. </strong>Pada CA yang kamu inginkan, tekan <strong>edit </strong>dan pada bagian <strong>CA Life Cycle, </strong>Pilih <strong>revoke</strong><strong>.</strong></p>
<figure id="attachment_2476" aria-describedby="caption-attachment-2476" style="width: 928px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-2476 size-full" src="http://blog.goreinnamah.com/wp-content/uploads/2018/05/11.png" alt="" width="928" height="448" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/05/11.png 928w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/11-300x145.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/11-768x371.png 768w" sizes="auto, (max-width: 928px) 100vw, 928px" /><figcaption id="caption-attachment-2476" class="wp-caption-text">ImporCA masih berstatus aktif dan kita akan mengeditnya</figcaption></figure>
<figure id="attachment_2497" aria-describedby="caption-attachment-2497" style="width: 444px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-2497 size-full" src="http://blog.goreinnamah.com/wp-content/uploads/2018/05/Screenshot-from-2018-05-05-01-00-04.png" alt="" width="444" height="83" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/05/Screenshot-from-2018-05-05-01-00-04.png 444w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/Screenshot-from-2018-05-05-01-00-04-300x56.png 300w" sizes="auto, (max-width: 444px) 100vw, 444px" /><figcaption id="caption-attachment-2497" class="wp-caption-text">Revoke CA dengan alasan Key telah dicuri</figcaption></figure>
<figure id="attachment_2498" aria-describedby="caption-attachment-2498" style="width: 719px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-2498 size-full" src="http://blog.goreinnamah.com/wp-content/uploads/2018/05/19.png" alt="" width="719" height="330" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/05/19.png 719w, https://blog.goreinnamah.com/wp-content/uploads/2018/05/19-300x138.png 300w" sizes="auto, (max-width: 719px) 100vw, 719px" /><figcaption id="caption-attachment-2498" class="wp-caption-text">statusnya sekarang sudah di revoke</figcaption></figure>
<p style="text-align: justify;">Ketika melakukan <em>revoke, </em>ada beberapa hal yang perlu diperhatikan:</p>
<ul style="text-align: justify;">
<li>Jika kita me-<em>revoke </em><strong>ROOTCA</strong>, maka kita akan me-<em>revoke </em>semua sertifikat yang ada di database yang dikeluarkan oleh ROOTCA tersebut, dan membuat CRL.</li>
<li>Jika kita me-<em>revoke </em><strong>SUBCA, </strong>maka kita akan me-<em>revoke </em>semua sertifikat di database yang dikeluarkan oleh SUBCA tersebut, SUBCA itu sendiri dan membuat CRL. Ini terjadi secara otomatis jika SUBCA dan ROOTCA ditangani oleh instance EJBCA yang sama. Jika SUBCA ditandatangani oleh <strong>external CA, </strong>sertifikat SUBCA harus di-revoke oleh external CA yang menandatanganinya.</li>
<li>Jika kita me-<em>revoke </em>external CA, sertifikat dari external CA tersebut akan di-<em>revoke </em>dan ditempatkan pada CRL dari CA yang menerbitkannya.</li>
</ul>
<p style="text-align: justify;">Yup, itu tadi sedikit tulisan mengenai cara mengelola CA pada EJBCA 6.10.1.2. Semoga bisa membantu ya <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f642.png" alt="🙂" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
<h4 style="text-align: justify;"><em><strong>sumber: <a href="https://www.ejbca.org/docs/Managing_CAs.html">EJBCA Docs</a></strong></em></h4><p>The post <a href="https://blog.goreinnamah.com/blog/2018/05/05/mengelola-ca-pada-ejbca-6-10-1-2/">Cara Mengelola CA pada EJBCA 6.10.1.2</a> first appeared on <a href="https://blog.goreinnamah.com">GoBlog</a>.</p>]]></content:encoded>
					
					<wfw:commentRss>https://blog.goreinnamah.com/blog/2018/05/05/mengelola-ca-pada-ejbca-6-10-1-2/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
			</item>
		<item>
		<title>Menambahkan Validation Authority pada EJBCA 6.2.0</title>
		<link>https://blog.goreinnamah.com/blog/2017/02/01/menambahkan-validation-authority-pada-ejbca/</link>
					<comments>https://blog.goreinnamah.com/blog/2017/02/01/menambahkan-validation-authority-pada-ejbca/#comments</comments>
		
