<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Recent posts to Discussion</title><link>https://sourceforge.net/p/ejbca/discussion/</link><description>Recent posts to Discussion</description><atom:link href="https://sourceforge.net/p/ejbca/discussion/feed.rss" rel="self"/><language>en</language><lastBuildDate>Tue, 14 Apr 2026 08:01:20 -0000</lastBuildDate><atom:link href="https://sourceforge.net/p/ejbca/discussion/feed.rss" rel="self" type="application/rss+xml"/><item><title>Basic authentication after client certificate failure when attempting to access the EJBCA administrator interface.</title><link>https://sourceforge.net/p/ejbca/discussion/123123/thread/8b1bef47a0/?limit=50#6cc0</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;Discussions moved here. &lt;a href="https://github.com/Keyfactor/ejbca-ce/discussions" rel="nofollow"&gt;https://github.com/Keyfactor/ejbca-ce/discussions&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Tomas Gustavsson</dc:creator><pubDate>Tue, 14 Apr 2026 08:01:20 -0000</pubDate><guid>https://sourceforge.netd9833dae482c0bb9c1895cdde61a8a1287a382b7</guid></item><item><title>Basic authentication after client certificate failure when attempting to access the EJBCA administrator interface.</title><link>https://sourceforge.net/p/ejbca/discussion/123123/thread/8b1bef47a0/?limit=25#ad77</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;Hello, I am attempting to restore EJBCA CE 7.11.0 on an EC2 instance running Ubuntu. I am using WildFly version 25.0.0. The issue I am encountering is that, once I have completed the entire setup process, I am able to access the web interface via port 8442; however, when attempting to access it via port 8443, the browser (Chrome on Windows 10) prompts me to select a certificate. When I select the correct certificate, the authentication appears to fail, and the system switches to an alternative authentication method, asking me to enter a username and password instead. An important detail: if I provide an incorrect certificate, the connection is denied—as expected—so the problem specifically lies with the correct certificate. I suspect this issue may be related to the WildFly version, as I followed the exact same steps I previously used with version 24.0.1, and it worked correctly back then. Here are other troubleshooting steps I have tried, all of which resulted in the same behavior:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;I generated a new &lt;code&gt;superAdmin.p12&lt;/code&gt; file.&lt;/li&gt;
&lt;li&gt;I reviewed the logs and did not find anything unusual.&lt;/li&gt;
&lt;li&gt;I updated my web browser.&lt;/li&gt;
&lt;/ol&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Erlis Paula</dc:creator><pubDate>Mon, 13 Apr 2026 20:13:49 -0000</pubDate><guid>https://sourceforge.netbca75d5835e16b641d1930457961c0ba7b0430d9</guid></item><item><title>Error revoking certificate by EJBCA REST</title><link>https://sourceforge.net/p/ejbca/discussion/123123/thread/0fcf0bc34b/?limit=50#35a0</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;We're using the discussion forum at GitHub now.  &lt;a href="https://github.com/Keyfactor/ejbca-ce/" rel="nofollow"&gt;https://github.com/Keyfactor/ejbca-ce/&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Tomas Gustavsson</dc:creator><pubDate>Tue, 18 Nov 2025 08:09:55 -0000</pubDate><guid>https://sourceforge.net1cccd19c2a3a1e77e97ad3a00027c34abc6b1e1e</guid></item><item><title>Error revoking certificate by EJBCA REST</title><link>https://sourceforge.net/p/ejbca/discussion/123123/thread/0fcf0bc34b/?limit=25#f8b3</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;I have EJBCA 8.3.2 Community installed. I can create certificates using the REST API: v1/certificate/pkcs10enroll, and it works without problems. However, when I try to revoke a certificate with: /v1/certificate/{issuer_dn}/{certificate_serial_number}/revoke, as specified here: &lt;a href="https://docs.keyfactor.com/ejbca/latest/open-api-specification" rel="nofollow"&gt;https://docs.keyfactor.com/ejbca/latest/open-api-specification&lt;/a&gt;, the revocation doesn't work, and the EJBCA logs don't show any errors. But when I make the request, it generates a 400 error. What else do I need to do to make the revocation work? Any help would be appreciated.&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Ruben Cortes</dc:creator><pubDate>Mon, 17 Nov 2025 19:19:05 -0000</pubDate><guid>https://sourceforge.netbc6b67b5829cc8b616485c8a2aeb3a4f4a994bc0</guid></item><item><title>How can I change the Management CA Certificate Profile</title><link>https://sourceforge.net/p/ejbca/discussion/123122/thread/17e8f4a129/?limit=50#4bd4</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;The question on GitHub was the correct place to ask questions  &lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Tomas Gustavsson</dc:creator><pubDate>Tue, 08 Jul 2025 15:57:49 -0000</pubDate><guid>https://sourceforge.netb23c40512cb1329ea5c3483eb653a60cdcaf5e34</guid></item><item><title>EJBCA-CE Docker - API enabled but not working</title><link>https://sourceforge.net/p/ejbca/discussion/123123/thread/7033e7b585/?limit=25#e637</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;I have the same problem. How did u fix it? &lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Muhamed K</dc:creator><pubDate>Thu, 03 Jul 2025 12:49:40 -0000</pubDate><guid>https://sourceforge.net23830354e3c9dafaf58a684f579519a643fd429e</guid></item><item><title>Client certificate or OAuth bearer token required</title><link>https://sourceforge.net/p/ejbca/discussion/123123/thread/0623fc22ec/?limit=25#db8a</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;Hi&lt;br/&gt;
