Problem with easy-rsa and RANDFILE

This forum is for general conversation and user-user networking.

Moderators: TinCanTech, TinCanTech, TinCanTech, TinCanTech, TinCanTech, TinCanTech

Post Reply
BKiepke
OpenVpn Newbie
Posts: 2
Joined: Thu Aug 18, 2011 7:05 am

Problem with easy-rsa and RANDFILE

Post by BKiepke » Thu Aug 18, 2011 7:28 am

Hello,

I'm not quite sure if this is the right forum to ask such a question. If it is not redirect me to a suitable one, please.

To access our network from the outer world we want to use openvpn to provide a more secure access. To administrate all user accounts we want to use certificates and a self-build webinterface, which uses a database for handling the user/cert related infos at a higher level.

So the architecture of our software is as follows. The system where this is running on is GNU/Debian5. A supervisor will login to webinterface and provide relevant data of a user. The Webinterface is written in PHP5 and will call a bash script which is setup as a TCP-Server by using xinetd to create all certs based on the data provided by the supervisor. So far this works.

When i manually call the bash script everything works as expected. When the "webservice" calls the bash script than something went wrong.

This is the error message:

Code: Select all

20250:error:0906906F:PEM routines:PEM_ASN1_write_bio:read key:pem_lib.c:331: 
Googling for that shows up a possible solution. It is said that it is needed to set the $RANDFILE-Variable within a script or to set the option "-rand" when calling one of the scripts provided by easy-rsa.

I actually don't know where to set the $RANDFILE-Variable. I tried to change the one provided by openssl.cnf within the eays-rsa/2.0-directory but nothing changes. I also tried to set the parameter "-rand" within the pkitool-script but things get even worse.

Can someone give me a hint where to set the "-rand" parameter exactly, please?

greetings
benny

User avatar
janjust
Forum Team
Posts: 2703
Joined: Fri Aug 20, 2010 2:57 pm
Location: Amsterdam
Contact:

Re: Problem with easy-rsa and RANDFILE

Post by janjust » Thu Aug 18, 2011 8:39 am

try setting the env var RANDFILE in the 'vars' file - this is an openssl issue, not an openvpn issue. For details, read up here:
http://www.openssl.org/support/faq.cgi

BKiepke
OpenVpn Newbie
Posts: 2
Joined: Thu Aug 18, 2011 7:05 am

Re: Problem with easy-rsa and RANDFILE

Post by BKiepke » Thu Aug 18, 2011 9:25 am

Thanks for the hint.

I'd tried that but it didn't work. Will post a message in a forum related to openssl.

Thanks again for reply

greetings
Benny

User avatar
janjust
Forum Team
Posts: 2703
Joined: Fri Aug 20, 2010 2:57 pm
Location: Amsterdam
Contact:

Re: Problem with easy-rsa and RANDFILE

Post by janjust » Thu Aug 18, 2011 10:17 am

it would help if you showed exactly which command is failing ...

Post Reply