		<dc:creator><![CDATA[Darius Go Reinnamah]]></dc:creator>
		<pubDate>Wed, 01 Feb 2017 08:00:50 +0000</pubDate>
				<category><![CDATA[Information Technology]]></category>
		<category><![CDATA[Certification Authority]]></category>
		<category><![CDATA[ejbca]]></category>
		<category><![CDATA[jboss]]></category>
		<category><![CDATA[ocsp]]></category>
		<category><![CDATA[ocsp properties]]></category>
		<category><![CDATA[ocsp responder]]></category>
		<category><![CDATA[subca]]></category>
		<category><![CDATA[VA]]></category>
		<category><![CDATA[va properties]]></category>
		<category><![CDATA[va publisher]]></category>
		<category><![CDATA[validation authority]]></category>
		<guid isPermaLink="false">http://blog.goreinnamah.com/?p=295</guid>

					<description><![CDATA[<p>Sebelum memulai tahap ini, pastikan bahwa Management CA sudah terinstal dan berjalan dengan baik (Baca cara instalasi EJBCA disini). Setelah[...]</p>
<p>The post <a href="https://blog.goreinnamah.com/blog/2017/02/01/menambahkan-validation-authority-pada-ejbca/">Menambahkan Validation Authority pada EJBCA 6.2.0</a> first appeared on <a href="https://blog.goreinnamah.com">GoBlog</a>.</p>]]></description>
										<content:encoded><![CDATA[<p style="text-align: justify;">Sebelum memulai tahap ini, pastikan bahwa Management CA sudah terinstal dan berjalan dengan baik (Baca cara instalasi EJBCA <a href="http://blog.goreinnamah.com/blog/2017/01/27/instalasi-ejbca-6-2-0-pada-jboss-7-1-1-dan-ubuntu-16-04/"><strong>disini</strong></a>). Setelah sudah yakin kalau Management CA berjalan dengan baik, barulah kita bisa menambahkan fungsi validasi kepada server kita. Untuk proses validasi ini, Primekey memasukkan setiap proses yang  melakukan validasi sertifikat (CMP, OCSP, Distribusi CRL) sebagai bagian dari &#8220;Validation Authority&#8221;.</p>
<p style="text-align: justify;">Merujuk pada Diagram Layout logical ASCII berikut:</p>
<figure id="attachment_301" aria-describedby="caption-attachment-301" style="width: 849px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-301" src="http://blog.goreinnamah.com/wp-content/uploads/2017/01/1-layout-ASCII.png" alt="" width="849" height="178" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/01/1-layout-ASCII.png 849w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/1-layout-ASCII-300x63.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/1-layout-ASCII-768x161.png 768w" sizes="auto, (max-width: 849px) 100vw, 849px" /><figcaption id="caption-attachment-301" class="wp-caption-text">pic via ejbcacentos</figcaption></figure>
<p style="text-align: justify;">Apa yang tidak diperlihatkan oleh diagram ini adalah <strong>VA (Validation Authority)</strong> memiliki datasource Jboss tersendiri yang berbeda dari datasource yang digunakan oleh <strong>CA (Certifictaion Authority)</strong>. Namun, dalam environment standalone, koneksi ini mengarah ke database yang sama (database ejbca) yang digunakan oleh <strong>CA</strong>.</p>
<ul style="text-align: justify;">
<li style="text-align: justify;">Mendfinisikan datasource <strong>VA</strong> adalah tujuan utama dari file <strong>va-publisher.properties</strong> (file berada di /<strong>opt/ejbca/conf/</strong> setelah di copy dari <strong>/opt/ejbca/conf/sample/</strong>).</li>
<li style="text-align: justify;">seperti datasource <strong>CA</strong>, konfigurasi datasource <strong>VA</strong> juga akan ditambahkan ke dalam file <strong>standalone.xml</strong> selama deployment. (setelah file<strong> . properties</strong> yang spesifik dengan VA dibuat).</li>
<li style="text-align: justify;">Perlu dicatat bagaimana PrimeKey menggunakan istilah &#8220;Publisher&#8221;. Publisher ini digunakan untuk menggambarkan gagasan tentang informasi dari komponen &#8220;publishing&#8221; EJBCA (dari sebuah datasource) ke sebuah server terpisah pada sebuah instalasi EJBCA yang terdistribusi.</li>
<li style="text-align: justify;">Misalkan server standalone kita hanya &#8220;publishing&#8221; ke service VA-nya sendiri , kita masih membutuhkan &#8220;publisher&#8221; untuk dimasukkan dalam <strong>va-publisher.properties</strong>.</li>
<li style="text-align: justify;">file <strong>va.properties</strong> menjelaskan operasi VA secara umum seperti fungsi pemeriksaan kesehatan (<strong>healthcheck</strong>).</li>
<li style="text-align: justify;">file <strong>ocsp.properties</strong> mendefinisikan fungsionalitas protokol <strong>OCSP</strong>.</li>
<li style="text-align: justify;">File <strong>va.properties</strong> berisi instruksi spesifik bagaimana mengizinkan download <strong>CRL/OCSP</strong> alias untuk beberapa (multiple) instance CA.</li>
</ul>
<p style="text-align: justify;">Langkah pertama untuk menjalankan VA adalah membuat file-file properties yang terkait validasi pada direktori <strong>/opt/ejbca/conf</strong>. caranya:</p>
<pre><strong>cd /opt/ejbca/conf
</strong><strong>cp sample/ocsp.properties.sample ocsp.properties
</strong><strong>cp sample/va.properties.sample va.properties
</strong><strong>cp sample/va-publisher.properties.sample va-publisher.properties</strong></pre>
<h2 style="text-align: justify;"><strong>Konfigurasi file-file Validation Authority</strong></h2>
<h3 style="text-align: justify;"><strong>ocsp.properties</strong></h3>
<pre><strong>### Start ocsp.properties ###</strong>
 
