KCA gives invalid signature when approving certificate request
Originally Published: 2003-06-05
Last Modified: 2023-10-06
Article Number
Applies To
Microsoft Windows 2000 Server SP3
Certificate enrollment with a PKCS#10
Issue
Request does not give error on older versions of KCA
Cause
Attributes { ATTRIBUTE:IOSet } ::= SET OF Attribute{{ IOSet }}
The "Attributes" field is not marked as OPTIONAL, so it must be present. However, a "SET OF" can include zero or more elements. So, a properly constructed Certificate Request with no attributes will include the encoded SET OF with a zero length for the contents.
Historically, some PKI products (including earlier versions of the Keon Certificate Authority) have misinterpreted the standard and omitted the "Attributes" field when no attributes were present. This causes interoperability issues, and the issues have been fixed in later versions of KCA.
When attempting to import into KCA a PKCS#10 Certificate Request that omits the "Attributes" field, an error will be returned.
Resolution
Workaround
KCA 6.5 validates certificate request where older versions did not
Related Articles
RSA Governance & Lifecycle Sharepoint Connector Guide 8Number of Views RSA Governance & Lifecycle Lotus Notes Connector Guide 1Number of Views RSA Governance & Lifecycle Exchange SSH Connector Datasheet 59Number of Views RSA Governance & Lifecycle RACF SSH Connector Datasheet Guide 24Number of Views Weblogic agent (identity asserter) does not allow cookie name other than CTSESSION 21Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Reporting on RSA Authentication Manager 8.x users with On-Demand Token, a fixed passcode or a hardware/software token assi… How to Download OTP Token Seed Files from myRSA Anomalix idGenius - SAML Relying Party Configuration - RSA Ready Implementation Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?