[xmlsec] Help to decode this error message!

Aleksey Sanin aleksey at aleksey.com
Tue Jun 12 08:58:13 PDT 2012


The code can't verify the signature on the certificate. No idea why.

Aleksey


On 6/12/12 5:54 AM, Renato Tegon Forti wrote:
> Hi I need help to decode this error msg!
> 
>  
> 
> Certs that I load:
> 
>  
> 
> /usr/lib/ssl/certs/Serasa_Certificadora_Digital_v2.pem
> 
> /usr/lib/ssl/certs/Serasa_Autoridade_Certificadora_Principal_v2.pem
> 
> /usr/lib/ssl/certs/*/Autoridade_Certificadora_Raiz_Brasileira_v2.pem/*
> 
> [ loaded cert with:  xmlSecCryptoAppKeysMngrCertLoad(mngr,
> certs[i].c_str(), xmlSecKeyDataFormatPem, xmlSecKeyDataTypeTrusted) ]
> 
>  
> 
> ubuntu at ip-10-248-26-61:/Projects/project.dokfile.vses/hades/trunk/products/doksafe/engine/libs/xmldsig/test/bin/xmldsig_test.test/gcc-4.6/debug/threading-multi$
> sudo ./xmldsig_test
> 
>  
> 
> ========================================================================
> 
> I need understand this:
> 
> ========================================================================
> 
>  
> 
> func=xmlSecOpenSSLX509StoreVerify:file=x509vfy.c:line=360:obj=x509-store:subj=X509_verify_cert:error=4:crypto
> library function failed:subj=/C=BR/O=ICP-Brasil/OU=*/Autoridade
> Certificadora Raiz Brasileira v2/*/CN=SERASA Autoridade Certificadora
> Principal v2;err=7;msg=*certificate signature failure (**à**I load it!
> Why this error?)*
> 
> func=xmlSecOpenSSLX509StoreVerify:file=x509vfy.c:line=408:obj=x509-store:subj=unknown:error=71:certificate
> verification failed:err=7;msg=*certificate signature failure (**à**Again!)*
> 
> func=xmlSecOpenSSLX509StoreVerify:file=x509vfy.c:line=360:obj=x509-store:subj=X509_verify_cert:error=4:crypto
> library function failed:subj=/C=BR/O=ICP-Brasil/OU=Autoridade
> Certificadora Raiz Brasileira v2/CN=SERASA Autoridade Certificadora
> Principal v2;err=7;msg=certificate signature failure *(**à Again!)*
> 
> func=xmlSecOpenSSLX509StoreVerify:file=x509vfy.c:line=408:obj=x509-store:subj=unknown:error=71:certificate
> verification failed:err=7;msg=certificate signature failure *(**à**Again!)*
> 
> func=xmlSecKeysMngrGetKey:file=keys.c:line=1370:obj=unknown:subj=xmlSecKeysMngrFindKey:error=1:xmlsec
> library function failed:
> 
> func=xmlSecDSigCtxProcessKeyInfoNode:file=xmldsig.c:line=871:obj=unknown:subj=unknown:error=45:key
> is not found: *(**à**What this mean?!)*
> 
> func=xmlSecDSigCtxProcessSignatureNode:file=xmldsig.c:line=565:obj=unknown:subj=xmlSecDSigCtxProcessKeyInfoNode:error=1:xmlsec
> library function failed:
> 
> func=xmlSecDSigCtxVerify:file=xmldsig.c:line=366:obj=unknown:subj=xmlSecDSigCtxSigantureProcessNode:error=1:xmlsec
> library function failed:
> 
> Error: signature verify
> 
> func=xmlSecDSigCtxDebugXmlDump:file=xmldsig.c:line=1148:obj=unknown:subj=output
> != NULL:error=100:assertion:
> 
> func=xmlSecDSigCtxDebugDump:file=xmldsig.c:line=1068:obj=unknown:subj=output
> != NULL:error=100:assertion:
> 
> xmldsig_test.cpp(435): test verify_xmldsig() == 0 failed in function:
> 'int do_test_xmlsec()'
> 
>  
> 
> **** 1 error detected
> 
>  
> 
> 
> 
> _______________________________________________
> xmlsec mailing list
> xmlsec at aleksey.com
> http://www.aleksey.com/mailman/listinfo/xmlsec
> 



More information about the xmlsec mailing list