<strong> # ------------ OCSP responder configuration ---------------------</strong>
 
<span style="color: #ff0000;"><strong> ocsp.enabled=true</strong></span>
<strong> #ocsp.enabled=false</strong>
 
<strong> # ini path untuk URL OCSP</strong>
<span style="color: #ff0000;"><strong> ocsp.contextroot=/ejbca/publicweb/status</strong></span>
<strong> #ocsp.contextroot=/status</strong>
 
<strong> # ini adalah DN dari CA yang akan merespon untuk serifikat yang gak dikenal</strong>
<span style="color: #ff0000;"><strong> ocsp.defaultresponder=CN=NamaCALo,O=PerusahaanLo,C=ID</strong></span>
 
<span style="color: #ff0000;"><strong> ocsp.includecertchain=true</strong></span>
<span style="color: #ff0000;"><strong> ocsp.includesignercert=true</strong></span>
<span style="color: #ff0000;"><strong> ocsp.responderidtype=keyhash</strong></span>
<span style="color: #ff0000;"><strong> ocsp.signaturealgorithm=SHA1WithRSA;SHA1WithECDSA;SHA1WithDSA</strong></span>
<span style="color: #ff0000;"><strong> ocsp.signingCertsValidTime=300</strong></span>
<span style="color: #ff0000;"><strong> ocsp.warningBeforeExpirationTime=10000</strong></span>
 
<span style="color: #ff0000;"><strong> ocsp.nonexistingisgood=false</strong></span>
 
<strong> #ocsp.nonexistingisgood.uri.1=.*/thisEndingIsGood$</strong>
<strong> #ocsp.nonexistingisgood.uri.2=^http://good.myhost.nu:8080/.*</strong>
<strong> #ocsp.nonexistingisbad.uri.1=.*/thisEndingIsBad$</strong>
<strong> #ocsp.nonexistingisbad.uri.2=^http://bad.myhost.nu:8080/.*</strong>
<span style="color: #ff0000;"><strong> ocsp.nonexistingisrevoked=false</strong></span>
<strong> #ocsp.nonexistingisrevoked.uri.1=.*/thisEndingIsRevoked$</strong>
<strong> #ocsp.nonexistingisrevoked.uri.2=^http://revoked.myhost.nu:8080/.*</strong>
 
<span style="color: #ff0000;"><strong> ocsp.expiredcert.retentionperiod = 31536000</strong></span>
<strong> #ocsp.expiredcert.retentionperiod = -1</strong>
 
