Categories:
DH Keys (39)
DSA Keys (72)
EC Keys (331)
Firefox (32)
General (13)
Google Chrome (25)
Intermediate CA (152)
Java VM (20)
JDK Keytool (25)
Microsoft CertUtil (26)
Mozilla CertUtil (18)
OpenSSL (237)
Other (17)
Portecle (38)
Publishers (1858)
Revoked Certificates (30)
Root CA (87)
RSA Keys (2168)
Tools (47)
Tutorial (7)
What Is (21)
Windows (129)
Collections:
Other Resources:
OpenSSL "ca" Error "lookup failed for ca::database"
Why I am getting the "variable lookup failed for ca::database" error when running OpenSSL "ca" command?
✍: FYIcenter.com
You are getting the "variable lookup failed for ca::database" error,
because OpenSSL "ca" command can not find the required "database" option
in the configuration file.
For example, if you have the follow configuration file, test.cnf, without "database" option defined:
C:\Users\fyicenter>type test.cnf # Unnamed section of generic options # section for the "default_ca" option [ca] default_ca = my_ca_default # default section for "ca" command options [my_ca_default] new_certs_dir = ./my_ca/certs
You will get an error, because "database" is a required option:
C:\Users\fyicenter>\local\OpenSSL-Win32\bin\openssl.exe OpenSSL> ca -in test.csr -keyfile my_ca.key -cert my_ca.crt -config test.cnf Using configuration from test.cnf Enter pass phrase for my_ca.key:fyicenter variable lookup failed for my_ca_default::database 2896:error:0E06D06C:configuration file routines:NCONF_get_string: no value:.\crypto\conf\conf_lib.c:324:group=my_ca_default name=database error in ca
Fixing this error is easy. Just add the "database" option in the section pointed by the "default_ca" option in the configuration file:
C:\Users\fyicenter>type test.cnf # Unnamed section of generic options # section for the "default_ca" option [ca] default_ca = my_ca_default # default section for "ca" command options [my_ca_default] new_certs_dir = ./my_ca/certs database = ./my_ca/certs.db
Remember to create empty file .\my_ca\certs.db, if it does not exist. This database file will be used to track each new certificate and revoked certificate.
⇒ OpenSSL "ca" Error "lookup failed for ca::default_md"
⇐ OpenSSL "ca" Error "... directory for new certificate ..."
2016-09-08, 9144👍, 0💬
Popular Posts:
What is a Java Keystore file? I heard that it used to provide CA certificates to Java applications. ...
What is the file name is used by Firefox to store CA certificates on Windows 7 systems? Where this f...
How to view general information of a certificate in a certificate store using "certmgr.msc"? You can...
Certificate Summary: Subject: login.yahoo.com Issuer: DigiCert High Assurance CA-3 Expiration: 2014-...
Where to find tutorials on managing certificate in Google Chrome? I want to learn how IE stores and ...