This may no longer be required, but I thought I would post it here in case there is someone that can use this and save many hours of frustration.&lt;br/&gt;
If you use 3 port separation, port 8442 is for public web and 8443 is for private web. Yes I know this may be obvious, but....&lt;br/&gt;
In setting up EJBCA-CE I assumed that all commands need to b e run as root. This is not the case. I, after trying the docs as is, decided to install EJBCA-CE as follows:&lt;br/&gt;
I created a system user called wildfly on linux with a homedir as /opt/pki&lt;br/&gt;
Assigned sudo privs to the user and then sudoed to that user and performed the installation. Apart from one or 2 commands that require sudo privs most commands do not and the installation in general runs all the way through with no issues.&lt;/p&gt;
&lt;p&gt;Have a great day&lt;br/&gt;
Kobus&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Kobus Bensch</dc:creator><pubDate>Wed, 25 Jun 2025 16:24:01 -0000</pubDate><guid>https://sourceforge.netc4d1d5e74cf61c668e3337641eb7edc20bff5e0a</guid></item><item><title>Urgent: Compatibility Issue During EJBCA Upgrade (Log4j Conflict)</title><link>https://sourceforge.net/p/ejbca/discussion/132019/thread/091d8eb9a6/?limit=50#bdf0</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;Hi Omar,&lt;/p&gt;
&lt;p&gt;That sounds like a question you should ask in the forum. For the benefit of the whole Community.&lt;br/&gt;
Unless you are a support customer, and have access to the Enterprise support system of course.&lt;/p&gt;
&lt;p&gt;Cheers,&lt;br/&gt;
Tomas&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Tomas Gustavsson</dc:creator><pubDate>Mon, 07 Apr 2025 08:29:52 -0000</pubDate><guid>https://sourceforge.netdf7aea53bdb13f4bab4a6946e2b24d6974cf102a</guid></item><item><title>Urgent: Compatibility Issue During EJBCA Upgrade (Log4j Conflict)</title><link>https://sourceforge.net/p/ejbca/discussion/132019/thread/091d8eb9a6/?limit=25#688a/79c5</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;Hi Tomas,&lt;/p&gt;
&lt;p&gt;Thank you for your response.&lt;/p&gt;
&lt;p&gt;i  found the same bug on Github :&lt;/p&gt;
&lt;p&gt;&lt;a href="https://github.com/Keyfactor/ejbca-ce/issues/821" rel="nofollow"&gt;https://github.com/Keyfactor/ejbca-ce/issues/821&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;we’d like to confirm if any of the following approaches are valid or recommended. Your input would be greatly appreciated:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Option 1 – Exclude Log4j API using Kubernetes ConfigMap&lt;/strong&gt;&lt;br/&gt;
We’re deploying EJBCA in a Kubernetes environment. One idea is to mount a volume with a custom META-INF/jboss-deployment-structure.xml file that includes:&lt;/p&gt;
&lt;p&gt;xml&lt;br/&gt;
Copier&lt;br/&gt;
Modifier&lt;br/&gt;
&amp;lt;exclusions&amp;gt;&lt;br/&gt;
    &amp;lt;module name="org.apache.logging.log4j.api"&amp;gt;&lt;br/&gt;
&amp;lt;/module&amp;gt;&amp;lt;/exclusions&amp;gt;&lt;br/&gt;
This allows us to exclude the Log4j 2 API temporarily to bypass the conflict. After the upgrade, we could remove the exclusion to restore full logging functionality.&lt;br/&gt;
Would this approach be safe, or could it cause instability or log loss during the upgrade process?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Option 2 – Upgrade in Two Steps (via 8.3.2)&lt;/strong&gt;&lt;br/&gt;
Would it be possible to first upgrade to an intermediate version like EJBCA 8.3.2, and then proceed to 9.0.0?&lt;br/&gt;
If so, does this path avoid the Log4j issue, and is it a supported upgrade method?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Option 3 – Wait for a Future Release&lt;/strong&gt;&lt;br/&gt;
We noticed that EJBCA Community 9.1.1 has been released recently.&lt;br/&gt;
Do you know if this version addresses the Log4j conflict? If not, will an upcoming release (e.g., 9.2 or 9.3) include a permanent fix?&lt;/p&gt;
&lt;p&gt;Thanks again for your time and help. Looking forward to your feedback so we can move forward safely with the upgrade.&lt;/p&gt;
&lt;p&gt;Best regards,&lt;br/&gt;
Omar Salek&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">omar salek</dc:creator><pubDate>Sat, 05 Apr 2025 11:31:04 -0000</pubDate><guid>https://sourceforge.net93b409642365c3d194e0eb3c8194ec84a500b460</guid></item><item><title>Urgent: Compatibility Issue During EJBCA Upgrade (Log4j Conflict)</title><link>https://sourceforge.net/p/ejbca/discussion/132019/thread/091d8eb9a6/?limit=50#688a</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;You can find information about this at GitHub there the forum is now located. You can find a link to GitHub Discussions on the web page. &lt;a href="https://www.ejbca.org/engage/" rel="nofollow"&gt;https://www.ejbca.org/engage/&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Tomas Gustavsson</dc:creator><pubDate>Fri, 04 Apr 2025 18:39:23 -0000</pubDate><guid>https://sourceforge.netfcdef2ddcb83f18a0d591c2b29499067782d2f1d</guid></item></channel></rss>