<span style="color: #ff0000;"><strong> ocsp.untilNextUpdate = 0</strong></span>
<strong> #ocsp.999.untilNextUpdate = 50</strong>
<span style="color: #ff0000;"><strong> ocsp.revoked.untilNextUpdate = 0</strong></span>
<strong> #ocsp.999.revoked.untilNextUpdate = 50</strong>
<span style="color: #ff0000;"><strong> ocsp.maxAge = 30</strong></span>
<strong> #ocsp.999.maxAge = 100</strong>
<span style="color: #ff0000;"><strong> ocsp.revoked.maxAge = 30</strong></span>
<strong> #ocsp.999.revoked.maxAge = 100</strong>
 
<strong> #ocsp.extensionoid=</strong>
<strong> #ocsp.extensionclass=</strong>
 
<strong> #ocsp.uniddatsource=</strong>
<strong> #ocsp.unidtrustdir=</strong>
<strong> #ocsp.unidcacert=</strong>
<strong> #ocsp.signaturerequired=false</strong>
 
<strong> #ocsp.rekeying.trigging.password=</strong>
<strong> #ocsp.rekeying.wsurl = https://milton:8443/ejbca/ejbcaws/ejbcaws</strong>
<strong> #ocsp.rekeying.update.time.in.seconds=</strong>
<strong> #ocsp.rekeying.safety.margin.in.seconds=</strong>
<strong> #ocsp.rekeying.trigging.hosts=</strong>
 
<strong> # Default: false</strong>
<span style="color: #ff0000;"><strong> ocsp.trx-log = true</strong></span>
<span style="color: #ff0000;"><strong> ocsp.log-date = yyyy-MM-dd:HH:mm:ss:z</strong></span>
<strong> #ocsp.log-timezone = GMT</strong>
<strong> #ocsp.trx-log-pattern = \\$\\{(.+?)\\}</strong>
<strong> # The next line will probably line-wrap in your browser:</strong>
<strong> #ocsp.trx-log-order = ${SESSION_ID};${LOG_ID};${STATUS};${REQ_NAME}"${CLIENT_IP}";"${SIGN_ISSUER_NAME_DN}";"${SIGN_SUBJECT_NAME}";${SIGN_SERIAL_NO};"${LOG_TIME}";${REPLY_TIME};${PROCESS_TIME};${NUM_CERT_ID};0;0;0;0;0;0;0;"${ISSUER_NAME_DN}";${ISSUER_NAME_HASH};${ISSUER_KEY};${DIGEST_ALGOR};${SERIAL_NOHEX};${CERT_STATUS}</strong>
 
<span style="color: #ff0000;"><strong> ocsp.audit-log = true</strong></span>
<strong> #ocsp.audit-log-pattern = \\$\\{(.+?)\\}</strong>
<strong> # The next line will probably line-wrap in your browser:</strong>
<strong> #ocsp.audit-log-order = SESSION_ID:${SESSION_ID};LOG ID:${LOG_ID};"${LOG_TIME}";REPLY TIME:${REPLY_TIME};\nTIME TO PROCESS:${PROCESS_TIME};\nOCSP REQUEST:\n"${OCSPREQUEST}";\nOCSP RESPONSE:\n"${OCSPRESPONSE}";\nSTATUS:${STATUS}</strong>
<strong> #ocsp.log-safer = true</strong>
 
