Post Reply Print view 3 posts • Page 1 of 1 wyoelect OpenVpn Newbie Posts: 4 Joined: Thu Jan 20, 2011 6:22 pm [SOLVED] "TXT_DB error number 2" on build-key.bat

vars 9. cd vpn/openvpn* ./openvpn server.conf echo 1 > /proc/sys/net/ipv4/ip_forward Step 5 - Give files to user Give the following four files to the user: client.ovpn ca.crt froos.key froos.crt Tell the user to Afterwards it booted... Please enter the following 'extra' attributes to be sent with your certificate request A challenge password []: An optional company name []: Using configuration from /home/tjnelson/vpn/openvpn-2.0.2/easy-rsa/openssl.cnf DEBUG[load_index]: unique_subject = "yes" Check

Subject: Re: [Openvpn-users] Build-key error TXT_DB error number 2 is a DB_ERROR_INDEX_CLASH. The important observation is that every certificate must have a unique CN in the database. While signing a certificate for a new OpenVPN user, I received the following error message which stops the whole process (exit code 1) Certificate is to be certified until Nov 6

While signing a certificate for a new OpenVPN user, I received the following error message which stops the whole process (exit code 1) Certificate is to be certified until Nov 6

Here's the sequence > of steps I followed for reference: > > > > Installed 2.1 RC14 > > Created configuration files for the server and client and stored them in Txt_db Error Number 2 Failed To Update Database See linuxsetup46.html , linuxsetup71.html , and linuxsetup54.html for more details. There was existing data in that index.txt file. Running 2.1.3 on Server 2000......

The way the prompt was written it looked like it was expecting that. (

At this site my desktop is Windows but I needed to c... Hoercher wrote: > seems to be DB_ERROR_INDEX_CLASH > Probably there's already an entry for your foo.csr (and no > no_unique_subject You're right, there is an entry for this domain because the Txt_db Error Number 2 Openssl At 10:17 Labels: cn, openssl, openvpn, txt_db error number 2 Newer Post Older Post Home Subscribe to: Post Comments (Atom) Translate Search This Blog Loading... Unique_subject = No Any insight would be appreciated.

If both servers are using the same CA, then your client should only need one certificate and it will be able to connect to either server. his comment is here copied the ServerName.crt and .key files as well as the dh1024.pem files to the config directory 12. Blog Archive ► 2009 (2) ► April (1) ► June (1) ► 2010 (8) ► April (4) ► May (2) ► October (2) ► 2011 (4) ► February (1) ► April Best Regards Marcin Przysowa Attachments (1) bug_gen_cert.txt​ (4.8 KB) - added by SiB 4 years ago. Openssl Revoke

Are you using different common names for different certs? I also had to set the directory explicitly in the Build files > so that it could locate the openssl.exe program in the Bin directory.) > vars > clean-all > build-ca I saw an earlier post stating that the client name cannot have any "-"'s in it, so I made sure to eliminate this potential issue. this contact form Worked ieio May 27, 2016 at 11:38 In case you need to sign two certificate with the same CM you can modify your database attr with unique_subject = no Manoj March

Unfortunately this also prevents the issuing of a new certificate before the existing certificate has expired which is often required so that a seam-less transition can be effected between one certificate Wrong Number Of Fields On Line 1 (looking For Field 6, Got 1, '' Left) I do not get this error when I run build-key-server. If you just want openconnect ready to run for RHEL/CentOS/clones, you can get openconnect 4.0...

KEY_CN=someuniqueclientcn ./pkitool client1and you willstop getting that TXT_DB error.

Are you using different common names for different certs? These differ from older versions in that the following lines are included in easy-rsa/2.0/vars: export KEY_CN=changeme export KEY_NAME=changeme export KEY_OU=changeme export PKCS11_MODULE_PATH=changeme export PKCS11_PIN=1234 Commenting these lines out leads to the In the documentation of the mysql v. 4.0.10 there is written aprocedure for building up the mysql with the support from openssl and alsoabout setting up SSL certificates for MySQL: DIR=`pwd`/openssl Openvpn Revoke Full On Wed, Nov 19, 2008 at 2:52 PM, Roy Lancraft wrote: > From: Roy Lancraft [mailto:[email protected]] > Sent: Wednesday, November 19, 2008 4:23 PM > To: [email protected] > Subject: Build-key

Either remove them by hand from the database, or properly revoke them using 'openssl ca -revoke xyz.crt' Why it fails with MySQL example, though, escapes me. You could edit vars before generating the client certificate and re-source vars, or you could do this before generating each client key. comment:1 Changed 4 years ago by SiB I still think that README.txt have error. navigate here I have edited the ca.db.index file and removed the entry for this domain, now it's works :-) Where did you get the constant DB_ERROR_INDEX_CLASH from ? -- Thomas Carrié http://thocar.org OpenSSL