 
<strong> ### End ocsp.properties ###</strong></pre>
<figure id="attachment_309" aria-describedby="caption-attachment-309" style="width: 1010px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-309" src="http://blog.goreinnamah.com/wp-content/uploads/2017/01/3-ocsp-properties.png" alt="" width="1010" height="483" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/01/3-ocsp-properties.png 1010w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/3-ocsp-properties-300x143.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/3-ocsp-properties-768x367.png 768w" sizes="auto, (max-width: 1010px) 100vw, 1010px" /><figcaption id="caption-attachment-309" class="wp-caption-text">ocsp.properties 1</figcaption></figure>
<figure id="attachment_311" aria-describedby="caption-attachment-311" style="width: 1011px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-311" src="http://blog.goreinnamah.com/wp-content/uploads/2017/01/4-ocsp-properties.png" alt="" width="1011" height="667" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/01/4-ocsp-properties.png 1011w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/4-ocsp-properties-300x198.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/4-ocsp-properties-768x507.png 768w" sizes="auto, (max-width: 1011px) 100vw, 1011px" /><figcaption id="caption-attachment-311" class="wp-caption-text">ocsp.properties 2</figcaption></figure>
<figure id="attachment_312" aria-describedby="caption-attachment-312" style="width: 1010px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-312" src="http://blog.goreinnamah.com/wp-content/uploads/2017/01/5-ocsp-properties.png" alt="" width="1010" height="652" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/01/5-ocsp-properties.png 1010w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/5-ocsp-properties-300x194.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/5-ocsp-properties-768x496.png 768w" sizes="auto, (max-width: 1010px) 100vw, 1010px" /><figcaption id="caption-attachment-312" class="wp-caption-text">ocsp.properties 3</figcaption></figure>
<figure id="attachment_314" aria-describedby="caption-attachment-314" style="width: 1010px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-314" src="http://blog.goreinnamah.com/wp-content/uploads/2017/02/6-ocsp-properties.png" alt="" width="1010" height="612" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/02/6-ocsp-properties.png 1010w, https://blog.goreinnamah.com/wp-content/uploads/2017/02/6-ocsp-properties-300x182.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2017/02/6-ocsp-properties-768x465.png 768w" sizes="auto, (max-width: 1010px) 100vw, 1010px" /><figcaption id="caption-attachment-314" class="wp-caption-text">ocsp.properties 4</figcaption></figure>
<figure id="attachment_315" aria-describedby="caption-attachment-315" style="width: 1010px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-315" src="http://blog.goreinnamah.com/wp-content/uploads/2017/02/7-ocsp-properties.png" alt="" width="1010" height="543" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/02/7-ocsp-properties.png 1010w, https://blog.goreinnamah.com/wp-content/uploads/2017/02/7-ocsp-properties-300x161.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2017/02/7-ocsp-properties-768x413.png 768w" sizes="auto, (max-width: 1010px) 100vw, 1010px" /><figcaption id="caption-attachment-315" class="wp-caption-text">ocsp.properties 5</figcaption></figure>
<figure id="attachment_316" aria-describedby="caption-attachment-316" style="width: 1010px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-316" src="http://blog.goreinnamah.com/wp-content/uploads/2017/02/8-ocsp-properties.png" alt="" width="1010" height="666" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/02/8-ocsp-properties.png 1010w, https://blog.goreinnamah.com/wp-content/uploads/2017/02/8-ocsp-properties-300x198.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2017/02/8-ocsp-properties-768x506.png 768w" sizes="auto, (max-width: 1010px) 100vw, 1010px" /><figcaption id="caption-attachment-316" class="wp-caption-text">ocsp.properties 6</figcaption></figure>
<h3 style="text-align: justify;"><strong>va.properties</strong></h3>
<pre><strong>### Start va.properties ###</strong>
 
<strong> #------------------- Validation Authority (VA) Healthcheck settings -------------</strong>
<span style="color: #ff0000;"><strong> ocsphealthcheck.signtest=true</strong></span>
<span style="color: #ff0000;"><strong> ocsphealthcheck.checkSigningCertificateValidity=true</strong></span>
 
 
<strong> # PrimeKey's instructions here are particularly terrible. Let me see if I can translate:</strong>
 
<strong> # In this last setting, we will define an alias 'root' for a particular RFC 4985 Section 2.1 "Search Key ID Hash" or "sKIDHash"</strong>
<strong> # Our example sKIDHash is:'O4RdnGNf3WPioslAQsX71aR1/MI'</strong>
<strong> # sKIDHashes are unique to each CA instance that you run on your ejbca server.</strong>
 
<strong> # This has the effect of making the following URLs equivalent. This simplifies the entries in your certificates that specify</strong>
<strong> # CRL/OCSP download locations, and grants the ability to have simultaneous CRL/OCSP download URLs</strong>
<strong> # Typically, you will define a unique sKIDHash alias for each of your CA instances.</strong>
 
<strong> # Example URL for certificate search: http://myhost.com:8080/certificates/search.cgi?sKIDHash=O4RdnGNf3WPioslAQsX71aR1/MI</strong>
<strong> # This will be the same as http://myhost.com:8080/certificates/search.cgi?alias=root</strong>
 
<strong> # Example URL for CRL download: http://myhost.com:8080/crls/search.cgi?sKIDHash=O4RdnGNf3WPioslAQsX71aR1/MI</strong>
<strong> # is the same as http://myhost.com:8080/crls/search.cgi?alias=root</strong>
 
<strong> # Example URL for Delta CRL download: http://myhost.com:8080/crls/search.cgi?sKIDHash=O4RdnGNf3WPioslAQsX71aR1/MI&amp;delta=</strong>
<strong> # is the same as http://myhost.com:8080/crls/search.cgi?alias=root&amp;delta=</strong>
 
 
<strong> # To determine the hash to use here, navigate to http://yourhost.com:8080/crls/search.cgi or http://yourhost.com:8080/certificates/search.cgi</strong>
<strong> # (Omit the :8080 if you are browsing from somewhere other than localhost)</strong>
<strong> # This URL will give you a list of the unique validation identifiers (including the sKIDHash) for each of your defined CAs.</strong>
 
<strong> # Copy the sKIDHashes for the CA instances. Remember, you will have more than one, and you can omit the Management CA as it is solely internal to ejbca.</strong>
<strong> # Add an entry like the one below for each of your CAs, paste the sKIDHash into the entry, then redeploy ejbca.</strong>
 
 
<strong> #va.sKIDHash.alias.root=O4RdnGNf3WPioslAQsX71aR1/MI</strong>
 
<strong> ### End va.properties ###
</strong></pre>
<figure id="attachment_317" aria-describedby="caption-attachment-317" style="width: 1185px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-317" src="http://blog.goreinnamah.com/wp-content/uploads/2017/02/8-va-properties-1.png" alt="" width="1185" height="265" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/02/8-va-properties-1.png 1185w, https://blog.goreinnamah.com/wp-content/uploads/2017/02/8-va-properties-1-300x67.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2017/02/8-va-properties-1-768x172.png 768w, https://blog.goreinnamah.com/wp-content/uploads/2017/02/8-va-properties-1-1024x229.png 1024w" sizes="auto, (max-width: 1185px) 100vw, 1185px" /><figcaption id="caption-attachment-317" class="wp-caption-text">va.properties</figcaption></figure>
<h3 style="text-align: justify;"><strong>va-publisher.properties</strong></h3>
<pre><strong>Start va-publisher.properties ###
 
 #-------------- Validation Authority(VA) publisher db configuration-------------------------
 # All the "ocsp-database.*" properties are used to configure the VA connection to the database.
 #
 # In "PrimeKeyese": Configure these options if you are configuring EJBCA that will publish 
 # certificates to a VA.
 
 
<span style="color: #ff0000;"> ocsp-datasource.jndi-name=OcspDS</span>
<span style="color: #ff0000;"> ocsp-database.url=jdbc:mysql://127.0.0.1:3306/ejbcadb?characterEncoding=UTF-8</span>
<span style="color: #ff0000;"> ocsp-database.driver=com.mysql.jdbc.Driver</span>
<span style="color: #ff0000;"> ocsp-database.username=ejbcadbuser</span>
 
 
 # password Databasenya diatur di sini
 <span style="color: #ff0000;">ocsp-database.password=asalaja</span>
 
 ### End va-publisher.properties ###
</strong></pre>
<figure id="attachment_319" aria-describedby="caption-attachment-319" style="width: 918px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-319" src="http://blog.goreinnamah.com/wp-content/uploads/2017/02/9-va-publisher.png" alt="" width="918" height="477" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/02/9-va-publisher.png 918w, https://blog.goreinnamah.com/wp-content/uploads/2017/02/9-va-publisher-300x156.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2017/02/9-va-publisher-768x399.png 768w" sizes="auto, (max-width: 918px) 100vw, 918px" /><figcaption id="caption-attachment-319" class="wp-caption-text">va-publisher.properties</figcaption></figure>
<p style="text-align: justify;">Untuk membuat VA berjalan, kita perlu mengeksekusi beberapa perintah yang sama sebelum kita melakukan deployment awal:</p>
<pre><strong>su - jboss
</strong><strong>cd /opt/jboss/bin
</strong><strong>ps -ax | grep jboss
</strong><strong>kill -9 &lt;proses_jboss&gt;
</strong><strong>chown -R jboss:jboss /opt/jboss-as-7.1.1.Final
</strong><strong>chown -R jboss:jboss /opt/ejbca_ce_6_2_0
</strong><strong>nohup ./standalone.sh -b 0.0.0.0 -bmanagement=0.0.0.0 &amp;</strong>
<strong>cd /opt/ejbca</strong>
<strong>ant deploy</strong></pre>
<figure id="attachment_322" aria-describedby="caption-attachment-322" style="width: 751px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-322" src="http://blog.goreinnamah.com/wp-content/uploads/2017/02/10-build-success.png" alt="" width="751" height="156" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/02/10-build-success.png 751w, https://blog.goreinnamah.com/wp-content/uploads/2017/02/10-build-success-300x62.png 300w" sizes="auto, (max-width: 751px) 100vw, 751px" /><figcaption id="caption-attachment-322" class="wp-caption-text">hasil ant deploy jika berhasil (Validation Authority)</figcaption></figure>
<p style="text-align: justify;">ingat bahwa dalam <strong>ocsp.properties</strong>, kita mendefinisikan &#8220;<strong>ocsp.defaultresponder</strong>&#8220;. Ini adalah DN dari CA yang akan menjawab permintaan OCSP untuk CA yang tidak diketahui. Primekey merekomendasikan agar kita menggunakan <strong>Management CA (Root CA)</strong> untuk ini. Namun, alangkah lebih baiknya bila kuta menggunakan <strong>default CA (Sub CA)</strong> untuk tujuan ini atau kita menggunakan Sebuah <strong>SubCA</strong> yang kita buat terlebih dahulu.</p>
<p style="text-align: justify;">sampai SubCA itu berhasil dibuat, kita akan melihat pesan berikut dalam console log (nohup.out):</p>
<figure id="attachment_323" aria-describedby="caption-attachment-323" style="width: 1352px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-323" src="http://blog.goreinnamah.com/wp-content/uploads/2017/02/11-ocsp-responder-.png" alt="" width="1352" height="55" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/02/11-ocsp-responder-.png 1352w, https://blog.goreinnamah.com/wp-content/uploads/2017/02/11-ocsp-responder--300x12.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2017/02/11-ocsp-responder--768x31.png 768w, https://blog.goreinnamah.com/wp-content/uploads/2017/02/11-ocsp-responder--1024x42.png 1024w" sizes="auto, (max-width: 1352px) 100vw, 1352px" /><figcaption id="caption-attachment-323" class="wp-caption-text">error Management CA saat pembuatan VA</figcaption></figure>
<p>dan terakhir, kalau terjadi masalah dengan file <strong>va-publisher.properties</strong> milik kita, mungkin kita akan melihat pesan berikut:</p>
<pre><strong>06:31:45,632 WARN  [org.ejbca.core.protocol.certificatestore.CertificateCache] (MSC service thread 1-2) org.bouncycastle.ocsp.OCSPException: problem creating ID: java.security.NoSuchProviderException: no such provider: BC</strong></pre>
<p>&#8220;BC&#8221; adalah <strong>Bouncycastle</strong> (OCSP Java Module)</p>
<p>&nbsp;</p>
<p>Itu tadi cara menambahkan Validation Authority ke dalam EJBCA. Untuk pengujian VA tersebut, nantikan postingan selanjutnya ya.</p>
<p>Adios!!!</p>
<h3><a href="http://ejbcacentos.blogspot.co.id/2014/04/how-to-install-ejbca-611-on-centos-65.html"><strong>Source: EJBCACENTOS</strong></a></h3><p>The post <a href="https://blog.goreinnamah.com/blog/2017/02/01/menambahkan-validation-authority-pada-ejbca/">Menambahkan Validation Authority pada EJBCA 6.2.0</a> first appeared on <a href="https://blog.goreinnamah.com">GoBlog</a>.</p>]]></content:encoded>
					
					<wfw:commentRss>https://blog.goreinnamah.com/blog/2017/02/01/menambahkan-validation-authority-pada-ejbca/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin

Object Caching 0/273 objects using Memcached
Page Caching using Disk: Enhanced 
Database Caching using Memcached (Request-wide modification query)

Served from: blog.goreinnamah.com @ 2026-09-28 19:44:17 by W3 Total Cache
-->